2026-10-09 07:00 UTC
Other
Group-IB · indexed 2026-10-09 08:00 UTC
Agentic AI is the breakthrough of the moment, in security as everywhere else: agents that are threat-aware, active, and proactive in investigation. But it is also the technology behind a recent documented autonomous AI intrusion. Both facts are true, and the distance between them is what this article is about.
P0
2026-10-09 06:39 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 06:55 UTC
The U.S. Federal Bureau of Investigation (FBI) and Department of Justice (DoJ) have announced the disruption of malicious tools used by a China-linked advanced persistent threat group known as Flax Typhoon. To that end, the agencies seized several domains and blocked access to platforms that were used to scan, and in some cases infiltrate, U.S. critical infrastructure. The list of seized
P0
2026-10-08 16:57 UTC
Security Journalism
The Record · indexed 2026-10-08 17:15 UTC
The company said its investigation, carried out with external experts, found the attackers had accessed “some personal information, including names and contact details, and certain non-personal account related information.”
P0
2026-10-08 16:52 UTC
Community
SANS Internet Storm Center · indexed 2026-10-08 17:10 UTC
We just did a major update to FOR577 and added a lot of new material on day 5 about investigating AI usage in incident response. In the new material we dicsuss 8 of the most popular AI coding assistants and agents including Claude Code, Codex, Gemini CLI, Cursor, Copilot, Warp, Windsurf, and Qwen Code. I've been using Claude Code and a little bit of Codex, but I also have recently been playing with OpenCode and am setting up Hermes. I decided t…
P0
2026-10-08 12:50 UTC
Vendor Research
Tenable Blog · Robert McSulla · indexed 2026-10-08 13:10 UTC
Community-built AI agents, skills, and MCP servers are landing in SOC workflows fast. Here’s what the Exchange Inspector tests before a listing earns its vetted tag on the CyberAgents Exchange. Three tools have already passed.Key takeawaysEvery Inspector-vetted listing clears three gates: an automated check, a frontier model assessment, and human verification. Tenable uses Tenable One AI Exposure to screen for prompt injection and exposed secrets, and OpenAI GPT Cyber models to assess the code …
P0
2026-10-07 19:29 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-10-07 19:50 UTC
In Part 1 of this series, we looked at the security challenges created by fragmented, campus-by-campus environments. Higher education also faces a second pressure that makes that fragmentation harder to sustain: overlapping compliance obligations across FERPA, GLBA, HIPAA, and CMMC.Each framework brings different requirements, reporting timelines, and consequences for failure. Managing them across one institution is already complex, but across a multi-campus university system with separate tool…
P15
2026-10-07 18:31 UTC
Security Journalism
The Record · indexed 2026-10-07 18:45 UTC
The investigation into the incident revealed cybercriminals were able to breach the Fines/Fees and Restitution Enforcement (FARE) Program, a statewide program that helps the court collect outstanding debts tied to traffic and criminal violations.
P0
2026-10-07 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-09-30 16:25 UTC
On October 7, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables. To remediate the vulnerabilities that were disclosed on October 7, 2026, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the Foundation: A Predictable, Customer-Focused Response to AI-Accelerated Vulne…
P20
2026-10-07 12:11 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-10-07 12:30 UTC
OverviewOn October 5, 2026, Atlassian published a security advisory for CVE-2026-21589, a critical arbitrary file access vulnerability affecting eight products: Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian assigned the vulnerability a CVSSv4 score of 9.3. An unauthenticated remote attacker who knows a target file's exact name and path can access it within the…
P5
2026-10-07 11:56 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 12:20 UTC
The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. "The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat
P0
2026-10-07 10:40 UTC
Vendor Research
Rapid7 · Emma Burdett · indexed 2026-10-07 10:50 UTC
This week, ASOS customers opened their phones to find a hostile push notification delivered through the retailer’s own app. The message claimed the company’s Snowflake environment had been compromised and directed ASOS to engage with the sender through Telegram. ASOS later confirmed to Sky News that an unauthorized customer notification had been sent and said it was investigating activity involving third-party platforms used to communicate with customers. The company also said basic personal in…
P0
2026-10-07 07:50 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-07 08:40 UTC
Wikimedia found unauthorized OpenAI agent activity on its platforms, including unapproved edits, proxy attempts and millions of automated API requests. Wikimedia ran its own investigation after other organizations started reporting rogue AI agents breaking into websites, and the answer came back yes, it happened here too. The foundation found unauthorized bot activity tied to OpenAI […]
P0
2026-10-07 07:30 UTC
Vendor Research
ANY.RUN Blog · ANY.RUN · indexed 2026-10-07 07:50 UTC
US SOC teams are under pressure to detect and contain threats faster, but the real challenge is often not a lack of security solutions. It’s the growing amount of alerts, fragmented investigation data, evasive attack techniques, and the time analysts spend connecting the dots. As attacks become harder to validate and easier to hide inside […] The post 5 Critical Pain Points of Modern US SOCs and How to Solve Them appeared first on ANY.RUN's Cybersecurity Blog.
