IT Security News: today roundup
- CISA added actively exploited SharePoint and MikroTik flaws to KEV.
- A Tennessee science center hosted family squid dissection events.
- Researchers created 5G-Shark to intercept cellular signals without jamming.
- Chinese hackers exploited Chrome and Windows zero-days to deploy CLEANGULP.
- Threat actors actively targeted unpatched Roundcube email servers.
- AI integration in Microsoft DevLabs DebugMCP enabled remote code execution.
- ServiceNow patched critical AI Platform flaws allowing unauthorized data extraction.
- Fake business complaints targeted Asian companies to deliver malware archives.
- Apple released iOS 27 featuring expanded Siri AI capabilities.
- A WordPress formatting bug allowed server takeover through user comments.
- Voice phishing scammers mocked Google by publishing exposed attack scripts.
- TWEAKOS malware steals messaging accounts to sell on Telegram marketplaces.
- Sauron Loader targeted German organizations using evasive DLL side-loading techniques.
- The CARBONATO botnet deployed AI agents across exposed Docker servers.
- Hackers exploited Samsung MagicINFO software to assemble in-system cryptocurrency miners.
- Police arrested two human traffickers exploiting restaurant workers across Europe.
- A legacy Linux kernel vulnerability permitted local root privilege escalation.
- An analysis argued for embedding security controls directly into networks.
- OxygenOS flaws allowed zero-permission apps root access on OnePlus devices.
- Cybercrime group ShinyHunters claimed it breached the FBI for self-preservation.
- Suspected North Korean hackers stole $351.6 million from exchange Bitget.
- Cisco released the open-source CAIRN framework alongside cybersecurity news updates.
- Vercel fixed a critical Next.js vulnerability enabling server code execution.
- Apple released high-end Mac Studio desktops targeting enterprise AI workloads.
- ShinyHunters claimed it breached the FBI and stole employee records.
Sources in this roundup
| Cyber Security News |
|
9 article(s) |
| The Hacker News |
|
3 article(s) |
| www.theregister.com – Articles |
|
3 article(s) |
| Security Affairs |
|
2 article(s) |
| Blog |
|
1 article(s) |
| Cybersecurity Headlines |
|
1 article(s) |
| Hackread – Cybersecurity News, Data Breaches, AI and More |
|
1 article(s) |
| News |
|
1 article(s) |
| Panda Security Mediacenter |
|
1 article(s) |
| Schneier on Security |
|
1 article(s) |
| Security Archives – TechRepublic |
|
1 article(s) |
| Silicon UK |
|
1 article(s) |
Most-mentioned keywords
| hackers |
|
4 mention(s) |
| malware |
|
4 mention(s) |
| attackers |
|
3 mention(s) |
| flaw |
|
3 mention(s) |
| zero |
|
3 mention(s) |
| access |
|
2 mention(s) |
| apple |
|
2 mention(s) |
| business |
|
2 mention(s) |
Sources
- U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog
- Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee
- 5G-Shark Lures Phones to Rogue 5G Cells Without Network Jamming
- Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
- Attackers Target Unpatched Roundcube Servers With CVE-2026-48842
- From Debugging to Code Execution: RCE in Microsoft DevLabs’ DebugMCP?
- Critical ServiceNow Vulnerabilities Let Attackers Bypass Authorization – Update Now!
- Attackers Are Turning Everyday Business Emails Into Malware Delivery Machines
- Why would you want to turn off Apple Intelligence and Siri AI on iOS 27?
- WordPress Comment2Shell Vulnerability Lets Hackers Take Over Sites Through Comments
- Fake Google Security Team ad says 'no script reading' in voice phishing – then prints the script
- TWEAKOS Malware Turns Telegram Into a Stealer, C2 Platform and Stolen Account Marketplace
- Sauron Loader Malware Uses DLL Side-Loading and In-Memory Decryption to Evade Detection
- Researchers Found a Botnet That Uses an AI Agent to Operate Inside Compromised Servers
- Hackers Used a Samsung Flaw to Build a Cryptominer Inside Victim Systems
- International investigation identifies over 70 potential victims exploited in Indian restaurants
- 14-Year-Old Linux Kernel Flaw Lets Local Users Gain Root Access and Escape Containers
- Why security belongs in the network
- OnePlus 15 Flaws Let Zero-Permission Apps Gain Root Access Through OxygenOS Services
- ShinyHunters tells The Reg: We hacked the FBI to 'protect our business'
- Cryptocurrency exchange Bitget Says North Korea-Linked Hackers Stole $351.6 Million
- CAIRN framework, Muse zero-day, BigDiskBuster
- Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
- Apple Ships Desktops Pitched As Enterprise AI Alternative
- ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
