2026  January(387) February(431) March(447) April(451) May(495) June(499) July(647) August(1282) September(893) October(161) November(0) December(0) | YEARS(4 225)  STATISTICS (0)

DATE

NAME

Info

CATEG.

WEB

6.10.26

47-Day TLS Certificates: 5 Steps to Prepare Somewhere in your organization is a spreadsheet of certificate expiry dates, and someone who owns it. That is not a caricature. DigiCert’s 2026 research with Omdia surveyed more than 400 senior IT leaders and found that 47% still rely on manual tracking methods such as spreadsheets, and only 34% have a complete, current view of what they hold. Security blog Imperva

6.10.26

Harvest Now, Decrypt Later: End-to-End PQC TLS Somewhere, an attacker is recording your encrypted traffic. Not breaking it. Recording it. The bet is patient and simple: store ciphertext today, wait for quantum computers to mature, decrypt at leisure. The industry calls it harvest now, decrypt later (HNDL), and it is the rare security threat with a believable deadline attached: data with a ten-year shelf life, encrypted with algorithms on a countdown. Security blog Imperva

6.10.26

New Remote DoS Attacks Against GraphQL Java Imperva Threat Research identified a series of remote denial‑of‑service vulnerabilities in GraphQL Java, one of the most widely used libraries for GraphQL in the Java ecosystem. Attack blog Imperva

6.10.26

The Hidden DoS Vector in SQL Parsers SQL parsers are critical components of the modern data stack. They validate queries before they reach the database, transpile between dialects, and lint codebases for style violations. Increasingly, they also power AI-driven SQL generation in LLM-integrated data tools. Attack blog Imperva

6.10.26

Behind the tags: How Elastic SIEM grades 1,781 detection rules on noise, speed, and threat coverage This article explains how Elastic SIEM uses a monthly automated telemetry pipeline to score prebuilt detection rules across noise, performance, threat, and profile dimensions, helping security teams decide which rules to enable first. Spam blog Elastic Security Labs

6.10.26

Machine-speed attacks require machine-speed prevention and detection Artificial intelligence (AI) is transforming the way cyberattacks are handled. Reconnaissance has become faster, phishing is more convincing, and vulnerabilities are identified and exploited sooner, and after initial access, automation can accelerate privilege escalation, lateral movement, and data theft. Hacking blog Threatlocker

6.10.26

IQUALIF Leak, IUT Breach, SMTP Dump and Struts Exploit SOCRadar Dark Web Team identified several new underground posts, including an alleged IQUALIF-based French residential data leak, an alleged breach affecting IUT Paris Seine, and an alleged initial access auction for a U.S. manufacturing company. Other posts advertised an alleged 19 million SMTP credential dump and access to servers reportedly compromised through CVE-2017-5638. Exploit blog SOCRADAR

6.10.26

FortiMail Zero-Day Under Active Exploitation Fortinet has confirmed that CVE-2026-104286, a critical path traversal flaw in FortiMail, is being exploited in zero-day attacks, and CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on the same day the advisory went live. Exploit blog SOCRADAR

6.10.26

CVE-2026-90970: GitLab AI Gateway RCE GitLab has patched CVE-2026-90970, a critical vulnerability in the Self-Hosted AI Gateway that can allow an authenticated user with Duo Agent Platform access to execute arbitrary commands on the gateway. Vulnerebility blog SOCRADAR

6.10.26

ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure How ClingSTUN combines vulnerability exploitation, persistence, and STUN-assisted connectivity on Linux devices Malware blog FortiGuard Labs

6.10.26

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files Vulnerebility The Hacker News

6.10.26

FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the BigBrothers The Hacker News

6.10.26

Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account Unauthorized parties have gained access to the names, addresses, and personal identification numbers of about 8.8 million people, living and Incindent The Hacker News

6.10.26

ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser's cache. Hack The Hacker News

6.10.26

Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as Vulnerebility The Hacker News

5.10.26

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2 Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling . " Exploit The Hacker News

5.10.26

Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed OS The Hacker News

5.10.26

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The Vulnerebility The Hacker News

5.10.26

New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline Citrix has released security updates for a high-severity security flaw in NetScaler ADC and Citrix NetScaler Gateway that has been exploited as Exploit The Hacker News

5.10.26

Anthropic asks Claude users to share voice data for AI model training Anthropic has started asking Claude users to voluntarily share their voice conversations to help train and improve its AI models. AI BleepingComputer

5.10.26

Google Gemini could soon get full access to your Mac’s files, apps and the web Google's Gemini could soon access any file on your macOS device, open apps, browse the web, and perform actions without asking for permission every time. AI BleepingComputer

5.10.26

ShinyHunters hacker reportedly detained in Jordan, aiding FBI A suspected ShinyHunters hacking group member known online as "Rey" has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members of the extortion group. CyberCrime BleepingComputer

5.10.26

Danish university DTU breach exposes data of up to 200,000 people The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data. Incindent BleepingComputer

5.10.26

Frontline Education breach exposes school district employee data Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers. Incindent BleepingComputer

5.10.26

Warlock ransomware breach SharePoint in water, telecom operator attacks The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access. Ransom BleepingComputer

5.10.26

GitLab warns of critical RCE vulnerability in AI Gateway service GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances. Vulnerebility BleepingComputer

5.10.26

US sanctions Tren de Aragua gang members in ATM hacks crackdown The U.S. Treasury Department has sanctioned eight members of the Venezuelan gang Tren de Aragua (TdA) for their role in the theft of millions of dollars in ATM jackpotting attacks across the United States. CyberCrime BleepingComputer

5.10.26

The EDR blind spot: 3 ways browser attacks evade endpoint telemetry Browser-based attacks can steal sessions, abuse extensions, or manipulate users without creating the endpoint artifacts EDR is designed to detect. NordLayer explains three ways attacks can evade endpoint telemetry and why browser-level controls can help close the gap. Security BleepingComputer

