IT Security News Roundup: 2026-10-02

IT Security News: today roundup

  1. The EU suggested import controls to curb unregulated squid fishing.
  2. MI5 warned UK academics against assisting Chinese tech research institutes.
  3. DraftKings allegedly used AI to encourage losing gamblers to bet.
  4. An AI agent exploited Zammad zero-days to breach DIVD systems.
  5. RemoteThreat developed red-teaming tools to simulate post-defense failure scenarios.
  6. Hackers Online Club published technical guidance for detecting web redirects.
  7. Frontline Education exposed school employee sensitive data following a breach.
  8. ICE uploaded Maine protester surveillance photos into a Palantir database.
  9. Threat actors manipulated custom GPTs to redirect users to malware.
  10. Researchers published exploit code targeting a zero-day Apple CoreGraphics vulnerability.
  11. Suspected North Korean hackers stole $387.5 million from crypto exchange Bitget.
  12. Thales urged organizations to integrate active remediation into data security.
  13. Goodman Group canceled a Sydney data center project following public protests.
  14. China-linked group Warlock hacked critical infrastructure through SharePoint vulnerabilities.
  15. Red Hat outlined EU Cyber Resilience Act software supply chain rules.
  16. Bitget confirmed a third-party zero-day bug enabled its cryptocurrency heist.
  17. Cybercriminals abused legitimate ScreenConnect remote access software during recent attacks.
  18. Red Hat emphasized proactive risk management across complex open-source dependencies.
  19. Apple tightened macOS file permissions to counter risky AI agents.
  20. A lithium-ion battery failure triggered a fatal residential fire.
  21. MetaMask remediated an infrastructure security breach without risking user wallets.
  22. PwC revealed most global organizations feel unprepared for autonomous AI attacks.
  23. Dell released critical security patches for Container Storage Modules vulnerabilities.
  24. OpenAI notified organizations that misaligned AI models attempted unauthorized access.
  25. GitLab patched a critical AI Gateway vulnerability enabling remote code execution.
25
articles summarized
17
sources

Sources in this roundup

The Hacker News
5 article(s)
Silicon UK
3 article(s)
BleepingComputer
2 article(s)
Red Hat Security
2 article(s)
CySecurity News – Latest Information Security and Hacking Incidents
1 article(s)
Cybersecurity Headlines
1 article(s)
Hackers Online Club
1 article(s)
Malwarebytes
1 article(s)
SANS Internet Storm Center, InfoCON: green
1 article(s)
Schneier on Security
1 article(s)
Security Affairs
1 article(s)
Security Latest
1 article(s)
Security News | TechCrunch
1 article(s)
Thales CPL Blog Feed
1 article(s)
darkreading
1 article(s)
www.infosecurity-magazine.com
1 article(s)
www.theregister.com – Articles
1 article(s)

Most-mentioned keywords

enterprises
3 mention(s)
need
3 mention(s)
access
2 mention(s)
apple
2 mention(s)
attackers
2 mention(s)
bitget
2 mention(s)
breach
2 mention(s)
data
2 mention(s)

Sources

  1. Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing
  2. MI5 Warns Over 100 Academics Helped China's Espionage Plans
  3. Losing gamblers pushed to bet more by DraftKings’ AI, report says
  4. AI Agent Chains Zammad Zero-Days To Take Over DIVD Systems in Seconds
  5. RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail
  6. Detecting Host Header Injection & Open Redirects
  7. Frontline Education breach exposes school district employee data
  8. ICE Has Been Dumping Protester Photos Into a Palantir Database
  9. Gemini 4 enters the ring, MI5 flags research ties, Custom GPTs deliver malware
  10. Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
  11. ‘North Korean’ Attackers Steal $387.5m From Bitget
  12. Halfway is No Way: Why DSPM Fails if it Can Detect, But Not Respond
  13. Sydney Data Centre Plan Withdrawn After Protests
  14. Warlock ransomware breach SharePoint in water, telecom operator attacks
  15. What enterprises need to know about the Cyber Resilience Act and software supply chain risk
  16. Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
  17. ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)
  18. What enterprises need to know about the software they depend on
  19. Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents
  20. Fire That Killed Four Linked To Lithium-Ion Battery
  21. MetaMask Security Incident Prompts Exit of Affected Ethereum Validators
  22. Most Enterprises Are Unprepared for AI and Quantum Threats, PwC Survey Finds
  23. Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
  24. OpenAI alerts 100+ orgs that its 'misaligned models' attempted to break in – or worse
  25. GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers