> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> InfoSec News Nuggets – 09/16/2026

[SOURCE] AboutDFIR [AUTHOR: Mary] [DATE: 16/09/2026 10:40] [LANGUAGE: EN]
Iranian Cyber Spies Used Fake MRI Scan Results to Hack ‘Enemy of Regime’  The UK’s National Cyber Security Centre, the FBI, and the Netherlands’ AIVD issued a joint advisory naming CHOSEN BRICK, a Windows spyware family Iranian state actors have used since at least 2025 to target dissidents, activists, and journalists in the UK, US, and Netherlands. Operators build rapport with targets over WhatsApp or Telegram for days while posing as someone the victim already knows, then deliver the malware disguised as legitimate files — including a fake MRI scan of a disk herniation — that display a convincing decoy while quietly installing a persistent implant capable of harvesting contacts, emails, and social media messages, capturing the screen, and activating the microphone. The NCSC warned that Iran “almost certainly” uses this kind of cyber activity to support repression of perceived regime critics, noting that in some cases Iranian intelligence services have plotted kidnappings or lethal operations against individuals abroad.      Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens  A critical vulnerability in WSO2 API Manager, tracked as CVE-2026-5430 with a CVSS score of 9.8, is now seeing active in-the-wild exploitation according to watchTowr, which captured forged JWT tokens carrying baked-in administrator privileges arriving at its honeypot network on September 13. The flaw stems from improper verification of a cryptographic signature — the platform’s JWT authentication mechanism incorrectly accepts tokens signed with algorithms it doesn’t explicitly support, allowing an attacker to craft a token that grants unauthorized access, including potential full administrative account takeover. WSO2 published the original advisory back in May, but the confirmed shift to live exploitation attempts means organizations still running unpatched deployments should treat this as an urgent priority.      Apple’s iOS 27 Update Closes More Than 100 Security Gaps  Apple’s iOS 27 release, alongside macOS Golden Gate 27, addresses more than 100 security vulnerabilities on iPhone and roughly 200 across the Mac update, spanning memory corruption bugs, kernel-level flaws capable of granting root access, and a Bluetooth issue that could enable remote code execution. Notably, Apple credited Anthropic’s Claude for three of the discovered fixes and acknowledged OpenAI’s Codex Security in its recognition section — a small but telling sign of how AI-assisted vulnerability research is increasingly feeding directly into major vendor patch cycles. Users on supported iPhone 11 and newer devices should update as soon as practical.      Suspected Black Axe Gang Leaders Face Cybercrime Charges in the US  Five alleged leaders of the Cape Town Zone of Black Axe — a violent transnational criminal organization also known as the Neo Black Movement of Africa — were extradited from South Africa to the United States on September 11 to face wire fraud and money laundering charges tied to a decade-long romance scam and advance-fee fraud campaign that ran from 2011 to 2021. Prosecutors allege the group built fake romantic relationships with more than 100 American women through dating sites and social media, manufacturing emergencies to extract money, and in some cases threatening to leak private photos when victims resisted. The extradition follows last month’s Operation Jackal IV, a 22-country law enforcement action that arrested 58 individuals and identified 263 suspects linked to African-coordinated cybercrime networks.      Google Chrome 153 Fixes 42 Security Flaws, Including Critical WebGL and Use-After-Free Bugs  Google shipped a fresh Chrome 153 update addressing 42 security vulnerabilities, including three critical-severity flaws in WebGL and Chrome Internals/Workers, part of a broader shift toward a faster two-week update cadence that Firefox and Edge are adopting around the same time. The most severe issue, CVE-2026-91726, is an out-of-bounds read in WebGL that could let a malicious website trigger unexpected memory access within the browser’s graphics-processing path, while two use-after-free flaws in Internals and Workers round out the critical-rated fixes. Google hasn’t indicated any of the 42 vulnerabilities are being actively exploited, but the volume of memory-safety issues — including 28 additional high-severity bugs spanning Input, Skia, DOM, V8, and PDF components — makes prompt patching important for both consumer and managed enterprise deployments.    The post InfoSec News Nuggets – 09/16/2026 appeared first on AboutDFIR - The Definitive Compendium Project.
[messages.read_original_source] →