Archive of

WordPress CVE-2026-87902 now exploited for code execution

Attackers have moved beyond scanning for WordPress sites vulnerable to CVE-2026-87902. They are now exploiting the flaw to plant files that run shell commands when they are accessed, according to WordPress security firm Patchstack.

The vulnerability was fixed in WordPress 7.1.2. Scanning began less than five hours after that release. Since then, malicious traffic has grown tenfold, and attackers are now trying to deliver payloads.

Patchstack says it saw the first malicious requests at 17:44 UTC on September 22. They came from a small group of IP addresses and targeted several sites under the company's protection.

A path traversal bug with a critical rating

Read More


File notification APIs leak user activity across major OSes

Researchers at Graz University of Technology in Austria have shown that the file-change notification features in Linux, Android, Windows and macOS can be used to spy on other users of the same system. The information exposed ranges from the rhythm of someone's typing to the websites they visit.

All four operating systems let applications ask to be told when files are created, modified or deleted. Text editors, file managers, sync clients and antivirus tools rely on this. It needs no elevated privileges, only read access to the watched location.

The attacks never reveal what is inside a file. The researchers found that file names and the timing of events are enough to piece together what users, applications and the system are doing. Most scenarios assume an attacker who can already run code on the machine under a separate account. On Android, that attacker could be an app that asks for no permissions at all.

Read More


Carbonato malware uses AI agents to hijack Docker hosts

A newly discovered botnet called Carbonato is breaking into poorly secured Docker hosts and installing the Hermes Agent AI framework, which then carries out the operators' orders on compromised machines, according to ThreatDown.

The enterprise security company found the malware in an unauthenticated Docker registry that held nearly 60 repositories and 4.3 GB of image data. The operational evidence recovered from it covers the period from October 2024 to August 2026. The archive also held details on a separate campaign that pushed counterfeit cryptocurrency wallet apps, a lure that has recently shown up in Mac-focused stealer campaigns as well.

Read More


Salt Typhoon prompts bill for voluntary telecom cyber rules

Two US senators from opposite parties want the telecommunications industry to follow a common set of cybersecurity best practices. Adoption would be voluntary, and there would be an optional certification for companies that can show they follow them.

Sens. Mark Warner (D-VA) and Ted Cruz (R-TX) introduced the Telecommunications Cybersecurity and Resilience Act on Thursday. They pointed to the Salt Typhoon campaign, in which Chinese hackers broke into nearly all of the major US telecom providers over several years.

“The Salt Typhoon intrusion was the worst telecom hack in our nation’s history and showed us just how vulnerable our critical infrastructure is, but it does not have to be that way,” Warner said. “If telecommunications companies adopt cybersecurity best practices, our networks can be more resilient.”

Read More


RemControl Android banking malware hits Europe and Canada

A newly discovered Android malware-as-a-service (MaaS) platform called RemControl is going after banking customers in Europe, Canada and the Middle East. According to Group-IB, the malware spreads through malvertising campaigns that impersonate TVTap, an IPTV streaming app.

Researchers say the infrastructure behind RemControl has been running since at least May. The first samples appeared in July and already carried more than 30 phishing overlays built to capture banking credentials. Targeted countries include Italy, France, Spain, Poland and Portugal, as well as Canada and several Middle Eastern states.

Fake Google Play pages and ad-driven traffic

Victims land on fake Google Play pages that pose as the TVTap download. At least one Italian campaign used geofencing and checked mobile User-Agent strings, so only visitors who matched the intended profile would see the malicious content.

Read More