Sentinel Logo
Ex-soldier's telecom hacking spree earns him 70 months
Active-duty campaign targeted at least ten organizations and sought $1 million in ransom payments
ShinyHunters tells The Reg: We hacked the FBI to 'protect our business'
Data theft and extortion biz, that is
Bitget blames North Korea for $387.5M crypto wallet raid
Familiar fingerprints point to Kim’s regime … to the surprise of nobody
Clop gets a taste of its own medicine after ShinyHunters hijack leak site
Rival crew demands eight figures and threatens to expose companies that paid to keep quiet
North Korea's fake job interviews infected 30,000 devices
WaterPlum recruiters used bogus coding tests to backdoor jobseekers and raid more than 7,000 crypto wallets
FBI: Fake cop and government impersonation scams cost victims $1.6B
AI, fake uniforms, and mock offices help crooks sell the con
Spain gets its first taste of AI-aided cyber attack
Data protection chiefs call for 'immediate review' of data protection models
Iranian spies hit Windows machines with Chosen Brick data-stealing malware
'Enemies of the regime' on notice
HBO Max Reddit account compromised to serve ClickFix attacks
Part of a 'massive 48-hour malvertising blitz' targeting macOS and Windows machines with malware
More JFrog Artifactory bugs under attack, and all 3 have patches
If you're waiting for a sign to upgrade to a fixed version: this is it
Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars
Swapping legal work for malware development ended in extradition and a guilty plea
Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script
Human operator: don't touch CIS orgs. AI agents: look a squirrel!
ASCII smuggling isn't just an AI security risk
Phishers find a new use for invisible Unicode tag characters
Cybercrooks trawl Fishbrain to net password hashes
Armed with password hashes and salts, attackers could already be kraken those creds
Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes
23-year-old botnet down
Another Artifactory CVE under attack by AI agents or humans
Unauthenticated intruders can mint admin tokens, and exposed servers are already being hit
Healthcare cyberattacks hit pacemakers and millions of patient records
McKesson admits breach as ShinyHunters demands $55.2M
CRPx0 hacking service for dummies claims victim count more than quintupled
It's 'built to be operated by a human with no technical background'
More than 100 water systems were hit in July cyberattacks
'These are test runs for a larger-scale attack'
Boston Scientific discloses 'global disruption' in ongoing cyberattack
No timeline to restore IT systems as probe remains ongoing
Iran-linked cyberattack shut down a UK power plant
No risk to wider energy system, government tells The Reg
Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it
Ukrainian hacktivists exploiting the bugs, but TrueConf's reach stretches well beyond home turf
Hackers poison popular Rust crates to steal developers' credentials
Malicious updates turned routine builds into a delivery system for infostealer malware
Ransomware crook poses as recovery firm to steal payments from fellow extortionists
Because apparently even ransomware gangs can't trust the people they do business with
Australian hotel chain leaks guests’ PII after breach at third-party database operator
Unknown parties know where you stayed last summer, down under, across 120 Quest properties
Crook hawks millions of records allegedly plundered from corporate Azure tenants
McDonald's, Vodafone, TCS, Kyndryl, and others named as researchers point to compromised credentials
1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack
Another one bites the dust
Water system controllers don't belong on the internet, says ex-NSA chief after suspected Iran attacks
Calling all defenders
IBM's agentic AI platform is under active attack - patch now
A critical Langflow flaw allowing RCE on default deployments is being exploited, says the CISA
AI is 'both the weapon and the target' in latest wave of cyberattacks
CrowdStrike tracks 89% surge in machine-assisted activity as patch windows shrink to 48 hours
Europol flags 4,340 'horrific' URLs linked to The Com
Stop the spread (of online recruiting and propaganda)
Attackers pummel critical WordPress vuln to create all sorts of mischief
Plus dozens of PoCs in the public domain
Frontier LLMs couldn't help Hugging Face fight off evil agents
Chinese open-weight model GLM 5.2 happily obliged
C'mon, just copy this text string and paste it into your macOS Terminal – it'll fix your computer, honest
Newly documented stealer ClickLock comes for the more trusting Mac user with spot of social engineering
Brit Scattered Spider duo handed tickets to prison over Transport for London attack
Sentencing bookends the biggest cybercrime conviction in UK history
Tech support scam caused massive data breach at Australian airline Qantas
It’s possible to leak PII describing 5.7 million people without breaching privacy rules
An unnamed US county – perhaps in Ohio – paid $1M extortion demand to cybercriminals
Leaked negotiations spill the tea
Suspected Chinese snoops caught breaking into universities' Roundcube mailservers
Proofpoint researcher tells The Reg: 'We estimate the total volume of targets would be a few dozen'
Windows is watching: Anti-piracy tool fingers Scattered Spider suspect
Along with other telemetry, Windows GDID makes online activity more traceable
CAI cloud worm gives competitors' malware the boot, then steals secrets and mines for coin
Dog-eat-dog world for credential-stealing attackers
Predatorgate snoopfest victims launch €8M sueball at spyware maker
Greek lawsuit comes as rights campaigners lobby the EU to take firmer stance on spyware abuses
Fake IT bods on Microsoft Teams coax workers into installing malware
Unit 42 says attackers are posing as helpdesk staff and persuading employees to hand over remote control before dropping EtherRAT trojan
MFA-optional banks leave safe doors (and accounts) wide open for thieves to pillage
Financial institutions are putting their clients at risk in the name of convenience.
Dev says Google warned him about account hijack – then charged him $11,000 anyway
Left hand, meet right hand
Oracle E-Business Suite was under attack via critical flaw before the public exploit code was even released
Attackers appear to have reverse-engineered Big Red's patch
EvilTokens device-code phishing kit totally more evil than we all thought
It's a 'complete BEC operations environment,' Talos researcher says
Anonymous researcher drops 0-day 'exploitarium' repo
At least two vulnerabilities are already under attack
Amazon Q flaw let booby-trapped Git repos execute code, swipe cloud creds
Researchers warn many AI coding assistants now execute commands from project configurations
Ex-Huntress analyst claims company insider fed info to a ransomware crim. Social media drama ensues
Former employee accuses company of prioritizing pending IPO over client security
Microsoft uses AI to link two malware operations in racketeering suit
200+ C2 servers linked to StealC and Amadey shut down
OpenAI grilled over rogue agents by Australian inquiry
AI giant admits its initial responses 'fell short'.
Mobile networks finally get a disaster backup
Telstra, Optus and TPG activate emergency roaming.
South Australia names AI Royal Commission panel
The state?s landmark inquiry gets underway.
The data centre giants paying no tax in Australia
ATO scrutinises the rapidly growing industry.
Tech job vacancies plunge 15pc in a year
Sector has 5,000 fewer open roles.
Student visa crackdown puts migration agents on notice
Unscrupulous agents rush to enrol students before deadline.
OpenAI researchers fired after sharing ?sensitive? safety data
What did they discover about runaway AI?
Atlassian's CEO on why his IT team now reports to HR
Mike Cannon-Brookes explains company's 'unusual' structure.
Companies now rehiring jobs they cut for AI
Employers discover human judgement remains critical in many roles.
QLD cybersecurity department loses $800k in cyberattack
Third-party service was 'misused' for financial gain.
Cyber Incidents Put U.S. Water Infrastructure And Public Safety At Risk

