2026-10-02 12:37 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-02 12:50 UTC
Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments. [...]
P0
2026-10-02 12:23 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-02 12:45 UTC
OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported. "We have parted ways with three individuals for violating our policies on accessing and handling sensitive company information," a spokesperson for the company was quoted as saying. "Our investigation confirmed that these
P0
2026-10-02 11:46 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-10-02 12:00 UTC
Hackers used the account, which has 13 million followers, to amplify a Clippy-themed cryptocurrency account. The post Crypto Scammers Hijack Microsoft’s Official X Account appeared first on SecurityWeek.
P0
2026-10-02 11:30 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-02 11:45 UTC
The quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and the EDR console. Someone is building a spreadsheet to reconcile them. Someone else is turning that spreadsheet into slides. Then a board member asks three questions: How secure is the organization, overall? What is
P0
2026-10-02 11:14 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-02 11:20 UTC
Amir Barati, an alleged member of the Mabna Institute, was indicted for targeting universities, private organizations, and government entities in the US and abroad. The post In Rare Move, Alleged Iranian State Hacker Extradited to US appeared first on SecurityWeek.
P0
2026-10-02 09:34 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-02 09:40 UTC
The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025. The post Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks appeared first on SecurityWeek.
P0
2026-10-02 09:29 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-02 09:30 UTC
On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token. [...]
P0
2026-10-02 08:38 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-10-02 08:40 UTC
The attacks targeted the US Department of Education and Library and Archives Canada, and researchers linked some agents to OpenAI. The post AI Agents Aimed SQL Injection at US and Canadian Government Sites appeared first on SecurityWeek.
P0
2026-10-02 08:07 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-02 08:20 UTC
CVE-2026-104286 is a critical-severity path traversal vulnerability that could allow attackers to write arbitrary files to the system. The post Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action appeared first on SecurityWeek.
P30
2026-10-02 08:01 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-02 08:20 UTC
Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android applications abusing the API serving as the main conduit for malware and financial fraud, the tech giant said the move would block a major attack pathway. Advanced Protection is a
P0
2026-10-02 06:05 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-02 07:20 UTC
Asymmetric Security traces rogue OpenAI AI agent activity that probed government sites, accessed staging servers, and evaded sandbox limits. Researchers at Asymmetric Security spent 48 hours over the last weekend reconstructing reported rogue OpenAI AI agent activity that hit the Australian government and other organizations between March and September this year. They worked from public […]
P0
2026-10-02 05:50 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-02 06:00 UTC
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Fortinet FortiMail flaw, tracked as CVE-2026-104286 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is a path traversal vulnerability that can be triggered through […]
P35
2026-10-02 05:49 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-02 06:25 UTC
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. "An improper
P80
2026-10-02 05:47 UTC
Other
Group-IB · indexed 2026-10-02 08:20 UTC
Group-IB descubre BraZetsu, un nuevo malware para Windows basado en Python que funciona como un toolkit maestro para Initial Access Brokers y potencia un marketplace clandestino único, mejorado con IA, para comercializar objetivos comprometidos en Iberoamérica y Latinoamérica.
P0
2026-10-02 02:00 UTC
Community
SANS Internet Storm Center · indexed 2026-10-02 02:15 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-10-01 22:42 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-10-01 22:45 UTC
Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. [...]
P30
2026-10-01 21:37 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-10-01 21:50 UTC
Law enforcement from multiple countries collaborated to disrupt a cybercrime operation that has claimed some 500 victims worldwide in the past two years.
P15
2026-10-01 21:15 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-10-01 21:35 UTC
Bulletin ID: 2026-123-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/01/2026 14:00 PM PDT Description: Powertools for AWS Lambda (Python) is a developer toolkit that implements serverless best practices and increases developer velocity. We identified CVE-2026-104002, a fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python). This issue might allow actors to read sensitive field values that the application intended to…
P5
2026-10-01 21:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
See how the Huntress SOC runs security incident investigations from first signal to final resolution, including the ones closed as benign.
P0
2026-10-01 20:52 UTC
Security Journalism
BleepingComputer · Ionut Ilascu · indexed 2026-10-01 21:05 UTC
Autonomous AI agents using aggressive strategies attempted to hack U.S. and Canadian government websites to find school and divorce statistics. [...]
P0
2026-10-01 20:50 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-10-01 21:00 UTC
Bulletin ID: 2026-122-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/01/2026 13:30 PM PDT Description: Amazon Ion Python is an open-source Python implementation of the Amazon Ion data notation. We identified CVE-2026-104020, an issue in the Ion reader in Amazon Ion Python before version 0.15.0 where a crafted, deeply nested Ion value could cause the application to raise an error or crash, resulting in a denial of service. Impacted versions: < 0.15.0 Please refe…
P5
2026-10-01 20:15 UTC
Security Journalism
The Record · indexed 2026-10-01 20:30 UTC
An Iranian national accused by the U.S. of taking part in dozens of breaches involving the theft of academic data and intellectual property has been extradited from Montenegro.
P0
2026-10-01 19:32 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-10-01 19:40 UTC
Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace. [...]
P0
2026-10-01 19:25 UTC
Security Journalism
The Record · indexed 2026-10-01 19:45 UTC
The findings, released Thursday by Asymmetric Security, are just the latest example of rogue behavior spurred by OpenAI’s software.
P0
2026-10-01 18:16 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-10-01 18:20 UTC
Bulletin ID: 2026-121-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/01/2026 10:30 AM PDT Description: security-agent-mcp-server is an open-source Model Context Protocol (MCP) server, published by AWS in the awslabs/mcp repository, that AI assistants use to run local security scans (including differential "diff" scans) over source code. We identified CVE-2026-97662, an argument injection issue in the diff scan operation: a crafted reference value supplied to th…
P5
2026-10-01 18:16 UTC
Security Journalism
The Record · indexed 2026-10-01 18:30 UTC
Two separate reports by cybersecurity companies highlight China-linked hacking operations, including a phishing campaign that impersonated Western experts.
P0
2026-10-01 18:08 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-01 19:00 UTC
Operation KillSwitch: Europol says the KillSec ransomware group, allegedly led by a 16-year-old, was dismantled after attacks on about 1,000 victims. Law enforcement seized control of KillSec ‘s dark web leak site, the Tor website the group used to threaten victims with publishing stolen files unless they paid up. That single action locked down more […]
P15
2026-10-01 18:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · Amy Ciminnisi · indexed 2026-10-01 18:05 UTC
In this week’s edition, Amy reflects on the importance of prioritizing family and personal well-being over the pressure to remain constantly productive.
P0
2026-10-01 18:00 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-10-01 18:20 UTC
Fifteen years after coining the framework, John Kindervag insists zero trust still works in the AI era—if you get the implementation right. The post Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks appeared first on SecurityWeek.
P0
2026-10-01 17:16 UTC
Security Journalism
Security Week · SecurityWeek News · indexed 2026-10-01 17:20 UTC
Hybrid risk intelligence company Osavul has raised $10 million in a Series A funding round led by 33N Ventures. The post Osavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical Domains appeared first on SecurityWeek.
P0