access ai android api apple attack authentication backdoor breach business ceo china cisa cisco ciso cloud compliance control credentials crypto cve cyber cyberattack cybercrime cybersecurity data data-breach defense detection email endpoint exploit finance flaw framework fraud google governance government group hacker hacking healthcare identity infrastructure intelligence Internet jobs law leak linux malicious malware microsoft monitoring network open-source password phishing privacy ransomware remote-code-execution resilience risk russia scam service software strategy supply-chain technology theft threat tool unclassified update usa vulnerability windows zero-day
-
Healthcare AI Governance Has a Visibility Problem
Study Finds 91% Can’t Verify AI Tools in Use; New AI Playbook Covers Clinical Risks. Most healthcare organizations have AI governance policies, but 91% can’t verify all AI tools in use, a new study finds. As security and oversight gaps persist, new industry guidance urges healthcare providers to prepare for AI failures that could disrupt…
-
Breach Roundup: FortiBleed Still Hemorrhaging Credentials
Also: AI Agents Hit Wikimedia, Asos Traces Breach to Employee. This week: Fortibleed, OpenAI agents attacked Wikimedia, FBI hacking fallout hits Accenture, Silent Ransom leak and a Flydubai attack. Asos breach traced to employee account. A Hafnium hacker bounty. Google spotted compromised third-party cc-TLD domains. Man accused of illegally exporting chips. First seen on govinfosecurity.com…
-
FBI Seizes Domains Used in Flax Typhoon Attacks
US Authorities Say Infrastructure Supported Scanning, Phishing and Data Theft. The FBI seized seven domains allegedly used by China-linked hackers to scan critical infrastructure, deliver malware and steal files. A joint advisory urges organizations to hunt for lingering access. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/fbi-seizes-domains-used-in-flax-typhoon-attacks-a-33049 also interesting: Cybersecurity Snapshot: Study Raises Open Source…
-
FBI Seizes Domains Used in Flax Typhoon Attacks
US Authorities Say Infrastructure Supported Scanning, Phishing and Data Theft. The FBI seized seven domains allegedly used by China-linked hackers to scan critical infrastructure, deliver malware and steal files. A joint advisory urges organizations to hunt for lingering access. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/fbi-seizes-domains-used-in-flax-typhoon-attacks-a-33049 also interesting: Cybersecurity Snapshot: Study Raises Open Source…
-
FBI Seizes Domains Used in Flax Typhoon Attacks
US Authorities Say Infrastructure Supported Scanning, Phishing and Data Theft. The FBI seized seven domains allegedly used by China-linked hackers to scan critical infrastructure, deliver malware and steal files. A joint advisory urges organizations to hunt for lingering access. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/fbi-seizes-domains-used-in-flax-typhoon-attacks-a-33049 also interesting: Cybersecurity Snapshot: Study Raises Open Source…
-
FBI Seizes Domains Used in Flax Typhoon Attacks
US Authorities Say Infrastructure Supported Scanning, Phishing and Data Theft. The FBI seized seven domains allegedly used by China-linked hackers to scan critical infrastructure, deliver malware and steal files. A joint advisory urges organizations to hunt for lingering access. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/fbi-seizes-domains-used-in-flax-typhoon-attacks-a-33049 also interesting: Cybersecurity Snapshot: Study Raises Open Source…
-
Anthropic rolls out program for ‘long-term commitment’ to secure critical infrastructure, open source software
The critical infrastructure defense program will seek to pair Claude models, Anthropic engineers and threat research with the expertise of cybersecurity companies. First seen on cyberscoop.com Jump to article: cyberscoop.com/anthropic-cybersecurity-program-critical-infrastructure-open-source/ also interesting: Walking the Walk: How Tenable Embraces Its >>Secure by Design<< Pledge to CISA Cybersecurity Snapshot: CISA Highlights Vulnerability Management Importance in Breach Analysis,…
-
Leader of 764 pleads guilty, faces up to 30 years in prison
Prasan Nepal ran the nihilistic violent extremist network for almost four years and played a crucial role facilitating the grooming, manipulation and extortion of minors. First seen on cyberscoop.com Jump to article: cyberscoop.com/764-leader-prasan-nepal-guilty/ also interesting: Cybersecurity Snapshot: CISA Hands Down Cloud Security Directive, While Threat from North Korean IT Workers Gets the Spotlight The dirty…
-
Leader of 764 pleads guilty, faces up to 30 years in prison
Prasan Nepal ran the nihilistic violent extremist network for almost four years and played a crucial role facilitating the grooming, manipulation and extortion of minors. First seen on cyberscoop.com Jump to article: cyberscoop.com/764-leader-prasan-nepal-guilty/ also interesting: Cybersecurity Snapshot: CISA Hands Down Cloud Security Directive, While Threat from North Korean IT Workers Gets the Spotlight The dirty…
-
‘AgentCorruption’ Puts AWS Environments At Risk With Single Prompt
A now-patched vulnerability in AWS Bedrock AgentCore could allow an attacker to use one AI chatbot to take over an organization’s entire fleet. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/agentcorruption-aws-environments-at-risk-single-prompt also interesting: We’ve crossed the security singularity – Impart Security With CISOs stretched thin, re-envisioning enterprise risk may be the only fix Are you…
-
TP-Link Faces 5 State Lawsuits: Are Its Routers Still Legal in the US?
