BigCommerce breached and more - Sept 27, 2026

Featured

BigCommerce has revealed they were victim of a data breach

The attackers compromised third-party Ribon app credentials to inject malicious scripts into merchant stores

This Week’s Updates

Breaches

Australia's government confirms OpenAI's AI agents breached the Medicare statistics portal and accessed internal data, though no patient records were exposed

Bitget confirms hackers stole $351.6 million from its hot and warm wallets

Clop ransomware gang confirms its dark web leak site was hacked and defaced through an unpatched Grav CMS flaw

Vulnerabilities

OpenAI confirms and patches two Codex sandbox escape flaws that let researchers run commands on the host system

WordPress patches a pre-auth RCE flaw dubbed Click2Shell in Core version 7.1.1 after technical details and a PoC exploit went public

CISA warns three Linux kernel vulnerabilities are being actively exploited

CISA orders federal agencies to patch a Zyxel GS1900 switch flaw, CVE-2026-7273, after nearly 1,000 devices were compromised

D-Link warns of a maximum-severity zero-day, CVE-2026-86296, in legacy DIR-822A routers with public PoC code and no patch available

Check Point releases emergency hotfixes for a critical Management Server zero-day already being exploited in attacks

F5 patches a critical BIG-IP APM zero-day that attackers were exploiting for remote code execution

Arista patches a VeloCloud Orchestrator zero-day that was actively exploited before the fix shipped

Hackers begin exploiting a critical WordPress Core path traversal flaw, CVE-2026-87902, patched in version 7.1.2

Check Point confirms active exploitation of a pre-auth RCE flaw, CVE-2026-85102, in its Security Gateway VPN

CISA warns ransomware gangs are now exploiting a critical, already-patched JetBrains TeamCity vulnerability

Hackers actively exploit a critical Roundcube Webmail flaw that was patched back in May

CISA warns hackers are exploiting CVE-2026-5430, an authentication bypass affecting SharePoint, WSO2, and Adobe Commerce

Elementor patches a WordPress plugin CSRF flaw, affecting roughly 2 million sites, that let attackers create admin accounts

Next
Next

Revolut breached and more - Sept 20, 2026