This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Oct. 6, 2026 – Listen to the Podcast Episode A new study shows that malware stealing employee passwords has put more than a thousand U.S. water and wastewater providers at risk of cyberattacks.

The post Cyber Incidents Put U.S. Water Infrastructure And Public Safety At Risk appeared first on Cybercrime Magazine.

Bank CISO On Social Engineering Defense

This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Oct. 5, 2026 – Listen to the Podcast Episode Kevin Novak is the CISO at Evansville, Ind.-based Old National, the sixth largest commercial bank headquartered in the Midwest and a top 25 U.S.

The post Bank CISO On Social Engineering Defense appeared first on Cybercrime Magazine.

Black Hat Europe 2026 Discount Code: CYBERCRIME. Register Now. Dec. 7-10, London

This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Oct. 2, 2026 Black Hat Europe 2026 returns to the Excel in London with a four-day program, Dec. 7-10. The event will open with two-and four-day options of specialized cybersecurity Trainings, with

The post Black Hat Europe 2026 Discount Code: CYBERCRIME. Register Now. Dec. 7-10, London appeared first on Cybercrime Magazine.

Cybersecurity Brands Use YouTube Videos To Show Up In Google AI Overviews

This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Oct. 1, 2026 – Read the Full Report Cybercrime Magazine’s 2026 Cybersecurity CMO Report sheds light on a powerful Generative Engine Optimization (GEO) strategy to help cybersecurity companies show up in Google

The post Cybersecurity Brands Use YouTube Videos To Show Up In Google AI Overviews appeared first on Cybercrime Magazine.

BreachLock 2026 Penetration Testing Intelligence Report

This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 30, 2026 – Watch the YouTube Video The fifth annual BreachLock Penetration Testing Intelligence Report analyzes 531,770 security findings from 4,970 penetration tests across more than 60 industries, revealing the vulnerabilities,

The post BreachLock 2026 Penetration Testing Intelligence Report appeared first on Cybercrime Magazine.

From Influence to Evidence: Teaching the SOC Not to Make the Same Mistake Twice

AI-driven security, Artificial Intelligence, Machine Learning, Security Operations Center (SOC), SOC, SOCless – Christophe Briguet, Sr. Director of Product Management – AI & Security Analytics, Stellar Cyber San Jose, Calif. – Sep. 29, 2026 A year ago I made an argument. This year, we measured

The post From Influence to Evidence: Teaching the SOC Not to Make the Same Mistake Twice appeared first on Cybercrime Magazine.

