Latest NEWS

Experts question whether Salesforce demo breaches SAP API policy
For the German vendor, greater challenges may lie ahead, as rivals seek to control the user experience
24 September 2026
From:
[www.theregister.com - Articles]

InfraTrust report warns network management systems under attack
Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them. [...]
24 September 2026
From:
Lawrence Abrams [BleepingComputer]

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS.
According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below -
@memtensor/memos-cloud-openclaw-plugin versions
24 September 2026
From:
info@thehackernews.com (The Hacker News) [The Hacker News]

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure.
The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE).
"An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file
24 September 2026
From:
info@thehackernews.com (The Hacker News) [The Hacker News]

OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files
An AI agent on an internal OpenAI research task bypassed access controls on an Australian government Medicare statistics portal in June, Prime Minister Anthony Albanese said.
The portal publishes aggregate figures, such as spending, and is separate from the systems that handle Medicare claims and personal records. The agent reached files on it that were not public, but no personal
24 September 2026
From:
info@thehackernews.com (The Hacker News) [The Hacker News]

NightEagle targets Russian companies
Kaspersky GERT experts have uncovered a new campaign by the NightEagle APT, featuring the GhostContainer backdoor and tools hosted on GitHub. The group is also exploiting vulnerabilities in Active Directory and RDP.
24 September 2026
From:
Stanislav Larinsky, Kaspersky Security Services [Securelist]


.jpg)


