2026-10-08 10:24 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-10-08 10:30 UTC
SEC Consult has published technical details on vulnerabilities mentioned in a complaint filed by several US states. The post TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws appeared first on SecurityWeek.
P0
2026-10-08 10:11 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-08 10:30 UTC
The U.S. offers $10M for Zhang Yu, accused of helping run HAFNIUM attacks that compromised thousands of organizations worldwide. The U.S. State Department is offering a $10 million reward for information leading to the arrest of Zhang Yu. He is accused of being a key figure in the HAFNIUM campaign, the 2021 operation that targeted […]
P0
2026-10-08 10:01 UTC
Vendor Research
Cisco Talos Intelligence Blog · Joey Chen · indexed 2026-10-08 10:30 UTC
Cisco Talos identified an APT spear-phishing campaign against individuals affiliated with Taiwan research organizations. The operation leveraged legitimate public event themes and impersonated reputable academic and policy institutions.
P0
2026-10-08 10:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · Ryan Fetterman · indexed 2026-10-08 10:30 UTC
“AI-analysis evasion” encapsulates the real-world techniques malware authors are developing in attempt to obstruct or defeat any layers of automated AI analysis.
P0
2026-10-08 09:46 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 09:55 UTC
Cybersecurity researchers have discovered a cluster of 16 malicious Mozilla Firefox extensions that are capable of stealing cryptocurrency wallet recovery phrases and private keys. "The extensions masquerade as wallet portals, desktop utilities, and browser tools, but their code intercepts recovery phrases and private keys during wallet import flows and attempts to send those secrets to
P0
2026-10-08 09:27 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-08 09:30 UTC
Zohar Pinhasi was paying ransoms to obtain decryption keys and then charging victims substantially more for remediation. The post Fake Decryption Tools Masked $11M Markup in Ransomware Recovery Scheme appeared first on SecurityWeek.
P15
2026-10-08 08:45 UTC
Other
ESET · indexed 2026-10-09 01:45 UTC
ESET Research catalogs the changes of UAC-0099’s MATCHBOIL downloader from 2024 to 2026
P0
2026-10-08 08:23 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-10-08 08:30 UTC
The figure is far higher than the counts that surfaced in earlier filings and patient notifications. The post Oracle Health Data Breach Tally Climbs to Nearly 20 Million appeared first on SecurityWeek.
P0
2026-10-08 07:52 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-08 07:55 UTC
Attackers are creating new accounts and deleting existing ones and passwords to prevent legitimate access. The post FortiBleed Attackers Locking Victims Out of Fortinet Devices appeared first on SecurityWeek.
P0
2026-10-08 07:46 UTC
Vendor Research
ANY.RUN Blog · ANY.RUN · indexed 2026-10-08 07:50 UTC
Threat intelligence on its own is only data. Its value depends on how effectively SOC teams can turn it into action. Simply put, this was the premise of our recent webinar. The SOC and business impact of threat intelligence depends largely on how quickly analysts can use it to validate threats, make confident decisions, and […] The post Making Threat Intelligence Work for SOC Teams: ANY.RUN & Elastic Webinar Insights appeared first on ANY.RUN's Cybersecurity Blog.
P0
2026-10-08 07:42 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 08:10 UTC
The U.S. State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 2021 Microsoft Exchange Server attacks known as HAFNIUM. The reward is for information leading to his identification or location, the news outlet NTD reported this week, citing a notice
P0
2026-10-08 07:41 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 08:10 UTC
The U.S. Department of Justice (DoJ) on Wednesday announced charges against a 50-year-old U.S. and Israeli national for allegedly defrauding ransomware victims by secretly paying the attackers to obtain decryptors while claiming to use proprietary tools to recover their data. Zohar Pinhasi (aka Zack Silver and Zack Green) has been charged with two counts of wire fraud and one count of wire
P15
2026-10-08 07:26 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-08 08:10 UTC
Threat actors are exploiting CVE-2026-21589, a critical Atlassian flaw that can expose sensitive files across multiple Data Center products. Threat actors have started exploiting CVE-2026-21589 (CVSS score of 9.3), a critical arbitrary file access flaw in Atlassian Data Center products. The vulnerability could allow attackers to access sensitive files under certain conditions. Affected products include […]
P5
2026-10-08 06:32 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-08 06:40 UTC
On the second day of Pwn2Own Ireland 2026, security researchers collected $232,500 in cash awards after exploiting 45 unique zero-day vulnerabilities. [...]
