Latest news as of 9/15/2026, 2:35:01 PM
The Register
Package dependencies can create vulnerabilities that are fiendishly hard to find and stamp out
The Register
A plethora of pwn-prevention, including a 'Patch The Planet' pledge
Bleeping Computer
An ongoing malware campaign is targeting WhatsApp users in multiple countries with deceptive messages that push VBScript files, leading to remote system access. [...]
Bleeping Computer
The JaredFromSubway Ethereum MEV (Maximal Extractable Value) bot suffered a $15 million loss after an attacker manipulated the opportunity-detection logic by creating fake cryptocurrency trading opportunities. [...]
The Register
Makers of Chrome, Edge, Firefox back bot-fraud defense called Private Access Control Tokens
Bleeping Computer
A newly disclosed FFmpeg flaw dubbed 'PixelSmash' could be exploited for remote code execution on Jellyfin servers under certain conditions, and can also trigger a denial-of-service condition in applications like Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio. [...]
The Register
Makers of Chrome, Edge, Firefox back bot-fraud defense called Private Access Control Tokens
Bleeping Computer
Security firm SOCRadar says the large-scale FortiBleed campaign targeting Fortinet FortiGate devices used custom sniffers to harvest authentication secrets from compromised firewalls and steal credentials. [...]
The Register
As yet another extortion crew Icarus exploits Salesforce-linked integrations
The Hacker News
Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official release channels and push backdoor code. "Attackers compromised the vendor's build and distribution pipeline, injecting backdoor code into Pro plugin releases distributed through official licensed update channels," Wordfence said in an analysis