29 Sep, 2026

Cloudflare fixes Containers cross-tenant flaw exposing customer data

Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers’ containers on the same physical host. Cloudflare Containers is a service available on the Workers Paid plan that lets developers run containerized applications on Cloudflare’s infrastructure, alongside Cloudflare Workers. Developers and […]

2 mins read

Anthropic turns Claude into an AI marketplace with 2,000+ plugins and connectors

Anthropic has just announced a new Claude Marketplace, and it brings all AI-related tools into one place, including plugins, connectors, agents, and more. Claude’s marketplace is already public, and Anthropic says it’s already offering more than 2,000 connectors and plugins. These plugins or connectors are available from companies like Atlassian, Google, Microsoft, Notion, Salesforce, and […]

2 mins read

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers. Google’s Mandiant and Threat Intelligence Group (GTIG) say this new technique has allowed the threat actor to once again […]

5 mins read

Claude Opus 5.5 uses 95% fewer em dashes, but its answers are getting longer

Anthropic’s Claude Opus 5.5 appears to be changing how it writes, with new analysis showing fewer obvious AI writing patterns, shorter sentences, and simpler wording compared with Opus 5. Claude Opus 5.5 is not only one of the best models for coding, but it also appears to be a bit better at writing, as Anthropic […]

1 min read

Microsoft pauses KB5002907 update after Office license deactivations

Microsoft has paused the rollout of the KB5002907 Microsoft 365 update after users report that it deactivated, or in some cases completely removed, perpetual Office 2016 and Office 2019 installations. KB5002907, titled “Optional update for out-of-date Microsoft 365 Apps installations,” was released to help users update Microsoft 365 Apps installations that are more than 90 days […]

4 mins read

GitHub Actions re-enabled with Mini Shai-Hulud payload still active

Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code. After being compromised on May 18, the GitHub security team removed actions-cool/issues-helper and actions-cool/maintain-one-comment, preventing any downstream workflow from downloading malware. According to researchers at […]

2 mins read

OpenAI’s AI agents accidentally uploaded user-provided images to third-party sites

OpenAI has confirmed it’s aware of a new security incident in which its AI agents uploaded user-provided images to third-party image-hosting services. OpenAI says most users were not affected, as it could only identify 53 incidents where agents accidentally uploaded images to the internet. The disclosure comes from OpenAI’s broader investigation into misaligned agent behavior […]

2 mins read

Kiteworks urges 6-hour server shutdown over potential zero-day attacks

Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent cyberattack. According to German technology publication Heise, Kiteworks CISO Frank Balonis emailed customers warning that the company had received “credible threat intelligence from law enforcement indicating […]

3 mins read

ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that GeekFeed has learned is an unauthenticated path traversal vulnerability. The Clop leak site was breached earlier this month by the ShinyHunters extortion gang, which first uploaded a […]

5 mins read

Elementor WordPress flaw lets attackers create admin accounts

A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. Threat actors can exploit the flaw by tricking a logged-in administrator into opening a malicious link, causing the victim’s authenticated session to perform a REST API action permitted by their account. On default installations, […]

2 mins read