Sam's News β security β 2026-09-25¶
Security¶
7.5 North Korean hackers steal $351.6 million from Bitget crypto exchange¶
Cryptocurrency exchange Bitget disclosed a $351.6 million theft on September 24, 2026, attributed to suspected North Korean hackers who compromised a backend wallet system. The attackers spoofed transaction data to move funds without stealing private keys, affecting ETH, XRP, BNB, AVAX, USDT, and USDC across multiple blockchains.
- $351.6 million stolen from hot and warm wallets September 24, 2026
- XRP comprised ~$157.4 million of theft
- Attackers compromised backend system and spoofed transaction data without stealing private keys
- Attribution to North Korean hackers based on IP patterns and on-chain analysis
- Largest crypto exchange breach of 2026; cold wallets and customer balances remained secure
Sources: The Hacker News AI Web Searched, Startup Fortune AI Web Searched, BleepingComputer RSS
7 Roundcube Webmail Pre-Auth SQL Injection Flaw Actively Exploited¶
Canadian Centre for Cyber Security warns that CVE-2026-48842, a pre-authentication SQL injection vulnerability in Roundcube Webmail's virtuser_query plugin, is being actively exploited in the wild.
Sources: The Hacker News RSS, SecurityWeek RSS Update to: Critical Roundcube webmail vulnerability from May now actively exploited in code injection attacks
7 'SalesBleed' Vulnerabilities in Salesforce Agentforce Enable Data Exfiltration¶
Three vulnerabilities in Salesforce Agentforce, collectively called 'SalesBleed,' allow attackers to hijack agents, steal data, and launch phishing attacks without user interaction. The flaws can be exploited via Web-to-Lead forms and affect the Agentforce-Slack integration, discovered by security firm Zenity Labs.
- Three vulnerabilities in Salesforce Agentforce (SalesBleed)
- Two vulnerabilities enable zero-click data exfiltration via Web-to-Lead forms
- Attackers inject malicious instructions into web forms that execute when agents access them
- Slack integration flaw causes requests carrying CRM data via automatic link preview retrieval
- Weaponized Trusted URLs mechanism failure allowed data transmission reported as blocked
Sources: SecurityWeek AI Web Searched
7 Cloudflare Fixes Data Leakage Flaw in Containers Service¶
Cloudflare patched a vulnerability in its Containers service where shared disks retained unwiped residual data from previous customers' containers. Using Linux thin provisioning, 64-kilobyte blocks were reused without wiping, allowing recovered data including databases, credentials, and browser profiles from other customers.
- Flaw allowed reading residual disk data from other customers' containers on shared servers
- Affected Cloudflare Containers and Sandboxes services
- Linux thin provisioning allocated 64-kilobyte blocks; deletion returned blocks to pool unwiped
- Testing found recoverable data on 18 of 24 tries across servers, 20 of 22 machines across 4 continents
- Reported September 4; fixed in two steps, cleanup completed September 19; disclosed September 24
Sources: The Hacker News AI Web Searched
7 WSO2 and Adobe Commerce Vulnerabilities Added to CISA KEV Catalog¶
CISA added two critical vulnerabilities to its Known Exploited Vulnerabilities catalog on September 25 due to active exploitation. CVE-2026-5430 affects WSO2 platforms enabling remote code execution, while CVE-2026-71362 affects Adobe Commerce allowing attackers to gain elevated access and switch customer sessions.
- CVE-2026-5430 (CVSS 9.8): WSO2 path traversal enabling remote code execution
- CVE-2026-71362 (CVSS 9.1): Adobe Commerce incorrect authorization flaw
- WSO2 exploitation confirmed since September 13, 2026; ~1,000 customers in banking, government, telecom, logistics
- Adobe Commerce exploitation detected August 2026; exploitation attempt September 10 from Australian IP
- Federal agencies must patch by September 27, 2026
Sources: The Hacker News AI Web Searched
7 Medicare breach exposes system vulnerabilities¶
A security breach of Medicare systems has revealed significant vulnerabilities in the healthcare administration infrastructure.
Sources: governmentnews.com.au Web Search
6 Microsoft Confirms Desktop Loading Issues After August 2026 Windows Updates¶
Microsoft has confirmed that recent August 2026 preview updates and subsequent updates are causing desktop loading issues and black screens for some users.
Sources: BleepingComputer RSS