2026-10-09 06:39 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 06:55 UTC
The U.S. Federal Bureau of Investigation (FBI) and Department of Justice (DoJ) have announced the disruption of malicious tools used by a China-linked advanced persistent threat group known as Flax Typhoon. To that end, the agencies seized several domains and blocked access to platforms that were used to scan, and in some cases infiltrate, U.S. critical infrastructure. The list of seized
P0
2026-10-09 05:41 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-09 05:50 UTC
The Pwn2Own Ireland 2026 hacking contest has concluded, with hackers collecting $1,262,000 in rewards after exploiting 98 zero-day flaws. [...]
P25
2026-10-09 04:12 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-10-09 04:20 UTC
Researchers from George Washington University have published a paper examining whether the time and cause of AI going rogue can be predicted. The post Formula Predicts When AI Chatbots Are at Risk of Turning Bad appeared first on SecurityWeek.
P0
2026-10-09 00:55 UTC
Security Journalism
The Record · indexed 2026-10-09 01:10 UTC
Raheim Hamilton, 30, pleaded guilty earlier this year to a drug conspiracy charge and agreed to forfeit more than $100 million worth of bitcoin and several properties in Virginia.
P0
2026-10-08 21:42 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-10-08 21:45 UTC
The FBI has seized seven domains used by Chinese state-sponsored hackers known as Flax Typhoon to operate two hacking tools, MicroScan and FishHub, used in attacks that breached critical infrastructure and other organizations worldwide. [...]
P0
2026-10-08 20:44 UTC
Vendor Research
Microsoft Security Blog · Microsoft Security Research, Lora Randolph, Tahmina Ahmad and Karina Sirota Goodley · indexed 2026-10-08 21:00 UTC
Prepare for post-quantum authentication by testing certificate ecosystems now. Learn how Microsoft’s PQC TLS Pilot Program helps advance future readiness. The post Post-quantum authentication: Why organizations should start testing certificate ecosystems now appeared first on Microsoft Security Blog.
P0
2026-10-08 20:39 UTC
Security Journalism
Dark Reading · Rob Wright · indexed 2026-10-08 21:10 UTC
A now-patched vulnerability in AWS Bedrock AgentCore could have allowed an attacker to use one AI chatbot to take over an organization's entire fleet.
P0
2026-10-08 20:27 UTC
Security Journalism
The Record · indexed 2026-10-08 20:40 UTC
The proposed sale would include about 100 million emails, 500 million Microsoft Teams messages, employment contracts, employee and timecard records and payroll and tax information, Rep. Steven Horsford (D-NV) said in a press release.
P0
2026-10-08 20:09 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-10-08 20:20 UTC
IDC Frontier, a major Japanese cloud and digital infrastructure company, disclosed that its IDCF Cloud service was targeted in a ransomware attack that caused an outage at a data center cluster serving the eastern part of the country. [...]
P15
2026-10-08 20:00 UTC
Security Journalism
Huntress · indexed 2026-10-09 07:50 UTC
Threat actors are exploiting AhsayCBS flaws, including CVE-2026-105133 and CVE-2026-105134, to deploy webshells and XMRig cryptominers. Update to 10.3.4 and restrict access now.
P5
2026-10-08 19:49 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P5
2026-10-08 19:49 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P5
2026-10-08 19:44 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-10-08 20:10 UTC
Bulletin ID: 2026-131-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/08/2026 12:30 PM PDT Description: AWS CDK is an open source framework that allows customers to build cloud infrastructure using their favorite programming language (Python, Typescript, C#, Go). That infrastructure is then able to be deployed with AWS CDK command line commands to AWS CloudFormation. We identified CVE-2026-107608, which is an issue where Docker files could be configured to inser…
P5
2026-10-08 19:33 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-08 20:30 UTC
Italy’s Foreign Ministry is defending its website against a cyberattack, checking embassy sites and pushing for EU action to identify attackers. On the morning of October 8, Italy’s Ministry of Foreign Affairs said its website was being attacked. According to the ministry’s own statement, its protection systems have mitigated the attack so far, with no […]
P0
2026-10-08 19:29 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-10-08 19:10 UTC
Bulletin ID: 2026-130-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/08/2026 11:30 AM PDT Description: Amazon Agent Plugins for AWS is an open source collection of plugins that extends supported AI coding agents with AWS-focused workflows and tool integrations. The databases-on-aws plugin provides database design, development, migration, and operational guidance, including Aurora DSQL helper scripts. We identified CVE-2026-107322, where an incomplete list of di…
P5
2026-10-08 19:20 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-10-08 19:25 UTC
A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies. [...]
