2026-10-05 09:37 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-05 09:45 UTC
Microsoft confirmed over the weekend that some games and applications using AC-3 (Dolby Digital) audio decoding will crash after installing the September 2026 KB5124010 Windows 11 preview update. [...]
P0
2026-10-05 09:12 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-05 09:20 UTC
MI5 warns UK universities that over 100 academics may have unknowingly worked on research funded by a Chinese institute linked to the MSS. On September 30, MI5 published a formal warning naming the China General Technology Research Institute, CGTRI, also called CAGT in some translations, as an outfit with very strong ties to China’s Ministry […]
P0
2026-10-05 08:33 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-05 09:20 UTC
Iranian hacker Amir Barati faces extradition to the US over an alleged Iranian campaign that stole 31TB of data from universities. Amir Barati spent June 25 getting arrested in Montenegro, and this week a Montenegrin court signed off on sending him to the United States. He’s a dual Turkish and Iranian citizen, 40 years old, […]
P0
2026-10-05 08:27 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-05 08:30 UTC
Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports. [...]
P0
2026-10-05 08:09 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-05 09:30 UTC
A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and
P20
2026-10-05 07:30 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-05 08:25 UTC
OpenAI safety veteran David Robinson resigns, warning that the company’s culture and fast AI development model could create bigger risks. OpenAI safety veteran David Robinson knows how his resignation looks. He starts his essay by calling himself “something of a cliché”: an AI company employee who quits and then raises concerns about the company. But […]
P0
2026-10-05 07:16 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-05 07:30 UTC
Known as Rey, the suspect is reportedly helping the FBI identify and locate other members of the extortion group. The post Alleged ShinyHunters Leader Arrested in Jordan appeared first on SecurityWeek.
P0
2026-10-05 06:40 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-05 08:00 UTC
Citrix has released security updates for a high-severity security flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0. "CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to
P30
2026-10-05 05:14 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-10-05 05:30 UTC
Citrix has confirmed that a new zero-day vulnerability, CVE-2026-88779, emerged just days after two other exploited flaws were patched. The post Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier appeared first on SecurityWeek.
P30
2026-10-05 02:00 UTC
Community
SANS Internet Storm Center · indexed 2026-10-05 02:15 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-10-05 00:15 UTC
Community
SANS Internet Storm Center · indexed 2026-10-05 00:25 UTC
For an experiment, I created a script [1] that parses and send the TTY logs collected from actors or bots activity that run various commands after they successfully login the DShield sensor. Those TTY logs are sent daily at the end of each day to the DShield SIEM [2] to be correlated with all the data. 
P0
2026-10-04 21:58 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-10-04 22:00 UTC
Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution. [...]
P65
2026-10-04 15:28 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-04 15:50 UTC
Security Affairs AI-CYBERSECURITY newsletter includes a collection of the best articles and research on AI in the international landscape Artificial intelligence is rapidly changing cybersecurity, reshaping both the techniques used by attackers and the tools available to defenders. AI agents can automate tasks, analyze large amounts of data, discover vulnerabilities and accelerate offensive operations. At […]
P0
2026-10-04 14:57 UTC
Security Journalism
Security Week · Associated Press · indexed 2026-10-04 15:10 UTC
The announcement comes after Trump hosted top executives of AI companies at the White House last week. The post Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force appeared first on SecurityWeek.
P0
2026-10-04 14:00 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-04 14:35 UTC
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Lunex Unmasked: A New Information Stealer Deployed Through BYOVD Storm-3168: Agentic-driven cloud attacks using compromised service principals Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties […]
P0
2026-10-04 13:41 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-04 14:35 UTC
A suspected ShinyHunters member arrested in Jordan is reportedly cooperating with the FBI, helping investigators track down the group. A suspected member of ShinyHunters, the group that claims to have stolen data on every FBI employee, was picked up in Jordan this week. The man is Saif al-Din Khader, detained by Jordanian authorities, with two […]
P0
2026-10-04 10:53 UTC
Security Journalism
BleepingComputer · Mayank Parmar · indexed 2026-10-04 11:00 UTC
Anthropic has started asking Claude users to voluntarily share their voice conversations to help train and improve its AI models. [...]
P0
2026-10-04 07:58 UTC
Community
SANS Internet Storm Center · indexed 2026-10-04 08:00 UTC
Sometimes I have to smile, or my interest is triggered, when I review new User Agent Strings in the honeypot logs.
P0
2026-10-04 07:58 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-04 09:00 UTC
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Fake Zoom installer hides macOS backdoor CloudSyncD CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed Antino Backdoor Lets […]
P5
2026-10-04 07:49 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-04 08:00 UTC
Warlock ransomware continues to exploit unpatched SharePoint flaws to breach water utilities, telecoms, governments, and universities worldwide. Warlock ransomware made headlines back in mid-2025 for exploiting a chain of SharePoint zero-days collectively dubbed ToolShell. More than a year later, the same group is still using that door, and it’s still getting in. Symantec tracks the […]
P40
2026-10-04 07:22 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-04 07:45 UTC
A suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter. Rey, whose real name is Saif al-Din Khader, is said to have been brought into custody on September 29, 2026, and cooperating with the U.S. Federal Bureau of Investigation (FBI)
P0
2026-10-04 07:20 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-04 07:45 UTC
A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations. The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at a
P0
2026-10-03 23:12 UTC
Security Journalism
BleepingComputer · Mayank Parmar · indexed 2026-10-03 23:15 UTC
Google's Gemini could soon access any file on your macOS device, open apps, browse the web, and perform actions without asking for permission every time. [...]
P0
2026-10-03 19:09 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-10-03 19:20 UTC
A suspected ShinyHunters hacking group member known online as "Rey" has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members of the extortion group. [...]
P0
2026-10-03 15:11 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-03 15:30 UTC
Jamf Threat Labs details CloudSyncD, a fake macOS Zoom installer that hides a phished password using invisible zero-width Unicode characters. Jamf Threat Labs found CloudSyncD while doing routine scanning on VirusTotal, buried inside a disguised Zoom client. They first spotted it on September 15, clearly still under construction, and within two days watched it move […]
P0
2026-10-03 14:40 UTC
Community
SANS Internet Storm Center · indexed 2026-10-03 14:50 UTC
YARA-X's 1.21.0 release brings 5 improvements and 4 bugfixes.
P0
2026-10-03 14:38 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-03 15:25 UTC
The U.K.'s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering efforts on behalf of Beijing's state security service. In a "Security Service Espionage Alert" issued on September 30, 2026, MI5 said the "primary purpose of the China General Technology Research Institute (CGTRI) 中国通用技术研究院 is to fund research that
P0
2026-10-03 14:36 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-03 15:25 UTC
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. "In the
P15
2026-10-03 14:35 UTC
Security Journalism
BleepingComputer · Ionut Ilascu · indexed 2026-10-03 14:45 UTC
The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data. [...]
P0
2026-10-03 11:45 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-10-03 12:00 UTC
doxx.net’s new ADN platform prevents agentic misadventure while the agent is operating under the user’s authority. The post doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures appeared first on SecurityWeek.
P0