access ai android api apple attack authentication backdoor breach business ceo china cisa cisco ciso cloud compliance control credentials crypto cve cyber cyberattack cybercrime cybersecurity data data-breach defense detection email endpoint exploit finance flaw framework fraud google governance government group hacker hacking healthcare identity infrastructure intelligence Internet jobs law leak linux malicious malware microsoft monitoring network open-source password phishing privacy ransomware remote-code-execution resilience risk russia scam service software strategy supply-chain technology theft threat tool unclassified update usa vulnerability windows zero-day
-
Ransomware attack disrupts Japan’s IDCF Cloud used by govt clients
IDC Frontier, a major Japanese cloud and digital infrastructure company, disclosed that its IDCF Cloud service was targeted in a ransomware attack that caused an outage at a data center cluster serving the eastern part of the country. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ransomware-attack-disrupts-japans-idcf-cloud-used-by-govt-clients/ also interesting: The healthcare industry is at a cybersecurity…
-
Italy’s Foreign Ministry Under Cyberattack as Embassy Sites Come Under Review
Italy’s Foreign Ministry is defending its website against a cyberattack, checking embassy sites and pushing for EU action to identify attackers. On the morning of October 8, Italy’s Ministry of Foreign Affairs said its website was being attacked. According to the ministry’s own statement, its protection systems have mitigated the attack so far, with no…
-
Ransomware recovery CEO indicted after allegedly paying hackers and pocketing millions
Zohar Pinhasi allegedly deceived ransomware recovery clients into a payment scheme disguised as a specialized service that helped victims avoid paying cybercriminals. First seen on cyberscoop.com Jump to article: cyberscoop.com/monstercloud-zohar-pinhasi-ransomware-recovery-scheme/ also interesting: 8 Cyber Predictions for 2025: A CSO’s Perspective Password managers under increasing threat as infostealers triple and adapt 13 ways attackers use generative…
-
DOJ, FBI seize Flax Typhoon-linked hacking tools Microscan, FishHub
The seizures of the tools, allegedly operated by the Chinese firm Integrity Tech, accompanied a warning from the FBI, CISA and NSA. First seen on cyberscoop.com Jump to article: cyberscoop.com/doj-fbi-seize-flax-typhoon-hacking-tools-microscan-fishhub/ also interesting: Cybersecurity Snapshot: Study Raises Open Source Security Red Flags, as Cyber Agencies Offer Prevention Tips Against Telecom Spying Attacks The 2024 cyberwar playbook:…
-
Lawmakers warn Google could expose Spirit Airlines data in $10 million AI training deal
The proposed sale would include about 100 million emails, 500 million Microsoft Teams messages, employment contracts, employee and timecard records and payroll and tax information, Rep. Steven Horsford (D-NV) said in a press release. First seen on therecord.media Jump to article: therecord.media/lawmakers-warn-of-google-spirit-ai-training-deal also interesting: This new cipher tech could break you out of your Gen…
-
Let’s Encrypt cuts certificate lifetimes to 64 days starting February 2027
Tags: unclassifiedFree SSL/TLS certificate lifetimes reduce to 64 days in February. First seen on arstechnica.com Jump to article: arstechnica.com/gadgets/2026/10/lets-encrypt-cuts-certificate-lifetimes-to-64-days-starting-february-2027/ also interesting: Datenschutzpanne: Tracking von DHL und Yun Express verriet Empfängeradressen Holiverse Makes NASA’s Latest Achievements Accessible to Everyone adesso holt zum fünften Mal in Folge Platin beim BigData-Insider Award FBI Investigates Suspicious Activity in Surveillance Platform
-
ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories
The crooks have trust problems of their own. One ransomware affiliate decided to keep the profits for himself. Elsewhere, an attacker left a server exposed, complete with tools and traces of an intrusion. Apparently, keeping things secure is a problem on both sides of the fence.The rest of the week isn’t much more reassuring. Malicious…
-
FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails
Tags: access, breach, china, cybersecurity, email, flaw, government, group, hacker, healthcare, law, technology, toolHackers tied to a Chinese cybersecurity company stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, the FBI and agencies in 6 other countries said on October 8.The company, Integrity Technology Group, has been sanctioned by the U.S. and the UK. The hackers scanned websites for flaws using…
-
Venezuelan Cartel’s Malware Honcho Nabbed for ATM Jackpotting
The first cybercriminal to ever make the FBI’s 10 Most Wanted Fugitives list allegedly infused Tren de Aragua’s violent criminal operations with cash. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/venezuelan-cartel-malware-honcho-nabbed-atm-jackpotting also interesting: Cybercriminals target transportation companies in North America with info-stealing malware A new ransomware regime is now targeting critical systems with weaker networks…
