OpenAI has scrapped the planned October release of GPT-6.1 Astra after internal testing found the model did not meet the company’s safety and alignment…
Police dismantle KillSec ransomware gang allegedly led by 16-year-old
An international law enforcement operation dubbed “Operation KillSwitch” seized the KillSec ransomware gang’s data leak site and servers, led to three…
Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected
Mandiant researchers said dozens of organizations have been impacted by attacks attributed to advanced and suspected state-sponsored threat groups. They…
AMD agrees to buy World Labs to fill out its AI stack
Advanced Micro Devices (AMD) has agreed to buy World Labs, a developer of AI “world models” that incorporate knowledge of the physical world, to extend…
The Day-One Hole in Zero Trust Architecture
Zero Trust can verify users once they are established, but onboarding creates a gap where organizations must decide who to trust before strong…
IT Security News Hourly Summary 2026-10-01 23h : 32 posts
32 posts published in the last hour 20:32Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution 20:32Cloudflare plans to issue quantum-safe TLS certificates 20:32National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations 20:32Proton Extends Easy…
Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution
A patched Unsloth Studio vulnerability allows malicious AI models to execute arbitrary Python code during inspection, via the trust_remote_code setting.
Cloudflare plans to issue quantum-safe TLS certificates
The move will be part of a major overhaul of the ecosystem for website authentication.
National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations
Sean Cairncross talked about regulations, China, pilot projects and more Thursday.
Proton Extends Easy Switch to Microsoft 365
Proton has extended its Easy Switch for Business migration tool to support Microsoft 365, enabling organizations to transfer email, calendars, and…
AI cuts software developers some slack
My mom used to say that Hodges’s law was “Junk expands to fill the space allotted for it.” We lived in three houses over the years, each one bigger than…
‘NeedyMantis’ Provides Long-Term Access to Compromised Networks
Microsoft observed a China-based actor using a previously unidentified malware framework in targeted intrusions against telcos, universities, medical, and…
Attackers have been exploiting critical Zimbra flaw to steal emails
A simple email gives the attackers the ability to remotely inject OS commands.
OpenAI reveals ‘novel’ encryption bypass used in distillation attack
The company said individuals associated with Chinese company MoonshotAI were behind parts of the attack, but did not offer hard evidence for the claim.
Japanese Railway Operators Hit with Cyber Attacks
Three major Japanese transport operators have disclosed significant cyber attacks within days of each other, compromising customer data but leaving…
Meta’s next big AI bet is enterprise; its biggest hurdle may be trust
Meta is once again repositioning itself to target the enterprise market. This week, the company announced the Meta Enterprise Platform , which it says…
Cloudflare Announces Public Certificate Authority for the Post-Quantum Web
Automated certificates for everyone, built for today, and hardened for the era of quantum computing.
Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members
The teenager-run cybercrime group victimized roughly 500 organizations in less than two years.
ShinyHunters expands Oracle PeopleSoft campaign
Google Threat Intelligence Group warned Friday that ShinyHunters (tracked as UNC6240) has launched an expanded campaign targeting vulnerable Oracle…
Observability for AI-native systems: New SLIs beyond latency and error rate
When HTTP 200 means nothing An AI assistant can return a response in under a second, maintain 99.9% availability and still give customers a fabricated…
South Africa Seeks Help After Cyberattack Targets Air Traffic Control
As aviation infrastructure suffers more cyberattacks, air traffic systems are the latest target, with a ransomware toolkit installed on at least one…
AI policy circles targeted in China-linked phishing operation
Cybersecurity firm Proofpoint said TA419 impersonated officials and AI industry figures in an effort to gain access to cloud accounts held by U.S. think…
Validating AI models and agents with property-based testing
Testing deterministic systems is relatively straightforward. Create an assertion that the system should pass, and automate validating it against a series…
Apple Zero-Day Vulnerability Weaponized in Targeted Attacks
Attackers are exploiting CVE-2026-86950, an out-of-bounds write flaw, in an extremely sophisticated fashion, according to Apple.
