2026-10-02 12:23 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-02 12:45 UTC
OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported. "We have parted ways with three individuals for violating our policies on accessing and handling sensitive company information," a spokesperson for the company was quoted as saying. "Our investigation confirmed that these
P0
2026-10-01 21:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
See how the Huntress SOC runs security incident investigations from first signal to final resolution, including the ones closed as benign.
P0
2026-10-01 13:00 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-10-01 13:20 UTC
As AI takes on more of the enrichment, correlation, and initial assessment inside the SOC, roles, skills, and KPIs still require deliberate redesign. Security leaders need to decide where automation is dependable, where human judgment should remain decisive, and how teams should be measured when alert handling is no longer the center of the operating modelThe Gartner® report, The Roles Required for the AI-Enabled Security Operations Center (SOC), examines the roles and capabilities Gartner expe…
P0
2026-10-01 05:21 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 05:55 UTC
Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist. "Their investigation identified malicious activity involving third-party security products, including a zero-day vulnerability, and recovered a customized tool used by the attacker
P25
2026-09-30 23:43 UTC
Security Journalism
Security Week · Associated Press · indexed 2026-09-30 23:50 UTC
An FTC spokesperson confirmed the investigation but declined further comment. The post FTC is Investigating OpenAI and Anthropic Over Possible Risks to Consumers appeared first on SecurityWeek.
P0
2026-09-30 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-09-30 16:25 UTC
On October 7, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products: Application Policy Infrastructure Controller (security hardening release) Finesse License On-Prem, formerly Cisco Smart Software Manager On-Prem (security hardening release) Meraki (security hardening release) NX-OS Software for MDS 9000, Nexus 3000, 7000, and 9000 Series Switches…
P0
2026-09-30 14:16 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-09-30 15:05 UTC
Higher education faces a difficult security equation. Universities hold large volumes of sensitive student, financial, health, and research data while supporting open networks, distributed users, legacy infrastructure, and increasingly complex cloud environments. Attackers have taken notice, and the pressure on security teams continues to grow.In Q2 2025, universities faced an average of 4,388 cyberattacks per organization per week, up 24% from the same period in 2024. Nine in ten universities …
P40
2026-09-30 13:26 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-30 14:25 UTC
DOJ charges against Oxygen Forensics reveal the Russian-linked firm also sold forensic software to EU projects and European police forces for years. Last week’s Justice Department indictment of Oxygen Forensics looked, at first, like an American procurement scandal. CEO Lee Reiber and Russian co-founder Oleg Davydov stand accused of hiding that the company was Russian-owned […]
P0
2026-09-29 11:01 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-29 11:20 UTC
Pepijn van der Stap was convicted in 2023 for hacking multiple organizations, stealing their data, and extorting them. The post Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation appeared first on SecurityWeek.
P0
2026-09-29 08:35 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-29 09:50 UTC
Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. "It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters," the Politie Landelijke Opsporing en Interventies said in an X post Monday. Police said the individual is expected to appear before the
P0
2026-09-29 07:30 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-29 08:10 UTC
Dutch police confirm the arrest of a 24-year-old Amsterdam man as part of an investigation into the ShinyHunters hacking group. Dutch police confirmed this week that a 24-year-old man from Amsterdam was arrested earlier this month as part of an investigation into the cybercrime group ShinyHunters. The suspect appears before Rotterdam District Court today, September […]
P0
2026-09-28 19:49 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-28 19:55 UTC
Dutch police have confirmed that a 24-year-old Amsterdam man arrested earlier this month was detained as part of an investigation into the ShinyHunters hacking group. [...]
P0
2026-09-28 15:08 UTC
Independent Research
Krebs on Security · BrianKrebs · indexed 2026-09-28 15:15 UTC
Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p.
P15
2026-09-25 19:35 UTC
Security Journalism
The Record · indexed 2026-09-25 19:45 UTC
Security changes include creating an incident response plan for vendor security failings, limiting how much data Labcorp shares with vendors and building an expansive risk management team charged with tracking vendors’ compliance with data security practices.
P0
2026-09-24 20:35 UTC
Security Journalism
Security Week · Associated Press · indexed 2026-09-24 20:40 UTC
The prospect of legal accountability is unclear. Lawsuits are a possibility, but some legal experts believe any criminal investigations would face an extremely high burden. The post Autonomous AI Hacks Raise Thorny Questions of Legal Accountability appeared first on SecurityWeek.