5.10.26

Dell asks admins to patch max severity CSM flaws as soon as possible Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments. Vulnerebility BleepingComputer

5.10.26

Microsoft’s X account hacked in crypto pump-and-dump scheme On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token. Social BleepingComputer

4.10.26

Fortinet warns of critical FortiMail flaw exploited in zero-day attacks Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. Exploit BleepingComputer

4.10.26

Autonomous AI agents tried to hack US, Canadian government websites Autonomous AI agents using aggressive strategies attempted to hack U.S. and Canadian government websites to find school and divorce statistics. AI BleepingComputer

4.10.26

Microsoft says threat actors are ahead in the early AI race Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace. AI BleepingComputer

4.10.26

Police dismantle KillSec ransomware gang allegedly led by 16-year-old An international law enforcement operation dubbed "Operation KillSwitch" seized the KillSec ransomware gang's data leak site and servers, led to three arrests, and identified a 16-year-old as the group's alleged administrator. Ransom BleepingComputer

4.10.26

The Day-One Hole in Zero Trust Architecture Zero Trust can verify users once they are established, but onboarding creates a gap where organizations must decide who to trust before strong authentication exists. Specops explains why identity verification should begin before credentials, MFA methods, and access are issued. Security BleepingComputer

4.10.26

Kiteworks patches max severity code injection vulnerability Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting its Email Protection Gateway (EPG) security solution. Vulnerebility BleepingComputer

4.10.26

Microsoft enables Windows settings backup by default for orgs Microsoft announced that Windows settings backup and restore is now enabled by default on all Microsoft Entra-joined or Microsoft Entra hybrid-joined enterprise systems upgraded to Windows 11 26H2. OS BleepingComputer

4.10.26

Hackers stole Pentagon personnel records of over 3 million people The Pentagon's Defense Manpower Data Center (DMDC) is notifying millions of military service members that hackers stole their data after breaching the Pentagon's human resources management system in October 2025. Incindent BleepingComputer

4.10.26

Metamask discloses security incident affecting its infrastructure On Thursday, cryptocurrency wallet provider MetaMask has disclosed an ongoing infrastructure security incident affecting some of its infrastructure. Cryptocurrency BleepingComputer

4.10.26

Russian state hackers use new RedFlick technique to push malware The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse backdoor. APT BleepingComputer

4.10.26

DIVD says Zammad zero-days enabled AI-driven network breach The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. AI BleepingComputer

4.10.26

Over 543,000 valid credentials exposed in public GitHub repositories More than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platform's security measures to prevent accidental leaks of sensitive data. Incindent BleepingComputer

4.10.26

CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition. Vulnerebility BleepingComputer

4.10.26

Cisco warns of new SD-WAN zero-day exploited in attacks Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges. Exploit BleepingComputer

4.10.26

AI's Third Wave: Coworkers Break the Security Model That Worked for Agents Persistent AI coworkers may operate continuously with standing access, creating identity risks that existing security models were not designed to handle. Token Security explains why these agents need their own identities, owners, scoped permissions, and lifecycle controls. AI BleepingComputer

4.10.26

ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members A suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters reported , citing three people familiar with the matter. CyberCrime The Hacker News

4.10.26

China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial APT The Hacker News

4.10.26

Microsoft to block Entra ID script injection attacks starting October Microsoft has reminded customers that the Entra ID authentication system will get better protection against external script injection attacks starting next month. Hack BleepingComputer

4.10.26

TeamViewer urges users to patch severe flaws “as soon as possible” Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. Vulnerebility BleepingComputer

4.10.26

Bitget hacked via zero-day in third-party security products Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. Exploit BleepingComputer

4.10.26

Microsoft is rolling out Linux container support to WSL Microsoft is taking Windows Subsystem for Linux beyond just running Linux distributions, as WSL Containers is now generally available. OS BleepingComputer

4.10.26

Signal adds encypted local backup support to iOS, desktop apps Signal, the secure messaging app, released version 8.30, completing the rollout of its secure backups feature across all supported operating systems (Android, iOS, Linux, macOS, and Windows). Social BleepingComputer

4.10.26

Custom ChatGPTs push ClickFix attacks to deploy RAT malware Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware. AI BleepingComputer

4.10.26

FBI tells ShinyHunters members to turn themselves in after recent arrest The FBI is warning members of the ShinyHunters extortion group to turn themselves in after Dutch police arrested a man the bureau described as one of the group's alleged leaders. BigBrothers BleepingComputer

4.10.26

Hackers exploit Citrix NetScaler zero-day to deploy web shells Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks. Exploit BleepingComputer

4.10.26

Former US Air Force members sent to prison over BEC attacks Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. Spam BleepingComputer

4.10.26

Windows 11 2026 Update released, here's everything you need to know Microsoft has started rolling out Windows 11 26H2 to everyone, and while it's this year's big annual feature update, you probably won't notice a massive difference after installing it. OS BleepingComputer

4.10.26

New Spectre v2 attack variant leaks Linux root password hash in minutes A new Branch Target Reuse (BTR) attack has been devised that can recover root password hashes on Intel computers running Linux in 3-5 minutes on average. Attack BleepingComputer

4.10.26

Automated AI agent used to breach cybersecurity nonprofit DIVD The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyberattack that the organization described as "loud and very, very messy." AI BleepingComputer

4.10.26

Catch threats before they escalate with real-time Identity Telemetry Identity governance helps control who should have access, but periodic reviews alone may not reveal attacks as they happen. tenfold Software explains how real-time identity telemetry can help security teams investigate suspicious activity before it escalates. Security BleepingComputer

4.10.26

Vietnamese man charged in $16 million 'pig butchering' crypto scam A Vietnamese national was charged with money laundering for his role in a massive "pig butchering" scam, which defrauded a victim out of $16 million worth of cryptocurrency. Cryptocurrency BleepingComputer

