ShinyHunters Leader Detained in Jordan, KillSec Takedown, Vicksburg Ransomware, and OpenAI Agent Lawsuit Host David Shipley reports that Jordan detained…
2026-10-01: Traffic analysis exercise – Natureforce
This post has no text preview — click the link below to read the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2026-10-01: Traffic analysis exercise – Natureforce
Telegram Account Behind ASOS Rogue Notification Tied to Gaming Trading
A Group-IB researcher has found the Telegram account linked to the unauthorized ASOS customer notification previously engaged in gaming-item trading
CrowdStrike Named a Leader in The Forrester Wave™: Proactive Security Platforms, Q3 2026
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: CrowdStrike Named a Leader in The Forrester Wave™: Proactive Security Platforms, Q3 2026
ISC Stormcast For Monday, October 5th, 2026 https://isc.sans.edu/podcastdetail/10122, (Mon, Oct 5th)
This post has no text preview — click the link below to read the original article. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: ISC Stormcast For Monday, October 5th, 2026 https://isc.sans.edu/podcastdetail/10122,…
SonicWall warns of max severity SSRF flaw in SMA1000 gateways
SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances. […]
Verify it, don’t assume it: why untested security controls are making life easy for attackers
This year’s Cybersecurity Awareness Month theme, “Don’t Make It Easy for Them”, is usually read as advice for individuals. Cynthia Overby, director of…
Hackers hijack three country-code domain registries, obtain HTTPS certificates for Google domains
Attackers who took control of three country-code top-level domains (ccTLDs) used that access to obtain HTTPS certificates for several Google domains and…
OpenAI Sandbox Escape Flaw Allowed Free Access to Paid AI Models Without an API Key
Security researcher Oliver Fish says he found an OpenAI sandbox escape that let him request paid AI models without an API key or an account. A screenshot…
Apple’s Verified Photography System
Apple just released a system called “Reference Image.” It can verify the image is exactly as taken by an iPhone—new models only—without tying it to a…
Hackers Use ERP Web Shell and IDOR Flaws to Breach Major South Korean Churches
Attackers breached two of South Korea’s largest churches through distinct intrusion chains, combining an ERP web shell, privileged database access, leaked…
Anthropic Mythos AI Finds Rejetto HFS Flaw That Lets Attackers Forge Admin Sessions and Execute Code
Anthropic’s Mythos AI has identified a critical vulnerability in Rejetto HTTP File Server that could allow remote attackers to forge administrator…
TTY Logs and the Data it Captures, (Sun, Oct 4th)
For an experiment, I created a script [1] that parses and send the TTY logs collected from actors or bots activity that run various commands after they…
Critical Progress DataDirect GenAI Flaw Lets Malicious OpenAPI Files Execute OS Commands
Progress disclosed critical command injection flaw CVE-2026-91140 in DataDirect Autonomous REST Connector AI Model Generator agents, allowing malicious…
IT Security News Hourly Summary 2026-10-07 14h : 15 posts
15 posts published in the last hour 11:02The ASOS incident: When attackers use the channels customers trust 11:02Cybercrime Detective Explains Cybersecurity Jargon in 60-Second Videos for Cybersecurity Awareness Month 11:02Chrome 155 Update Patches 247 Vulnerabilities 11:02Elastic Patches 14 Security Flaws,…
The ASOS incident: When attackers use the channels customers trust
ASOS customers opened their phones to find a hostile push notification delivered through the retailer’s own app. The message claimed the company’s…
Cybercrime Detective Explains Cybersecurity Jargon in 60-Second Videos for Cybersecurity Awareness Month
COPENHAGEN, Denmark, 7 October 2026 – Heimdal today officially launches the “Cyber in 60” weekly video series in which Adam Pilton, a former cybercrime…
Chrome 155 Update Patches 247 Vulnerabilities
Four critical-severity use-after-free defects were fixed in Chromecast, Browser, Navigation, and Track.
Elastic Patches 14 Security Flaws, Including One Enabling Cross-Tenant Data Interception
Elastic published 14 security advisories addressing various vulnerabilities in Elasticsearch, Kibana, and Elastic Agent/Endpoint. Among these, a…
Anthropic Creates Three Tiers for Claude Cyber Access
Anthropic created three access tiers for Claude’s offensive security use, matching cyber capabilities and safeguards to the user’s level of trust.…
SonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances (CVE-2026-102255)
SonicWall has patched four vulnerabilities in its popular Secure Mobile Access (SMA) 1000 series of appliances, including one (CVE-2026-102255) that could…
Another ShinyHunters suspect arrested
The net is tightening around the Shiny Hunters cybercrime group following the reported arrest of a second member.
FortiBleed still a bleeding nuisance as FBI confirms ongoing attacks
Tens of thousands more victims and more ransomware groups getting in on the act
Musician sent to prison for $10 million streaming fraud using AI bots
A North Carolina musician was sentenced to 18 months in prison for collecting more than $10 million in royalties from Spotify, Apple Music, Amazon Music,…