P0
2026-10-08 19:20 UTC
Security Journalism
The Record · indexed 2026-10-08 19:40 UTC
The U.S. and other nations took down digital tools and infrastructure by Beijing-based Integrity Tech that allowed "widespread vulnerability scanning and, in some cases, intrusions" as part of the Flax Typhoon campaign.
P0
2026-10-08 19:08 UTC
Security Journalism
Dark Reading · Robert Lemos · indexed 2026-10-08 19:25 UTC
The first cybercriminal to ever make the FBI's "10 Most Wanted Fugitives" list allegedly infused Tren de Aragua's violent criminal operations with cash.
P0
2026-10-08 18:49 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P5
2026-10-08 18:49 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P20
2026-10-08 18:49 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P5
2026-10-08 18:49 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P5
2026-10-08 18:32 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 18:55 UTC
Hackers tied to a Chinese cybersecurity company stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, the FBI and agencies in 6 other countries said on October 8. The company, Integrity Technology Group, has been sanctioned by the U.S. and the UK. The hackers scanned websites for flaws using a tool containing more
P0
2026-10-08 18:01 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-10-08 18:10 UTC
Cyber-espionage actor UAC-0099 has been steadily refining its flagship dropper in campaigns targeting Ukrainian organizations.
P0
2026-10-08 18:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · Pierre Cadieux · indexed 2026-10-08 18:20 UTC
Pierre's debut newsletter explores the messy, real-world side of risk management and how to keep vital systems running when a perfect patch isn't an option.
P0
2026-10-08 17:58 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 18:55 UTC
The crooks have trust problems of their own. One ransomware affiliate decided to keep the profits for himself. Elsewhere, an attacker left a server exposed, complete with tools and traces of an intrusion. Apparently, keeping things secure is a problem on both sides of the fence. The rest of the week isn't much more reassuring. Malicious code turned up in developer packages and extensions that
P15
2026-10-08 17:47 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-08 18:10 UTC
Hunt.io traced BraZetsu ‘s infrastructure and found that hosting patterns and certificate data remained useful after published IOCs became outdated. Group-IB researchers published a detailed writeup on BraZetsu back on August 31, naming it a Python framework compiled with Nuitka and tying it to a Brazilian actor called Exilware with high confidence. Hunt.io checked whether […]
P0
2026-10-08 17:43 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-10-08 17:50 UTC
Bulletin ID: 2026-129-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/08/2026 10:30 PM PDT Description: AWS Toolkit for Visual Studio Code is an open source extension that lets developers work with AWS services, including Amazon CodeCatalyst, from within Visual Studio Code. We identified CVE-2026-107332, an issue in the CodeCatalyst connection handler. When a user connected to a CodeCatalyst Dev Environment, the extension cached the user's CodeCatalyst bearer to…
P5
2026-10-08 17:10 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-10-08 17:20 UTC
More than 17,000 fake repositories on GitHub are distributing the SmartLoader malware after the FakeGit campaign reactivated earlier this month to push the StealC infostealer. [...]
P0
2026-10-08 17:00 UTC
Security Journalism
The Record · indexed 2026-10-08 17:15 UTC
The owner of a ransomware recovery firm was hit with wire fraud charges for allegedly making secret ransom payments while overcharging the victims of attacks.
P15