CFToday Curated security signals.

Daily edition · 2026-10-06 · latest

Tuesday, 6 October 2026

68 items across 8 sections, selected from 3823 candidates over 5 runs. 173 carried the panel unanimously.

Show
Section

India

1

Indian organisations, regulators and infrastructure, pulled out of the sections below.

  1. Why India’s banks need a common playbook for data breaches and cyberattacks (opens in a new tab)

    Google News: enforcement · MediaNama ·Governance, Risk & Compliance ·fetched 6 Oct 2026, 15:35 UTC

    Why readExamines the need for unified incident response playbooks across the Indian banking sector.

    Discussion of cyber risk posture across Indian financial institutions advocating for standardized breach reporting and response rules. The piece highlights policy gaps in banking sector incident coordination.

  1. Hackers obtain counterfeit TLS certificates for Google and other large services (opens in a new tab)

    Ars Technica Security ·Dan Goodin ·fetched 6 Oct 2026, 19:34 UTC Must read

    Why readAttackers hijacked three ccTLDs to manipulate DNS records and obtain unauthorized TLS certificates for Google and other global services.

    Attackers compromised the registry infrastructure for the .gh, .sl, and .as country-code top-level domains, allowing them to alter DNS records for selected domains. By intercepting domain validation traffic, the threat actors successfully requested and received unauthorized TLS certificates for Google domains and other major services. Google updated Chrome to block all identified rogue certificates and coordinated with other CAs and browser vendors to revoke them.

  2. Midnight Blizzard Abuses Hotel Wi-Fi Captive Portals to Deliver Malware and Steal Credentials (opens in a new tab)

    Cybersecurity News ·Tushar Subhra Dutta ·fetched 6 Oct 2026, 11:35 UTC Must read

    Why readUncovers Midnight Blizzard's CaptiveCrunch campaign abusing hotel Wi-Fi portals to deploy a Rust variant of CornFlake malware.

    Microsoft identified activity from Midnight Blizzard sub-cluster Storm-2945 targeting hotel Wi-Fi networks in a campaign named CaptiveCrunch. The threat actor tampers with captive portal sign-in pages to serve malicious update prompts that drop a Rust-based variant of the CornFlake malware, harvesting credentials and session tokens from traveling corporate users.

    Indicators12
    Hashes
    918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593 be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c
    Addresses
    149[.]3[.]170[.]186 31[.]57[.]243[.]154 38[.]146[.]28[.]75 104[.]194[.]159[.]150 107[.]189[.]26[.]194 213[.]145[.]86[.]112
    Domains
    ms365-device[.]com ms365-live[.]com m365-owa[.]com owa-ms365[.]com
  3. SubQuery Ecosystem Compromise: Hidden Credential Theft and Backdoors (opens in a new tab)

    StepSecurity (CI/CD) ·fetched 6 Oct 2026, 07:33 UTC Research

    Why readMalicious npm package @subql/[email protected] drops a backdoor and steals credentials from developer machines and CI/CD pipelines.

    StepSecurity discovered a malicious release in the @subql/common npm package (version 5.8.3) containing hidden credential-stealing logic and remote shell functionality. The payload executes on installation and import, targeting local developer workstations and GitHub Actions runners.

    Indicators5
    Hashes
    51e2a2c985c3c869510a36e8c37a3b3557af4a3c bbbca2ddaa5d8feaa63e36b76fdaad77386f024f 031267ee37c5a84c25cb0542cbfeb49f30d5604305b0bdccdeafbedcbbe6849b f0c8b0cde86b98a2869a22fd43ffcf61f1dcca252729e2be291e590e3dc5f49a 7b2807bfb5bfec2383b46ba8226f47edb330ae6b32178eab61e377f3c3486c47
  4. Blinder Tunnel Campaign Targets Iraqi Infrastructure (opens in a new tab)

    Unit 42 ·Unit 42 ·fetched 6 Oct 2026, 11:35 UTC Must read Research

    Why readExposes Iranian threat group CL-STA-1178 targeting Iraqi critical infrastructure with trojanized coding lures and custom tunneling malware.

    Palo Alto Networks Unit 42 details an Iranian state-aligned campaign dubbed Blinder Tunnel targeting Iraqi critical infrastructure. The adversary masqueraded as Dubai Airports IT staff to distribute trojanized coding challenges that deploy custom tunneling malware.

    Indicators16
    Hashes
    6e7d9b33f1e72ea1ede71373a604ecdb060dab7d42055179c1eede9ecd1fd239 f5b12772db6817f7a765a6fe7565fd3d4f87edc28e42fe3ec0244a372a410fc9 53f35e49eb9b271fd8cbcd3daacb525328dbf159a03dbd1c7adebe0363daa402 3fd810a3aa0039993393741b32287c367a9a5037a41e826906440887cdd3ed13 76273382e4252c1f60a2251141e108942494409c759358320735891762c0682e d3561bd4aad003dc3e08157b0891860bb496b80cd6e44901692e08ab1d4e8260 f5ba1645694c62f527ed6ceda8c68a5c3dd92b4032439167e8e937e72803b4bd 7cc571aca6d8715d9aaad3d83e1bcd30467565d583db1dfe73697c5d00a1f875
    URLs
    hxxps://cloud[.]g-drive[.]cam/drive/file/d/[generated hxxps://cloud[.]g-drive[.]cam/signin/v2/identifier
    Addresses
    91[.]107[.]156[.]29 65[.]109[.]214[.]145 38[.]180[.]136[.]127
    Domains
    musicdel[.]ir asdfafadafg[.]online ns1[.]soroshpasargad[.]com
  5. FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware (opens in a new tab)

    SecurityWeek ·Ionut Arghire ·fetched 6 Oct 2026, 15:35 UTC

    Why readDetails the arrest of the principal author behind the widely deployed Ploutus ATM jackpotting malware family.

