Apple patched an iPhone flaw that may have been exploited in targeted attacks. Here’s what iOS 26 users need to know and how to update.
Hackers steal protective order and foster care records from Arizona courts
Attackers copied sensitive court records, including more than 150,000 foster care reports, raising privacy and safety concerns for those Arizonans…
Global Group Ransomware Abuses WinMerge to Deploy Encryptor
Cofense researchers reveal how Global Group uses payment-themed phishing, malicious ISO files and WinMerge to deploy ransomware and extort large…
The EDR blind spot: 3 ways browser attacks evade endpoint telemetry
Browser-based attacks can steal sessions, abuse extensions, or manipulate users without creating the endpoint artifacts EDR is designed to detect.…
Mass exploitation of Citrix NetScaler: What we currently know
Suspected state-linked actors targeted critical vulnerabilities in the widely used platform, causing widespread disruption across Europe and North America.
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of…
Ship fast, verify independently: keeping application security in step with AI-written code
AI coding assistants have transformed how quickly software can be built, but they have also intensified a long-running tension between development speed…
84% of Indian SMEs Plan Higher Cybersecurity Spending as Readiness Gaps Remain
A large proportion of Indian small and medium enterprises (SMEs) plan to boost cybersecurity spending in the next 12-24 months yet experience gaps in…
OpenAI’s wandering AI agents earn it a California subpoena
Plus: Attorneys-general say investigators should have direct access to AI companies’ records when things go wrong
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that…
IT Security News Hourly Summary 2026-10-02 17h : 30 posts
30 posts published in the last hour 14:33Vulnerability Backlogs Are an Ownership Problem 14:32Oxygen Forensics, A Russian-run forensics firm spent a decade inside European police departments 14:32Legit Security launches agentic remediation for open-source dependency vulnerabilities 14:32Opsec Fail Leaks a Rare…
Vulnerability Backlogs Are an Ownership Problem
Organizations don’t need better vulnerability scanners; they need to know who owns their assets and has the authority and capacity to actually fix them.
Oxygen Forensics, A Russian-run forensics firm spent a decade inside European police departments
DOJ charges against Oxygen Forensics reveal the Russian-linked firm also sold forensic software to EU projects and European police forces for years. Last…
Legit Security launches agentic remediation for open-source dependency vulnerabilities
Tel Aviv, Israel, 30th September 2026, CyberNewswire
Opsec Fail Leaks a Rare Look Inside a Media-Buy-Powered Scam Operation
Inside the leaked Keitaro-powered backend of a cloaked investment scam targeting South Africa.
MetaMask Takes Precautionary Action After Infrastructure Security Incident
Crypto wallet provider MetaMask is taking precautions following a security incident impacting one of its infrastructures as it deals with the consequences…
Microsoft: AI Cuts Post-Compromise Attack Time to Minutes
Microsoft has warned that threat actors have gained the advantage over defenders by using AI to enhance the speed and scale of attacks
Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570
Microsoft Threat Intelligence examines CVE-2026-73570 exploitation in Zimbra, including observed attack paths, detection opportunities, and mitigation…
Cyber Briefing: 2026.10.02
Shadow AI exposure, healthcare tracking disputes, a hijacked Microsoft X account, accelerated vulnerability-reporting requirements, an Iranian hacking…
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks,…
Six arrests for smuggling migrants via Schengen airports
Europol supported a migrant smuggling investigation involving law enforcement authorities from 17 countries. The criminal network was also engaged in…
IBM’s Bob wants to move in: Agent available for on-prem deployment
Bob, IBM’s agentic software development platform is now available to run on premises and in private clouds, sovereign clouds, and air-gapped environments…
Hackers Turned a Microsoft SQL Server Into a Command and Data Exfiltration Channel
Hackers turned a Microsoft SQL Server into a channel for running commands and moving collected files in an intrusion linked to a Viva Aerobus environment.…
MCP Python SDK Flaw Exposes OAuth Credentials
A high-severity security vulnerability in the official Model Context Protocol (MCP) Python SDK could allow malicious MCP servers to steal OAuth…
