ZCyberNews — Cybersecurity & Tech Intelligence
Mirage Kitten Deploys Node.js, JavaScript RATs in Aviation, FinTech
Mirage Kitten targets aviation and FinTech sectors across the Middle East and Africa with NodeRabbit and PollCat RATs, delivered via trojanized coding challenges on LinkedIn.
See more updates →6 min read
Florida DMV Breach Tied to ShinyHunters, Stolen Officer Credentials
ShinyHunters breached the Florida DMV after a Plant City officer's login sat on a personal device. The state confirmed the claim on September 10 after days of silence.
CVE-2026-20079
CISA Adds Cisco CVE-2026-20079 With Perfect 10.0 Score to KEV
CVSS 10.0 · government, federal civilian executive branch
CISA's KEV catalog now lists CVE-2026-20079, a CVSS 10.0 authentication bypass in Cisco software, alongside exploited Citrix and Fortinet flaws. Federal patch deadline: Sept. 12.
Read →More from today
See all →- 1dAI SecurityAnthropic Disrupts APT29 Spies Abusing Claude in 20+ Hacks
- 1dVulnerabilitiesCISA Flags CVE-2026-42016 in JFrog Artifactory as Exploited
- 2dMalwareSPIFFE/SPIRE Identity Spoofing: Root on K8s Node Harvests SVIDs
- 3dVulnerabilitiesMicrosoft Patches 964 Flaws, Two Zero-Days Exploited in Wild
- 5dMalwareBerlin Probes New Data Leak After Hackers Post Login Credentials
Threat Intel

Mirage Kitten Deploys Node.js, JavaScript RATs in Aviation, FinTech
Mirage Kitten targets aviation and FinTech sectors across the Middle East and Africa with NodeRabbit and PollCat RATs, delivered via trojanized coding challenges on LinkedIn.
HelloNet Campaign Hijacks ViPNet Update System to Deploy Malicious
Kaspersky details HelloNet APT campaign targeting Russian government, energy, and transport sectors via ViPNet update system DLL sideloading since May 2026.
Cavern Manticore: Iran-Linked Modular C2 Framework Exposed
Check Point Research tracks Cavern Manticore, an Iran MOIS-linked APT targeting Israeli govt and IT sectors with a modular .NET C2 framework.
Vulnerabilities
—
informational
CISA Flags CVE-2026-42016 in JFrog Artifactory as Exploited
CVE-2026-42016
10.0
critical
CISA Adds Cisco CVE-2026-20079 With Perfect 10.0 Score to KEV
CVE-2026-20079
7.8
high
Microsoft Patches 964 Flaws, Two Zero-Days Exploited in Wild
CVE-2026-81963
Malware
Spiffe
MALWARE
SPIFFE/SPIRE Identity Spoofing: Root on K8s Node Harvests SVIDs
Sep 10 · —
Rhysida
RANSOMWARE
Berlin Probes New Data Leak After Hackers Post Login Credentials
Sep 7 · HIGH
Toy Ghouls
BACKDOOR
Toy Ghouls Debuts Custom Windows Backdoors in Russia Attacks
Sep 4 · HIGH
Industry News
Florida DMV Breach
SHINYHUNTERS
Florida DMV Breach Tied to ShinyHunters, Stolen Officer Credentials
Sep 12 · INFO
G7 Urges Organizations
QUANTUM COMPUTING
G7 Urges Organizations to Prepare for Quantum Cyber Threats
Sep 5 · INFO
Boston Scientific Cyberattack
BOSTON SCIENTIFIC
Boston Scientific Cyberattack Disrupts Medical Device Shipments
Aug 27 · HIGH
Tools & Techniques

Metasploit Adds Vim Plugin Persistence, Exploits for Three CVEs
Rapid7's Metasploit Framework adds Vim plugin persistence, exploits for CVE-2025-6793 (Marvell QConvergeConsole), CVE-2024-48760 (GestioIP), and CVE-2023-30253 (Dolibarr).
Signal Adds In-App Warnings to Block Russian-Linked Phishing Attacks
Signal introduced new in-app confirmations and warnings to counter phishing attacks linked to Russian state hackers who abused the Linked Device feature to hijack high-profile...
Anthropic Launches Claude Security for AI-Driven Exploit Defense
Anthropic released Claude Security, a defensive AI suite to counter autonomous exploit tools like Mythos that weaponize zero-days in minutes. Targets enterprise SOCs.
AI Security
Anthropic
PROVIDER
Anthropic Disrupts APT29 Spies Abusing Claude in 20+ Hacks
Sep 11 · HIGH
AI Safety
AI SECURITY
AIs Go Rogue in Cyber Challenges: Supply-Chain Attack Attempts
Aug 21 · HIGH
Black Hat Usa 2026
AI SECURITY
Black Hat USA 2026: AI Outpaces Security Controls, Accountability Gaps
Aug 13 · INFO
Stay Updated
Get the latest cybersecurity news delivered to your inbox.