-
Low-cost Android phones ship with residential proxy malware
A malware campaign dubbed ‘Midnight Mimosa’ has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/low-cost-android-phones-ship-with-residential-proxy-malware/ also interesting: Privacy Roundup: Week 4 of Year 2025 The…
-
International coalition seizes tools used by cyber firm behind Flax Typhoon
The U.S. and other nations took down digital tools and infrastructure by Beijing-based Integrity Tech that allowed “widespread vulnerability scanning and, in some cases, intrusions” as part of the Flax Typhoon campaign. First seen on therecord.media Jump to article: therecord.media/flax-typhoon-china-tools-integrity-tech-international-takedown also interesting: Cybersecurity Snapshot: Study Raises Open Source Security Red Flags, as Cyber Agencies Offer…
-
Russian Spies Give ‘MatchBoil’ Malware a Stealthy Facelift
Cyber-espionage actor UAC-0099 has been steadily refining its flagship dropper in campaigns targeting Ukrainian organizations. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/russian-spies-matchboil-malware-facelift also interesting: Russian Hackers Deploy HATVIBE and CHERRYSPY Malware Across Europe and Asia International effort erases PlugX malware from thousands of Windows computers Russia-Linked SpyPress Malware Exploits Webmails to Spy on Ukraine…
-
Ransomware Response Firm CEO Accused of Data Recovery Fraud
MonsterCloud CEO Disguised Ransom Payments as Proprietary Tool, Say Prosecutors. A ransomware service that offered clients an extortion-free shortcut to unlocking their files was too good to be true, say U.S. federal prosecutors who say the secret behind Florida-based MonsterCloud was actually succumbing to hacker demands and paying a ransom to attackers, at victims’ expense.…
-
Hunt.io Finds New Infrastructure Of BraZetsu Access Broker Months Before Disclosure
Hunt.io traced BraZetsu ‘s infrastructure and found that hosting patterns and certificate data remained useful after published IOCs became outdated. Group-IB researchers published a detailed writeup on BraZetsu back on August 31, naming it a Python framework compiled with Nuitka and tying it to a Brazilian actor called Exilware with high confidence. Hunt.io checked whether…
-
OpenAI says Iran, Russia used AI journalists, think tanks to influence Western media
The two campaigns were rated 4 and 5 out of 6 for severity, the first time OpenAI has reported what it considers a high-impact influence campaigns. First seen on cyberscoop.com Jump to article: cyberscoop.com/openai-disrupts-russia-iran-ai-influence-operations/ also interesting: OpenAI Disrupts AI-Deployed Influence Operations Report on the Malicious Uses of AI OpenAI Shuts Down ChatGPT Accounts Linked to…
-
Making sure the checks get printed
Pierre’s debut newsletter explores the messy, real-world side of risk management and how to keep vital systems running when a perfect patch isn’t an option. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/making-sure-the-checks-get-printed/ also interesting: Not all cuts are equal: Security budget choices disproportionately impact risk Do CISOs need to rethink service provider risk? More…
-
Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks
Attackers behind a string of personal data leaks at Japanese organizations have abused APIs for mobile apps and targeted known software flaws, the JPCERT Coordination Center (JPCERT/CC) said.The Tokyo-based center, which takes incident reports, based its October 8, 2026 alert on those reports and other information. The alert names no attacker and no affected organization.JPCERT/…
-
FakeGit malware campaign returns with 17,610 malicious GitHub repos
More than 17,000 fake repositories on GitHub are distributing the SmartLoader malware after the FakeGit campaign reactivated earlier this month to push the StealC infostealer. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/fakegit-malware-campaign-returns-with-17-610-malicious-github-repos/ also interesting: Getting the Most Value Out of the OSCP: The PEN-200 Course Hackers Post Dozens of Malicious Copycat Repos to GitHub…
-
Scope of Asos data breach wider than first reported
Following a data breach earlier in October, cyber criminals appear to have a much more complete picture of Asos’ user base than first thought, it has emerged. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366651860/Scope-of-Asos-data-breach-wider-than-first-reported also interesting: US Employee Background Check Firm Hacked, 3 Million Records Exposed BK Technologies Data Breach, IT Systems Compromised, Data…
-
Cryptohack Roundup: Conviction in Uranium Finance Hack