4.10.26

Kiteworks patches critical flaw, brings customer systems online American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability. Vulnerebility BleepingComputer

3.10.26

MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics The U.K.'s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering BigBrothers The Hacker News

3.10.26

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both Ransom The Hacker News

3.10.26

Apple patches CoreGraphics zero-day flaw exploited in attacks Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices. Vulnerebility BleepingComputer

3.10.26

Japan's Keio confirms ransomware attack disrupted business systems Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems. Incindent BleepingComputer

3.10.26

Times Car confirms data breach affecting 6.6 million user accounts Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. Incindent BleepingComputer

3.10.26

Dutch police confirm arrest in ShinyHunters hacking investigation Dutch police have confirmed that a 24-year-old Amsterdam man arrested earlier this month was detained as part of an investigation into the ShinyHunters hacking group. CyberCrime BleepingComputer

3.10.26

Over 16,000 Supabase databases expose PII, passwords, auth tokens Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens. Hack BleepingComputer

3.10.26

JadePuffer agentic AI attacks target Azure, destroy cloud resources The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components. AI BleepingComputer

3.10.26

80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking Infostealer logs exposed AI account credentials and sessions tied to more than 80,000 corporate domains, creating risks ranging from stolen conversations to LLMjacking. SOCRadar examines the growing market for stolen AI logins and how organizations can identify their exposure. AI BleepingComputer

3.10.26

Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million. Cryptocurrency BleepingComputer

3.10.26

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain Vulnerebility The Hacker News

3.10.26

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The APT The Hacker News

3.10.26

AI-Enabled Cyber Attacks: What They Are and How to Defend Against Them AI-enabled cyber attacks are malicious operations in which adversaries use AI, most often large language models (LLMs), to plan, carry out, or scale any part of an attack. That includes writing phishing lures and deepfake pretexts, developing and debugging malware, discovering and exploiting vulnerabilities, and running intrusions end to end. AI blog PICUSSECURITY

3.10.26

CrowdSec Bot Detection Uncovers a 75,000-IP Bot Network On the 31st of August, we released CrowdSec 1.8.0 that included the bot detection feature. Despite the fact that the feature was (is) still tagged as alpha, some mad lads promptly slapped it on their production infrastructure. Thanks for the trust! BotNet blog CROWDSEC

3.10.26

AI-Agentic attacks Optimized Operations AI is changing cyberattacks from isolated activities into connected operations that require a new level of speed, context, and understanding. AI blog WatchGuard Blog

3.10.26

PolinRider is A/B Testing its Way Past Your Detections We've seen fa-solid-400.woff2 become 500 and 900, change from .woff2 to .llf files, move folders, and drop its whitespace padding. Malware blog OpenSource Malware Blog

3.10.26

Prompt Forcing: The Scarier Sibling of Prompt Injection Breaking down a newly discovered prompt attack technique that isn't prompt injection. AI blog Forever Security

3.10.26

Introducing the SysQL Skill: Ask your security graph anything Dashboards answer the questions someone already decided to build a screen for. Every other question — the one a new CVE just made urgent, or the one no vendor anticipated — waits until someone writes a report or files a ticket. Vulnerebility blog Sysdig

3.10.26

Swarming Against Citrix 0-Day Exploitation GreyNoise observes adversary activity through our Global Observation Grid (GOG), a network of sensors that draws attacker scanning and exploitation onto infrastructure we control. This lets us study adversary infrastructure, tooling, and tradecraft directly, without waiting for a victim investigation. Exploit blog GREYNOISE

3.10.26

Open Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation GreyNoise observes adversary activity through our Global Observation Grid (GOG), a network of sensors that draws attacker scanning and exploitation onto infrastructure we control. This lets us study adversary infrastructure, tooling, and tradecraft directly, without waiting for a victim investigation. Exploit blog GREYNOISE

3.10.26

Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF GreyNoise observes adversary activity through our Global Observation Grid (GOG), a network of sensors that draws attacker scanning and exploitation onto infrastructure we control. This lets us study adversary infrastructure, tooling, and tradecraft directly, without waiting for a victim investigation. AI blog GREYNOISE

3.10.26

Threat Actors Are Posing as OpenAI, Anthropic and DeepSeek to Target Credentials and Secrets GreyNoise is observing automated scanners posing as the web crawlers of OpenAI, Anthropic, DeepSeek, and Fortune 500 companies. These forged automated scanners have been observed requesting files often exposed on misconfigured web servers and by other commonly leaked secret and credential methods. AI blog GREYNOISE

3.10.26

Separating Signal from Slop: Triaging CVEs in the Age of… Tools that can read a codebase, identify a vulnerability, and generate a working proof-of-concept have lowered the skill floor for vulnerability research. They also produce a wave of bugs that look terrifying on paper (remote code execution, popular software, no authentication,) yet they often depend on a configuration rarely enabled in real deployments. Vulnerebility blog Bishop Fox

3.10.26

One Port to Root: Weaponizing Check Point Management… The Check Point management server is the brain of a Check Point firewall estate: it holds the policy every gateway enforces, the administrator credentials, and the certificate authority the whole deployment trusts. A flaw already used in real attacks lets anyone who can reach that server take it over completely without logging in. Vulnerebility blog Bishop Fox

3.10.26

AI-Assisted Attacks Still Leave a Behavioral Trace AI is increasingly being used to accelerate cyber-attacks, but attackers still leave detectable behavioral traces. This blog explores how Darktrace identified suspicious file delivery, command-and-control communications, beaconing activity, and other anomalies linked to AI-assisted campaigns through behavioral analysis. AI blog DARKTRACE

