Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Microsoft: September updates break File History backup feature

    September 21, 2026

    InfoSec News Nuggets – 09/21/2026 – AboutDFIR

    September 21, 2026

    A Phone Call Can Now Spread a Zero-Click Worm | Threat Wire

    September 21, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»InfoSec News Nuggets – 09/21/2026 – AboutDFIR
    News

    InfoSec News Nuggets – 09/21/2026 – AboutDFIR

    adminBy adminSeptember 21, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Gyazo server flaw exploited to steal 23.6 million user records

    The cloud-based screenshot platform Gyazo, operated by Helpfeel, confirmed that attackers exploited a server vulnerability on September 11 to access its database and steal roughly 23.6 million user records, including names, emails, password hashes, device and session IDs, and some connected-account tokens, along with 490 million image metadata records tied mostly to pre-2019 uploads. The company took the service offline for maintenance, patched the flaw, and is notifying affected users while urging them to change reused passwords.

     

    Critical Orkes Conductor Vulnerability Exploited in Attacks

    A critical, unauthenticated remote code execution flaw in the open-source workflow orchestration platform Orkes Conductor, tracked as CVE-2026-58138 with a CVSS score of 9.8, has been under active exploitation for at least a month, letting attackers submit malicious inline workflow definitions that execute arbitrary system commands, often with root privileges. Although a fix shipped in June, proof-of-concept code published in August accelerated attacks, and one vendor blocked roughly 1,300 exploitation attempts in a single week, prompting renewed calls to patch and keep Conductor instances off the public internet.

     

    SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

    SolarWinds shipped an update for Access Rights Manager after disclosing CVE-2026-28326, an 8.8-severity flaw caused by a hard-coded static key that could let an unauthenticated attacker achieve remote code execution on all ARM versions through 2026.2. The issue, credited to a researcher at Armadin, has been fixed in ARM 2026.2.1, and the vendor said it has no evidence of in-the-wild exploitation, though the disclosure follows other recent fixes for SAML bypass and denial-of-service bugs across the company’s product line.

     

    Job hunting? North Korean fake recruiters infected 30,000 devices

    A joint advisory from Japanese, US, Australian, and German authorities details how the North Korean group WaterPlum, also known as Contagious Interview, infected more than 30,000 devices across over 100 countries by posing as recruiters and instructing job seekers to run malicious code during fake technical interviews. The campaign compromised more than 7,000 cryptocurrency wallets and funneled at least $10.71 million to North Korea, and investigators say they dismantled a laptop farm in Japan that helped operate the scheme.

     

    Critical Check Point Management Flaw Allows Unauthenticated Remote Root Access

    Check Point patched a critical stack-based buffer overflow, CVE-2026-91843 with a CVSS score of 9.8, in its Security Management and Log Servers that lets an unauthenticated remote attacker send an oversized username during login to gain root-level code execution. The flaw affects several supported release branches, and with thousands of internet-facing instances still showing the default server identity, administrators are urged to apply the LivePatch fix issued on September 16, restrict management access to known IPs, and watch logs for oversized-username login attempts.

     



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleA Phone Call Can Now Spread a Zero-Click Worm | Threat Wire
    Next Article Microsoft: September updates break File History backup feature
    admin
    • Website

    Related Posts

    News

    Microsoft: September updates break File History backup feature

    September 21, 2026
    News

    Microsoft fixes broken copy and paste for Excel 2016 users

    September 20, 2026
    News

    Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts

    September 20, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202679 Views

    How fraudsters target credit unions

    May 4, 202644 Views

    IP Address Investigations and Local OSINT

    March 20, 202641 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202679 Views

    How fraudsters target credit unions

    May 4, 202644 Views

    IP Address Investigations and Local OSINT

    March 20, 202641 Views
    Our Picks

    Microsoft: September updates break File History backup feature

    September 21, 2026

    InfoSec News Nuggets – 09/21/2026 – AboutDFIR

    September 21, 2026

    A Phone Call Can Now Spread a Zero-Click Worm | Threat Wire

    September 21, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.