Close Menu
NCIJ Network NCIJ Network
    What's Hot

    You Don’t Have a Right to Safe Drinking Water, Trump-Appointed Judge Rules

    September 12, 2026

    In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

    September 12, 2026

    Government Defeated As Lords Back UK Digital Assets Strategy

    September 12, 2026
    Facebook X (Twitter) Instagram
    Trending
    • You Don’t Have a Right to Safe Drinking Water, Trump-Appointed Judge Rules
    • In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review
    • Government Defeated As Lords Back UK Digital Assets Strategy
    • An Overdue Trash Bill Left This Alabama Woman in Handcuffs. She’s Not Alone.
    • The hill I will die on: Comedians should not be hot | Amy Annette
    • Russia strikes cargo vessels, steel plants across Ukraine | Russia-Ukraine war News
    • The Trump Alien ‘Disclosure Speech’ Rumors Are Reaching a Fever Pitch
    • Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, September 12
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 12, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape.

    This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers stay well-informed about the evolving cybersecurity environment.

    Here are this week’s highlights: 

    Invisible Unicode slips past phishing filters

    Microsoft says attackers are using invisible Unicode tag characters, a technique associated with AI prompt injection (ASCII Smuggling), to evade phishing detection. In a campaign tracked from February through June, the characters were inserted into financial lure terms such as “funding,” generating as many as 2.37 million messages per day and potentially disrupting ML- and NLP-based filtering.

    Advertisement. Scroll to continue reading.

    WordPress Super Forms flaw under attack

    Attackers are exploiting CVE-2026-14894, a critical flaw in the WordPress Super Forms plugin that allows unauthenticated arbitrary file uploads. Exploitation can be used to upload and execute PHP webshells, potentially giving attackers complete control of affected sites. Users are advised to update to version 6.3.314.

    US puts $10 million bounty on Iranian cyber official

    The US is offering up to $10 million for information leading to the identification or location of Amir Yaryab, an IRGC-CEC official who leads its Cyber Operations Command. US authorities say groups under his direction have targeted critical infrastructure across sectors including defense, energy, financial services, telecommunications, shipping and travel, while affiliated groups such as CyberAv3ngers have used malware against civilian infrastructure worldwide.

    CISA updates insider threat playbook

    CISA has released an updated insider threat guide covering measures to mitigate both physical and cyber threats posed by insiders, addressing aspects such as remote work and AI advancements. The guide is designed to help organizations develop or improve their insider threat program. 

    FBI warns of consent phishing 

    The FBI is warning that threat actors are using OAuth consent phishing to gain persistent access to victims’ accounts without stealing their passwords. Attackers impersonate trusted figures and direct targets to malicious applications that request legitimate-looking permissions, allowing them to access email, files and other data. 

    Deep ties between Chinese hacking group QTFY and military contractors

    A new analysis from Natto Thoughts expands on a joint US advisory linking China-based hacking group QTFY to Nanjing Xinjiuwei Network Technology Co. (XJW), highlighting ties involving ELEX and Nanjing Lexbell Information Technology. The analysis says ELEX’s historical client lists included MSS, Ministry of Public Security and PLA-affiliated entities, while Lexbell has military-focused products, PLA-linked leadership and contracts with the National University of Defense Technology.

    Ex-AT&T employee sentenced to prison for SIM swapping

    Former AT&T employee Kenneth Carter was sentenced to 16 months in prison for using his access to perform SIM swaps that helped criminals take over customers’ bank accounts. Three victims suffered intended losses of nearly $600,0000, with Carter typically receiving $1,000 to $2,000 for each fraudulent SIM swap.

    Russian accused of running cybercrime infrastructure

    Russian national Sergei Anatolyevich Filimonov was extradited from Georgia and arraigned in the US over an alleged credential-harvesting and bank fraud operation targeting US banking customers. Prosecutors say fake financial websites and sponsored search results directed victims to phishing sites, while infrastructure allegedly maintained by Filimonov stored more than 5,000 stolen credentials and supported attempts to steal millions of dollars.

    InjectEave attack turns devices into eavesdropping targets

    Researchers demonstrated InjectEave, a new class of electromagnetic side-channel attacks in which an external RF signal induces hardware nonlinearities that leak low-frequency analog information. Tests on 11 commercial devices, including headphones, VoIP phones, smart fans and lamps, showed that attackers could recover private audio or determine appliance states without physical access or modifying the devices.

    Glasswing findings face a reality check

    VulnCheck’s review of Anthropic’s Project Glasswing ledger found that only 202 of 26,153 claimed findings had been fixed after nearly five months, while 245 had been withdrawn. It also found a significant gap between Claude’s severity assessments and those of maintainers: Claude rated 91.5% of findings with available ratings as high or critical, compared with 51.3% from maintainers.

    Related: In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions

    Related: In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation

    attack findings Glasswing InjectEave News review sentenced SIM Swapper
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Russia strikes cargo vessels, steel plants across Ukraine | Russia-Ukraine war News

    Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6

    Artifactory flaws chained in attacks deploying backdoor malware

    Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

    Review: Sally Hayden’s ‘This Is Also a Love Story’ Reimagines War Reporting

    ‘War on terror’: How 9/11 changed the language of conflict | Human Rights News

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    You Don’t Have a Right to Safe Drinking Water, Trump-Appointed Judge Rules

    September 12, 2026

    In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

    September 12, 2026

    Government Defeated As Lords Back UK Digital Assets Strategy

    September 12, 2026

    An Overdue Trash Bill Left This Alabama Woman in Handcuffs. She’s Not Alone.

    September 12, 2026
    Latest Posts

    After 3 reverse stock splits and a $13.5M loss, this real estate firm bet $8M on crypto it may not be allowed to withdraw

    August 3, 2026

    There Are 2 Eclipses This August. Here’s How to See Them

    August 3, 2026

    Europe’s ETS revision is an opportunity to strengthen maritime competitiveness – POLITICO

    August 3, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    You Don’t Have a Right to Safe Drinking Water, Trump-Appointed Judge Rules

    September 12, 2026

    In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

    September 12, 2026

    Government Defeated As Lords Back UK Digital Assets Strategy

    September 12, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.