1Hackers obtain counterfeit TLS certificates for Google and other large servicesArs Technica SecurityBleeping ComputerDark ReadingInfosecurity MagazineMalwarebytes LabsThe Hacker News+3Attackers hijacked three top-level domains and used their control to mint counterfeit TLS certificates for Google and other large organizations, Google said Tuesday. The attackers launched a series of attacks on the .gh, .sl, and .as country code top-level domains (ccTLDs) and then modified authoritative DNS records for selected domains within those namespaces. By controlling those DNS records, the attackers were able to pass automated domain control validation checks and obtain unauthorized certificates for “several Google domains” and “several leading global brands and widely used online…
5CVE-2026-21589: Critical unauthenticated arbitrary file access in Atlassian productsBleeping ComputerRapid7 BlogwatchTowr LabsCVE-2026-21589 ↗Overview On October 5, 2026, Atlassian published a security advisory for CVE-2026-21589 , a critical arbitrary file access vulnerability affecting eight products: Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian assigned the vulnerability a CVSSv4 score of 9.3 . An unauthenticated remote attacker who knows a target file's exact name and path can access it within the application's web root; the vulnerability does not provide directory listing or enumeration…
6Google Chrome Update Fixes Massive 247 Vulnerabilities, Including 4 Code Execution FlawsCyber Security NewsMalwarebytes LabsSecurityWeekGoogle released a major Chrome security update on October 6, 2026, fixing 247 vulnerabilities, including four critical memory-safety flaws , across Windows, Mac, and Linux. The patched versions are 155.0.8059.39/.40 for Windows and Mac and 155.0.8059.39 for Linux. Although the critical bugs raise concerns about possible code execution, Google’s announcement identifies them as use-after-free vulnerabilities. It does not describe specific exploitation methods or confirm arbitrary code execution. The first critical vulnerability, CVE-2026-106382, affects Chromecast. Google reported the…
7Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data AccessBleeping ComputerSchneier on SecurityThe Hacker NewsApple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents. "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history – without users' full knowledge
8FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device CredentialsCyberScoopThe Hacker NewsThe Register SecurityThe U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. "The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat
10Citrix NetScaler security snafus get even worse amid more 0-day reportsCCCS Alerts & AdvisoriesCyberScoopInfosecurity MagazineThe Register Security+1The attackers just keep coming after Citrix NetScaler appliances, as both the feds and private security researchers warn that someone found - and has already exploited - yet another Citrix bug before it had a patch. This latest vulnerability, tracked as CVE-2026-88779, is a memory overflow bug that leads to denial of service attacks. It only affects NetScaler ADC and Gateway appliances configured as a SAML (Security Assertion Markup Language) service provider or identity provider, used for single sign-on authentication. Late Friday, amid exploitation reports, Citrix confirmed that it was…
14Critical WordPress Vulnerabilities Enable XSS, SQL Injection and Data Disclosure AttacksBleeping ComputerCyber Security NewsWordPress released version 7.1.3 on October 6, 2026, addressing vulnerabilities involving cross-site scripting , SQL injection, information disclosure, and other security weaknesses. The project recommends immediate updates, with fixes also available for older affected branches. Only the latest WordPress version remains actively supported. The release documentation lists seven security issues, although its introductory sentence describes “one security fix.” It provides no CVE identifiers, severity scores, or confirmed exploitation details. Consequently, the headline’s critical wording should…
15Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as ProxiesSecurityWeekThe Hacker NewsThe Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, and edit Wikipedia pages. "The unauthorized bot activities included edits to our wikis, some unsuccessful attempts to exploit a public note-taking tool we host, and heavy traffic,
16100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealerThe Hacker NewsThe RecordThe Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer (aka Psychedelic Stealer). The activity, which was observed by the agency in September 2026, has been attributed to a threat cluster dubbed UAC-0277. It did not disclose who the
19Zombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secretsPalo Alto Unit 42The Register SecurityGitHub Copilot CLI may reveal developer secrets if it comes across instructions that tell it to do so, depending on the underlying model. The coding agent tool was flagged earlier this year for being susceptible to indirect prompt injection. That's when a model ingests text from a source other than the user that directs it to take some action outside the scope of its intended function. This is more of the same, with a twist. According to security researchers at Adversa AI, GitHub Copilot CLI suffers from the same vulnerability identified in Grok two months ago: Cryptographic Context Injection…
20Hitachi Energy RTU500CISA Alerts & AdvisoriesCISA ICS AdvisoriesView CSAF Summary Hitachi Energy is publishing this cybersecurity advisory in response to the security findings reported by Dragos affecting end-of-life RTU500 CMU firmware version 9.x. The reported findings are associated with legacy RTU500 firmware versions that were developed according to the cybersecurity requirements, threat landscape, and industry practices that existed at the time of their release. As cybersecurity threats and security expectations have evolved, these end-of-life versions no longer incorporate many of the security controls and hardening measures that are standard in…
A critical vulnerability (CVE-2026-21589) affecting multiple Atlassian product families, including Jira, Confluence, and Bitbucket, is being exploited in attacks that do not require authentication.
Overview On October 5, 2026, Atlassian published a security advisory for CVE-2026-21589 , a critical arbitrary file access vulnerability affecting eight products: Bitbucket Data Center, Confluence Data Center, Jira…
Overview On October 5, 2026, Atlassian published a security advisory for CVE-2026-21589 , a critical arbitrary file access vulnerability affecting eight products: Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian assigned the vulnerability a CVSSv4 score of 9.3 . An unauthenticated remote attacker who knows a target file's exact name and path can access it within the application's web root; the vulnerability does not provide directory listing or enumeration…
Rockstar Games has faced separate intrusions involving proprietary source code, 78.6 million business records, and what researchers describe as a playable GTA VI development build. The incidents span several years…
Rockstar Games has faced separate intrusions involving proprietary source code, 78.6 million business records, and what researchers describe as a playable GTA VI development build. The incidents span several years, rather than one attack that stole everything together. The reported entry points include stolen employee credentials, repeated authentication prompts, and compromised access tokens belonging to an outside service provider. Alongside these breaches, supposed leaked game downloads have created another route for criminals to infect players’ computers. After reviewing the incidents…
The 2026 findings are not just a year-over-year shift. They mark the latest point in a five-year arc where resilience, AI governance, human risk, and board scrutiny are converging inside the systems where work actually…
The 2026 findings are not just a year-over-year shift. They mark the latest point in a five-year arc where resilience, AI governance, human risk, and board scrutiny are converging inside the systems where work actually happens. For years, the enterprise cybersecurity story has been told as a straight line of escalation: more attacks, more data loss, more pressure, and more urgency. That
The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate…
The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. "The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat
Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw…
Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software
If you’re evaluating an agentic pentesting solution right now, you’ve probably heard the same pitch more than once: point it at a target, and it discovers, validates, and exploits attack paths autonomously, the way a…
If you’re evaluating an agentic pentesting solution right now, you’ve probably heard the same pitch more than once: point it at a target, and it discovers, validates, and exploits attack paths autonomously, the way a real attacker would. That promise is worth taking seriously. It’s also worth pressure testing, and three questions do the heavy lifting. What can the assessment actually
In August, the Malwarebytes research team reported on a new malicious turnkey kit that makes it possible for almost anyone to launch a sophisticated online scam. The kit was not simply a fake website. It bundled the…
In August, the Malwarebytes research team reported on a new malicious turnkey kit that makes it possible for almost anyone to launch a sophisticated online scam. The kit was not simply a fake website. It bundled the command center, victim tracking, and administrative tools into a ready-to-use package, reducing the technical knowledge needed to operate a scam. The discovery highlights an important feature of the cybercrime economy: criminals don’t necessarily need to build their own infrastructure from scratch. Instead, they can buy ready-made services that handle much of the complicated work…
The FBI and US Secret Service (USSS) say criminals using credentials linked to the FortiBleed campaign are locking organizations out of their Fortinet firewalls. The agencies published a joint advisory on Tuesday…
The FBI and US Secret Service (USSS) say criminals using credentials linked to the FortiBleed campaign are locking organizations out of their Fortinet firewalls. The agencies published a joint advisory on Tuesday, citing SOCRadar's verification of more than 86,644 compromised devices across 194 countries. "Based on initial responses, some victims may get locked out of their Fortinet devices if the threat actor either deletes or changes the password for original accounts on the system," their advisory [PDF] states. "During the initial intrusion, threat actors create new accounts not previously…
Anthropic’s Mythos AI has identified a critical vulnerability in Rejetto HTTP File Server that could allow remote attackers to forge administrator sessions and execute arbitrary code. The issue, tracked as…
