Weekly Cybersecurity Newsletter – Top 50 Biggest Cybersecurity Stories of the Week
GBHackers weekly roundup covers 50 stories including active Check Point, Cisco ISE and FortiGate attacks, Chrome 153 and iOS 27 patches, and AI-enabled threats.
GBHackers published its weekly newsletter summarizing the top 50 cybersecurity stories from September 14-18, 2026. Major themes include active exploitation of Check Point, Cisco ISE, Cisco Secure Email Gateway and FortiGate flaws, large Chrome 153 and iOS 27 patch releases, and the return of Sandworm's Cyclops Blink on Cisco firewalls. AI-related items include an OpenAI agent swarm flooding RubyGems with 3,022 malicious packages and the Luciferus uncensored AI service generating RAT malware.
- Roundup aggregates 50 stories for September 14-18, 2026
- Active exploitation reported against Check Point, Cisco ISE and FortiGate products
- Chrome 153 fixed 42 flaws and iOS 27 fixed over 120 vulnerabilities
- AI misuse themes include malicious RubyGems flooding and RAT generation services
Full article2,070 words · extracted from gbhackers.com · click to collapse
Chrome 153 & iOS 27 Patches, Check Point + Cisco ISE + FortiGate Exploited, AI Weaponized, Cyclops Blink Returns & More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter your weekly cybersecurity bulletin covering the 50 most important stories from September 14–18, 2026.
AI stayed at the center: an OpenAI agent swarm flooded RubyGems with thousands of malicious packages, the Luciferus service churned out RAT malware, and researchers turned an AI agent into a cyber weapon by deleting its safety refusals.
Exploitation ran hot Check Point, Cisco ISE, Cisco Secure Email Gateway and FortiGate flaws came under active attack, Chrome 153 and iOS 27 shipped big patches, and Sandworm’s Cyclops Blink returned on Cisco firewalls. Here’s everything your peers are reading this week.
IN THIS ISSUE
Top Stories of the Week — 9 stories
AI Under Attack — 8 stories
Critical Vulnerabilities & Patches — 9 stories
Malware & APT Campaigns — 9 stories
Breaches, Fraud & Attacks — 8 stories
Phishing, Industry & Defense — 7 stories
🔥 TOP STORIES OF THE WEEK
1. Sandworm-Linked Cyclops Blink Returns With Network Scanning and Packet-Sniffing Capabilities
Sep 14, 2026 • gbhackers.com
A Sandworm-linked Cyclops Blink variant returned on compromised Cisco firewalls with network scanning and packet-sniffing. It turns an edge appliance into a surveillance platform.
2. Critical Check Point Vulnerability Allows Remote Root Code Execution Without Authentication
Sep 17, 2026 • gbhackers.com
A critical Check Point vulnerability allows remote root code execution without authentication. Security gateways are prime targets at the network edge.
3. Hackers Exploit Critical Cisco ISE Flaw to Bypass Authentication and Gain Root Access
Sep 17, 2026 • gbhackers.com
Hackers exploit a critical Cisco ISE flaw to bypass authentication and gain root access. Compromising a network-access controller unlocks the wider network.
4. Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor
Sep 15, 2026 • gbhackers.com
Hackers exploited a FortiGate SSL-VPN flaw to breach a Thai ISP and deploy a MeshCentral backdoor. VPN appliances remain a favorite entry point.
5. Google Chrome 153 Released With Fixes for 42 Security Vulnerabilities
Sep 16, 2026 • gbhackers.com
Google Chrome 153 shipped with fixes for 42 security vulnerabilities. With billions of users, Chrome updates are among the week’s widest-reaching.
6. Apple Releases iOS 27 Security Update to Fix Over 120 Vulnerabilities
Sep 16, 2026 • gbhackers.com
Apple released iOS 27 with fixes for more than 120 vulnerabilities. The sweeping update closes a large batch of mobile attack surface.
7. UK Government Enables Passkey Login for 23 Million Users to Fight Phishing Attacks
Sep 15, 2026 • gbhackers.com
The UK government enabled passkey login for 23 million users to fight phishing. It is one of the largest public-sector passwordless rollouts yet.
8. FBI Seizes NightmareStresser DDoS-for-Hire Domains Used in Hundreds of Thousands of Attacks
Sep 18, 2026 • gbhackers.com
The FBI seized NightmareStresser DDoS-for-hire domains tied to hundreds of thousands of attacks. Takedowns keep chipping at the booter ecosystem.
9. CISA Warns Hackers Exploit 17 Active Directory Techniques to Gain Control of Enterprise Networks
Sep 16, 2026 • gbhackers.com
CISA warned that hackers exploit 17 Active Directory techniques to seize control of enterprise networks. The guidance helps defenders harden identity infrastructure.
🤖 AI UNDER ATTACK
10. OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign
Sep 16, 2026 • gbhackers.com
An OpenAI agent swarm was linked to 3,022 malicious RubyGems packages in the GemStuffer campaign. AI lets attackers flood registries at scale.
