2026-10-08 17:10 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-10-08 17:20 UTC
More than 17,000 fake repositories on GitHub are distributing the SmartLoader malware after the FakeGit campaign reactivated earlier this month to push the StealC infostealer. [...]
P0
2026-10-08 17:00 UTC
Security Journalism
The Record · indexed 2026-10-08 17:15 UTC
The owner of a ransomware recovery firm was hit with wire fraud charges for allegedly making secret ransom payments while overcharging the victims of attacks.
P15
2026-10-08 16:57 UTC
Security Journalism
The Record · indexed 2026-10-08 17:15 UTC
The company said its investigation, carried out with external experts, found the attackers had accessed “some personal information, including names and contact details, and certain non-personal account related information.”
P0
2026-10-08 16:52 UTC
Community
SANS Internet Storm Center · indexed 2026-10-08 17:10 UTC
We just did a major update to FOR577 and added a lot of new material on day 5 about investigating AI usage in incident response. In the new material we dicsuss 8 of the most popular AI coding assistants and agents including Claude Code, Codex, Gemini CLI, Cursor, Copilot, Warp, Windsurf, and Qwen Code. I've been using Claude Code and a little bit of Codex, but I also have recently been playing with OpenCode and am setting up Hermes. I decided t…
P0
2026-10-08 15:45 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 17:20 UTC
Attackers behind a string of personal data leaks at Japanese organizations have abused APIs for mobile apps and targeted known software flaws, the JPCERT Coordination Center (JPCERT/CC) said. The Tokyo-based center, which takes incident reports, based its October 8, 2026 alert on those reports and other information. The alert names no attacker and no affected organization. JPCERT/
P0
2026-10-08 15:45 UTC
Security Journalism
The Record · indexed 2026-10-08 16:00 UTC
A 25-year-old man who helped steal nearly $260,000 in cryptocurrency through a SIM-swapping fraud scheme was sentenced to two and a half years in prison at a London court.
P0
2026-10-08 15:28 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-08 15:30 UTC
The security defects could lead to unauthorized access, information leaks, privilege escalation, DoS attacks, and remote code execution. The post Cisco Patches a Dozen Critical Vulnerabilities appeared first on SecurityWeek.
P25
2026-10-08 15:26 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 15:40 UTC
The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN. According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel. The cybersecurity company is tracking the cluster under the name Earth Sirrush (previously SHADOW-EARTH-065). ASHVEIN,
P0
2026-10-08 15:26 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-10-08 15:40 UTC
Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privileges on Nexus switches. [...]
P10
2026-10-08 14:46 UTC
Security Journalism
The Record · indexed 2026-10-08 15:00 UTC
In leaked chats, members track dozens of victims, haggle over multimillion-dollar payments and direct operatives based in the United States whom they call “agents.”
P0
2026-10-08 14:30 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-10-08 14:30 UTC
All enterprises conduct security awareness training for their employees. But whether this has tangible benefits is debatable. The post Security Awareness Training Isn’t Dead, but It Needs a Rethink appeared first on SecurityWeek.
P0
2026-10-08 14:12 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 15:40 UTC
Cybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence (AI) pen testing tool named ARTEX to carry out the attacks. The activity, per CrowdStrike Intelligence, was active from late September to early October 2026, and resulted in data exfiltration from various South Korea-based financial firms,
P0
2026-10-08 14:11 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-10-07 16:15 UTC
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation of data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP request to the NX-API of an affected device. A successful exploit could allow the attacker to execute arbitra…
P20
2026-10-08 14:04 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-10-08 14:10 UTC
Threat actors have started targeting CVE-2026-21589, a critical vulnerability in Atlassian’s self-hosted Data Center products. The post Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication appeared first on SecurityWeek.
P15
2026-10-08 14:00 UTC
Security Journalism
BleepingComputer · Sponsored by Nudge Security · indexed 2026-10-08 14:05 UTC
OAuth grants create data highways between SaaS apps, AI agents, and other tools. And, they are multiplying faster than any security team can review them. As the recent Klue breach showed, attackers are taking notice and exploiting forgotten OAuth grants to gain access to corporate data. This article covers why OAuth risks are so hard [...]
