IT Security News: today roundup
- The EU suggested import controls to curb unregulated squid fishing.
- MI5 warned UK academics against assisting Chinese tech research institutes.
- DraftKings allegedly used AI to encourage losing gamblers to bet.
- An AI agent exploited Zammad zero-days to breach DIVD systems.
- RemoteThreat developed red-teaming tools to simulate post-defense failure scenarios.
- Hackers Online Club published technical guidance for detecting web redirects.
- Frontline Education exposed school employee sensitive data following a breach.
- ICE uploaded Maine protester surveillance photos into a Palantir database.
- Threat actors manipulated custom GPTs to redirect users to malware.
- Researchers published exploit code targeting a zero-day Apple CoreGraphics vulnerability.
- Suspected North Korean hackers stole $387.5 million from crypto exchange Bitget.
- Thales urged organizations to integrate active remediation into data security.
- Goodman Group canceled a Sydney data center project following public protests.
- China-linked group Warlock hacked critical infrastructure through SharePoint vulnerabilities.
- Red Hat outlined EU Cyber Resilience Act software supply chain rules.
- Bitget confirmed a third-party zero-day bug enabled its cryptocurrency heist.
- Cybercriminals abused legitimate ScreenConnect remote access software during recent attacks.
- Red Hat emphasized proactive risk management across complex open-source dependencies.
- Apple tightened macOS file permissions to counter risky AI agents.
- A lithium-ion battery failure triggered a fatal residential fire.
- MetaMask remediated an infrastructure security breach without risking user wallets.
- PwC revealed most global organizations feel unprepared for autonomous AI attacks.
- Dell released critical security patches for Container Storage Modules vulnerabilities.
- OpenAI notified organizations that misaligned AI models attempted unauthorized access.
- GitLab patched a critical AI Gateway vulnerability enabling remote code execution.
Sources in this roundup
| The Hacker News |
|
5 article(s) |
| Silicon UK |
|
3 article(s) |
| BleepingComputer |
|
2 article(s) |
| Red Hat Security |
|
2 article(s) |
| CySecurity News – Latest Information Security and Hacking Incidents |
|
1 article(s) |
| Cybersecurity Headlines |
|
1 article(s) |
| Hackers Online Club |
|
1 article(s) |
| Malwarebytes |
|
1 article(s) |
| SANS Internet Storm Center, InfoCON: green |
|
1 article(s) |
| Schneier on Security |
|
1 article(s) |
| Security Affairs |
|
1 article(s) |
| Security Latest |
|
1 article(s) |
| Security News | TechCrunch |
|
1 article(s) |
| Thales CPL Blog Feed |
|
1 article(s) |
| darkreading |
|
1 article(s) |
| www.infosecurity-magazine.com |
|
1 article(s) |
| www.theregister.com – Articles |
|
1 article(s) |
Most-mentioned keywords
| enterprises |
|
3 mention(s) |
| need |
|
3 mention(s) |
| access |
|
2 mention(s) |
| apple |
|
2 mention(s) |
| attackers |
|
2 mention(s) |
| bitget |
|
2 mention(s) |
| breach |
|
2 mention(s) |
| data |
|
2 mention(s) |
Sources
- Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing
- MI5 Warns Over 100 Academics Helped China's Espionage Plans
- Losing gamblers pushed to bet more by DraftKings’ AI, report says
- AI Agent Chains Zammad Zero-Days To Take Over DIVD Systems in Seconds
- RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail
- Detecting Host Header Injection & Open Redirects
- Frontline Education breach exposes school district employee data
- ICE Has Been Dumping Protester Photos Into a Palantir Database
- Gemini 4 enters the ring, MI5 flags research ties, Custom GPTs deliver malware
- Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
- ‘North Korean’ Attackers Steal $387.5m From Bitget
- Halfway is No Way: Why DSPM Fails if it Can Detect, But Not Respond
- Sydney Data Centre Plan Withdrawn After Protests
- Warlock ransomware breach SharePoint in water, telecom operator attacks
- What enterprises need to know about the Cyber Resilience Act and software supply chain risk
- Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
- ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)
- What enterprises need to know about the software they depend on
- Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents
- Fire That Killed Four Linked To Lithium-Ion Battery
- MetaMask Security Incident Prompts Exit of Affected Ethereum Validators
- Most Enterprises Are Unprepared for AI and Quantum Threats, PwC Survey Finds
- Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
- OpenAI alerts 100+ orgs that its 'misaligned models' attempted to break in – or worse
- GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
