2026-10-07 12:49 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-10-07 12:50 UTC
A critical vulnerability (CVE-2026-21589) affecting multiple Atlassian product families, including Jira, Confluence, and Bitbucket, is being exploited in attacks that do not require authentication. [...]
P35
2026-10-07 12:37 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-10-07 12:50 UTC
The Japanese chip testing giant said hackers stole personal information from its servers in the February 2026 cyberattack. The post Advantest Discloses Data Breach Months After Ransomware Attack appeared first on SecurityWeek.
P15
2026-10-07 12:11 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-10-07 12:30 UTC
OverviewOn October 5, 2026, Atlassian published a security advisory for CVE-2026-21589, a critical arbitrary file access vulnerability affecting eight products: Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian assigned the vulnerability a CVSSv4 score of 9.3. An unauthenticated remote attacker who knows a target file's exact name and path can access it within the…
P5
2026-10-07 11:57 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 12:20 UTC
The 2026 findings are not just a year-over-year shift. They mark the latest point in a five-year arc where resilience, AI governance, human risk, and board scrutiny are converging inside the systems where work actually happens. For years, the enterprise cybersecurity story has been told as a straight line of escalation: more attacks, more data loss, more pressure, and more urgency. That
P0
2026-10-07 11:56 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 12:20 UTC
The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. "The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat
P0
2026-10-07 11:49 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 12:20 UTC
Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software
P5
2026-10-07 11:42 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 12:20 UTC
If you’re evaluating an agentic pentesting solution right now, you’ve probably heard the same pitch more than once: point it at a target, and it discovers, validates, and exploits attack paths autonomously, the way a real attacker would. That promise is worth taking seriously. It’s also worth pressure testing, and three questions do the heavy lifting. What can the assessment actually
P0
2026-10-07 11:37 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-07 11:55 UTC
SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances. [...]
P0
2026-10-07 10:51 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-07 11:00 UTC
Four critical-severity use-after-free defects were fixed in Chromecast, Browser, Navigation, and Track. The post Chrome 155 Update Patches 247 Vulnerabilities appeared first on SecurityWeek.
P0
2026-10-07 10:40 UTC
Vendor Research
Rapid7 · Emma Burdett · indexed 2026-10-07 10:50 UTC
This week, ASOS customers opened their phones to find a hostile push notification delivered through the retailer’s own app. The message claimed the company’s Snowflake environment had been compromised and directed ASOS to engage with the sender through Telegram. ASOS later confirmed to Sky News that an unauthorized customer notification had been sent and said it was investigating activity involving third-party platforms used to communicate with customers. The company also said basic personal in…
P0
2026-10-07 10:35 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-07 10:45 UTC
A North Carolina musician was sentenced to 18 months in prison for collecting more than $10 million in royalties from Spotify, Apple Music, Amazon Music, and YouTube Music in a massive streaming royalty fraud scheme. [...]
P0
2026-10-07 10:27 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-10-07 10:35 UTC
Advantest Corporation is notifying affected individuals that a ransomware attack earlier this year exposed their personally identifiable data. [...]
P15
2026-10-07 10:07 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-10-07 10:20 UTC
Anthropic is integrating the CVP and Project Glasswing into a single offering, with three levels of access to its most capable AI models. The post Anthropic Introduces 3-Tier Cyber Verification Program for AI Access appeared first on SecurityWeek.
P0
2026-10-07 10:06 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-07 11:10 UTC
Anthropic created three access tiers for Claude’s offensive security use, matching cyber capabilities and safeguards to the user’s level of trust. Anthropic is trying to solve the difficult balance between using AI for cybersecurity and preventing misuse. The same model that helps security teams fix vulnerabilities can also help attackers break into systems. Its answer, […]
P0
2026-10-07 10:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · Jerzy ‘Yuri’ Kramarz · indexed 2026-10-07 10:30 UTC
The cybersecurity community has seen examples of autonomous agents, built inside AI labs, attacking public infrastructure. How you prepare for agentic threats is what makes the difference during real incidents.
P0
2026-10-07 09:46 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-07 10:00 UTC
Hackers compromised a third-party communication platform and sent rogue notifications to ASOS users. The post ASOS Confirms Cyberattack, Data Breach appeared first on SecurityWeek.