Gambling Philanthropist Scammed Out Of $1.25M: How It Happened

This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 29, 2026 – Listen to the Podcast episode The scam happened in a chat group with Youtube superstars MrBeast and Mark Rober, streamer giant Adin Ross, and billionaires Tobi Lütke and

The post Gambling Philanthropist Scammed Out Of $1.25M: How It Happened appeared first on Cybercrime Magazine.

Klez Worm (2001): One Of The Scariest Computer Viruses Ever Created

This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 28, 2026 – Watch the YouTube Video With nearly $20 billion in estimated damages, The Klez Worm infected about 7.2 percent of all computers in 2001, or 7 million PCs. Possibly

The post Klez Worm (2001): One Of The Scariest Computer Viruses Ever Created appeared first on Cybercrime Magazine.

OPSWAT: AI-Powered Cybersecurity Protects the World’s Critical Infrastructure

This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 25, 2026 – Watch the YouTube Video OPSWAT prevents known, unknown, and AI-generated threats from reaching the systems the world depends on. The MetaDefender Platform, OPSWAT’s AI-powered cybersecurity solution, secures every

The post OPSWAT: AI-Powered Cybersecurity Protects the World’s Critical Infrastructure appeared first on Cybercrime Magazine.

Keeper Security: The Future of Identity Security; Next-Generation Privileged Access Management

This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 24, 2026 – Watch the YouTube Video “The biggest security concern with regards to AI is the management of identities and secrets,” says Craig Lurey, CTO and co-founder of Keeper Security,

The post Keeper Security: The Future of Identity Security; Next-Generation Privileged Access Management appeared first on Cybercrime Magazine.

LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings
A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro. The attack works only when the program's Java support is enabled. So far, it has only been shown as a proof of concept, and there are no reports of its use in
Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies
The Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, and edit Wikipedia pages. "The unauthorized bot activities included edits to our wikis, some unsuccessful attempts to exploit a public note-taking tool we host, and heavy traffic,
Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers
In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterprises plugged them into agent workflows. The ecosystem around it fell short. Earlier this year, our team at OX Security,  traced critical vulnerabilities in Anthropic's MCP
Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports
Google has stopped accepting product vulnerability reports through its bug bounty program for its open-source software. The change, in effect since October 1, means researchers can no longer submit security flaws in the code of projects such as Go, Angular, and Protocol Buffers there for a reward. Reports about supply chain compromises are still accepted, and reports filed before October 1 are
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must already know a file's exact name and path and cannot list what the directory holds. Atlassian disclosed the flaw, CVE-2026-21589, on October 5, rated it 9.3 out of 10, and
FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach
The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the theft of personal details of thousands of bureau employees. That's according to a report from Reuters, citing two sources familiar with the matter. "To date, our review has determined that the incident occurred as the result of a security failure ​
Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account
Unauthorized parties have gained access to the names, addresses, and personal identification numbers of about 8.8 million people, living and dead, in Denmark's national population register, the country's digitalization ministry said on October 5. They used a private Danish company's lawful right to look up records in the Central Person Register (CPR). The ministry has told people never to
ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits
A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser's cache. "Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file," the Microsoft Threat Intelligence team said in a post on X.
Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system. "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a
⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats keep finding leverage in small things that were easy to overlook. There are actively exploited bugs in the mix, cleaner intrusion paths, smarter automation, and a long patch list waiting behind them. Some attacks are getting more capable. Others
The Credential Layer Is Expanding Faster Than Security Teams Can See It
Every modern enterprise depends on credentials. This is how humans, systems, and now AI, all connect to data, services, and each other securely. GitGuardian helps secure that credential layer through three connected capabilities: Detect, Remediate, and Prevent. The journey starts with detection, because organizations first need to understand what credentials exist, where they live, and what they
Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2
Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said in a report
Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access
Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents. "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history – without users' full knowledge
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and
New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
Citrix has released security updates for a high-severity security flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0. "CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to
ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members
A suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter. Rey, whose real name is Saif ‌al-Din Khader, is said to have been brought into custody on September 29, 2026, and cooperating with the U.S. Federal Bureau of Investigation (FBI)
China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations. The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at a
MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics
The U.K.'s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering efforts on behalf of Beijing's state security service. In a "Security Service Espionage Alert" issued on September 30, 2026, MI5 said the "primary purpose of the China General Technology Research Institute (CGTRI) 中国通用技术研究院 is to fund research that
Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. "In the
The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations
Featuring: Cybersecurity is being reshaped by the expansion of cloud infrastructure, AI, distributed systems, and increasingly complex digital environments. As organizations manage more identities, devices, data, and internet-facing infrastructure, security is shifting toward continuous visibility, control, and the ability to respond to risk at scale. This report examines how core areas of
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory. The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act. The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1. The flaw
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster
Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems. The vulnerabilities are listed below - CVE-2026-63688 (CVSS score: 10.0) - A missing authentication for critical function vulnerability in the csm-authorization-storage gRPC server that an
OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling
OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported. "We have parted ways with three individuals for violating our policies on accessing and handling sensitive company information," a spokesperson for the company was quoted as saying. "Our investigation confirmed that these
Why CISOs Struggle to Answer the Board's Three Hardest Questions, and How to Fix the Report
The quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and the EDR console. Someone is building a spreadsheet to reconcile them. Someone else is turning that spreadsheet into slides. Then a board member asks three questions: How secure is the organization, overall? What is
Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools
Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android applications abusing the API serving as the main conduit for malware and financial fraud, the tech giant said the move would block a major attack pathway. Advanced Protection is a
Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. "An improper
Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers
Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid. The 16-year-old was one of 3 people arrested on September 30, when police also took control of that site. Investigators identified him as KillSec's suspected
ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than people expect. A model check can run code. A cache can mix up requests. A public secret can stay useful for years. That is the lesson running through the list. Attackers do not always need a brilliant new trick. They can
WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed SC after the "SC_" markers present in the injected content. Sucuri has described the malware as a "self-healing mesh" that's
How Financial Services Companies Can Modernize Their Software Supply Chain
Every security leader at a bank, insurer, or asset manager has had a version of this conversation: Security wants to eliminate a class of vulnerabilities. Engineering explains what it would take to upgrade the platform where they live. Somebody prices out the regression testing. Somebody else raises the change-freeze calendar. The finding gets an exception, a compensating control, and a date
OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates
OpenAI on Wednesday said it identified and disrupted a coordinated distillation campaign that was designed to illicitly extract protected reasoning from its artificial intelligence (AI) models. A "core cluster of the activity," going back to the first week of July, has been attributed to individuals associated with Moonshot AI, a Chinese AI company based in Beijing. It did not cite any
CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation. The vulnerability, tracked as CVE-2026-76504 (CVSS score: 9.8), could allow an unauthenticated, remote attacker to access an affected system with
Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version
Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program. "It delivers frontier performance in complex workflows across real-world software engineering, enterprise knowledge work like legal and finance, and cybersecurity defense," Koray Kavukcuoglu,
Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption into a working
Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist. "Their investigation identified malicious activity involving third-party security products, including a zero-day vulnerability, and recovered a customized tool used by the attacker
MetaMask Security Incident Prompts Exit of Affected Ethereum Validators
MetaMask on Thursday said it's responding to what it described as an "ongoing security incident" impacting part of its infrastructure. "We are actively addressing and remediating the issue internally, in coordination with external partners and security advisors," the software cryptocurrency wallet maker said. "At this time, we have identified no immediate threat to MetaMask wallets." MetaMask
Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs
Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data. LevelBlue's Threat Hunt Operations & Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team. The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated operating system command injection flaw that can lead to remote code execution when Simple Network Management Protocol
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content. "Once executed, the legitimate MSP360 installer, distributed under a deceptive file name established remote management access on affected
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an advisory on September 30. The flaw, CVE-2026-76504, could allow a remote attacker with no login access to use the Manager's API as the admin user. Fixed releases are available, and there is no workaround. It carries a
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms. Prior campaigns have weaponized shared
Know Your Enemy: Browser-Based Attack Techniques in 2026
Given that the browser is where business apps are accessed and used, it makes sense that attacks are happening there too. Most breaches today begin in a browser session. Often, they never leave it, with the entire attack chain from initial access to exfiltration playing out in the browser. Here are the six most dangerous techniques that should be on every security team's radar in 2026. 1.
AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub
AI coding agents asked to share screenshots of code changes for review have put internal company images in public GitHub repositories, security company Glow said. Its researchers found more than 13,000 internal images from developers at over 300 organizations, including customer billing records and screens of features not yet released. In most cases, they sat under developers' personal accounts
US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access
ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud
Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT
Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has targeted government, financial services, technology, education, and legal and professional
OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted
A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way
Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution
Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that's rooted in the NetScaler
French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks
An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July. Neither the tax administration nor France's national cybersecurity agency saw the data leave. The attack was not sophisticated, the agency, ANSSI, says in a report (in French) published on Tuesday: it worked because of weak
New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses
A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in web browsers, language runtimes, and the operating system kernel, across multiple CPU vendors. The new Spectre v2 variant has been codenamed Branch Target Reuse (BTR). "The key insight is that, while modern CPUs
More sources will be added in due sources from other feeds.