2026-10-09 13:56 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-09 14:20 UTC
Anthropic launches free OSS Scanner, using AI to find open-source vulnerabilities and help maintainers fix bugs before attackers exploit them. Anthropic is launching OSS Scanner, a vulnerability scanner for open-source code that costs nothing for projects to join. It grew directly out of lessons learned running Claude against real-world targets during Project Glasswing. The backdrop […]
P0
2026-10-09 13:50 UTC
Security Journalism
The Record · indexed 2026-10-09 14:05 UTC
A Latin American propaganda operation run by Russians and a cluster of Iranian fake journalist identities each had help from now-closed ChatGPT accounts, OpenAI's safety team said.
P0
2026-10-09 13:22 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 14:35 UTC
Four more U.S. states sued router maker TP-Link Systems on October 6, bringing the total to five, with Texas filing a suit in February. Florida, Iowa, Montana and Nebraska allege the California company misled buyers about how secure its routers are and how separate it is from China. TP-Link denies the claims and says it will fight them in court. TP-Link Systems is based in
P0
2026-10-09 13:00 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-10-09 13:10 UTC
As AI agents gain authority over business systems, attackers can manipulate them like business email compromise (BEC) victims.
P0
2026-10-09 12:59 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 14:35 UTC
Security researchers have published a full working exploit for a pre-authentication remote code execution flaw in AnyDesk Linux that gives attackers root access before anyone approves the connection. AnyDesk patched the flaw in version 8.0.3 in June, but its changelog described the fix only as "fixed a bug that could lead to a crash," with no CVE assigned and no security
P15
2026-10-09 12:47 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 14:35 UTC
Anthropic on Thursday unveiled OSS Scanner as an opt-in vulnerability scanner to help secure the open-source ecosystem using artificial intelligence (AI). "It's an opt-in service informed by our experience using Claude to find vulnerabilities during Project Glasswing," Anthropic said. "Projects that join will receive thorough, periodic security scans by our strongest models at no cost."
P0
2026-10-09 12:47 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 14:35 UTC
Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners. Details of the flaws are below - CVE-2026-105133 (CVSS v4 score: 5.5) - An improper authentication vulnerability in the checkSysPwd() function in the "com/ahsay/obs/api/ApiStructsAction.java"
P5
2026-10-09 12:32 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-09 12:45 UTC
Attackers are exploiting a maximum-severity vulnerability in SonicWall SMA1000 appliances (CVE-2026-102255) that was patched on Tuesday, three days ago. [...]
P25
2026-10-09 12:21 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 12:55 UTC
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their abuse by a China-linked threat actor known as Flax Typhoon. The vulnerabilities in question are listed below - CVE-2015-3306 (CVSS score: 10.0) - An improper access control vulnerability in ProFTPD that could allow
P35
2026-10-09 12:03 UTC
Security Journalism
Security Week · SecurityWeek News · indexed 2026-10-09 12:10 UTC
Noteworthy stories that might have slipped under the radar: Tensorlake npm SDK compromised, Empire Market co-founder gets 40 years, exposed NVIDIA GPU monitors leak telemetry. The post In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 Years appeared first on SecurityWeek.
P0
2026-10-09 11:43 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-09 11:50 UTC
Hackers hijacked the .gh, .sl, and .as ccTLDs and obtained HTTPS certificates for several Google domains. The post Google Domains Impacted by Recent ccTLD Hijacks appeared first on SecurityWeek.
P0
2026-10-09 11:30 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 11:40 UTC
As enterprises race to deploy autonomous AI agents to accelerate business, a new report reveals they are tethered to security architectures built for a different era. The "Horizons of Identity Security" report from SailPoint highlights a critical “velocity paradox,” in which organizations invest in AI-speed business operations while continuing to rely on human-speed security controls, creating a
P0
2026-10-09 11:14 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-09 11:25 UTC
A Ukrainian-Russian dual citizen has pleaded guilty to running a massive money laundering operation that laundered millions for cybercriminals worldwide. [...]
