Citrix NetScaler Zero-Days Exploited, Kiteworks Shutdown Warning, ShinyHunters WAF Bypass, FBI Medical Files Leak, OpenAI Medicare “Hack” Reframed Citrix…
Tag: EN
Meta disputes claim that Muse read a user’s private messages without permission
Meta says its Muse AI agent cannot access a user’s Messages without explicit permission, disputing a journalist’s account that the agent read his private…
ISC Stormcast For Monday, September 28th, 2026 https://isc.sans.edu/podcastdetail/10112, (Mon, Sep 28th)
This post has no text preview — click the link below to read the original article. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: ISC Stormcast For Monday, September 28th, 2026 https://isc.sans.edu/podcastdetail/10112,…
101 Malicious npm Packages Secretly Enroll Developers into WhatsApp Spam Channels
Researchers at OX Security have flagged 101 npm packages that silently subscribe developers to WhatsApp spam channels the moment they are installed. The…
Hackers steal protective order and foster care records from Arizona courts
Attackers copied sensitive court records, including more than 150,000 foster care reports, raising privacy and safety concerns for those Arizonans…
Global Group Ransomware Abuses WinMerge to Deploy Encryptor
Cofense researchers reveal how Global Group uses payment-themed phishing, malicious ISO files and WinMerge to deploy ransomware and extort large…
84% of Indian SMEs Plan Higher Cybersecurity Spending as Readiness Gaps Remain
A large proportion of Indian small and medium enterprises (SMEs) plan to boost cybersecurity spending in the next 12-24 months yet experience gaps in…
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that…
National cyber director defends private-sector hacking program, urges focus on security basics
Letting businesses help the government deter cybercrime will benefit all Americans, Sean Cairncross said.
Attacker signs up as a member to plant webshells on parks and recreation platform, hunts for card data
Security researchers at Huntress have detailed a multi-stage intrusion in which a threat actor compromised three web servers belonging to a popular…
MCP Python SDK Flaw Exposes OAuth Credentials
A high-severity security vulnerability in the official Model Context Protocol (MCP) Python SDK could allow malicious MCP servers to steal OAuth…
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
Attackers are exploiting a critical flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in…
Opsec Fail Leaks a Rare Look Inside a Media-Buy-Powered Scam Operation
Inside the leaked Keitaro-powered backend of a cloaked investment scam targeting South Africa.
Legit Security launches agentic remediation for open-source dependency vulnerabilities
Tel Aviv, Israel, 30th September 2026, CyberNewswire
Six arrests for smuggling migrants via Schengen airports
Europol supported a migrant smuggling investigation involving law enforcement authorities from 17 countries. The criminal network was also engaged in…
Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570
Microsoft Threat Intelligence examines CVE-2026-73570 exploitation in Zimbra, including observed attack paths, detection opportunities, and mitigation…
Cyber Briefing: 2026.09.30
Executive phishing, browser flaws, and AI-assisted development workflows are creating paths to account compromise, system exploitation, and unintended…
Oxygen Forensics, A Russian-run forensics firm spent a decade inside European police departments
DOJ charges against Oxygen Forensics reveal the Russian-linked firm also sold forensic software to EU projects and European police forces for years. Last…
Google: AI Is Changing the Pace and Profile of Vulnerability Discovery
Google’s analysis found that AI-discovered vulnerabilities are more likely to enable remote code execution.
The devil is still in the email – but wears a new mask
When phishing can increasingly pass familiar checks, avoiding or limiting the damage depends on how quickly your company can detect and contain the attack