Also: A US Court Orders $30M Penalty in Fundsz Fraud Case. This week, a conviction in a $54 million exploit, a $30 million Fundsz fraud penalty, Near Intents post-hack, Abstract Blockchain will shutdown, Velocity’s victim reimbursements, two U.S. regulatory proposals withdrawn, a ZachXBT North Korean laundering probe and ransomware-linked wallets identified. First seen on govinfosecurity.com…
-
ASOS: Hackers tricked way into employee account before sending rogue push notification
Tags: hackerThe company said its investigation, carried out with external experts, found the attackers had accessed “some personal information, including names and contact details, and certain non-personal account related information.” First seen on therecord.media Jump to article: therecord.media/asos-says-hackers-tricked-employee-access-push-notification also interesting: Researchers Found North Korean Hackers Advanced Tactics, techniques, and procedures Google, Microsoft say Chinese hackers are…
-
DOJ charges ransomware recovery CEO for secretly paying hackers
The owner of a ransomware recovery firm was hit with wire fraud charges for allegedly making secret ransom payments while overcharging the victims of attacks. First seen on therecord.media Jump to article: therecord.media/ransomware-recovery-charges-doj also interesting: Top 10 Cybersecurity Predictions for 2026 8 Cyber Predictions for 2025: A CSO’s Perspective Cybersecurity Snapshot: New Standard for AI…
-
WorkNest Secure Achieves CREST STAR-FS Accreditation for Red Teaming
WorkNest Secure has achieved CREST Simulated Targeted Attack & Response for Financial Services (STAR-FS) accreditation, recognising its ability to deliver intelligence-led red teaming assessments for organisations operating in high-risk and regulated environments. The accreditation confirms that WorkNest Secure meets CREST’s standards for conducting threat-led penetration testing, using realistic attack scenarios to assess how effectively organisations…
-
Crypto thief who splurged on gold grills sentenced in London
A 25-year-old man who helped steal nearly $260,000 in cryptocurrency through a SIM-swapping fraud scheme was sentenced to two and a half years in prison at a London court. First seen on therecord.media Jump to article: therecord.media/cryptocurrency-sim-swap-london also interesting: US Pig Butchering Victims ‘Will’ Get Refunds, Feds Seize $225M Cryptocurrency Banks need stricter controls to…
-
ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms
Tags: ai, attack, crowdstrike, cybersecurity, data, finance, intelligence, penetration-testing, theft, threat, toolCybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence (AI) pen testing tool named ARTEX to carry out the attacks.The activity, per CrowdStrike Intelligence, was active from late September to early October 2026, and resulted in data exfiltration.”In this activity, the threat actor leveraged…
-
UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML
The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN.According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel. The cybersecurity company is tracking the cluster under the name Earth Sirrush (previously SHADOW-EARTH-065).ASHVEIN, First seen on…
-
Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between What Your Developers Declare and What’s Actually in Your Code New snippet-level scanning shows security and compliance leaders which open-source code and which AI-written code never made it into a manifest. Insignary Inc. today announced the general availability of Insignary…
-
Cisco warns of critical flaws allowing Nexus switch takeover
Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privileges on Nexus switches. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisco-warns-of-critical-flaws-allowing-nexus-switch-takeover/ also interesting: Cybersecurity Snapshot: Industrial Systems in Crosshairs of Russian Hackers, FBI Warns, as MITRE Updates List…
-
The Security Interviews: Evren Karaibrahimgil, Welsh FA
Evren Karaibrahimgil, IT manager at the FAW, on securing the national football association of Wales against evolving cyber threats, with Euro 2028 on home soil in mind First seen on computerweekly.com Jump to article: www.computerweekly.com/feature/The-Security-Interviews-Evren-Karaibrahimgil-Welsh-FA also interesting: Ukraine-targeted cyber, influence threat actors subjected to EU sanctions Hackers Are Stealing Salesforce Data, Google Warns UNC2891 Hackers…
-
Midnight Mimosa Malware Found Preinstalled on Low-Cost Android Phones
Low-cost Android phones can arrive already compromised, with malware embedded in their firmware before buyers switch them on. First seen on hackread.com Jump to article: hackread.com/midnight-mimosa-malware-preinstalled-android-phones/ also interesting: Privacy Roundup: Week 9 of Year 2025 New Trinda Malware Targets Android Devices by Replacing Phone Numbers During Calls Cybersecurity Snapshot: Global Agencies Target Criminal “Bulletproof” Hosts,…
-
Asos confirms breach of customer data after hackers send rogue app notification
