Cybersecurity
Cyberattacks, vulnerabilities, data breaches, ransomware, threat intelligence and security responses.
lite.news is a news feed and wire service for publishers and platforms. Below is a live sample of our continuously updated reporting. Learn more about accessing and reusing our reporting | Get News Feeds
-
WordPress Releases Emergency Patch for Critical wp2shell Vulnerability
WordPress released version 7.0.2 on July 17, 2026, to address a critical vulnerability allowing remote code execution, according to security reports.
-
BigDiskBuster Tool Blocks Microsoft Defender Updates, No Patch Issued
A tool released on September 21, 2026, prevents updates for Microsoft Defender Antivirus, according to reports. No patch has been issued.
-
RemControl Android Malware Platform Disclosed Targeting Multiple Regions
Group-IB reported RemControl, an Android malware targeting users in Europe, Canada, and the Middle East through fraudulent Google Play apps.
-
F5 Reports Active Exploitation of BIG-IP Zero-Day Vulnerability
F5 issued a security advisory on September 22, 2026, confirming active exploitation of a critical BIG-IP vulnerability allowing remote code execution.
-
South African Pension Fund Systems Restored After Ransomware Attack
A ransomware attack on GPAA systems accessed 168,000 records. Full restoration was completed by June 21, 2024, according to agency statements.
-
Check Point Releases Emergency Fix After Zero-Day Attacks on Management Server
Check Point issued emergency hotfixes on September 22, 2026, for a critical vulnerability (CVE-2026-93616) affecting its Management Server.
-
KISA Expands AI-Driven Cybersecurity and Vulnerability Management
KISA is enhancing national cybersecurity through AI and big data for vulnerability management, promoting security product commercialization, according to reports.
-
UK Cyber Security Bill Proposes Stricter Reporting and Wider Scope
A filing describes the Cyber Security and Resilience Bill introduced in November 2025, according to official documents. It mandates 24-hour reporting.
-
CISA Adds Three Actively Exploited Linux Kernel Flaws to KEV Catalog
CISA added three high-risk Linux kernel vulnerabilities to its KEV catalog. Agencies must patch these flaws by September 21, 2026, according to reports.
-
BigCommerce Confirms Data Breach Linked to Ribon App Credentials
A statement details a data breach involving Ribon app credentials, according to reports. Customer data was accessed from merchant storefronts.
-
Swiss Court Sentences Ransomware Developer and Plugin4Shell Flaw Disclosed
A Ukrainian ransomware developer received a 12-year sentence, according to court documents. A vulnerability related to Plugin4Shell was also disclosed.
-
AI Chatbots and Agents Highlight Widespread Security Gaps
AI agents have breached systems like Hugging Face, highlighting security flaws in frameworks, according to researchers. Vulnerabilities were automated.
-
Cyber Resilience Act Sets New Reporting Rules for Manufacturers
Manufacturers must report cybersecurity incidents starting September 2026, according to the Cyber Resilience Act and ENISA's Single Reporting Platform.
-
Ransomware Guidance Urges Boards To Address Full Attack Chain
Microsoft's ransomware guidance stresses that boards must address vulnerabilities throughout the entire attack process, according to reports.
-
Ransomware Attacks on Manufacturers Rise Sharply in 2026
Manufacturing represented 22% of ransomware victims in 2026, with attacks increasing nearly 40%, according to published data.
-
WooCommerce Wholesale Lead Capture Plugin Exploited in File Upload Attacks
A vulnerability in the WooCommerce Wholesale Lead Capture plugin allowed file uploads. Over 100,000 exploitation attempts were blocked, according to Wordfence.
-
RatHat AI Malware Discovered Targeting Android Devices
Zimperium's zLabs discovered RatHat, an AI-driven Android malware that captures credentials and prevents removal, according to security researchers.
-
NIST and CISA Publish Final Guidance on Protecting Identity Tokens
A report outlines token security recommendations, including key management, issued by the regulator on September 15, 2026, according to the agency.
-
KREMLIN Malware Bypasses Browser Protections to Target Brazilian Banks
KREMLIN malware targets Brazilian banks by installing unauthorized browser extensions on over 1,500 systems, according to Elastic Security Labs.
-
TP-Link Tapo C200 Security Camera Vulnerabilities Patched
Two vulnerabilities in TP-Link Tapo C200 cameras were patched with firmware update V5_1.4.6 on August 18, 2026, according to company reports.