Source context

Why this day matters

  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active
  • OpenAI says its AI agents uploaded user-provided images to third-party image-hosting services while carrying out research and evaluation tasks. [...]
Validated article intelligence

Enriched source records

Expand a row to inspect claims and citations

Luna-generated claims retained by the evidence and claim-validation gates. Automated validation does not imply human review. A record does not need a CVE to be included.

Luna-enriched source article · the hacker news

Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack

Kiteworks, formerly Accellion, urged customers to shut down their systems for nine hours over a weekend as a precaution after receiving threat intelligence about an imminent cyber attack.

2 retained claims2 cited excerpts

Source published Sep 26, 2026, 7:48 AM UTC · Evidence retrieved Sep 26, 2026, 1:23 PM UTC

What happened

Kiteworks, formerly Accellion, urged customers to shut down their systems for nine hours over a weekend as a precaution after receiving threat intelligence about an imminent cyber attack. [1]

Kiteworks said federal intelligence authorities provided credible threat intelligence indicating that a threat actor may attempt to target some Kiteworks systems. [2]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack.
  2. [2]
    "Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems," said Frank Balonis, Chief

Read the original article →

Luna-enriched source article · the hacker news

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

CISA added two vulnerabilities affecting Microsoft SharePoint and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation.

2 retained claims2 cited excerpts

Source published Sep 26, 2026, 8:49 AM UTC · Evidence retrieved Sep 26, 2026, 1:23 PM UTC

What happened

CISA added two vulnerabilities affecting Microsoft SharePoint and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. [1]

The supplied text identifies CVE-2026-65660 as a CVSS 8.8 code-injection vulnerability in Microsoft Office SharePoint. [2]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
  2. [2]
    The vulnerabilities in question are as follows - CVE-2026-65660 (CVSS score: 8.8) - A code injection vulnerability in Microsoft Office SharePoint

Read the original article →

Published records

Additional source records

Expand a row to inspect provenance
Threat and risk signals

Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

The Hacker News published a source item for review.

1 source recordContext source

What happened

The Hacker News published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

U.S. CISA adds WordPress flaw to its Known Exploited Vulnerabilities catalog

Securityaffairs published details for CVE-2026-87902.

1 source recordContext source

What happened

Securityaffairs published details for CVE-2026-87902.

Why it matters

A reviewed impact interpretation has not been published for this record.

Structured associations

CVE-2026-87902 mentioned

Reviewed next steps

  • Check asset inventory and patch status for CVE-2026-87902.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

AI and model reality

OpenAI's AI agents accidentally uploaded user-provided images to third-party sites

Bleepingcomputer published a source item for review.

1 source recordContext source

What happened

Bleepingcomputer published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

AI and model reality

New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining

Securityweek published a source item for review.

1 source recordContext source

What happened

Securityweek published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

AI and model reality

OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure

Securityweek published a source item for review.

1 source recordContext source

What happened

Securityweek published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.