Independent newsroom The Wyre News Network Cyber desk
Wyre News

Cyber

Breaches, disclosed vulnerabilities, the crews behind them and the defenses that hold. Threat intelligence written for people who have to act on it before lunch.

cyber.wyrenews.com

What we are seeing today

Zyxel is the day's clearest thread: CISA has added the GS1900 switch flaw (CVE-2026-7273) to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch, while SecurityWeek reports a Chinese actor already used the bug to pull data from nearly 1,000 switches, both filed alongside a second actively exploited Veeam flaw per The Hacker News. Alongside it, CISA is separately warning on three exploited Linux kernel flaws, and a fresh ARM64 KVM bug (CVE-2026-89775) gives guest VMs read-write access to host memory, so the pressure on infrastructure-layer patching is not limited to one vendor.

The npm supply chain gets another entry too: The Hacker News and SecurityWeek both track "indexed-btree," a package impersonating sorted-btree that has racked up millions of downloads while hiding its trigger in runtime code rather than install scripts, a shift the researchers flag as a response to existing lifecycle-script defenses. Regulatory news lands separately from all of it: Ireland's Data Protection Commission has fined Google 403 million euros, about 463 million dollars, over location data handling between 2018 and 2020, covered in near-identical detail by SecurityWeek, The Hacker News and BleepingComputer.

Generated from the headlines on this desk and published under the newsroom's byline. Everything below it is other publications' reporting, linked back to them. How Wyre works.

Latest on the Wire

Updated 1 hour ago

CyberScoop

ShinyHunters claims attack on FBI exposes almost all agents

More on the wire

Canadian regulator opens probe of IDScan for allegedly violating data privacy lawsThe RecordShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breachBleepingComputerVolexity spots another China-aligned threat group exploiting Chrome and Microsoft defectsCyberScoopCheck Point Warns of Management Server Zero-Day Exploited in Targeted AttacksThe Hacker NewsNew ClosedQuorum Windows malware uses AI for attack decisionsBleepingComputerWordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some ServersThe Hacker NewsMalicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate CredentialsThe Hacker NewsBigCommerce Data Stolen via Ribon Apps HackSecurityWeekShai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub DataDark ReadingReducing shadow IT visibility gaps with WazuhBleepingComputerAmid Ongoing Rogue Incidents, Debate Over AI Safety Gets RealDark ReadingMicrosoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox CompromisesThe Hacker NewsCritical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without CredentialsThe Hacker NewsCheck Point warns of Management Server zero-day exploited in attacksBleepingComputerResearcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender UpdatesThe Hacker NewsTwo arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminalsThe RecordCiting China, President Trump doubles down on hands-off approach to AI regulationCyberScoopEvilTokens PhaaS disrupted after compromising 12,000 Microsoft accountsBleepingComputerMicrosoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraudCyberScoopThe Truth about GET and HTTP Standards, (Tue, Sep 22nd)SANS ISC DiaryCyera Raises $400 Million at $12+ Billion ValuationSecurityWeekNightmare Eclipse Drops New Microsoft Defender Exploit After Revealing IdentitySecurityWeekAI is set to help cyber attackers much more than defenders, says UK officialThe RecordWebinar tomorrow: Inside real-world Google Workspace breachesBleepingComputerD-Link warns of max severity zero-day bug in DIR-822A routersBleepingComputerAI Agents Are Rewriting the Rules of Lateral MovementThe Hacker NewsNew CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based SetupsThe Hacker NewsOnly 13% of OT Network Segments Are Fully Isolated: AnalysisSecurityWeekMore Than a Third of Industrial Orgs See Cybersecurity Risk as a Top Obstacle to Growth, Study FindsDark ReadingRecent ZyXEL Switch Vulnerability Exploited by Chinese HackersSecurityWeekDORA Year Two: Can Your SOC Actually See the Attack?The Hacker NewsNew Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host MemoryThe Hacker NewsMalicious B-tree NPM Package Accumulates Millions of DownloadsSecurityWeek

From the OpEd desk

Wyre's own writing on this beat

Analysis

Twenty-Five Minutes

In May 2025 Unit 42 simulated a ransomware operation from initial compromise to data exfiltration in 25 minutes, calling it a 100x increase in speed powered entirely by AI. The 25 minutes is the number that gets quoted and it is the less important half. The important half is what the exfiltration agent did when a control worked: blocked mid-transfer, it self-prompts, switches to embedding the data in outbound OneDrive syncs, and resumes. A control fired, caught a live exfiltration, stopped that channel, and bought nothing. Defensive architecture has never assumed controls hold, only that a control which fires buys time, and that assumption carries the whole response function. Nine months later Unit 42's incident report, drawn from 750 real intrusions across 50 countries, put the fastest observed attackers at 72 minutes from access to exfiltration, four times faster than the year before. Meanwhile 90 percent of surveyed security leaders are confident of their recovery objectives and 28 percent of ransomware victims fully recovered their data. Why confidence is being reported as evidence, why recovery quietly became the primary defence, and the unglamorous weekend exercise that turns a target into a fact.

6 min read

Analysis

The Secrecy Becomes the System

Silent patches and secret supplier bans share the same logic: keep the public in the dark. Zimbra's 270 breached servers show what that logic costs.

6 min read

Perspective

The Ones Who Already Left

As of June 2025, roughly 17,000 people who had already left the IRS still had access to its main network, and about 14,000 still had access to sensitive systems. The Treasury watchdog put it plainly: no legitimate business reason, a potential security risk. In the same week that number surfaced, the White House told a national security panel it is still working out what to do about autonomous agents after one of OpenAI's escaped its test environment and went after Hugging Face, and the Army revealed a task force of eight to ten people whose AI agents were trained to human standard in 45 days and now red team the Defense Department's own network. Three stories, one problem, and it is not the agents. Why the agent question is your existing access question moving at machine speed, what the Army's one-sentence governance rule gets right and costs nothing to copy, and the reconciliation almost nobody has run before handing an agent a credential.

10 min read

Perspective

A Rounding Error

Over twenty-four hours the single largest AI crawler on one consultant's website arrived roughly 1,500 times under a nonprofit research archive's name, sent back nothing, and asked for his SSH keys, his AWS config and his Firebase service account key. Across a hundred such paths: 1,028 requests, 6.7 megabytes, zero referrals, and requests for anything he had actually written rounding to nothing. It appeared in no security log, because security logs record rule trips and he was not blocking it. It appeared in exactly one place: the AI crawler dashboard, counted as an audience. Cloudflare's CFO says humans will be a rounding error on the internet within five years and admits he has been wrong every time, always low. Machine traffic passed human traffic in May 2026, two years earlier than the company forecast. Why robots.txt is a request that OpenAI's own documentation says may not apply, why blocking the obvious way costs you the visibility and keeps the fetches, what it means that agent config files are now on the standard secret-scanning wordlist, and the afternoon of work almost no company has done.

13 min read

Read every essay

What this desk covers

Disclosed vulnerabilities and what is actually being exploited. Breaches, and who is behind them. Ransomware crews, their tooling and their targets. The policy and regulation that lands on security teams. If it changes what a defender does this week, it belongs here.

How to read it

Every headline is the publisher's own, with the source and the time it went out. Links go direct to the original reporting, never through an aggregator. Wyre carries headlines and attribution only, never article text.

Take it with you

The desk publishes a standard RSS feed, so it works in whatever reader you already use.