Google fixes actively exploited Android zero-day on Pixel devices
2026-09-16T07:23:20Z•3239e6d93dedf3215b9fa4e087dd89fb85d3a7654ba1b4e48192a63ac407c644
AcronisAndroidBambooTokenCisco Secure Email GatewayLinuxMQTTOAuth token theftPHP backdoorPixelPleskVMware vCenterWHMWindowsWooCommerceWordPressactive exploitationcPanelcybercrimedata breachransomwaresupply-chain compromisevulnerability remediationzero-day
What happened
A BleepingComputer security news digest covering multiple active threats and vulnerabilities, including exploited Android, Cisco Secure Email Gateway, VMware vCenter, Acronis backup plugin, and WordPress plugin flaws; malware using MQTT to control Windows and Linux systems; supply-chain compromise of a WordPress plugin; data breaches; exposed OAuth tokens; and cybercrime activity. Several items involve active exploitation, remote code execution, privilege escalation, backdoors, or ransomware operations.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 3239e6d93dedf3215b9fa4e087dd89fb85d3a7654ba1b4e48192a63ac407c644
- Enrichment time
- 2026-09-16T07:23:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.