Daily brief — Wednesday, 16 September 2026

ITsecurityNews · 2026-09-16


Elsewhere

Google fixes actively exploited Android zero-day on Pixel devices
BleepingComputer

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
The Hacker News

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News

What happens when AI agent governance is missing at scale
Help Net Security

Mythos has made 2026 patching hell. It might make 2027 a breeze
The Register

DeepZero: Open-source hunting for vulnerable Windows drivers
Help Net Security

The modern attack chain: Rethinking Google Workspace security in the age of AI
Help Net Security

MSPs say nearly half their customers rely on them for CISO services
Help Net Security

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches
The Register

Acronis warns of actively exploited flaw in its cPanel backup plugin
BleepingComputer

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
BleepingComputer

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?
SecurityWeek

All editions from ITsecurityNews