The hackers alerted the fashion giant’s customers through a push notification that said they had “fully compromised” the company’s cloud storage. First seen on techcrunch.com Jump to article: techcrunch.com/2026/10/08/asos-confirms-breach-of-customer-data-after-hackers-send-rogue-app-notification/ also interesting: AWS customers face massive breach amid alleged ShinyHunters regroup Top 12 ways hackers broke into your systems in 2024 Privacy Roundup: Week 11 of…
-
Leaked chats show Russian extortion gang sending ‘agents’ into US law firms
In leaked chats, members track dozens of victims, haggle over multimillion-dollar payments and direct operatives based in the United States whom they call “agents.” First seen on therecord.media Jump to article: therecord.media/leaked-chats-show-russian-extortion-gang-sending-agents-to-law-firms also interesting: Cybersecurity Snapshot: CISA Hands Down Cloud Security Directive, While Threat from North Korean IT Workers Gets the Spotlight 9 things CISOs…
-
What the C-suite needs to know about AI governance
As AI adoption surges, executives are learning tough lessons about security, oversight and accountability. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/c-suite-ai-governance/832497/ also interesting: ISMG Editors: AI Security Wake-Up Call From DeepSeek 5 key priorities for your RSAC 2026 agenda AI Governance and Risk Insights for Enterprises – Kovrr KI-Agenten absichern: Warum Identity zum Erfolgsfaktor…
-
Gefährliche EAnhänge: Outlook blockiert MSIX-Dateien
Tags: mailBeide Dateiformate erlauben die Installation von Anwendungen. Die Änderung gilt für Outlook im Web und das neue Outlook für Windows. First seen on golem.de Jump to article: www.golem.de/news/gefaehrliche-e-mail-anhaenge-outlook-blockiert-msix-dateien-2610-213884.html also interesting: Schutz vor Business E-Mail Compromise: 8 wichtige Punkte für Ihre BEC-Richtlinie Sieben gängige Wege, ein Smartphone zu hacken EAngriffe: Hacker setzen auf Täuschung statt Technik…
-
Cross-tenant data exposure – Cloudflare-Container gaben Datenreste fremder Kunden preis
First seen on security-insider.de Jump to article: www.security-insider.de/cloudflare-containers-sicherheitsluecke-datenreste-auslesbar-a-cbfeb9d28f7a7437a5583b4da98c551f/ also interesting: Beyond cryptocurrency: Blockchain 101 for CISOs and why it matters Beyond Testing: API Security as the Foundational Intelligence for an ‘industry leader’-Level Security Strategy Startup Amutable plotting Linux security overhaul to counter hacking threats What is Security Posture Management and Why is it Important?
-
Asos says customers’ names, contact details and search histories hacked
Experts say breadth of data accessed could help attackers devise “highly convincing” phishing scams<ul><li><a href=”https://www.theguardian.com/business/live/2026/oct/08/oil-prices-rise-shipping-attacks-rate-rise-uk-housing-market-bank-england-latest-live-updates”>Business live live updates</li></ul>Asos hackers gained access to millions of customers’ recent search histories as well as names, addresses and phone numbers, the online fashion retailer has revealed.Terms typed in by customers such as “glamorous wide fit” and “Asos petite” were…
-
ASOS Confirms Data Breach Linked to Stolen Employee Credentials
The ASOS hack comes from the compromise of agentic marketing platform Simon AI, said the attackers First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/asos-data-breach-stolen-employee/ also interesting: Don’t confuse asset inventory with exposure management What is Security Posture Management and Why is it Important? What is Security Posture Management and Why is it Important? What is…
-
Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware
Tags: breach, credentials, crypto, cyber, hacker, malicious, malware, software, supply-chain, threatA threat actor published a malicious version of the tensorlake npm package on October 8, 2026, embedding a new variant of the self-replicating Shai-Hulud supply-chain worm. The compromised release, tensorlake version 0.5.144, can steal developer secrets, target browser-stored cryptocurrency credentials, and use stolen publishing credentials to spread through connected software supply chains. The incident highlights…
-
Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware
Tags: breach, credentials, crypto, cyber, hacker, malicious, malware, software, supply-chain, threatA threat actor published a malicious version of the tensorlake npm package on October 8, 2026, embedding a new variant of the self-replicating Shai-Hulud supply-chain worm. The compromised release, tensorlake version 0.5.144, can steal developer secrets, target browser-stored cryptocurrency credentials, and use stolen publishing credentials to spread through connected software supply chains. The incident highlights…
-
OAuth grants pile up faster than you can review them. Here’s how to keep up.
