Canadian Cyber Security Journal
SOCIAL:
Filed under: News

Cybersecurity Daily Brief — Tuesday, September 29, 2026

Here are today’s top cybersecurity stories for Tuesday, September 29, 2026.

Over 16,000 Misconfigured Supabase Databases Expose Personal Data and Credentials
UpGuard examined roughly 300,000 domains showing signs of Supabase use and found more than 16,000 exposed databases. The cause was missing or ineffective row-level security policies and misuse of public keys. More than half held personally identifiable information, and a smaller set held passwords and authentication tokens. Examples included a Canadian immigration service with about 5,000 user records and 884 plaintext passwords. BleepingComputer

Apple Patches CoreGraphics Zero-Day Linked to an “Extremely Sophisticated” Attack
Apple released updates for CVE-2026-86950, an out-of-bounds write in CoreGraphics reported by Meta Product Security. Apple said the issue was possibly exploited in an extremely sophisticated attack against specific targeted individuals. The fix adds improved bounds checking. The Hacker News

Microsoft Dissects NeedyMantis Malware Used for Long-Term Access to Breached Networks
Microsoft tracks the activity as Storm-3069 and says the malware has targeted telecommunications firms, universities, medical nonprofits, intergovernmental organizations, and government contractors since October 2025. Investigators found NeedyMantis while examining the DAEMON Tools tampered installers. Microsoft has not seen the malware itself spread through the supply chain attack. The Hacker News

Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown
Kiteworks said it found and fixed a previously unknown critical vulnerability while its systems were offline on September 27. The flaw sat in a capability enabled for fewer than 1 percent of customers. The company reported no evidence of malicious exploitation and has not yet assigned a CVE. The Hacker News

101 Malicious npm Packages Add Developers to WhatsApp Groups Without Consent
OX Security identified 101 npm packages in the PhantomSub campaign, which abuse the Baileys WhatsApp project to enroll victims in attacker-controlled groups and channels. The packages logged 490,000 downloads, with 116,000 in the last 30 days. Most of the channels advertise game account sales and bot services aimed at Indonesian markets. The Hacker News

Official MCP Python SDK Flaw Lets Malicious Servers Steal OAuth Credentials
The Model Context Protocol Python SDK failed to validate the token endpoint against the expected authorization server. A malicious MCP server redirects the exchange and captures the client secret, authorization code, and PKCE proof key. The flaw is fixed in versions 1.30.0 and 2.2.0, and no CVE has been assigned. The Hacker News

Pentagon Personnel Agency Breach Affects About 3 Million People
The Defense Manpower Data Center reported unauthorized access to an unencrypted file-sharing server between October 2025 and April 2026. The exposed data includes Social Security numbers, names, dates of birth, and contact details for 2.76 million living and 294,000 deceased individuals. No group has claimed responsibility. SecurityWeek

New Spectre v2 Variant Leaks Linux Root Password Hash in Minutes
Researchers at VUsec and Scuola Superiore Sant’Anna describe Branch Target Reuse, tracked as CVE-2026-64507 and CVE-2026-64508. The attack recovers a root password hash in three to five minutes on average on Intel Raptor Cove and Lion Cove processors, and Intel, AMD, and Arm designs are all affected. Linux kernel patches are merged. BleepingComputer

Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation
Police in the Netherlands arrested Pepijn van der Stap, 24, of Amsterdam, who goes by the alias Umbreon and was convicted in 2023 for hacking and extortion. He was due before the Rotterdam District Court on September 29. Krebs on Security reports the arrest relates to an investigation of the ShinyHunters group. Krebs on Security

Attackers Use ChatGPT Custom GPTs in ClickFix Campaigns
Threat actors built personalized versions of ChatGPT to impersonate legitimate software. The custom GPTs trick users into running malicious PowerShell commands, extending the ClickFix technique to a trusted AI platform. SecurityWeek

Stay tuned for today’s in-depth analysis posts.

Enjoy this article? Don’t forget to share.