Five states have sued TP-Link over router security and disclosure claims. Here’s how the lawsuits, FCC restrictions, and firmware vulnerabilities affect existing owners. The post TP-Link Faces 5 State Lawsuits: Are Its Routers Still Legal in the US? appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-tp-link-router-lawsuits-fcc-ban-us/ also interesting: Critical TP-Link DHCP…
-
Ransomware attack disrupts Japan’s IDCF Cloud used by govt clients
IDC Frontier, a major Japanese cloud and digital infrastructure company, disclosed that its IDCF Cloud service was targeted in a ransomware attack that caused an outage at a data center cluster serving the eastern part of the country. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ransomware-attack-disrupts-japans-idcf-cloud-used-by-govt-clients/ also interesting: The healthcare industry is at a cybersecurity…
-
Italy’s Foreign Ministry Under Cyberattack as Embassy Sites Come Under Review
Italy’s Foreign Ministry is defending its website against a cyberattack, checking embassy sites and pushing for EU action to identify attackers. On the morning of October 8, Italy’s Ministry of Foreign Affairs said its website was being attacked. According to the ministry’s own statement, its protection systems have mitigated the attack so far, with no…
-
Ransomware recovery CEO indicted after allegedly paying hackers and pocketing millions
Zohar Pinhasi allegedly deceived ransomware recovery clients into a payment scheme disguised as a specialized service that helped victims avoid paying cybercriminals. First seen on cyberscoop.com Jump to article: cyberscoop.com/monstercloud-zohar-pinhasi-ransomware-recovery-scheme/ also interesting: 8 Cyber Predictions for 2025: A CSO’s Perspective Password managers under increasing threat as infostealers triple and adapt 13 ways attackers use generative…
-
DOJ, FBI seize Flax Typhoon-linked hacking tools Microscan, FishHub
The seizures of the tools, allegedly operated by the Chinese firm Integrity Tech, accompanied a warning from the FBI, CISA and NSA. First seen on cyberscoop.com Jump to article: cyberscoop.com/doj-fbi-seize-flax-typhoon-hacking-tools-microscan-fishhub/ also interesting: Cybersecurity Snapshot: Study Raises Open Source Security Red Flags, as Cyber Agencies Offer Prevention Tips Against Telecom Spying Attacks The 2024 cyberwar playbook:…
-
Lawmakers warn Google could expose Spirit Airlines data in $10 million AI training deal
The proposed sale would include about 100 million emails, 500 million Microsoft Teams messages, employment contracts, employee and timecard records and payroll and tax information, Rep. Steven Horsford (D-NV) said in a press release. First seen on therecord.media Jump to article: therecord.media/lawmakers-warn-of-google-spirit-ai-training-deal also interesting: This new cipher tech could break you out of your Gen…
-
Let’s Encrypt cuts certificate lifetimes to 64 days starting February 2027
Tags: unclassifiedFree SSL/TLS certificate lifetimes reduce to 64 days in February. First seen on arstechnica.com Jump to article: arstechnica.com/gadgets/2026/10/lets-encrypt-cuts-certificate-lifetimes-to-64-days-starting-february-2027/ also interesting: Datenschutzpanne: Tracking von DHL und Yun Express verriet Empfängeradressen Holiverse Makes NASA’s Latest Achievements Accessible to Everyone adesso holt zum fünften Mal in Folge Platin beim BigData-Insider Award FBI Investigates Suspicious Activity in Surveillance Platform
-
ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories
The crooks have trust problems of their own. One ransomware affiliate decided to keep the profits for himself. Elsewhere, an attacker left a server exposed, complete with tools and traces of an intrusion. Apparently, keeping things secure is a problem on both sides of the fence.The rest of the week isn’t much more reassuring. Malicious…
-
FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails
Tags: access, breach, china, cybersecurity, email, flaw, government, group, hacker, healthcare, law, technology, toolHackers tied to a Chinese cybersecurity company stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, the FBI and agencies in 6 other countries said on October 8.The company, Integrity Technology Group, has been sanctioned by the U.S. and the UK. The hackers scanned websites for flaws using…
-
Venezuelan Cartel’s Malware Honcho Nabbed for ATM Jackpotting
The first cybercriminal to ever make the FBI’s 10 Most Wanted Fugitives list allegedly infused Tren de Aragua’s violent criminal operations with cash. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/venezuelan-cartel-malware-honcho-nabbed-atm-jackpotting also interesting: Cybercriminals target transportation companies in North America with info-stealing malware A new ransomware regime is now targeting critical systems with weaker networks…