P0
2026-10-09 11:00 UTC
Vendor Research
Rapid7 · The Metasploit Team · indexed 2026-10-09 11:30 UTC
P0
2026-10-09 10:49 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-09 10:50 UTC
DOJ and FBI seized China-linked hacking tools Microscan and FishHub, linked to Integrity Tech and attacks on critical infrastructure worldwide. The Justice Department and FBI took down two hacking tools this week, Microscan and FishHub, both built and run by a Beijing-based company with direct government contracts. The tools were used to scan, and in […]
P0
2026-10-09 10:23 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-09 10:30 UTC
The flaws, CVE-2026-105133 and CVE-2026-105134, allow attackers to bypass authentication and inject OS commands. The post Unpatched AhsayCBS Vulnerabilities Exploited in the Wild appeared first on SecurityWeek.
P25
2026-10-09 10:12 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-09 10:20 UTC
Microsoft says devices running unsupported versions of Windows will stop receiving security updates after next year's Windows Update certificate rotation. [...]
P5
2026-10-09 10:04 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-09 10:50 UTC
Citrix patched CVE-2026-107406, a critical NetScaler ADC and Gateway flaw that could allow remote code execution or denial-of-service attacks. Citrix has released security updates to fix CVE-2026-107406 (CVSS score of 9.5), a critical flaw affecting NetScaler ADC and NetScaler Gateway that could allow remote code execution or denial-of-service (DoS) under certain conditions. The vulnerability is […]
P30
2026-10-09 09:55 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-10-09 10:10 UTC
Midnight Mimosa is the name given to a malware campaign primarily running preinstalled on low-cost Android devices. The post Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries appeared first on SecurityWeek.
P0
2026-10-09 09:03 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 09:55 UTC
A bug in GoBalance, a tool many dark-web sites use to stay reachable during attacks, lets anyone work out the secret key that controls a site's .onion address using only public information, and then take that address over. Searchlight Cyber, which disclosed the flaw on October 8, says an attacker who recovers the key can redirect the site's visitors to a copy of the site they control.
P0
2026-10-09 08:36 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-09 08:50 UTC
Flax Typhoon and other APTs used MicroScan and FishHub to scan and hack US and foreign critical infrastructure. The post US Disrupts Chinese State-Sponsored Hacking Tools appeared first on SecurityWeek.
P0
2026-10-09 08:27 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-09 08:40 UTC
Citrix has warned IT administrators to patch systems immediately against a new critical vulnerability affecting NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions. [...]
P25
2026-10-09 08:26 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 09:55 UTC
Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched. The contest pays researchers to show working exploits and passes the flaws to the vendors. One of the three Pixel exploits earned Ikotas Labs $300,000, the contest's top prize, and made the team the overall winner. Trend Micro's Zero
P0
2026-10-09 08:19 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-10-09 08:30 UTC
OSS Scanner sends unreviewed, model-generated vulnerability reports to open source maintainers that opt in. The post Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT Security appeared first on SecurityWeek.
P0
2026-10-09 08:11 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 09:55 UTC
Citrix has released patches for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions. "CVE-2026-107406 is a memory overflow vulnerability that may lead to remote code execution or denial-of-service under specific configuration conditions," Citrix said. The vulnerability
P20
2026-10-09 07:53 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-09 08:30 UTC
CrowdStrike analyzes open directories left by an attacker who used the ARTEX AI pentest tool and LLMs to breach South Korean financial firms. CrowdStrike published a research on a campaign against South Korean financial organizations that ran from late September to early October 2026 and ended with stolen data. The attacker left their working notes […]
P0
2026-10-09 07:52 UTC
Community
SANS Internet Storm Center · indexed 2026-10-09 08:00 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-10-09 07:00 UTC
Other
Group-IB · indexed 2026-10-09 08:00 UTC
Agentic AI is the breakthrough of the moment, in security as everywhere else: agents that are threat-aware, active, and proactive in investigation. But it is also the technology behind a recent documented autonomous AI intrusion. Both facts are true, and the distance between them is what this article is about.
P0
2026-10-09 06:53 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-09 07:10 UTC
The security defect, tracked as CVE-2026-107406, could lead to remote code execution or denial-of-service. The post Citrix Urges Immediate Patching of Critical NetScaler Vulnerability appeared first on SecurityWeek.
P20
2026-10-09 06:39 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-10-09 06:50 UTC
$1.2 million was paid out at Pwn2Own Ireland 2026 for exploits targeting phones, printers, smart speakers, smart home hubs, and AI infrastructure and coding tools. The post Google Pixel 10 Exploits Earned Hackers $560,000 at Pwn2Own appeared first on SecurityWeek.
P0