OAuth grants create data highways between SaaS apps, AI agents, and other tools. And, they are multiplying faster than any security team can review them. As the recent Klue breach showed, attackers are taking notice and exploiting forgotten OAuth grants to gain access to corporate data. This article covers why OAuth risks are so hard…
-
Global cyber attacks up 48% as ransomware and phishing climb, Check Point finds
Organisations worldwide faced an average of 2,803 cyber attacks per week in September 2026, up 16% on August and 48% on the same month last year, according to new data from Check Point Research. The figures point to sustained growth rather than a one-off spike. Weekly attacks per organisation have climbed 36% in five months,…
-
MonsterCloud Owner Charged With Secretly Paying Ransomware Demands
Tags: ransomwareMonsterCloud owner Zohar Pinhasi allegedly paid ransomware demands behind clients’ backs, then charged them millions for the supposed recovery. Zohar Pinhasi, the owner of Florida-based MonsterCloud, was charged this week with wire fraud. Federal prosecutors say his clients were scammed twice during the same ransomware crisis. Pinhasi (50) also used the names “Zack Silver” and…
-
Hackers target two South Korean megachurches, potentially exposing congregant data
Two of South Korea’s largest Protestant churches are investigating cyberattacks that may have exposed sensitive information about hundreds of thousands of members, including personal details, financial records and internal documents. First seen on therecord.media Jump to article: therecord.media/south-korea-hackers-megachurches also interesting: Top 10 Cybersecurity Predictions for 2026 The biggest data breach fines, penalties, and settlements so…
-
10 Browser Security Vendors Making Moves In 2026
Among the top browser security vendors making AI and agent security moves in 2026 include CrowdStrike, Palo Alto Networks and Zscaler, along with Microsoft, Google and Cyera. First seen on crn.com Jump to article: www.crn.com/news/security/2026/10-browser-security-vendors-making-moves-in-2026 also interesting: Threat intelligence platform buyer’s guide: Top vendors, selection advice CSPM buyer’s guide: How to choose the best cloud…
-
10 Browser Security Vendors Making Moves In 2026
Among the top browser security vendors making AI and agent security moves in 2026 include CrowdStrike, Palo Alto Networks and Zscaler, along with Microsoft, Google and Cyera. First seen on crn.com Jump to article: www.crn.com/news/security/2026/10-browser-security-vendors-making-moves-in-2026 also interesting: Threat intelligence platform buyer’s guide: Top vendors, selection advice Threat intelligence platform buyer’s guide: Top vendors, selection advice…
-
Asos says hacker accessed customers’ names, contact details and search histories
Millions of users’ personal data is said to have been compromised but not card details or passwords <ul><li><a href=”https://www.theguardian.com/business/live/2026/oct/08/oil-prices-rise-shipping-attacks-rate-rise-uk-housing-market-bank-england-latest-live-updates”>Business live live updates</li></ul>Asos hackers gained access to millions of customers’ recent search histories as well as names, addresses and phone numbers, the online fashion retailer has revealed.Terms typed in by customers such as “glamorous wide fit”…
-
Europol and US Spending Watchdog Sound the Alarm Over Quantum Threats
Europol and US Government Accountability Office urge faster transition to post-quantum cryptography First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/europol-us-gao-alarm-quantum/ also interesting: The most notorious and damaging ransomware of all time Trump takes aim at Biden’s cyber executive order but leaves it largely untouched U.S. House Homeland Security Appropriations Bill Seeks to Modernize Border Infrastructure…
-
Russia-Aligned UAC-0099 Evolves MATCHBOIL Malware
Russia-aligned UAC-0099 has steadily upgraded its MATCHBOIL downloader since 2024 First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/russia-aligned-uac-0099-evolves/ also interesting: Siemens Industrial Software Targeted by Stuxnet is Still Full of Holes Russian Script Kiddie Assembles Massive DDoS Botnet Russia detects first SuperCard malware attacks skimming bank data via NFC BlackSanta Malware Targets HR Staff with…
-
Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process deployments by exploiting unsafe Python pickle deserialization. This flaw is tracked as CVE-2026-105192 and has a CVSS score of 9.8. JFrog published an advisory and a public proof-of-concept exploit on October 7, 2026, stating that no fixed release was available…