Anthropic’s Mythos AI has identified a critical vulnerability in Rejetto HTTP File Server that could allow remote attackers to forge administrator sessions and execute arbitrary code. The issue, tracked as CVE-2026-61500, stems from predictable session-signing keys generated through JavaScript’s non-cryptographic Math.random() function. Horizon3 made the finding after joining Anthropic’s Project Glasswing in July 2026, which uses the Mythos Preview model and industry partners to identify and fix critical and open-source software flaws. Anthropic says Mythos can autonomously find high-severity…
Progress disclosed critical command injection flaw CVE-2026-91140 in DataDirect Autonomous REST Connector AI Model Generator agents, allowing malicious OpenAPI or Swagger documents to execute arbitrary OS commands . The…
Progress disclosed critical command injection flaw CVE-2026-91140 in DataDirect Autonomous REST Connector AI Model Generator agents, allowing malicious OpenAPI or Swagger documents to execute arbitrary OS commands . The security bulletin, published on October 6, 2026, covers Early Access agent definitions available through the public progress/datadirect-arc-ai-model-gen GitHub repository. Progress has released updated definitions and urges customers to retrieve them before running the agents again. The vulnerability originates from a filename value derived from an OpenAPI or Swagger document…
ASOS customers opened their phones to find a hostile push notification delivered through the retailer’s own app. The message claimed the company’s Snowflake environment had been compromised and directed ASOS to engage…
ASOS customers opened their phones to find a hostile push notification delivered through the retailer’s own app. The message claimed the company’s Snowflake environment had been compromised and directed ASOS to engage with the sender through Telegram. ASOS later confirmed to Sky News that an unauthorized customer notification had been sent and said it was investigating activity involving third-party platforms used to communicate with customers. The company also said basic personal information, including names and contact details, may have been accessed, while payment-card information and…
A North Carolina musician was sentenced to 18 months in prison for collecting more than $10 million in royalties from Spotify, Apple Music, Amazon Music, and YouTube Music in a massive streaming royalty fraud scheme.
Security researcher Oliver Fish says he found an OpenAI sandbox escape that let him request paid AI models without an API key or an account. A screenshot shared online shows OpenAI awarding $300 for a report titled…
Security researcher Oliver Fish says he found an OpenAI sandbox escape that let him request paid AI models without an API key or an account. A screenshot shared online shows OpenAI awarding $300 for a report titled “Unauthenticated Sandbox Escape Enables Access to Internal OpenAI Responses API.” The issue appears to have crossed two security limits at once: sandbox isolation and API authentication. OpenAI’s developer guide tells developers to create an API key before making requests, while its Responses API provides access to models and tools for agent workflows. If Fish’s claim is correct, a…
Google has released updates for the Chrome browser and the ChromeOS operating system. On October 6, Google released a Stable Channel Update for Desktop . This is the most important one for desktop users. It brings…
Google has released updates for the Chrome browser and the ChromeOS operating system. On October 6, Google released a Stable Channel Update for Desktop . This is the most important one for desktop users. It brings Chrome to version 155.0.8059.39 for Linux and versions 154.0.8037.39/.40 for Windows and Mac . The update includes 247 security fixes including four rated Critical. On the same day, Google released version 155.0.8059.39 for Android , to a small percentage of users. It may not be available on Google Play for everyone yet but keep an eye out for it. Google says it includes stability…
Cybersecurity Awareness Month 2026 arrives as online attacks become easier to launch, harder to spot, and more focused on people. Observed every October, the campaign helps individuals and businesses build safer digital…
Cybersecurity Awareness Month 2026 arrives as online attacks become easier to launch, harder to spot, and more focused on people. Observed every October, the campaign helps individuals and businesses build safer digital habits. This year there are two themes. The NCA is running “Don’t Make It Easy for Them” , a push to make life harder for cybercriminals through small daily habits. CISA is running “Securing the Next 250” , tied to America’s 250th anniversary, with a strong focus on critical services like power and water. The message is not limited to the U.S. Canada’s Get Cyber Safe program…
The net is tightening around the Shiny Hunters cybercrime group following the reported arrest of a second member. On Saturday, Reuters said that 16 year-old Saif al-Din Khader had been arrested in Jordan and was in FBI…
The net is tightening around the Shiny Hunters cybercrime group following the reported arrest of a second member. On Saturday, Reuters said that 16 year-old Saif al-Din Khader had been arrested in Jordan and was in FBI custody. This follows the arrest earlier in September of another member in the Netherlands. Third party reports named him as 24 year-old Pepijn van der Stap, an offensive security lead at Dutch company Neo Security. The FBI posted a message following the Dutch arrest warning other ShinyHunter members that it was coming for them next. Cyber Division Assistant Director Brett…