-
Low-cost Android phones ship with residential proxy malware
A malware campaign dubbed ‘Midnight Mimosa’ has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/low-cost-android-phones-ship-with-residential-proxy-malware/ also interesting: Privacy Roundup: Week 4 of Year 2025 The…
-
International coalition seizes tools used by cyber firm behind Flax Typhoon
The U.S. and other nations took down digital tools and infrastructure by Beijing-based Integrity Tech that allowed “widespread vulnerability scanning and, in some cases, intrusions” as part of the Flax Typhoon campaign. First seen on therecord.media Jump to article: therecord.media/flax-typhoon-china-tools-integrity-tech-international-takedown also interesting: Cybersecurity Snapshot: Study Raises Open Source Security Red Flags, as Cyber Agencies Offer…
-
Russian Spies Give ‘MatchBoil’ Malware a Stealthy Facelift
Cyber-espionage actor UAC-0099 has been steadily refining its flagship dropper in campaigns targeting Ukrainian organizations. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/russian-spies-matchboil-malware-facelift also interesting: Russian Hackers Deploy HATVIBE and CHERRYSPY Malware Across Europe and Asia International effort erases PlugX malware from thousands of Windows computers Russia-Linked SpyPress Malware Exploits Webmails to Spy on Ukraine…
-
Ransomware Response Firm CEO Accused of Data Recovery Fraud
MonsterCloud CEO Disguised Ransom Payments as Proprietary Tool, Say Prosecutors. A ransomware service that offered clients an extortion-free shortcut to unlocking their files was too good to be true, say U.S. federal prosecutors who say the secret behind Florida-based MonsterCloud was actually succumbing to hacker demands and paying a ransom to attackers, at victims’ expense.…
-
Hunt.io Finds New Infrastructure Of BraZetsu Access Broker Months Before Disclosure
Hunt.io traced BraZetsu ‘s infrastructure and found that hosting patterns and certificate data remained useful after published IOCs became outdated. Group-IB researchers published a detailed writeup on BraZetsu back on August 31, naming it a Python framework compiled with Nuitka and tying it to a Brazilian actor called Exilware with high confidence. Hunt.io checked whether…
-
OpenAI says Iran, Russia used AI journalists, think tanks to influence Western media
The two campaigns were rated 4 and 5 out of 6 for severity, the first time OpenAI has reported what it considers a high-impact influence campaigns. First seen on cyberscoop.com Jump to article: cyberscoop.com/openai-disrupts-russia-iran-ai-influence-operations/ also interesting: OpenAI Disrupts AI-Deployed Influence Operations Report on the Malicious Uses of AI OpenAI Shuts Down ChatGPT Accounts Linked to…
-
Making sure the checks get printed
Pierre’s debut newsletter explores the messy, real-world side of risk management and how to keep vital systems running when a perfect patch isn’t an option. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/making-sure-the-checks-get-printed/ also interesting: Not all cuts are equal: Security budget choices disproportionately impact risk Do CISOs need to rethink service provider risk? More…
-
Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks
Attackers behind a string of personal data leaks at Japanese organizations have abused APIs for mobile apps and targeted known software flaws, the JPCERT Coordination Center (JPCERT/CC) said.The Tokyo-based center, which takes incident reports, based its October 8, 2026 alert on those reports and other information. The alert names no attacker and no affected organization.JPCERT/…
-
FakeGit malware campaign returns with 17,610 malicious GitHub repos
More than 17,000 fake repositories on GitHub are distributing the SmartLoader malware after the FakeGit campaign reactivated earlier this month to push the StealC infostealer. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/fakegit-malware-campaign-returns-with-17-610-malicious-github-repos/ also interesting: Getting the Most Value Out of the OSCP: The PEN-200 Course Hackers Post Dozens of Malicious Copycat Repos to GitHub…
-
Scope of Asos data breach wider than first reported
Following a data breach earlier in October, cyber criminals appear to have a much more complete picture of Asos’ user base than first thought, it has emerged. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366651860/Scope-of-Asos-data-breach-wider-than-first-reported also interesting: US Employee Background Check Firm Hacked, 3 Million Records Exposed BK Technologies Data Breach, IT Systems Compromised, Data…