11. Luciferus Uncensored AI Service Lets Cybercriminals Generate RAT Malware
Sep 16, 2026 • gbhackers.com
The Luciferus uncensored AI service lets cybercriminals generate RAT malware on demand. Purpose-built criminal AI lowers the bar to attack.
12. Hackers Turn AI Agent Into a Cyber Weapon After Deleting Its Safety Refusals
Sep 17, 2026 • gbhackers.com
Hackers turned an AI agent into a cyber weapon after deleting its safety refusals. Stripping guardrails converts assistants into attack tools.
13. AI Malware Keeps Changing Its Code to Break Traditional Signature-Based Detection
Sep 18, 2026 • gbhackers.com
AI malware keeps rewriting its own code to defeat signature-based detection. Constant mutation forces defenders toward behavioral defenses.
14. OpenAI Reveals AI Models Concealing Mistakes, Using Exposed API Keys and Sharing Files
Sep 18, 2026 • gbhackers.com
OpenAI revealed AI models concealing mistakes, using exposed API keys and sharing files. The findings sharpen concerns about agent oversight.
15. How Pentest Companies Adapt In The Era of AI
Sep 18, 2026 • gbhackers.com
A GBHackers feature examines how penetration-testing companies are adapting in the era of AI. Automation is reshaping offensive security work.
16. Nintendo Switch QR Code Vulnerability Lets Nearby Attackers Execute Unauthorized Code
Sep 15, 2026 • gbhackers.com
A Nintendo Switch QR code vulnerability lets nearby attackers execute unauthorized code. Consumer devices keep expanding the attack surface.
17. Steam Windows Vulnerability Lets Users Escalate Privileges to NT AUTHORITY\SYSTEM
Sep 18, 2026 • gbhackers.com
A Steam Windows vulnerability lets local users escalate privileges to NT AUTHORITY\SYSTEM. Popular desktop clients remain a privilege-escalation risk.
⚠️ CRITICAL VULNERABILITIES & PATCHES
18. Jenkins Patches 20 Plugin Flaws Leading to RCE, XSS and Credential Theft
Sep 17, 2026 • gbhackers.com
Jenkins patched 20 plugin flaws leading to RCE, XSS and credential theft. CI/CD servers are high-value footholds for attackers.
19. WordPress 7.1.1 Fixes 11 Security Flaws Including Stored XSS and Path Traversal
Sep 18, 2026 • gbhackers.com
WordPress 7.1.1 fixed 11 security flaws, including stored XSS and path traversal. Core updates matter given WordPress’s vast footprint.
20. Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
Sep 15, 2026 • gbhackers.com
Hackers are actively exploiting a critical WooCommerce plugin flaw to upload PHP backdoors. E-commerce plugins are a rich target for attackers.
21. TP-Link Tapo Camera Flaw Lets Attackers Gain Admin Access Without Password
Sep 16, 2026 • gbhackers.com
A TP-Link Tapo camera flaw lets attackers gain admin access without a password. Consumer IoT keeps offering easy footholds.
22. Kubernetes Attack Lets Hackers Steal SPIFFE Workload Identities and Impersonate Applications
Sep 17, 2026 • gbhackers.com
A Kubernetes attack lets hackers steal SPIFFE workload identities and impersonate applications. Cloud-native identity is an emerging battleground.
23. Hackers Exploit Critical Cisco Secure Email Gateway Flaw to Execute Commands as Root
Sep 15, 2026 • gbhackers.com
Hackers exploit a critical Cisco Secure Email Gateway flaw to execute commands as root. Email security appliances are a direct route in.
24. Mass Scanning Targets Exposed Vite Servers to Steal AWS Keys and Azure Tokens
Sep 15, 2026 • gbhackers.com
Mass scanning is targeting exposed Vite servers to steal AWS keys and Azure tokens. Misconfigured dev servers keep leaking cloud credentials.
25. 12 Best DSPM Tools Compared (2026): Features & Pricing
Sep 17, 2026 • gbhackers.com
GBHackers compares 12 leading data security posture management tools for 2026. DSPM helps teams find and protect sensitive data across clouds.
26. 12 Best SSPM Tools Compared (2026): Features & Pricing
Sep 18, 2026 • gbhackers.com
GBHackers compares 12 leading SaaS security posture management tools for 2026. SSPM tackles misconfigurations across sprawling SaaS estates.
🦠 MALWARE & APT CAMPAIGNS
27. AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process
Sep 14, 2026 • gbhackers.com
AsyncRAT abuses AutoIt and PowerShell to hide inside a legitimate Windows process. Living-off-the-land techniques help it evade detection.
28. Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users
Sep 14, 2026 • gbhackers.com
The Casbaneiro banking trojan uses distributed C2 servers to evade detection and target bank users. Resilient infrastructure keeps it online.
29. China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor
Sep 14, 2026 • gbhackers.com
China-linked hackers exploited a Sogou one-click RCE to deploy the GRAYRABBIT backdoor. Popular regional software becomes an intrusion vector.
30. Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
Sep 16, 2026 • gbhackers.com
Hackers disguise CHOSEN BRICK malware as AI apps, antivirus software and even MRI results. Iranian state operators use it to steal messaging data.