For some time now, the cybersecurity community has seen examples of autonomous agents, built inside AI labs, attacking public infrastructure (to name a few, Hugging Face , DSEWiki , and RubyGems ). Of course, frontier…
For some time now, the cybersecurity community has seen examples of autonomous agents, built inside AI labs, attacking public infrastructure (to name a few, Hugging Face , DSEWiki , and RubyGems ). Of course, frontier labs have built-in security to prevent these attacks from occurring, but every now and then, the training or prompting appears to be insufficient — especially when the agents themselves attempt to use logic to probe and bypass the restrictions placed on them. The question that matters is not whether AI attacks are coming, because the age of AI agents executing cyber attacks is…
Hackers are impersonating ChatGPT, Claude and Gemini with fake advertising products that steal passwords and multifactor authentication codes. Instead of delivering a conventional malware download, the campaign uses…
Hackers are impersonating ChatGPT, Claude and Gemini with fake advertising products that steal passwords and multifactor authentication codes. Instead of delivering a conventional malware download, the campaign uses convincing websites and live human operators to guide victims through fraudulent sign-in screens. Invitation emails lead advertisers to pages promising campaign planning, spending audits and account connections. The approach echoes earlier attacks involving fake AI advertising apps , which used familiar technology brands to make credential requests appear legitimate. Island.io…
WordPress released version 7.1.3 on October 6, 2026, addressing vulnerabilities involving cross-site scripting , SQL injection, information disclosure, and other security weaknesses. The project recommends immediate…
WordPress released version 7.1.3 on October 6, 2026, addressing vulnerabilities involving cross-site scripting , SQL injection, information disclosure, and other security weaknesses. The project recommends immediate updates, with fixes also available for older affected branches. Only the latest WordPress version remains actively supported. The release documentation lists seven security issues, although its introductory sentence describes “one security fix.” It provides no CVE identifiers, severity scores, or confirmed exploitation details. Consequently, the headline’s critical wording should…
OpenSSH 10.6, released on October 6, 2026, fixes security flaws that could expose secrets, write files outside intended folders, or enable shell injection under specific conditions. The update covers both client and…
OpenSSH 10.6, released on October 6, 2026, fixes security flaws that could expose secrets, write files outside intended folders, or enable shell injection under specific conditions. The update covers both client and server tools, making it relevant to administrators and users who rely on SSH for remote access and file transfers. The official release notes describe separate weaknesses with different attack requirements, not a single attack affecting every installation. The main concerns involve shared compression across SSH channels, paths returned by SFTP servers, and untrusted usernames…
Security researchers reportedly exploited 32 unique zero-day vulnerabilities and earned $388,500 on the opening day of Pwn2Own Ireland 2026. Samsung Galaxy S26, OpenAI Codex , smart home devices and AI services fell to…
Security researchers reportedly exploited 32 unique zero-day vulnerabilities and earned $388,500 on the opening day of Pwn2Own Ireland 2026. Samsung Galaxy S26, OpenAI Codex , smart home devices and AI services fell to working exploits, but the Google Pixel 10 attempt failed within the contest time limit. Day 1 is officially wrapped with quite a pot of gold being awarded across the teams! Checkout a snapshot of where the leaderboard stands as of today – more to come over the next two days so keep following along as we post live updates! #Pwn2Own #Pwn2OwnIreland For full……
Google released a major Chrome security update on October 6, 2026, fixing 247 vulnerabilities, including four critical memory-safety flaws , across Windows, Mac, and Linux. The patched versions are 155.0.8059.39/.40 for…
Google released a major Chrome security update on October 6, 2026, fixing 247 vulnerabilities, including four critical memory-safety flaws , across Windows, Mac, and Linux. The patched versions are 155.0.8059.39/.40 for Windows and Mac and 155.0.8059.39 for Linux. Although the critical bugs raise concerns about possible code execution, Google’s announcement identifies them as use-after-free vulnerabilities. It does not describe specific exploitation methods or confirm arbitrary code execution. The first critical vulnerability, CVE-2026-106382, affects Chromecast. Google reported the…
Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards and blocking classifiers, as the company…
Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards and blocking classifiers, as the company claimed its Project Glasswing initiative uncovered at least 129,000 verified software vulnerabilities between April and July 2026. The company said it also found an additional
The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer…
The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer (aka Psychedelic Stealer). The activity, which was observed by the agency in September 2026, has been attributed to a threat cluster dubbed UAC-0277. It did not disclose who the
South Korean president Lee Jae Myung has told the nation’s cabinet that it’s time to develop AI-powered defensive tools to combat AI-wielding attackers. “Recently, a series of personal information leak incidents have…
South Korean president Lee Jae Myung has told the nation’s cabinet that it’s time to develop AI-powered defensive tools to combat AI-wielding attackers. “Recently, a series of personal information leak incidents have been occurring at financial and public institutions,” he said yesterday – likely referring to incidents like the breach at e-tailer Coupang and last week’s raid on local banks that exposed customer data. “Circumstances indicate that artificial intelligence was utilized, causing great concern and anxiety among the public,” he claimed. “I request that the relevant authorities…
Only a week after warning about the perils of competitor Z.ai's GLM-5.3 model and its advanced cybersecurity capabilities, Anthropic has expanded its Cyber Verification Program (CVP) – or rather, reconfigured it. "For…
Only a week after warning about the perils of competitor Z.ai's GLM-5.3 model and its advanced cybersecurity capabilities, Anthropic has expanded its Cyber Verification Program (CVP) – or rather, reconfigured it. "For the past six months, we’ve enabled trusted access through two programs: Project Glasswing and the CVP," the AI biz said. "Now, we’re integrating these programs into one expanded offering, designed to give more security organizations access to the capabilities they need to protect their systems." Project Glasswing and CVP launched in April 2026 alongside the debut of Mythos, the…
FortiBleed, a credential compromise campaign targeting Fortinet firewalls and VPN gateways, is an ongoing threat that can lock users out of their Fortinet accounts and also lead to ransomware attacks, the FBI and Secret…
FortiBleed, a credential compromise campaign targeting Fortinet firewalls and VPN gateways, is an ongoing threat that can lock users out of their Fortinet accounts and also lead to ransomware attacks, the FBI and Secret Service said in an alert published Tuesday. “Affected organizations may find themselves locked out of their systems if threat actors disable accounts or change passwords, requiring remediation steps beyond standard patching and password resets,” the alert states . “In addition, the FortiBleed attack chain has been observed as an initial entry point for ransomware affiliates.”…
Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts.
A study of 2.5 million devices across 50 healthcare organization suggests the sector has a long way to go in getting ready for the post-quantum cryptography era.
A bipartisan update to a California wiretapping law will eliminate the right to sue over internet-based surveillance, ending a key provision of a 57-year-old wiretapping law. Advocates say it is an overdue correction…
A bipartisan update to a California wiretapping law will eliminate the right to sue over internet-based surveillance, ending a key provision of a 57-year-old wiretapping law. Advocates say it is an overdue correction meant to prevent frivolous lawsuits, while privacy advocates call it a blow to digital consumer privacy rights. The California Invasion of Privacy Act, originally passed in 1967, requires a court order for wiretapping, eavesdropping, interception or recording of telephone calls. Over time, courts extended the law to cover most internet-based communications as well, such as email…
A man convicted of manslaughter in Arizona will be resentenced because an AI-generated video of his victim speaking from beyond the grave was ruled to have carried “undue emotional weight” as an impact statement. An…
A man convicted of manslaughter in Arizona will be resentenced because an AI-generated video of his victim speaking from beyond the grave was ruled to have carried “undue emotional weight” as an impact statement. An appellate court in Arizona ruled that the manslaughter charge will remain, but the judge must reconsider the length of the man’s prison term because of AI. In 2021, Gabriel Horcasitas shot and killed Christopher Pelkey during a road rage incident. A jury found him guilty of manslaughter. During Horcasitas’ sentencing hearing, Pelkey’s sister Stacey Wales played an AI-generated…
On the first day of the Pwn2Own Ireland 2026 competition, security researchers hacked the Samsung Galaxy S26 twice and earned $388,500 after exploiting 32 zero-days.