P0
2026-09-24 20:30 UTC
Security Journalism
The Record · indexed 2026-09-24 20:45 UTC
Two executives at a data extraction and digital forensics company that sold several U.S. agencies its software were arrested for allegedly lying about the fact that its technology is made in Russia.
P0
2026-09-24 13:00 UTC
Vendor Research
Rapid7 · Douglas McKee, Director, Vulnerability Intelligence · indexed 2026-09-24 13:20 UTC
Business Email Compromise (BEC) operates on a familiar playbook. Threat actors breach a mailbox, silently monitor operations, map approval chains, and ultimately exploit that access to divert funds or exfiltrate sensitive assets.This dynamic is central to our analysis as we kick off a series around Rapid7's collaborative research with Zimbra; upcoming installments will explore technical details and broader findings based within the Zimbra Collaboration Suite. Our investigation disrupted the tra…
P70
2026-09-24 10:31 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-24 11:45 UTC
OpenAI’s AI agent bypassed controls on an Australian health portal, accessed non-public files and triggered a government investigation. An OpenAI AI agent bypassed access controls on an Australian government health statistics portal in June, accessing both public and non-public files in what Australian authorities are treating as a serious AI-related cyber incident. The case was […]
P0
2026-09-23 13:56 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-23 14:20 UTC
ShinyHunters claims FBI breach via PeopleSoft zero-day, steals staff data; FBI investigating, no confirmation yet. The popular cybercrime group ShinyHunters is claiming that it breached the U.S. Federal Bureau of Investigation (FBI) and stole sensitive information belonging to FBI employees and job applicants. The group says the operation was not financially motivated and was instead […]
P25
2026-09-23 05:30 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 06:40 UTC
The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency. "We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job," the group said in a statement posted on their dark
P0
2026-09-22 19:52 UTC
Security Journalism
The Record · indexed 2026-09-22 19:55 UTC
The investigation, announced Monday, will probe IDScan’s security practices and whether victim notifications were adequate under Canada’s federal private-sector privacy law, the regulator said in a press release.
P0
2026-09-22 12:57 UTC
Security Journalism
BleepingComputer · BleepingComputer · indexed 2026-09-22 13:10 UTC
Tomorrow's webinar examines real Google Workspace breaches involving social engineering and malicious OAuth applications, from initial access through the critical first hours of incident response. Learn which security controls and response decisions can make the greatest difference. [...]
P0
2026-09-21 20:20 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-21 21:20 UTC
Ireland’s DPC fined Google €403 million over GDPR violations involving location data, transparency, retention and user control. Ireland’s Data Protection Commission (DPC) just fined Google €403 million, and the case behind it goes back six years, to a set of complaints that never really went away. The DPC launched the investigation in February 2020 after […]
P0
2026-09-21 07:28 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-21 08:25 UTC
A 2017 UK assessment warned that police data on Microsoft Azure could face foreign access risks. The risks may still exist. A Guardian investigation has surfaced a 2017 document signed off by then City of London police commissioner Ian Dyson, who also held the title of senior information risk owner for the entire country. That […]
P0
2026-09-19 13:28 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-19 14:30 UTC
Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon's annual Data Breach Investigations Report. This article explains what identity visibility means in IAM, why cloud and multicloud environments complicate it, which capabilities matter in
P0
2026-09-17 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-22 07:50 UTC
An incident response plan only works if it’s tested. Learn the 5 pillars of operational resilience and how to turn your plan into muscle memory before an attack hits.
P0
2026-09-17 11:33 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-17 11:40 UTC
The U.S. Federal Bureau of Investigation (FBI) seized the domains used by NightmareStresser, one of the world's longest-running distributed denial-of-service (DDoS) platforms. [...]
P0
2026-09-17 10:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · Takahiro Takeda · indexed 2026-09-17 10:15 UTC
Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims.
P15
2026-09-16 18:28 UTC
Security Journalism
The Record · indexed 2026-09-16 18:35 UTC
The Guarding Unprotected Aging Retirees from Deception Act (GUARD) attempts to address a common complaint from the victims of online scams like pig butchering — that such cases typically do not rise to the level of a federal investigation but local law enforcement is unequipped to properly investigate them.
P0
2026-09-16 16:07 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-09-09 16:30 UTC
On September 16, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables. To remediate these vulnerabilities, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the Foundation: A Predictable, Customer-Focused Response to AI-Accelerated Vulnerability Discovery. Cisco Identity…
P30