In part 1 of this series, we examined why enterprises need more than an inventory of the open source components in their software. Understanding where…
Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security…
ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)
Threat Actors do not always use top-notch techniques or very complex malware to perform their attacks. Sometimes, they just abuse of existing…
What enterprises need to know about the software they depend on
Knowing an application contains open source components is not the same as understanding the software and communities behind them.For many organizations,…
IT Security News Hourly Summary 2026-10-02 21h : 10 posts
10 posts published in the last hour 18:31Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents 18:31Fire That Killed Four Linked To Lithium-Ion Battery 18:31MetaMask Security Incident Prompts Exit of Affected Ethereum Validators…
Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents
Apple says it will add new controls around macOS’s Full Disk Access permission, warning that increasingly capable AI agents make broad access to users’…
Fire That Killed Four Linked To Lithium-Ion Battery
Electrical event caused lithium-ion battery to go into thermal runaway, sparking intense fire that killed mother, three children
MetaMask Security Incident Prompts Exit of Affected Ethereum Validators
MetaMask on Thursday said it’s responding to what it described as an “ongoing security incident” impacting part of its infrastructure. “We are actively…
Most Enterprises Are Unprepared for AI and Quantum Threats, PwC Survey Finds
Most organizations around the world are spending more on cybersecurity than at any point in their history. Very few are spending it on the threats that…
Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad…
OpenAI alerts 100+ orgs that its ‘misaligned models’ attempted to break in – or worse
Mostly ‘routine research tasks,’ and ‘some involved government websites, which our models often use,’ AI giant tells The Reg
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
A critical flaw in GitLab’s AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions,…
The legal questions raised by agentic AI hacks
Experts and policymakers want AI companies to face consequences for agentic hacks. There may not be a clear-cut answer under existing laws and regulations.
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which…
IT Security News Hourly Summary 2026-10-02 20h : 7 posts
7 posts published in the last hour 17:31Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response 17:31Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs 17:01ISC Stormcast For Thursday, October 1st, 2026 https://isc.sans.edu/podcastdetail/10118, (Thu, Oct 1st) 17:01Exabeam…
Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response
One company told customers to power down its data-protection platform during a nine-hour window, while the other remained mum on reported attacks prior to…
Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs
Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to…
ISC Stormcast For Thursday, October 1st, 2026 https://isc.sans.edu/podcastdetail/10118, (Thu, Oct 1st)
This post has no text preview — click the link below to read the original article. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: ISC Stormcast For Thursday, October 1st, 2026 https://isc.sans.edu/podcastdetail/10118,…
Exabeam Pushes The “Agentic SOC” Into The Cloud And On-Premises, With Analysts Kept In The Loop
Security operations centres are facing a two-sided problem. Attackers are increasingly automating their campaigns, while inside the business, AI agents…
GitLab warns of critical RCE vulnerability in AI Gateway service
GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable…
New Mexico Jury Finds Facebook Violated Consumer Protection Law More Than 43 Million Times
A New Mexico jury has found that Facebook violated the state’s Unfair Practices Act (UPA) more than 43 million times, according to the New Mexico…
IT Security News Hourly Summary 2026-10-02 19h : 16 posts
16 posts published in the last hour 16:31Defending against AI-fueled cyberattacks requires focus on identity, data governance, Microsoft says 16:31Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30) 16:31Is Your Organization Ready for 2027’s…
Defending against AI-fueled cyberattacks requires focus on identity, data governance, Microsoft says
Dive Brief: Businesses need to prepare for the ways in which AI is changing the cyberattack landscape, Microsoft warned on Thursday. AI is speeding up…
Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)
Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild.