-
Cryptohack Roundup: Conviction in Uranium Finance Hack
Also: A US Court Orders $30M Penalty in Fundsz Fraud Case. This week, a conviction in a $54 million exploit, a $30 million Fundsz fraud penalty, Near Intents post-hack, Abstract Blockchain will shutdown, Velocity’s victim reimbursements, two U.S. regulatory proposals withdrawn, a ZachXBT North Korean laundering probe and ransomware-linked wallets identified. First seen on govinfosecurity.com…
-
ASOS: Hackers tricked way into employee account before sending rogue push notification
Tags: hackerThe company said its investigation, carried out with external experts, found the attackers had accessed “some personal information, including names and contact details, and certain non-personal account related information.” First seen on therecord.media Jump to article: therecord.media/asos-says-hackers-tricked-employee-access-push-notification also interesting: Researchers Found North Korean Hackers Advanced Tactics, techniques, and procedures Google, Microsoft say Chinese hackers are…
-
DOJ charges ransomware recovery CEO for secretly paying hackers
The owner of a ransomware recovery firm was hit with wire fraud charges for allegedly making secret ransom payments while overcharging the victims of attacks. First seen on therecord.media Jump to article: therecord.media/ransomware-recovery-charges-doj also interesting: Top 10 Cybersecurity Predictions for 2026 8 Cyber Predictions for 2025: A CSO’s Perspective Cybersecurity Snapshot: New Standard for AI…
-
WorkNest Secure Achieves CREST STAR-FS Accreditation for Red Teaming
WorkNest Secure has achieved CREST Simulated Targeted Attack & Response for Financial Services (STAR-FS) accreditation, recognising its ability to deliver intelligence-led red teaming assessments for organisations operating in high-risk and regulated environments. The accreditation confirms that WorkNest Secure meets CREST’s standards for conducting threat-led penetration testing, using realistic attack scenarios to assess how effectively organisations…
-
Crypto thief who splurged on gold grills sentenced in London
A 25-year-old man who helped steal nearly $260,000 in cryptocurrency through a SIM-swapping fraud scheme was sentenced to two and a half years in prison at a London court. First seen on therecord.media Jump to article: therecord.media/cryptocurrency-sim-swap-london also interesting: US Pig Butchering Victims ‘Will’ Get Refunds, Feds Seize $225M Cryptocurrency Banks need stricter controls to…
-
ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms
Tags: ai, attack, crowdstrike, cybersecurity, data, finance, intelligence, penetration-testing, theft, threat, toolCybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence (AI) pen testing tool named ARTEX to carry out the attacks.The activity, per CrowdStrike Intelligence, was active from late September to early October 2026, and resulted in data exfiltration.”In this activity, the threat actor leveraged…
-
UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML
The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN.According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel. The cybersecurity company is tracking the cluster under the name Earth Sirrush (previously SHADOW-EARTH-065).ASHVEIN, First seen on…
-
Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between What Your Developers Declare and What’s Actually in Your Code New snippet-level scanning shows security and compliance leaders which open-source code and which AI-written code never made it into a manifest. Insignary Inc. today announced the general availability of Insignary…
-
Cisco warns of critical flaws allowing Nexus switch takeover
Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privileges on Nexus switches. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisco-warns-of-critical-flaws-allowing-nexus-switch-takeover/ also interesting: Cybersecurity Snapshot: Industrial Systems in Crosshairs of Russian Hackers, FBI Warns, as MITRE Updates List…
-
The Security Interviews: Evren Karaibrahimgil, Welsh FA
Evren Karaibrahimgil, IT manager at the FAW, on securing the national football association of Wales against evolving cyber threats, with Euro 2028 on home soil in mind First seen on computerweekly.com Jump to article: www.computerweekly.com/feature/The-Security-Interviews-Evren-Karaibrahimgil-Welsh-FA also interesting: Ukraine-targeted cyber, influence threat actors subjected to EU sanctions Hackers Are Stealing Salesforce Data, Google Warns UNC2891 Hackers…
-
Midnight Mimosa Malware Found Preinstalled on Low-Cost Android Phones