3.10.26

DirtyBlanket: Fake Express Packages on npm Spread a Linux Worm - Real-time Open Source Software Supply Chain Security Nine npm packages hide a self-spreading Linux worm. The npm account dirtyblanket published all nine on September 29, 2026, in 33 minutes. Eight of them copy the popular Express framework. One copies React. Malware blog SAFEDEP.IO

3.10.26

PolinRider Switches to Ethereum C2 in 30+ Repositories - Real-time Open Source Software Supply Chain Security The PolinRider loader family has a new way to find its command and control (C2) servers. It reads Ethereum mainnet and looks for small transactions from an operator wallet. The recipient address of each transaction holds the IP address of a C2 server. SafeDep found two operator wallets that use this method. One wallet has sent a transaction about every 51 minutes since 2026-06-23. Cryptocurrency blog NETCRAFT

3.10.26

'Super Intelligence' Executive Order Fuels Nearly Hundredfold Increase in .si Domain Registrations We previously reported that registrations of Slovenian .si domains overtook .ai in the 25 hours after President Trump told the UN General Assembly on September 22 that the U.S. would call AI “super intelligence” (SI). AI blog NETCRAFT

3.10.26

FinCEN Moves to Cut the A7 Network's Sub-Agents Off From the US Financial System FinCEN issued a finding and NPRM today identifying transactions involving any non-US company controlled by the A7 Network, which the agency calls "Sub-Agents," as a class of transactions of primary money laundering concern. The proposed rule would prohibit every covered US financial institution from sending or receiving funds or crypto involving a Sub-Agent. AI blog TRM Labs

3.10.26

How I Found a $113,337 AF_ALG Linux Local Privilege Escalation Before Copy Fail In 2025, I found an AF_ALG vulnerability in the Linux kernel that allowed an ordinary user to escalate privileges to root. This is a retrospective on how I found CVE-2025-39964 and how we developed the exploit, before Copy Fail drew wider attention to AF_ALG in 2026. OS Blog IDNSEC

3.10.26

CVE-2026-86950: The Great Glyph Grift Apple recently released iOS 26.7.1 to fix a bug in CoreGraphics (CVE-2026-86950). The security advisory stated that the vulnerability was reported by Meta Product Security and "may have been exploited in an extremely sophisticated attack against specific targeted individuals." For those who are unfamiliar with Apple’s English dialect, it means that the bug was actually exploited in the wild.  Vulnerebility blog Calif

3.10.26

Crypto Scam Extensions Masquerade as High-Profile Investors LayerX security researchers (now part of Akamai) uncovered a campaign of nearly 30 malicious browser extensions designed to scam cryptocurrency investors by masquerading as legitimate, high-profile financial and/or cryptocurrency investors such as Warren Buffett, Andy Kreiger, Thomas Bulkowski, and others. Spam blog Akamai

3.10.26

When Productivity Extensions Become Attack Platforms LayerX Research (now part of Akamai) discovered a coordinated campaign of 32 malicious browser extensions across the Chrome Web Store and Microsoft Edge Add-ons Store, affecting more than 6,150 users. Security blog Akamai

3.10.26

Beyond Vendor Assessments: Managing Third-Party Risk Software supply chain security has a well-defined starting line. It has no finish line, even though most programs are built as if it does. Cyber blog JSCRAMBLE

3.10.26

Aligning AI Speed with AI Trust: AI Agent Security Insights for CISOs and Security Leaders AI agent security is the practice of governing two separate things: what an autonomous AI system is allowed to reach, and what it is allowed to do. Most enterprises have built a program for the first one. Almost nobody has built one for the second, and that's where the losses are starting to show up. AI blog Morphisec Blog

3.10.26

From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat RATHat's Android malware remained largely static from late 2025 to September 2026, while its Command-and-Control (C2) panel was replaced entirely and went through three generations in six months, rebranded from BlackCat to Panda Workshop. Malware blog Cleafy

3.10.26

TIKTOUK: Tracing a WordPress Credential Collection Toolkit TIKTOUK brings together WordPress probing, collection of exposed configuration data, recovery of encrypted email credentials, and JavaScript secret scanning. Its two Python components and Go-based Linux crawler turn website responses into structured results for a central hub: an HTTP service that distributes target tasks and receives collected data and status reports. Hacking blog LEVELBLUE

3.10.26

Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts and Hunt Indicators CVE-2026-88771 is a critical pre-authentication command-injection vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. Citrix and security researchers have already documented the vulnerability and its underlying exploitation mechanism. This analysis focuses instead on exploitation activity identified by LevelBlue's Threat Hunt Operations & Research (THOR) team while hunting across multiple customer environments. Vulnerebility blog LEVELBLUE

3.10.26

Citrix NetScaler Zero-Day Exploited Globally On Sept 27, Citrix released patches for two critical vulnerabilities being exploited in the wild. Based on current information, we confirm there has been no exposure or impact to LevelBlue or our clients. CISA has already added these vulnerabilities to the Known Exploited Vulnerabilities (KEV) list. Vulnerebility blog LEVELBLUE

3.10.26

Hackers exploit FortiMail zero-day before a patch exists Fortinet says attackers are already exploiting a critical flaw in FortiMail, its email security gateway, and the fixed software has not shipped yet. The bug, tracked as CVE-2026-104286 and rated 9.8 on CVSS v3, lets an attacker with no login write arbitrary files to the appliance using crafted HTTP or HTTPS requests. Fortinet rates its impact as executing unauthorized code or commands. Vulnerebility blog IntelFusions

3.10.26

Introducing Cloudflare Basin: an open, serverless data platform, now generally available During Birthday Week 2025, we announced the Cloudflare Data Platform, a suite of products that ingest, store, and query your analytical data. Today, we’re announcing that the platform is generally available, and we’re giving it a new name: Cloudflare Basin. Cyber blog CLOUDFLARE

