IT Security News: Morning roundup, 2026-10-10
- REA links AI assistants like Claude Code to reverse-engineering tools.
- Hackers compromised over 500 GitHub accounts to steal API keys.
- SANS ISC warned against replacing internal data classifications with TLP.
- Coupang challenged a massive fine following a major customer breach.
- GAO warned US federal agencies are slow adopting post-quantum encryption.
- Core to Cloud named David Brown as its new Managing Director.
- Apple introduced a system verifying authentic photos while preserving privacy.
- Iranian VPN-over-DNS activity generated 40 billion queries across strategic domains.
- Cybersecurity news site Dark Reading announced plans for its next decade.
- An Empire Market co-creator received a 40-year US prison sentence.
- DarkBlinders used fake meeting apps to breach Middle Eastern targets.
- Hackers used AI agents and GodPotato to escalate Windows privileges.
- Zenity Labs exposed an AWS Bedrock vulnerability allowing prompt-injection hijacks.
- Attackers actively exploited two zero-day flaws in AhsayCBS backup servers.
- VirusTotal added daily global IPv4 port scanning to its platform.
- A flaw in Amazon Bedrock AgentCore allowed full agent compromise.
- Insignary released a tool detecting undeclared open-source and AI code.
- AT&T agreed to pay $177 million resolving two breach lawsuits.
- Meta's Muse AI compiles detailed personal profiles from online interactions.
- Microsoft Teams added warnings for malicious links inside QR codes.
Sources in this roundup
| GBHackers Security | #1 Globally Trusted Cyber Security News Platform |
|
6 article(s) |
| Cyber Security News |
|
4 article(s) |
| Cybersecurity Dive – Latest News |
|
1 article(s) |
| DataBreaches.Net |
|
1 article(s) |
| Hackread – Cybersecurity News, Data Breaches, AI and More |
|
1 article(s) |
| IT SECURITY GURU |
|
1 article(s) |
| Malwarebytes |
|
1 article(s) |
| SANS Internet Storm Center, InfoCON: green |
|
1 article(s) |
| Schneier on Security |
|
1 article(s) |
| Security Affairs |
|
1 article(s) |
| VirusTotal Blog |
|
1 article(s) |
| darkreading |
|
1 article(s) |
Most-mentioned keywords
| agents |
|
3 mention(s) |
| cloud |
|
3 mention(s) |
| data |
|
3 mention(s) |
| hackers |
|
3 mention(s) |
| steal |
|
3 mention(s) |
| aws |
|
2 mention(s) |
| billion |
|
2 mention(s) |
| code |
|
2 mention(s) |
Sources
- REA Tool Connects Claude Code and Cursor to Ghidra and IDA Pro to Reverse Engineer Anything
- GhostAction Hackers Compromise 500+ GitHub Accounts to Steal Cloud and AI API Credentials
- Why TLP should not replace your internal information classification, (Sat, Oct 10th)
- KR: Coupang files lawsuits against 620 billion won fine over data leak
- US government lagging in transition to post-quantum encryption, GAO finds
- Core to Cloud Appoints David Brown as Managing Director
- Apple’s Verified Photography System
- Iranian VPN-over-DNS Activity Generates 40 Billion DNS Observations During Military Conflict
- Writing the Next Chapter
- US Sentences Empire Market Co-Creator Over $430 Million Criminal Marketplace
- DarkBlinders Hackers Use Fake Meeting App to Deploy Backdoor and Steal Government Data
- Hackers Use AI Agents and GodPotato Exploit to Gain Windows SYSTEM Privileges
- One Prompt Could Hijack AWS AI Agents and Steal Cloud Credentials
- Two AhsayCBS Zero-Day Vulnerabilities Actively Exploited to Take Over Backup Servers
- Internet Scanning in VirusTotal: hunting infrastructure by what it exposes
- AWS Bedrock AgentCore Flaw Allowed Attackers to Hijack AI Agents Using a Single Prompt
- Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code
- AT&T to Pay $177 Million After Two Massive Customer Data Breaches
- Meta’s Muse AI files away your friendships, arguments, and secrets
- Microsoft Teams to Warn Users About Malicious Links Hidden in QR Codes