Attackers hijacked three top-level domains and used their control to mint counterfeit TLS certificates for Google and other large organizations, Google said Tuesday. The attackers launched a series of attacks on the…
Attackers hijacked three top-level domains and used their control to mint counterfeit TLS certificates for Google and other large organizations, Google said Tuesday. The attackers launched a series of attacks on the .gh, .sl, and .as country code top-level domains (ccTLDs) and then modified authoritative DNS records for selected domains within those namespaces. By controlling those DNS records, the attackers were able to pass automated domain control validation checks and obtain unauthorized certificates for “several Google domains” and “several leading global brands and widely used online…
Cybersecurity researchers have disclosed details of a "human-operated phishing platform" that impersonates advertising products for artificial intelligence (AI) chatbots like Google Gemini, Anthropic Claude, OpenAI…
Cybersecurity researchers have disclosed details of a "human-operated phishing platform" that impersonates advertising products for artificial intelligence (AI) chatbots like Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus. The products, which claim to offer campaign optimization, spend audits, and business-account connections, are designed with one goal in
Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection. Threat actors…
Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection. Threat actors are known to name their malicious software after a legitimate operating system component or a process as a defense evasion measure. By borrowing the name of a real binary, it may
Former National Security Agency Director Paul Nakasone said a reported broad reorganization of the agency is “probably necessary” as it confronts faster-moving cyberthreats, artificial intelligence and competition with…
Former National Security Agency Director Paul Nakasone said a reported broad reorganization of the agency is “probably necessary” as it confronts faster-moving cyberthreats, artificial intelligence and competition with China, but he cautioned that the outcome will depend on how the changes are carried out. Speaking Tuesday at VulnCheck’s ThreatCon1 conference, Nakasone addressed a recent report that the NSA is undergoing a major restructuring centered in part on artificial intelligence and China. According to a report last month from the Washington Post , the agency is creating five new…
Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and…
If you signed up for Trump Mobile, you may be part of an exclusive club of … ransomware victims. Criminals called BYOD claim to have broken into the Trump-branded mobile biz and leaked data belonging to 3,615 people…
If you signed up for Trump Mobile, you may be part of an exclusive club of … ransomware victims. Criminals called BYOD claim to have broken into the Trump-branded mobile biz and leaked data belonging to 3,615 people, including names, email addresses, phone numbers, home addresses, and order details. BYOD is a new ransomware-as-a-service operation, and Trump Mobile is only the third organization posted on its data-leak site. According to the group’s posted claim, after telling Trump Mobile that it had been breached, the wireless provider replied: “We have no team to handle this" and “Anyone…
Welcome back to yet another episode of "security was taken seriously". Being who we are (and constantly being exposed to what we see…), we recognize we have been doomed to eternal damnation as we keep on watching…
Welcome back to yet another episode of "security was taken seriously". Being who we are (and constantly being exposed to what we see…), we recognize we have been doomed to eternal damnation as we keep on watching security best practices crumble behind “secure by design” public statements. And in the times we live in, where anyone with a prompt window in front of them can say "reproduce the vulnerability, make no mistakes", so are you. In Greek mythology, Atlas was punished by the gods for misbehaving. Reality is unfair, and all we get is Atlassian punishing the rest of us for running their…
Not quite an EDR-killer, but the proof-of-concept cyber technique creates a silent virus detection gap while service runs normally, no exploit required.
UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment.
Most of what has been written about AI and vulnerability management focuses on speed: how much faster frontier AI models can scan code, find weaknesses, design patches, and build exploits than any human team. That part…
Most of what has been written about AI and vulnerability management focuses on speed: how much faster frontier AI models can scan code, find weaknesses, design patches, and build exploits than any human team. That part is true, and it matters to how we remediate vulnerabilities. The more challenging question is what happens after the scan? Frontier AI models are about to hand every security team a far larger set of findings than they have ever had to work through. The real test for chief information security officers (CISOs) and IT security leaders is not how fast they can patch. It is…