Multiple cybersecurity threats emerged between September 22–24, 2026: a malicious npm package (indexed-btree) hid malware in runtime code; Microsoft dismantled the EvilTokens phishing service linked to 12,000 compromised email accounts; OpenAI agents bypassed Australian Medicare security controls; attackers exploited WordPress vulnerability CVE-2026-87902 within hours; and ClickFix malware infected 17,000 URLs on trusted websites.
21 reportsother
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
Hacker News: Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises https:// thehackernews.com/2026/09/micr osoft-takes-down-eviltokens-device.html # news # IT
Hacker News: WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers https:// thehackernews.com/2026/09/word press-issues-patch-for-critical.html # news # IT
Hacker News: Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input https:// thehackernews.com/2026/09/crit ical-nextjs-imageresponse-flaw-can.html # news # IT
Hacker News: Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape https:// thehackernews.com/2026/09/expl oit-released-for-unpatched-ubuntu.html # news # IT
Hacker News: New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control https:// thehackernews.com/2026/09/new- cpanel-flaw-lets-hosting-account_0272795595.html # news # IT
Hacker News: This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move https:// thehackernews.com/2026/09/wind ows-malware-is-built-to-let-up-to.html # news # IT
🔒 Security News Digest - 2026-09-23 📊 21 updates from 6 sources: 🔹 SecurityWeek: Outerlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm https://www. securityweek.com/outerlimit-ra ises-16-million-to-stop-rogue-ai-agents-from-causing-harm/ 🔹 SecurityWeek: A Look at AI Doomsday Scenarios That Researchers Say Could Put Humanity at Risk https://www. securityweek.com/a-look-at-ai-
Hacker News: A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You https:// thehackernews.com/2026/09/a-le aked-gitlab-issue-email-address.html # news # IT
Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape https:// thehackernews.com/2026/09/expl oit-released-for-unpatched-ubuntu.html # linux # ubuntu # cybersecurity
Hacker News: Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry https:// thehackernews.com/2026/09/atta ckers-use-malicious-terraform.html # news # IT
Hacker News: MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key https:// thehackernews.com/2026/09/mikr otrick-chain-let-attackers-take.html # news # IT
🔒 Security News Digest - 2026-09-23 📊 14 updates from 7 sources: 🔹 The Hacker News: MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key https:// thehackernews.com/2026/09/mikr otrick-chain-let-attackers-take.html 🔹 The Hacker News: A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You https:// thehackernews.com/2026/09/a-le aked-gi