3.10.26

Introducing Clef: our open-source decision models, and new RL fine-tuning platform Over the last few weeks, there has been lots of buzz around decision models such as Typesafe AI’s Jev System One model. While classifier models have been around for some time, Jev introduces a new decision model concept into the world of AI — a model that produces bounded structured outputs cheaply, quickly and consistently that can be added into a workflow when a decision is required. AI blog CLOUDFLARE

3.10.26

One year later: Sovereign AI and the fight for choice It's Birthday Week, when we traditionally ship presents to the Internet. This year, two of them come from Europe: EuroLLM, which covers all 24 official EU languages, and Apertus, Switzerland's fully open model, trained on more than 1,500 languages. Both were built by public universities and research institutions. Both are coming to Workers AI, and you can request access today. AI blog CLOUDFLARE

3.10.26

Introducing Workers KV Instant — powered by Quicksilver Today, we’re introducing Workers KV Instant, a new mode for Workers KV that pushes your changes globally for instant availability without cold read penalties. Cyber blog CLOUDFLARE

3.10.26

Cloudflare OS: your company’s agent workspace, managed for you Cloudflare OS gives everyone in your organization an agent workspace that knows how your company works and connects to its data and systems. Today, we're opening the waitlist for fully managed Cloudflare OS deployments. Cyber blog CLOUDFLARE

3.10.26

Announcing Cloudflare K2: serverless event streams With traditional Remote Procedure Call (RPC) architectures, there exists a core challenge: producers and consumers must align in scale and in time. If your producers send too much data for your consumers to handle or if your consumers or downstream services become unavailable, events are dropped. Cyber blog CLOUDFLARE

3.10.26

We want you to build the next Git platform on Cloudflare GitHub was built for a world where humans write code, organize it into repositories, and collaborate through branches, commits, issues, and pull requests. Cyber blog CLOUDFLARE

3.10.26

AI Search is now generally available Cloudflare’s AI Search combines Workers AI, Vectorize, R2, and Browser Run into a fully managed index and retrieval pipeline. Since we launched AI Search over a year ago, we’ve seen developers use it to power a wide range of search use cases, from searching internal documentation to powering search for their websites. We use AI Search ourselves to power search on our own blog and developer docs. AI blog CLOUDFLARE

3.10.26

Support for modern cryptographic algorithms in Workers Today, Cloudflare Workers is adding support for post-quantum-resistant algorithms within Web Crypto. These are defined in Modern Algorithms in the Web Cryptography API draft community group report, and include: Cyber blog CLOUDFLARE

3.10.26

Cloudflare Impact reaches $100 million in donations This week, Cloudflare's Impact programs will reach $100 million in donated services. It's a significant milestone, and one that we are proud of because it means that thousands of organizations, like journalism outlets, civil society, state and local governments, election management bodies, and public schools are being protected from cyberattacks. Cyber blog CLOUDFLARE

3.10.26

Cut your AI spend with AI Gateway's Auto Router From our conversations with companies at every stage of their AI adoption journey, we've seen some common patterns. First, there is an exploration period as you bring on every new tool, dole out API keys freely, and let the tokens flow. Then, you converge on the canonical tools for your organization for agentic coding, for non-technical workflows, for running and deploying agents. AI blog CLOUDFLARE

3.10.26

Detect and send production issues straight to your agent As agents help us build more complex applications, both humans and agents need a better way to stay on top of what goes wrong in production. Coding agents can already query observability data, navigate a repository, change code, write tests, and open a pull request. AI blog CLOUDFLARE

3.10.26

Simplifying domains for people and agents You just thought of your next great idea, and buying the right domain feels like the easiest way to make that first bit of progress. Naturally, you open a new tab in your browser, only to find yourself face-to-face with an experience that feels like a budget airline peppering you with add-ons at checkout: Want security? How about a website? Do you want email? You’re just a few minutes into building your next idea, and it doesn’t feel fun anymore. AI blog CLOUDFLARE

3.10.26

Monetization Gateway beta: charge AI agents for consumption with HTTP 402 Today, we’re making the Cloudflare Monetization Gateway available as part of a closed beta, and showcasing four customer use cases that are in production today. Since we announced the plan three months ago, we have been working closely with our customers to make the Gateway fast, flexible, and easy to use. AI blog CLOUDFLARE

3.10.26

Pay Per Use: when AI uses your work, you should get paid AI answer engines read a publisher’s page and hand the reader a summary, so the visit, and the revenue that would come with it, never happens. Most publishers will never sign a licensing deal with the companies that use their work in AI products, and no company can negotiate with millions of sites. The web needs a way to say “yes, if you pay.” Pay Per Use is one way to say it, and it's now in beta. AI blog CLOUDFLARE

3.10.26

Spetsvuzavtomatika Leak Exposes an SVR Cyber Development Ecosystem The Spetsvuzavtomatika leak found on the darknet exposes a broad Russian cyber research and development program, with seven named projects defining its work. Two of the projects, Felix-23 and HAD, focus on target discovery, scanning, enrichment, and active testing. Another project, Putnik, supports internal-network access and credential theft. CyberCrime blog DomainTools Investigations

3.10.26

AI Security Strategy: 6 Steps for CISOs Security teams are used to vetting technology before it arrives. With AI, it was already everywhere before anyone asked them. AI blog Abnormal AI

3.10.26

Signatures Are the Floor, Not the Ceiling See why signature-based detection struggles against AI-generated attacks and how behavioral AI uses embeddings to detect novel threats without relying on known indicators. AI blog Abnormal AI

3.10.26

How Behavioral AI Detects Threats That Look Normal Attackers are no longer breaking in but blending in, mimicking normal behavior to breach organizations. A founding Abnormal AI engineer explains why we bet on behavioral AI to stop attackers walking through the front door. AI blog Abnormal AI

3.10.26

XCTDH Adopts Hash Hiding A blockchain-based C2 technique discovered in the XCTDH campaign's September 2026 evolution, where C2 addresses are steganographically encoded in Ethereum transaction destination addresses. Cryptocurrency blog Ransom-ISAC