Low-cost Android phones can arrive already compromised, with malware embedded in their firmware before buyers switch them on. First seen on hackread.com Jump to article: hackread.com/midnight-mimosa-malware-preinstalled-android-phones/ also interesting: Privacy Roundup: Week 9 of Year 2025 New Trinda Malware Targets Android Devices by Replacing Phone Numbers During Calls Cybersecurity Snapshot: Global Agencies Target Criminal “Bulletproof” Hosts,…
-
Asos confirms breach of customer data after hackers send rogue app notification
The hackers alerted the fashion giant’s customers through a push notification that said they had “fully compromised” the company’s cloud storage. First seen on techcrunch.com Jump to article: techcrunch.com/2026/10/08/asos-confirms-breach-of-customer-data-after-hackers-send-rogue-app-notification/ also interesting: AWS customers face massive breach amid alleged ShinyHunters regroup Top 12 ways hackers broke into your systems in 2024 Privacy Roundup: Week 11 of…
-
Leaked chats show Russian extortion gang sending ‘agents’ into US law firms
In leaked chats, members track dozens of victims, haggle over multimillion-dollar payments and direct operatives based in the United States whom they call “agents.” First seen on therecord.media Jump to article: therecord.media/leaked-chats-show-russian-extortion-gang-sending-agents-to-law-firms also interesting: Cybersecurity Snapshot: CISA Hands Down Cloud Security Directive, While Threat from North Korean IT Workers Gets the Spotlight 9 things CISOs…
-
What the C-suite needs to know about AI governance
As AI adoption surges, executives are learning tough lessons about security, oversight and accountability. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/c-suite-ai-governance/832497/ also interesting: ISMG Editors: AI Security Wake-Up Call From DeepSeek 5 key priorities for your RSAC 2026 agenda AI Governance and Risk Insights for Enterprises – Kovrr KI-Agenten absichern: Warum Identity zum Erfolgsfaktor…
-
Gefährliche EAnhänge: Outlook blockiert MSIX-Dateien
Tags: mailBeide Dateiformate erlauben die Installation von Anwendungen. Die Änderung gilt für Outlook im Web und das neue Outlook für Windows. First seen on golem.de Jump to article: www.golem.de/news/gefaehrliche-e-mail-anhaenge-outlook-blockiert-msix-dateien-2610-213884.html also interesting: Schutz vor Business E-Mail Compromise: 8 wichtige Punkte für Ihre BEC-Richtlinie Sieben gängige Wege, ein Smartphone zu hacken EAngriffe: Hacker setzen auf Täuschung statt Technik…
-
Cross-tenant data exposure – Cloudflare-Container gaben Datenreste fremder Kunden preis
First seen on security-insider.de Jump to article: www.security-insider.de/cloudflare-containers-sicherheitsluecke-datenreste-auslesbar-a-cbfeb9d28f7a7437a5583b4da98c551f/ also interesting: Beyond cryptocurrency: Blockchain 101 for CISOs and why it matters Beyond Testing: API Security as the Foundational Intelligence for an ‘industry leader’-Level Security Strategy Startup Amutable plotting Linux security overhaul to counter hacking threats What is Security Posture Management and Why is it Important?
-
Asos says customers’ names, contact details and search histories hacked
Experts say breadth of data accessed could help attackers devise “highly convincing” phishing scams<ul><li><a href=”https://www.theguardian.com/business/live/2026/oct/08/oil-prices-rise-shipping-attacks-rate-rise-uk-housing-market-bank-england-latest-live-updates”>Business live live updates</li></ul>Asos hackers gained access to millions of customers’ recent search histories as well as names, addresses and phone numbers, the online fashion retailer has revealed.Terms typed in by customers such as “glamorous wide fit” and “Asos petite” were…
-
ASOS Confirms Data Breach Linked to Stolen Employee Credentials
The ASOS hack comes from the compromise of agentic marketing platform Simon AI, said the attackers First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/asos-data-breach-stolen-employee/ also interesting: Don’t confuse asset inventory with exposure management What is Security Posture Management and Why is it Important? What is Security Posture Management and Why is it Important? What is…
-
Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware
Tags: breach, credentials, crypto, cyber, hacker, malicious, malware, software, supply-chain, threatA threat actor published a malicious version of the tensorlake npm package on October 8, 2026, embedding a new variant of the self-replicating Shai-Hulud supply-chain worm. The compromised release, tensorlake version 0.5.144, can steal developer secrets, target browser-stored cryptocurrency credentials, and use stolen publishing credentials to spread through connected software supply chains. The incident highlights…