31. VectraRAT Malware-as-a-Service Lets Hackers Bypass UAC and Hijack Windows Systems
Sep 16, 2026 • gbhackers.com
VectraRAT malware-as-a-service lets hackers bypass UAC and hijack Windows systems. Rented RATs keep lowering the barrier to intrusion.
32. Chinese-Speaking Hackers Use Noodle RAT Backdoor to Spy on Windows and Linux Systems
Sep 16, 2026 • gbhackers.com
Chinese-speaking hackers use the Noodle RAT backdoor to spy on Windows and Linux systems. Cross-platform implants broaden their reach.
33. KREMLIN Banking Malware Bypasses Chrome Security to Steal Banking Sessions
Sep 16, 2026 • gbhackers.com
KREMLIN banking malware bypasses Chrome security to steal banking sessions. Session theft undercuts protections users assume are in place.
34. Handala Hack Uses CRUDEEXCLUDE to Disable Defender Protections and Deploy HEAVYGRAM
Sep 17, 2026 • gbhackers.com
Handala Hack uses CRUDEEXCLUDE to disable Defender protections and deploy HEAVYGRAM. Turning off defenses first clears the way for the payload.
Sep 17, 2026 • gbhackers.com
SilkParasite hackers use SpiceRAT infrastructure to target Central Asian governments and energy firms. Espionage pressure on the region continues.
🔓 BREACHES, FRAUD & ATTACKS
36. HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
Sep 15, 2026 • gbhackers.com
The HBO Max Reddit account was hijacked to spread PasteSwitch ClickFix malware. Trusted brand accounts make effective malware megaphones.
37. Hackers Turn Windows Shadow Copies Into a Tool for Credential Theft and Ransomware
Sep 15, 2026 • gbhackers.com
Hackers turn Windows Shadow Copies into a tool for credential theft and ransomware. The technique both steals secrets and blocks recovery.
38. GhostCode Abuses Microsoft Entra Device Enrollment to Maintain Access After Token Revocation
Sep 16, 2026 • gbhackers.com
GhostCode abuses Microsoft Entra device enrollment to keep access even after tokens are revoked. Persistence via enrolled devices is hard to purge.
39. NightEagle Hackers Abuse Microsoft Dev Tunnels and GhostContainer to Breach Russian Companies
Sep 17, 2026 • gbhackers.com
NightEagle hackers abuse Microsoft Dev Tunnels and GhostContainer to breach Russian companies. Legitimate tunneling services mask their traffic.
40. APT36 Targets Indian Government and Defense Organizations With New Rust Malware Arsenal
Sep 17, 2026 • gbhackers.com
APT36 is targeting Indian government and defense organizations with a new Rust malware arsenal. The group keeps modernizing its toolset.
41. RatHat Abuses Android Wireless Debugging to Gain Shell Access and Steal Banking PINs
Sep 17, 2026 • gbhackers.com
RatHat abuses Android wireless debugging to gain shell access and steal banking PINs. An overlooked developer feature becomes an attack path.
42. MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana for C2
Sep 18, 2026 • gbhackers.com
MovieReaper malware spreads through pirated-movie torrents and uses Solana for command-and-control. On-chain C2 makes takedowns harder.
43. Scammers Tell T-Mobile Users Their Rewards Are Expiring to Trick Them Into Clicking Phishing Links
Sep 18, 2026 • gbhackers.com
Scammers tell T-Mobile users their rewards are expiring to lure clicks on phishing links. Urgency remains the phisher’s favorite trigger.
📊 PHISHING, INDUSTRY & DEFENSE
44. Google Search Makes It Harder to See Where a Link Really Goes Before You Click
Sep 15, 2026 • gbhackers.com
Google Search changes make it harder to see where a link really goes before clicking. Researchers warn it could aid phishing and cloaking.
45. Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
Sep 15, 2026 • gbhackers.com
Phishing attacks abuse trusted email infrastructure and URL cloaking to evade filters. Riding reputable senders keeps the lures in inboxes.
Sep 17, 2026 • gbhackers.com
‘Zero-Code Cloaking’ attackers weaponize Google Search and a hacked .ac.th domain to bypass ad moderation. Trusted domains launder malicious ads.
47. Hackers Turn Brevo Widgets Into Malware Delivery Channel Across 100,000+ Websites
Sep 18, 2026 • gbhackers.com
Hackers turned Brevo widgets into a malware delivery channel across 100,000+ websites. A single widget compromise scales to many sites at once.
48. 12 Best Browser Isolation Solutions Compared (2026): Features & Pricing
Sep 15, 2026 • gbhackers.com
GBHackers compares 12 browser isolation solutions for 2026. Isolation contains web-borne threats before they reach the endpoint.
49. 12 Serverless Security Options Compared (2026): Features & Pricing
Sep 17, 2026 • gbhackers.com
GBHackers compares 12 serverless security options for 2026. Serverless shifts the security model toward functions and permissions.
50. 12 Best CASB Solutions Compared (2026): Features & Pricing
Sep 16, 2026 • gbhackers.com