3.10.26

September 2026 Security Release An attacker-controlled, allow-listed remote URL can lead to Server-Side Request Forgery (for example to private IP ranges) during Image Optimization. If no images.remotePatterns are configured, your application is not affected. Security blog Next.js

3.10.26

Beyond Model Alignment: Securing Every Layer of the AI Agent Alignment makes a model well-intentioned, but it can’t secure the harness, tools, and data an agent touches in production. Real agent security means governing every layer with enforcement the agent itself can’t switch off. AI blog Trend Micro

3.10.26

ShinyHunters Returns to PeopleSoft With a One-Character WAF Bypass ShinyHunters is once again exploiting a previously patched vulnerability in PeopleSoft, which we analyzed in June 2026. Incident blog Trend Micro

3.10.26

Sckit Supply Chain Worm Hits MemTensor npm & PyPi scopes Compromised MemTensor npm releases turn an AI memory plugin into a credential-harvesting entry point, exposing prompts and creating a path to further package compromise. Malware blog StepSecurity

3.10.26

Managing Agentic AI: Why the Control Plane Problem Is an AI Problem On one hand, it’s somewhat befuddling how often people may need that reminder. In reality, it is not that they don’t know that happy mantra, it’s that they struggle to gain the requisite visibility into … everything in their IT and OT environments. AI blog GUIDESECURITY

3.10.26

Cloud Security Assessments: Set the Right Cadence While cloud practitioners are accustomed to their fast-moving environments, it’s still common practice to move on to the next priority after the cloud assessment report is delivered and the major findings get remediated. Cyber blog GUIDESECURITY

3.10.26

New Report from Rapid7 Labs: Why Q2 2026 signals the end of traditional patch cycles The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compress the time between disclosure and exploitation. The gap that patch cycles were built to fill is closing. Speed and volume are overwhelming security teams that have relied on traditional patch cycles and reactive programs. Cyber blog RAPID7

3.10.26

Why One-Time Approval Fails for AI Agent Skills A review answers one question, once: is this skill, MCP server or plugin allowed in? It never asks again, whether it took six weeks in a ticket queue or six minutes in a governance tool. AI blog Manifold

3.10.26

Spanish Carding Tutorial: How Fraudsters Think A 2,200-word tutorial titled “Complete Guide to Carding in Spain (2026)” appeared on the Carder Market forum in April 2026. It is exactly what it sounds like: a beginner’s playbook for credit card fraud targeting the Spanish market, complete with entry fees, expected returns, and step-by-step operational workflows (we are holding back specific names and techniques to execute attacks to prevent these from falling into those with malicious intentions). CyberCrime blog FLARE.IO

3.10.26

Revenge of the SD-WAN: Exploring and Exploiting Yet Another Critical Cisco SD-WAN Vulnerability (CVE-2026-76504) On Wednesday, September 30, Cisco dropped an out-of-band security advisory highlighting CVE-2026-76504, a brand new critical authentication bypass in the SD-WAN vManage line of products that was disclosed as an exploited zero-day vulnerability. Vulnerebility blog VULNCHECK

3.10.26

JCTables for Joomla: When "Already Escaped" Means Injectable Today VulnCheck is disclosing CVE-2026-76570, an unauthenticated arbitrary SQL read and write in JCTables, the Joomla data-table component published by JoomCode, that chains to remote code execution as the web user. It is being disclosed in accordance with VulnCheck's coordinated vulnerability disclosure policy. Vulnerebility blog VULNCHECK

3.10.26

CVE-2026-86950: Apple CoreGraphics Zero-Day Apple has issued an urgent security patch for CVE-2026-86950, a critical zero-day out-of-bounds write vulnerability in CoreGraphics that enables arbitrary code execution via malicious files. Exploited in targeted, highly sophisticated attacks against specific individuals, this flaw presents an immediate threat across affected Apple platforms. Vulnerebility blog SOCRADAR

3.10.26

CVE-2026-76504: Cisco SD-WAN Flaw Exploited Cisco has disclosed CVE-2026-76504, a critical authentication bypass vulnerability in Catalyst SD-WAN Manager, formerly known as vManage. The flaw allows an unauthenticated remote attacker to access the management API with administrator privileges. Vulnerebility blog SOCRADAR

3.10.26

TeamViewer Fixes Five Remote Access Flaws TeamViewer has patched five high-severity vulnerabilities in its Full Client and Host applications for Windows, Linux, and macOS. The flaws include local privilege escalation, potential code execution, and remote session access control bypass. The company strongly recommends that all users update to the latest available version as soon as possible. Vulnerebility blog SOCRADAR

3.10.26

Gotta Breach 'Em All! The Journey Of ShinyHunters ShinyHunters has outlasted forum takedowns, multiple arrests, and its own founders' convictions. This report traces six years of activity and tactical evolution. From stolen S3 buckets to zero-day exploits, we attempted to explain why the brand keeps surviving what should have ended it. Cyber blog SEKOIA

3.10.26

The New Rules of Patching: When a Fix Becomes a Blueprint for Attackers TL;DR: Frontier AI has collapsed the vulnerability exploit window from weeks to mere hours. Attackers now use advanced AI models to reverse-engineer published fixes and generate working exploits faster than human security teams can deploy updates. In the AI era, publishing a patch creates a blueprint for attackers. Surviving this threat requires vendors to tier sensitive disclosures and customers to treat patch application speed as a critical security metric. AI blog JFROG

3.10.26

ANY.RUN's Threat Coverage Digest: September 2026 September saw an expansion of detection coverage across network, file, and behavioral activity, providing analysts with additional visibility into suspicious activity. ANY.RUN added 76 behavior signatures, 16 YARA detections, and 1,098 Suricata rules, strengthening coverage across malware activity, suspicious files, and network communications. Cyber blog ANYRUN BLOG