P25
2026-10-08 05:46 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 06:40 UTC
The npm package known as "tensorlake," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack. The malicious version 0.5.144 "contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code," Socket said
P0
2026-10-08 02:00 UTC
Community
SANS Internet Storm Center · indexed 2026-10-08 02:10 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-10-08 00:18 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-10-07 16:15 UTC
As part of Cisco's ongoing commitment to proactive security and product quality, engineering teams conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerabilit…
P30
2026-10-07 23:04 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-10-07 23:15 UTC
The owner of ransomware remediation company MonsterCloud has been charged with allegedly defrauding ransomware victims by secretly paying their attackers for decryptors while claiming to use proprietary technology to recover encrypted data. [...]
P15
2026-10-07 22:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Eyal Rafian · indexed 2026-10-07 22:10 UTC
Unit 42 details how threat actors leverage Web3 infrastructure and open-source supply chain attacks to breach enterprise cloud environments The post Evolution of Web3 in Cloud Supply Chain Attacks appeared first on Unit 42.
P0
2026-10-07 21:49 UTC
Vendor Research
AWS Security Blog · Justin Kontny · indexed 2026-10-07 22:20 UTC
This post shows you how to configure an AI model to perform structured, evidence-based vulnerability triage with the consistency of a seasoned security analyst. You’ll learn the design decisions behind five configuration sections that enforce structural verification, evidence-based scoring, and infrastructure-aware prioritization across every analysis session. Our companion post—Building your AI vulnerability harness—covered the architecture; […]
P0
2026-10-07 21:49 UTC
Vendor Research
AWS Security Blog · Nidhi Ramakant · indexed 2026-10-07 22:20 UTC
Vulnerability scanners produce findings faster than manual triage can process them. Your developers ship more code with more dependencies, and the volume of candidate findings grows with it. Many findings a scanner produces are unlikely to be exploited. The ones that matter need to reach an engineer fast, with enough evidence that they can act […]
P0
2026-10-07 21:42 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-10-07 22:05 UTC
In the wake of an agentic attack against its own Medicare systems, Australia's government is feeling out what regulations might look like for frontier AI companies.
P0
2026-10-07 21:28 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-10-07 21:35 UTC
The FBI is warning that FortiBleed attacks are still ongoing, targeting exposed Fortinet FortiGate firewalls and SSL VPN gateways and locking out legitimate administrators. [...]
P0
2026-10-07 21:25 UTC
Security Journalism
Dark Reading · Rob Wright · indexed 2026-10-07 21:50 UTC
The Citizen Lab's Ron Deibert warns the US government is pushing for pervasive surveillance and says certain technology executives are all too happy to help.
P0
2026-10-07 20:51 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-10-07 21:20 UTC
Anthropic has merged Project Glasswing into a tiered access program for its advanced cyber LLMs, including Opus, Sonnet, and Mythos.
P0
2026-10-07 20:50 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-10-07 21:05 UTC
Hackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains in the country-code top-level domains (ccTLDs) for Ghana, American Samoa, and Sierra Leone after compromising third-party operators and modifying authoritative DNS records. [...]
P0
2026-10-07 20:19 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-10-07 20:30 UTC
Bulletin ID: 2026-128-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/07/2026 13:00 PM PDT Description: Missing authorization checks in Amazon Athena engine version 3 request handling could have allowed an authenticated user to read limited query metadata (AWS account identifiers and SQL statement text) from other AWS accounts. AWS remediated the issue on September 1, 2026, and has confirmed no customer metadata was accessed. Query results, credentials, and Amaz…
P5
2026-10-07 20:16 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P0
2026-10-07 20:16 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P20
2026-10-07 20:16 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P5