Cisco's Perfect 10 Flaw Is Being Exploited Right Now
Monday, September 21, 2026 · 5-minute read
A joint law enforcement advisory confirmed that North Korean hackers known as WaterPlum compromised at least 30,000 devices worldwide between December 2025 and July 2026. The group moved more than $10.7 million in stolen cryptocurrency back to North Korea. This fits a well-worn pattern: Pyongyang uses cybercrime to fund its government while dodging international sanctions.
↗ BleepingComputerIreland's Data Protection Commission hit Google with a €403 million ($463M) fine for breaking GDPR rules around how it handled users' location data. This is one of the largest privacy fines handed down in Europe. It's a reminder that even the biggest tech companies face real consequences for mishandling the data you share with them.
↗ BleepingComputerThe North Korean hacking group Jade Sleet — also known as TraderTraitor and Slow Pisces — broke into a small Indian IT services company using two macOS backdoors called FLATROOF and ROOFDECK. The same tools were used in a cryptocurrency bridge attack earlier this year. Jade Sleet has a history of targeting tech and crypto companies to steal funds for North Korea.
↗ The Hacker NewsA supply chain attack hit Brevo, a popular email marketing platform, injecting ClickFix scripts into customer websites. ClickFix is a con that shows you a fake error message and tells you to "fix" it by pasting a command into your computer — which actually installs malware. A separate campaign is also using ClickFix lures to spread a new remote access trojan called ChainScript, which disguises itself as Spotify, Zoom, or Microsoft Teams.
Researchers at Securonix uncovered a data-harvesting campaign called TASK#STOMP. It plants a PowerShell backdoor that automatically grabs business documents, watches for new files, steals saved Wi-Fi passwords, takes screenshots, and copies whatever is in your clipboard. The infection likely starts with a phishing email. Once it's running, it sends everything to the attacker's servers in real time.
Cisco's Identity Services Engine is software that companies use to control who gets onto their network — think of it as the bouncer at the door. This flaw lets a remote attacker walk right past the bouncer without any password or credentials at all, by exploiting a weakness in one of its API endpoints. A perfect 10.0 severity score means it's as bad as it gets. Attackers are already exploiting this in the wild right now.
Status: Cisco has issued a patch. If your organization uses Cisco ISE, contact your IT team immediately to confirm it has been applied.
Security researchers chained two bugs together to take over the ChatGPT and Codex accounts of several OpenAI employees and even reach an internal code repository. The chain started in OpenAI's public help forum software, then moved through a weakness in OpenAI's own login system. The researchers also found two ways to escape OpenAI's Codex sandbox, one of which let commands run on a developer's actual computer.
Status: OpenAI confirmed fixes within 14 hours of the report. Both issues are now patched. The research team received a $6,500 bug bounty.
Hackers exploited a server vulnerability in Gyazo — a popular tool for sharing screenshots — and stole 23.6 million user records. If you use Gyazo, your account information may be in the hands of criminals. This is exactly the kind of data that gets sold on underground markets and used in future credential stuffing attacks.
Status: Gyazo has confirmed the breach. Change your Gyazo password now, and change it anywhere else you used the same password.
Security researcher Gal Weizman of Forever Security built a proof-of-concept attack called BragJack that shows how a single malicious browser extension can take full control of the AI assistants built into Chrome, Edge, Opera Neon, Perplexity Comet, and the Claude extension for Chrome. The technique — called Prompt Forcing — essentially lets the attacker whisper instructions into the AI's ear, overriding what you asked it to do. Weizman reported the findings responsibly, earned over $20,000 in bounties, and received two CVEs for his work. The research highlights a growing blind spot: as AI agents do more on your behalf inside your browser, a compromised extension becomes a much more powerful weapon than it used to be.
For years, Radaris.com collected personal information on millions of Americans and ignored requests to remove it — including from police officers, judges, and government officials whose safety depended on keeping their home addresses private. This week, a court finally ran out of patience and ordered the domain itself transferred to the plaintiffs. It's a rare win in a fight that usually goes nowhere.
Radaris is what's called a people-search data broker. Type someone's name in and you can pull up their address, relatives, phone number, and more. The site's co-founders — Russian-born brothers Igor and Dmitry Lubarsky, living in Massachusetts — built a web of companies to obscure who actually owned and operated the site. When sued, they invented a fake CEO named "Gary Norden," quoted him in press releases, and even tried to attract investors using his name. When that unravelled, their attorneys argued the lawsuit had named the wrong entity. Then new shell companies appeared, registered in the Marshall Islands, the British Virgin Islands, and Seychelles. One of those entities didn't even exist yet when Radaris claimed it was managing the site. The game was: exhaust plaintiffs with paperwork until they give up.
The lawsuit was brought by Atlas Data Privacy Corp under New Jersey's Daniels Law, which lets law enforcement officers and public officials demand their information be scrubbed from data broker sites. The fine for ignoring that demand is $1,000 per violation. After years of delays, fake entities, and a lawyer who admitted his clients invented their CEO's name, the judge had seen enough. On August 26, the court ordered radaris.com and more than a dozen related domains transferred to the plaintiffs. It's a significant moment because courts rarely take a domain as a remedy — it sends a message that procedural stonewalling has a ceiling.
What does this mean for regular people? Data brokers are still largely unregulated at the federal level, and Radaris is just one of hundreds. But this case shows that state privacy laws with real teeth — and plaintiffs willing to commit the time and money to fight — can actually win. If you want your personal information removed from sites like these, services like DeleteMe or Privacy Bee automate the removal requests, though results vary. Opt-out links on individual broker sites are a free starting point. Watch for more states to pass Daniels Law-style protections in the next legislative cycle.