3.10.26

Copilot has the largest AI attack surface of any tool we tracked Microsoft Copilot accounts for a disproportionate share of the AI footprint we track, and it’s barely being used. It’s a massive attack surface featuring a minuscule rate of activity. AI blog ThreatDown

3.10.26

Milk Dragon: Huge Discounts on Social Media? Think Twice Before You Buy Milk Dragon, also known as NaiLong is an Adversary-in-the-Middle (AiTM) phishing kit active since October 2025. Unlike conventional phishing tactics that rely on fear and urgency, Milk Dragon lures victims with big discounts on consumer goods distributed via Facebook and TikTok marketplace advertisements. Phishing blog GROUP-IB

3.10.26

Anatomía de BraZetsu: Cómo los cibercriminales abastecen el ecosistema clandestino Group-IB descubre BraZetsu, un nuevo malware para Windows basado en Python que funciona como un toolkit maestro para Initial Access Brokers y potencia un marketplace clandestino único, mejorado con IA, para comercializar objetivos comprometidos en Iberoamérica y Latinoamérica. Malware blog GROUP-IB

3.10.26

Your State’s Scam Reality: What New Research Reveals Across All 50 States A package notification arrives, and we stop to check whether we actually ordered something. A recruiter reaches out about a job, but before replying, we research the person and the company. A bank alert appears, and instead of tapping the link, we open the banking app ourselves. Spam blog McAfee Blog

3.10.26

ClickFix Attacks: How They Work and How CrowdStrike Stops Them Consider this hypothetical scenario: An employee tries to join what looks like a routine video meeting. The page loads, but instead of the meeting, they see an error message along with a helpful fix: Copy the provided command, open the Windows Run dialog, paste it, and press Enter. Hacking blog CROWDSTRIKE

3.10.26

CrowdStrike Expands Federal SOC Modernization via CISA-Funded SIEMaaS Falcon Next-Gen SIEM is now part of CISA’s SIEMaaS technology stack, which gives eligible agencies a funded path to modernize security through the CDM DEFEND F shared service. Cyber blog CROWDSTRIKE

3.10.26

CrowdStrike and NVIDIA Extend Security Across the AI Stack CrowdStrike and NVIDIA are collaborating on the NVIDIA Open Agent Safety Platform, an open reference design to extend security deeper into the agentic stack and establish stronger boundaries for autonomous AI. AI blog CROWDSTRIKE

3.10.26

Citrix NetScaler vulnerabilities (CVE-2026-88771, CVE-2026-88772) in active exploitation On September 27, 2026, Citrix disclosed eight vulnerabilities affecting NetScaler Application Delivery Controller (ADC) and NetScaler Gateway. Two of these vulnerabilities are critical (CVSS score of 9.5) and can allow an unauthenticated remote attacker to execute code: Vulnerebility blog SOPHOS

3.10.26

TerminalFix and Lorem Ipsum Loader enable covert tunneling The activity is linked to a broader campaign that previously used a different delivery mechanism CyberCrime blog SOPHOS

3.10.26

GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond. AI blog Google Cloud Blog

3.10.26

NVIDIA and Eclypsium Partner for Trusted AI Infrastructure AI agents are moving from answering questions to taking action. They can read sensitive data, call APIs, write and execute code, use external tools, and coordinate with other agents. In some environments, their decisions may affect physical systems. AI blog Trend Micro

3.10.26

Inside DragonForce: How a Ransomware Cartel's Payload Actually Runs DragonForce is a Ransomware-as-a-Service (RaaS) operation that first surfaced in mid-to-late 2023. It initially presented itself as a hacktivist collective before shifting to a profit-driven model. Early payloads were built on leaked LockBit 3.0 source code and later supplemented with code derived from the leaked Conti builder. Ransom blog Seqrite

3.10.26

Telecom Attack Surface: SS7, BGP & Nation-State Intrusions SS7 and BGP were built on trust. Here's how nation-state actors exploit that trust, and telecom routers, to stay inside carrier networks for years. Hacking blog Cyble

3.10.26

Attack Surface Management 2026: Why Point-in-Time Scans Fail Quarterly scans leave cloud exposures hidden for months. Learn why CISA and FBI data now make continuous attack surface management essential in 2026. Cyber blog Cyble

3.10.26

Your IP, Their Traffic You install an app that offers a reward, a premium feature or perhaps a little money in exchange for sharing some of your unused internet bandwidth. It sounds harmless enough. Your connection is idle most of the time anyway. Cyber blog GENDIGITAL

3.10.26

Warlock Ransomware Attackers Hit Water and Telecom Operators China-nexus group behind Warlock is still exploiting SharePoint vulnerabilities, attacking organizations in Portuguese and Spanish-speaking countries, hitting critical infrastructure, government, and education organizations. Ransom blog SECURITY.COM

3.10.26

Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 Microsoft Threat Intelligence identified and tracked exploitation of CVE-2026-73570, an unauthenticated OS command injection vulnerability in the Zimbra Collaboration Suite SNMP notification path. Exploitation can be triggered by a specially crafted email against internet-facing Zimbra servers when the optional zimbra-snmp package is installed and SNMP notifications are enabled, without requiring authentication or user interaction. Vulnerebility blog Microsoft blog

3.10.26

Phishing Abuses RMM Tools for Persistent Access In July 2026, Microsoft Defender Experts observed phishing campaigns targeting organizations across multiple industries that distributed a masqueraded MSP360 Remote Monitoring and Management (RMM) installer through meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content. Phishing blog Microsoft blog

3.10.26

Safely Securing AI Agents Learn of the benefits of safely securing AI agents. AI blog Trend Micro