P0
2026-10-07 09:43 UTC
Vendor Research
Google Security Blog · Irene Ang · indexed 2026-10-07 23:25 UTC
Enabling the Next-Gen Enclave Architecture for On-Device AI on Android
P0
2026-10-07 09:00 UTC
Other
ESET · indexed 2026-10-08 05:00 UTC
A plausible-sounding sponsorship offer could mask an attempt to compromise your Google account
P0
2026-10-07 08:07 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 09:40 UTC
Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards and blocking classifiers, as the company claimed its Project Glasswing initiative uncovered at least 129,000 verified software vulnerabilities between April and July 2026. The company said it also found an additional
P0
2026-10-07 07:58 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-10-07 08:00 UTC
Wikimedia looked into whether its own websites had seen activity like that disclosed by other organizations The post Wikimedia Says Rogue OpenAI Agents Tried to Turn Its Tools Into Proxies appeared first on SecurityWeek.
P0
2026-10-07 07:52 UTC
Government
CERT-EU Security Advisories · indexed 2026-10-07 08:00 UTC
On 5 October 2026, Atlassian published a security advisory addressing a critical arbitrary file access vulnerability. It affects Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye. CERT-EU strongly recommends upgrading all affected installations to a fixed version as soon as possible, starting with instances accessible from the internet. CERT-EU also recommends checking access…
P10
2026-10-07 07:50 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-07 08:40 UTC
Wikimedia found unauthorized OpenAI agent activity on its platforms, including unapproved edits, proxy attempts and millions of automated API requests. Wikimedia ran its own investigation after other organizations started reporting rogue AI agents breaking into websites, and the answer came back yes, it happened here too. The foundation found unauthorized bot activity tied to OpenAI […]
P0
2026-10-07 07:30 UTC
Vendor Research
ANY.RUN Blog · ANY.RUN · indexed 2026-10-07 07:50 UTC
US SOC teams are under pressure to detect and contain threats faster, but the real challenge is often not a lack of security solutions. It’s the growing amount of alerts, fragmented investigation data, evasive attack techniques, and the time analysts spend connecting the dots. As attacks become harder to validate and easier to hide inside […] The post 5 Critical Pain Points of Modern US SOCs and How to Solve Them appeared first on ANY.RUN's Cybersecurity Blog.
P0
2026-10-07 06:57 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 07:45 UTC
The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer (aka Psychedelic Stealer). The activity, which was observed by the agency in September 2026, has been attributed to a threat cluster dubbed UAC-0277. It did not disclose who the
P0
2026-10-07 06:55 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-07 07:05 UTC
The patches resolve a critical vulnerability in Android’s System component that could lead to privilege escalation. The post Android’s October 2026 Updates Patch 25 Vulnerabilities appeared first on SecurityWeek.
P10
2026-10-07 06:37 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-07 06:50 UTC
Unauthenticated attackers could exploit the flaw to access specific files in the web application root directory. The post Atlassian Patches Critical Vulnerability Affecting 8 Products appeared first on SecurityWeek.
P10
2026-10-07 02:00 UTC
Community
SANS Internet Storm Center · indexed 2026-10-07 02:10 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-10-07 01:32 UTC
Security Journalism
Security Week · Associated Press · indexed 2026-10-07 01:50 UTC
The Arizona Supreme Court said the information was copied for people dating back as far as 30 years. The post Personal Information for Over 1 Million People Stolen in a Cyberattack on Arizona’s Court System appeared first on SecurityWeek.
P0
2026-10-06 21:00 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-10-06 21:05 UTC
Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts. [...]
P0
2026-10-06 20:41 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-10-06 20:55 UTC
Bulletin ID: 2026-127-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/06/2026 13:30 PM PDT Description: bedrock-agentcore-starter-toolkit is an AWS-maintained open-source Python package, distributed via GitHub and PyPI, that provides a command-line interface for importing Amazon Bedrock Agents into local development environments. We identified CVE-2026-105812, a code injection issue that could allow arbitrary code execution when a specially crafted agent is impo…
P5