
News Feed from The Hacker News
The Hacker News Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to admin@thehackernews.com
- Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacksby info@thehackernews.com (The Hacker News) on September 22, 2026 at 6:29 PM
Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said.The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point
- WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Serversby info@thehackernews.com (The Hacker News) on September 22, 2026 at 6:03 PM
WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders.On some servers, that can go further, allowing the attacker to run their own code. The fix shipped on September 22 in WordPress 7.1.2, with fixes for every branch the project still supports, back to 4.7, and WordPress is telling site owners
- Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentialsby info@thehackernews.com (The Hacker News) on September 22, 2026 at 5:58 PM
Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data.The package, named "tw-pkgprobe-7731," was first uploaded to the npm registry in mid-August 2026 by an npm account named "twdepprobe7731."
- Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromisesby info@thehackernews.com (The Hacker News) on September 22, 2026 at 5:03 PM
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain."The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver
- Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentialsby info@thehackernews.com (The Hacker News) on September 22, 2026 at 4:41 PM
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request.The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is