3.10.26

IBM Langflow OSS Unauthenticated RCE - CVE-2026-9198 The SonicWall Capture Labs threat research team became aware of an Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation in Langflow AI, assessed its impact and developed mitigation measures. Langflow AI is a Python-based web application that provides a visual interface to build AI-driven agents and workflows. Vulnerebility blog SonicWall

3.10.26

SmokeLoader Malware: A Modular Threat with Advanced Evasion and Persistence This week, the SonicWall Capture Labs Threat Research Team reviewed a sample of SmokeLoader malware. This is a modular program used by a variety of criminal and APT groups to gain a foothold on a system. It has vigorous anti-VM, anti-AV, and anti-analysis checks and capabilities. SmokeLoader can be used with RATs, ransomware, backdoors or botnets and uses both file and fileless methods of persistence. Malware blog SonicWall

3.10.26

VioletRAT v6.5: From .NET Loader to In-Memory RAT — A Deep Dive into the Infection Chain Recently, the SonicWall Capture Labs Threat Research Team discovered a sophisticated multi-stage .NET malware campaign that delivers VioletRAT v6.5 through a heavily obfuscated infection chain. The malware uses multiple .NET loader stages, an obfuscated batch script, in-memory assembly loading, and process injection into Msbuild.exe before executing the final VioletRAT payload. Malware blog SonicWall

3.10.26

OperTraitors: How Kubernetes Operators Betray Your Security Posture Kubernetes operators are coded to drastically reduce operational toil by acting as automated site reliability engineers. However, their reliance on highly privileged service accounts introduces a severe, often overlooked security weak spot. Hacking blog Palo Alto

3.10.26

Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30) Unit 42 is aware of possible zero-day activity against NetScaler devices. In a Citrix report that details several CVEs, they noted that CVE-2026-88771 and CVE-2026-88772 have been exploited in the wild. The threat actors exploited these vulnerabilities to deliver web shells and establish their initial access and persistence into organizations. Analysis is ongoing to determine any post-compromise activity. Vulnerebility blog Palo Alto

3.10.26

The Fine Art of Frustrating the Adversary For Cybersecurity Awareness Month, eight Cisco Talos researchers share practical ways defenders can frustrate adversaries at different stages of an operation. Cyber blog CISCO TALOS

3.10.26

Give yourself room to be human Fall is officially here in Maryland, and I can’t be more relieved. I flourish in 50 degree weather, where it feels natural to burrow under blankets, knit sweaters, and listen to an audiobook. Cyber blog CISCO TALOS

3.10.26

China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts. APT blog CISCO TALOS

3.10.26

Securing the keys to the kingdom: Announcing Executive Threat Detection Attackers are using greater sophistication to gain access to high-yield targets like executives, and company-wide security measures can easily miss these subtle, personal attacks. Cyber blog CISCO TALOS

3.10.26

Trust and the enticing consultancy offer In the cybersecurity industry, trust is the invisible currency. Every practitioner carries the implicit trust not to abuse privileged access or knowledge of vulnerabilities in each employment or engagement. This trust is valued by those who require our services, but also by threat actors. Vulnerebility blog CISCO TALOS

3.10.26

The Closed Quorum: Inside the first reported autonomous AI C2 implant CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). While we do not have confirmation of in-the-wild deployment, artifacts from the binary were used to connect the developer to postings on criminal forums related to carding, dating back to 2025. AI blog CISCO TALOS

3.10.26

This month in security with Tony Anscombe – September 2026 edition Autonomous AI agents go on a hacking spree, and Microsoft ships what used to be a year's worth of security patches in one go – here's how to keep pace Cyber blog Eset

3.10.26

Timeshare exit scams: From fake buyers to recovery scams Con artists are targeting timeshare owners who want out – and some victims are hit twice Spam blog Eset

3.10.26

The devil is still in the email – but wearing a new mask When phishing can increasingly pass familiar checks, avoiding or limiting the damage depends on how quickly your company can detect and contain the attack Spam blog Eset

3.10.26

Is that new (vibe coded) app safe? 5 questions to ask first As AI lets anyone build software, here’s how to vet that shiny new app before it exposes your data Cyber blog Eset

2.10.26

Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by Vulnerebility The Hacker News

2.10.26

OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street AI The Hacker News

2.10.26

Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as OS The Hacker News

2.10.26

Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Exploit The Hacker News

2.10.26

Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data CyberCrime The Hacker News

2.10.26

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure Virus The Hacker News

1.10.26

OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates OpenAI on Wednesday said it identified and disrupted a coordinated distillation campaign that was designed to illicitly extract protected reasoning from its artificial intelligence (AI) models. AI The Hacker News

1.10.26

CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Exploit The Hacker News

1.10.26

Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon , that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program. AI The Hacker News

1.10.26

US soldier gets 70 months in prison for extorting 10 tech, telecom firms A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024. CyberCrime BleepingComputer

1.10.26

CISA orders feds to patch exploited Citrix flaws by Wednesday The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities. Exploit BleepingComputer

1.10.26

OpenAI is preparing “o,” an always-on ChatGPT assistant that could handle email OpenAI is testing a new always-on assistant called "o", and references to the unannounced feature briefly showed up on the company's website. AI BleepingComputer

1.10.26

Citrix confirms two NetScaler RCE zero-days exploited in attacks Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws. Exploit BleepingComputer

1.10.26

Cloudflare fixes Containers cross-tenant flaw exposing customer data Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers' containers on the same physical host. Vulnerebility BleepingComputer

1.10.26

Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path Security researchers have published the first public proof-of-concept for CVE-2026-86950 , an Apple CoreGraphics flaw Apple says may have been Social The Hacker News

1.10.26

Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party Cryptocurrency The Hacker News

1.10.26

MetaMask Security Incident Prompts Exit of Affected Ethereum Validators MetaMask on Thursday said it's responding to what it described as an "ongoing security incident" impacting part of its infrastructure. "We are Cryptocurrency The Hacker News

1.10.26

Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data. Exploit The Hacker News