A high-severity denial-of-service flaw (CVE-2026-23870) in React Server Components can allow a remote attacker to freeze vulnerable Next.js servers by…
ISC Stormcast For Thursday, October 8th, 2026 https://isc.sans.edu/podcastdetail/10128, (Thu, Oct 8th)
This post has no text preview — click the link below to read the original article. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: ISC Stormcast For Thursday, October 8th, 2026 https://isc.sans.edu/podcastdetail/10128,…
Malicious PDF Reader With 10,000+ Installs on Google Play Delivers Anatsa Banking Trojan
A malicious Android PDF reader distributed through Google Play has recorded more than 10,000 installs while serving as an installer for the Anatsa banking…
Italian Foreign Ministry Website Hit By Disruption Attempt
Distributed denial of service attack attempts to take foreign ministry’s website offline, in incident linked to Russian group
Leaked Chat Logs Show Silent Ransomware Extorted Over $200,000,000 in 6 Months Without Encrypting Data
Alleged internal chats from Silent Ransom Group suggest the criminals collected $206.95 million from 27 firms in roughly six months without encrypting…
Anthropic Launches Cyber Mission to Protect Critical Infrastructure and Open-Source Software With Claude AI
Anthropic launched its Cyber Mission, a long-term initiative aimed at helping defenders secure critical infrastructure and open-source software. This…
Ransomware recovery CEO charged over secret ransom payments
The owner of ransomware remediation company MonsterCloud has been charged with allegedly defrauding ransomware victims by secretly paying their attackers…
Google Pixel 10 Exploits Earned Hackers $560,000 at Pwn2Own
$1.2 million was paid out at Pwn2Own Ireland 2026 for exploits targeting phones, printers, smart speakers, smart home hubs, and AI infrastructure and…
October 2026 Patch Tuesday forecast: Time for an Office cleanup
September 2026 Patch Tuesday set an all-time record with 973 CVEs addressed across the Microsoft portfolio. We’re only four months into the Patch…
FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure Intrusions
The U.S. Federal Bureau of Investigation (FBI) and Department of Justice (DoJ) have announced the disruption of malicious tools used by a China-linked…
Known Cybersecurity Expert and Owner of Florida Ransomware Remediation Company Charged with Defrauding Clients
Here’s another case where the folks who were supposed to be the good guys helping you may be harming you. Zohar Pinhasi, 50, also known as “Zack Silver”…
MATCHBOIL Malware Adds Sandbox Checks, .NET Reactor Obfuscation and Persistent C2
MATCHBOIL’s evolution from a basic C# downloader into a more evasive implant supporting recurring command-and-control communication. Operated by UAC-0099,…
Citrix Urges Immediate Patching of Critical NetScaler Vulnerability
The security defect, tracked as CVE-2026-107406, could lead to remote code execution or denial-of-service.
IT Security News Hourly Summary 2026-10-09 09h : 9 posts
9 posts published in the last hour 06:31What the BPFDoor backdoor tells us about attacks on the network edge 06:31Asos Acknowledges Theft Of Detailed Customer Data 06:31Critical Citrix NetScaler Vulnerability Allows Remote Code Execution Attacks – CVSS 9.5 06:31Midnight Blizzard…
What the BPFDoor backdoor tells us about attacks on the network edge
A backdoor that makes no noise is hard to catch, and that’s the point of BPFDoor. The Linux malware waits for a special “magic packet” before it acts. In…
Asos Acknowledges Theft Of Detailed Customer Data
Detailed profiles on users, including search history, stolen from third-party service in social engineering attack
Critical Citrix NetScaler Vulnerability Allows Remote Code Execution Attacks – CVSS 9.5
Citrix has disclosed a critical memory overflow vulnerability in NetScaler ADC and NetScaler Gateway that could enable remote code execution or denial of…
Midnight Blizzard Targets Hotel Wi-Fi: Malware and Phishing Put Travelers at Risk
Midnight Blizzard is abusing hotel Wi-Fi captive portals to deliver malware and steal credentials from travelers, putting corporate devices and accounts…
Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland
The Pwn2Own Ireland 2026 hacking contest has concluded, with hackers collecting $1,262,000 in rewards after exploiting 98 zero-day flaws. […]
ASOS Confirms Cyber Incident After Unauthorized App Notifications
ASOS is investigating unauthorized app notifications and possible customer data exposure. Learn what is confirmed and why messaging systems need…
Thousands of wind and solar park systems sit exposed on the internet across Europe
Modat and NCSC-NL, the Dutch government’s cybersecurity center, found 8,547 internet-facing systems at wind farms and solar parks in 35 countries in and…
Six arrests for smuggling migrants via Schengen airports
Europol supported a migrant smuggling investigation involving law enforcement authorities from 17 countries. The criminal network was also engaged in…
IT Security News Hourly Summary 2026-10-09 08h : 12 posts
12 posts published in the last hour 05:31Microsoft Pushes Enterprises to Test Post-Quantum Certificates Before Large-Scale Migration 05:31PCI SSC calls for human approval of AI agent actions involving cardholder data 05:31Critical Sungrow Authentication Bypass Flaw Lets Hackers Take Control of…
Microsoft Pushes Enterprises to Test Post-Quantum Certificates Before Large-Scale Migration
Microsoft is urging enterprises to prepare for post-quantum authentication by testing certificate dependencies before attempting broad infrastructure…