P0
2026-10-08 13:55 UTC
Security Journalism
The Record · indexed 2026-10-08 14:00 UTC
Two of South Korea's largest Protestant churches are investigating cyberattacks that may have exposed sensitive information about hundreds of thousands of members, including personal details, financial records and internal documents.
P0
2026-10-08 13:37 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-08 14:50 UTC
MonsterCloud owner Zohar Pinhasi allegedly paid ransomware demands behind clients’ backs, then charged them millions for the supposed recovery. Zohar Pinhasi, the owner of Florida-based MonsterCloud, was charged this week with wire fraud. Federal prosecutors say his clients were scammed twice during the same ransomware crisis. Pinhasi (50) also used the names “Zack Silver” and […]
P15
2026-10-08 13:18 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-08 13:25 UTC
A Maryland man was found guilty of stealing more than $53 million after hacking the decentralized crypto exchange Uranium Finance twice in April 2021. [...]
P0
2026-10-08 13:00 UTC
Security Journalism
The Record · indexed 2026-10-08 13:15 UTC
"It’s on the phone before the owner switches it on for the first time, and it can’t be uninstalled," researchers at Bitdefender said about ad fraud malware found on thousands of cheap Android devices.
P0
2026-10-08 12:50 UTC
Vendor Research
Tenable Blog · Robert McSulla · indexed 2026-10-08 13:10 UTC
Community-built AI agents, skills, and MCP servers are landing in SOC workflows fast. Here’s what the Exchange Inspector tests before a listing earns its vetted tag on the CyberAgents Exchange. Three tools have already passed.Key takeawaysEvery Inspector-vetted listing clears three gates: an automated check, a frontier model assessment, and human verification. Tenable uses Tenable One AI Exposure to screen for prompt injection and exposed secrets, and OpenAI GPT Cyber models to assess the code …
P0
2026-10-08 12:46 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-10-08 12:50 UTC
Zhang Yu was charged alongside Xu Zewei, who was extradited from Italy to the US in April 2026. The post US Seeks Alleged Chinese Hafnium Hacker With $10 Million Reward appeared first on SecurityWeek.
P0
2026-10-08 12:37 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-08 12:50 UTC
Critical and high-severity vulnerabilities could allow attackers to bypass authentication, execute arbitrary code, and elevate their privileges. The post SonicWall and Splunk Patch Critical Vulnerabilities appeared first on SecurityWeek.
P0
2026-10-08 12:30 UTC
Security Journalism
The Record · indexed 2026-10-08 12:45 UTC
Russian-aligned hackers have targeted Ukrainian transportation, manufacturing and energy companies with a constantly evolving malware strain designed to harvest system data, according to new research.
P0
2026-10-08 12:08 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-08 12:20 UTC
Microsoft will soon introduce support for third-party deepfake detection solutions and impersonation protection in Teams meetings. [...]
P0
2026-10-08 12:00 UTC
Security Journalism
The Record · indexed 2026-10-08 12:20 UTC
A drone strike on a large Yandex data center caused a significant disruption to the Russian tech giant's network, with connectivity reportedly falling to around 70 percent of normal levels.
P0
2026-10-08 12:00 UTC
Security Journalism
Dark Reading · Kelly Jackson Higgins · indexed 2026-10-08 12:05 UTC
Dark Reading is about to begin a new decade in its storied history, and we have some breaking news of our own to share.
P0
2026-10-08 11:42 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-10-08 11:50 UTC
ASOS is sending updates to affected customers about the cybersecurity incident it suffered earlier this week, confirming that hackers accessed some personal data. [...]
P0
2026-10-08 11:11 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-08 11:30 UTC
The cybersecurity startup will invest in product innovation, agentic research, and employee base expansion. The post Rein Security Raises $25 Million to Guard AI Agents at Runtime appeared first on SecurityWeek.
P0
2026-10-08 10:30 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 11:05 UTC
Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials. Attackers are increasingly building filtering, session management, and traffic controls into the infrastructure that delivers the phishing page itself. ANY.RUN has identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe
P0
2026-10-08 10:29 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-08 10:35 UTC
The co-creator of Empire Market, one of the largest dark web marketplaces before its shutdown, has been sentenced to 40 years in prison for facilitating $430 million in illegal transactions from 2018 to 2020. [...]
P0