2026-09-06
Population: stories the tracker first saw on this Coordinated Universal Time (UTC) calendar day; publisher date is used only if first-tracked time is unavailable and remains on each item.
- threat intel
Attackers conceal phishing lures using invisible Unicode characters
Threat actors are using invisible Unicode characters through ASCII smuggling techniques to conceal phishing lures and bypass email security filters. This method allows malicious content to evade detection while appearing legitimate to recipients. The technique represents an evolving evasion strategy in phishing campaigns.
Why it matters: Security teams and email administrators need to review filter configurations and user awareness training, as invisible character obfuscation can slip past existing defenses designed to catch phishing attempts.
- breaches incidents
NYS Comptroller DiNapoli releases more municipal cybersecurity audits
New York State Comptroller DiNapoli released municipal cybersecurity audits, including one for the Town of Wilton covering January 1, 2024 through August 8, 2025. The public audit versions examined cybersecurity posture at local government entities.
Why it matters: Municipal IT leaders and local government officials should review these audits to identify common cybersecurity gaps and remediation practices applicable to their own organizations.
- breaches incidents
Natural Resources Wales confirms data breach due to human error
Natural Resources Wales exposed sensitive employee data through an inadvertently published spreadsheet on its website. The breach disclosed personal information including ethnicity, disability status, religion, sexual orientation, and caring responsibilities for current and former staff members.
Why it matters: Current and former Natural Resources Wales employees should monitor for potential misuse of their sensitive personal data; HR and compliance teams must audit data handling practices and review access controls for published materials.
- vulnerabilities
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
Attackers are exploiting MikroTik routers with internet-exposed Secure Shell (SSH) services to achieve unauthenticated administrative access, according to CERT Polska. Active exploitation began by at least September 2, 2026.
Why it matters: Organizations running MikroTik routers with SSH exposed to the internet risk immediate compromise and full device takeover; audit network perimeter access and disable SSH exposure or enforce authentication.
- threat intel
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Elastic Security Labs identified four previously undocumented programs linked to REVSTEALER, a Windows information stealer, that persist on infected systems after the stealer removes itself. One of these programs disables Windows Update and Microsoft Defender to deploy a cryptocurrency miner. The malware uses multiple modules to establish persistence and evade security controls.
Why it matters: Windows users running systems with REVSTEALER infections face active cryptocurrency mining and disabled security updates, requiring immediate detection and remediation to prevent continued resource loss and exposure to additional threats.
- vulnerabilities
Week in review: Claude accounts compromised through infostealer, Patch Tuesday forecast
Anthropic has begun locking out Claude users whose login sessions were compromised by infostealer malware. September 2026 Patch Tuesday is forecast to continue record-high volumes of security patches and CVE disclosures.
Why it matters: Anthropic Claude users need to verify their account access and consider session security; security teams should prepare for elevated patching workload during Patch Tuesday.
Grouped: similar headlines.
- vulnerabilities
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Attackers exploit an unpatched zero-day vulnerability in Magento Open Source and Adobe Commerce to execute malicious code on e-commerce servers without authentication, according to Sansec. The flaw, dubbed StyleSmuggler, was under active exploitation as of September 4, 2026.
Why it matters: Online retailers running Magento or Adobe Commerce face immediate risk of server compromise and backdoor installation; patch status and indicators of compromise are critical to check today.
Grouped: similar headlines.
- threat intel
BengalSEO Part 1: Anatomy of the Operation
On March 2026, a security investigation documented an search engine optimization (SEO) poisoning campaign that delivered malware to users. The report provides analysis of the operation's structure and attack chain.
Why it matters: Organizations and users relying on search engines for legitimate software or resources face redirection to malicious payloads through SEO poisoning; defenders need to understand the tactics to identify and block similar campaigns.