P0
2026-10-06 14:11 UTC
Vendor Research
Rapid7 · Umair Mazhar · indexed 2026-10-06 14:20 UTC
As organizations deploy autonomous AI agents, security teams face a significant shift as non-human non-human entities making decisions, invoking tools, and delegating tasks to other agents without human intervention. Security architectures built around human users, static APIs, and distinct endpoints break down when AI agents dynamically collaborate across an environment. As these interactions become more common, securing agent-to-agent communication without blocking adoption will require secur…
P10
2026-10-06 09:27 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-06 09:40 UTC
Accenture lost an FBI contract after a missed security patch exposed sensitive employee data, raising serious concerns over operational security. The FBI pulled an Accenture contractor off its account on Monday, and the reason is almost mundane compared to the damage it caused. One update didn’t get installed on time. “The Federal Bureau of Investigation […]
P0
2026-10-06 06:56 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-06 07:40 UTC
The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the theft of personal details of thousands of bureau employees. That's according to a report from Reuters, citing two sources familiar with the matter. "To date, our review has determined that the incident occurred as the result of a security failure
P0
2026-10-05 21:41 UTC
Vendor Research
AWS Security Blog · Alexander Greaves-Tunnell · indexed 2026-10-05 21:50 UTC
As AI models become more capable, they uncover more security vulnerabilities and identify increasingly sophisticated paths to exploit them, raising the bar for how quickly defenders must respond. Security teams now face more potential vulnerabilities than their existing processes were designed to handle — each requiring investigation, reproduction, and a repair that must be tested […]
P0
2026-10-04 07:22 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-04 07:45 UTC
A suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter. Rey, whose real name is Saif al-Din Khader, is said to have been brought into custody on September 29, 2026, and cooperating with the U.S. Federal Bureau of Investigation (FBI)
P0
2026-10-02 12:23 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-02 12:45 UTC
OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported. "We have parted ways with three individuals for violating our policies on accessing and handling sensitive company information," a spokesperson for the company was quoted as saying. "Our investigation confirmed that these
P0
2026-10-01 21:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
See how the Huntress SOC runs security incident investigations from first signal to final resolution, including the ones closed as benign.
P0
2026-10-01 13:13 UTC
Vendor Research
ANY.RUN Blog · ANY.RUN · indexed 2026-10-06 14:56 UTC
September saw an expansion of detection coverage across network, file, and behavioral activity, providing analysts with additional visibility into suspicious activity. ANY.RUN added 76 behavior signatures, 16 YARA detections, and 1,098 Suricata rules, strengthening coverage across malware activity, suspicious files, and network communications. These updates provide SOC and MSSP teams with additional evidence during investigations, […] The post Threat Coverage Digest: New Malware Reports and 1,1…
P0
2026-10-01 13:00 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-10-01 13:20 UTC
As AI takes on more of the enrichment, correlation, and initial assessment inside the SOC, roles, skills, and KPIs still require deliberate redesign. Security leaders need to decide where automation is dependable, where human judgment should remain decisive, and how teams should be measured when alert handling is no longer the center of the operating modelThe Gartner® report, The Roles Required for the AI-Enabled Security Operations Center (SOC), examines the roles and capabilities Gartner expe…
P0
2026-10-01 05:21 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 05:55 UTC
Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist. "Their investigation identified malicious activity involving third-party security products, including a zero-day vulnerability, and recovered a customized tool used by the attacker
P25
2026-09-30 23:43 UTC
Security Journalism
Security Week · Associated Press · indexed 2026-09-30 23:50 UTC
An FTC spokesperson confirmed the investigation but declined further comment. The post FTC is Investigating OpenAI and Anthropic Over Possible Risks to Consumers appeared first on SecurityWeek.
P0
2026-09-30 14:16 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-09-30 15:05 UTC
Higher education faces a difficult security equation. Universities hold large volumes of sensitive student, financial, health, and research data while supporting open networks, distributed users, legacy infrastructure, and increasingly complex cloud environments. Attackers have taken notice, and the pressure on security teams continues to grow.In Q2 2025, universities faced an average of 4,388 cyberattacks per organization per week, up 24% from the same period in 2024. Nine in ten universities …
P40
2026-09-30 13:26 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-30 14:25 UTC
DOJ charges against Oxygen Forensics reveal the Russian-linked firm also sold forensic software to EU projects and European police forces for years. Last week’s Justice Department indictment of Oxygen Forensics looked, at first, like an American procurement scandal. CEO Lee Reiber and Russian co-founder Oleg Davydov stand accused of hiding that the company was Russian-owned […]
P0
2026-09-30 09:51 UTC
Vendor Research
ANY.RUN Blog · ANY.RUN · indexed 2026-10-06 14:56 UTC
Phishing investigations put pressure on SOC teams at several points at once: analysts need to uncover hidden activity, make a confident decision from incomplete evidence, prepare the case for escalation, and then determine whether the threat extends beyond a single incident. Every manual step adds time to the response. It also ties up analyst capacity […] The post Phishing Response Protocol: 3 Essential SOC Steps Powered by ANY.RUN’s Latest Updates appeared first on ANY.RUN's Cybersecurity Blog.
P0
2026-09-29 11:01 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-29 11:20 UTC
Pepijn van der Stap was convicted in 2023 for hacking multiple organizations, stealing their data, and extorting them. The post Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation appeared first on SecurityWeek.
P0
2026-09-29 08:35 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-29 09:50 UTC
Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. "It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters," the Politie Landelijke Opsporing en Interventies said in an X post Monday. Police said the individual is expected to appear before the
P0
2026-09-29 07:30 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-29 08:10 UTC
Dutch police confirm the arrest of a 24-year-old Amsterdam man as part of an investigation into the ShinyHunters hacking group. Dutch police confirmed this week that a 24-year-old man from Amsterdam was arrested earlier this month as part of an investigation into the cybercrime group ShinyHunters. The suspect appears before Rotterdam District Court today, September […]
P0