    US authorities arrested Anibal Alexander Canelon Aguirre, the key developer behind the Ploutus ATM jackpotting malware family. Operating under the alias 'Prometheus', Canelon Aguirre created tooling used by transnational crime syndicates to compromise automated teller machines across 47 US states. The arrest marks the first time a cybercrime author has been placed on the FBI's Top 10 Most Wanted list.

    Also covered byThe Record (opens in a new tab),BleepingComputer (opens in a new tab).

  6. ClickFix campaign in Ukraine compromises over 100 websites to spread Lunex malware (opens in a new tab)

    The Record ·fetched 6 Oct 2026, 15:35 UTC Must read

    Why readUkraine's CERT warns of a ClickFix campaign across 100 compromised websites that uses fake Cloudflare verification pages to trick users into running PowerShell commands to deliver Lunex Stealer.

    A ClickFix campaign discovered by CERT-UA compromised more than 100 websites in Ukraine to present visitors with fake Cloudflare verification challenges. The pages instruct users to copy and paste PowerShell commands into their terminal, which downloads Lunex Stealer to harvest credentials, tokens, and cryptocurrency wallet data.

  7. Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2 (opens in a new tab)

    The Hacker News ·The Hacker News ·fetched 6 Oct 2026, 07:33 UTC

    Why readThe Cling botnet is exploiting legacy Realtek SDK flaws and repurposing STUN network traffic as a C2 communications channel.

    Threat actors are actively exploiting CVE-2021-35394, an RCE flaw in the Realtek Jungle SDK, to deploy the Cling botnet. Cling uses Session Traversal Utilities for NAT (STUN) protocol requests to mask its command-and-control traffic as normal network traversal activity. The malware targets routers and embedded devices to facilitate proxying, tunneling, and denial-of-service attacks.

    Indicators2
    Addresses
    145[.]249[.]115[.]184 74[.]125[.]250[.]129
  8. Trump Mobile customers' data dumped - and some never even received their gold device (opens in a new tab)

    The Register Security ·fetched 6 Oct 2026, 19:34 UTC

    Why readDetails a data leak by new RaaS group BYOD impacting 3,615 Trump Mobile customers after an initial MVNO infostealer infection.

    Ransomware-as-a-service group BYOD published personal information and telecom details of 3,615 Trump Mobile subscribers. The attackers reportedly gained access by infecting an employee at MVNO Liberty Mobile with an infostealer.

  9. Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes (opens in a new tab)

    BleepingComputer ·Bill Toulas ·fetched 6 Oct 2026, 15:35 UTC

    Why readDetails a phishing campaign using fake AI assistant sites and Browser-in-Browser popups to steal advertising accounts and MFA codes from agency staff.

    Attackers are impersonating AI tools like ChatGPT, Gemini, Claude, and Meta's Muse agent to target media buyers and ad agency administrators. The phishing sites utilize Browser-in-Browser (BiB) popups that mimic authentic Google sign-in windows to capture login credentials and multi-factor authentication codes. Compromised accounts are used to spend existing balances on fraudulent ad campaigns or resold on underground markets.

  10. Osaka Metropolitan University cancels classes after suspected ransomware attack (opens in a new tab)

    The Record ·fetched 6 Oct 2026, 15:35 UTC

    Why readOsaka Metropolitan University shut down 500 servers and cancelled classes following a ransomware attack that affected data for 130,000 individuals.

    Osaka Metropolitan University suffered a severe network outage that forced approximately 500 servers offline and disrupted administrative, HR, payroll, and academic operations. University officials suspect a ransomware attack caused the incident, which compromised systems holding personal information for at least 130,000 current and former members.

  11. More RMM Tools In the Wild, (Tue, Oct 6th) (opens in a new tab)

    SANS ISC Diary ·fetched 6 Oct 2026, 11:35 UTC

    Why readDemonstrates how phishing PDFs abuse OpenAction URI handlers to download VBS payloads and deploy abused RMM tools.

    SANS ISC breaks down a malicious PDF sample using OpenAction annotations to fetch remote VBS scripts without exposing URLs in the email body. The downloader chain ultimately installs remote monitoring and management tooling on the victim system.

    Indicators6
    Hashes
    eaff35d250c9b04f51c971e70082740dbfeee5dd846829d541f588ad43378727 996b01e15f85e165899630721a141b178a9c372b6e878012180ec9e9d4e7bd06 1b19115d5ebdc216e0ab3adf2c643648cfc70a385f4caf0217c679f9f3b20342 941695d20d82dd5d62f74b0111feb23720637202f6c797df2a02e2cb6cb6e8e3
    URLs
    hxxps://up-theta-rose[.]vercel[.]app/adobe_new_update[.]vbs
    Domains
    server[.]na-2[.]action1[.]com
  12. Engineer sentenced for locking over 3,000 devices on employer network (opens in a new tab)

    BleepingComputer ·Sergiu Gatlan ·fetched 6 Oct 2026, 11:35 UTC

    Why readA former infrastructure engineer was sentenced to 32 months in prison for deleting domain admin accounts and locking thousands of enterprise devices.

    Daniel Rhyne, a former infrastructure engineer, was sentenced to 32 months in prison for executing an extortion attack against his employer's network. Rhyne used admin access to schedule tasks that deleted 13 domain admin accounts and changed passwords for over 3,300 workstation and server accounts.

  1. Citrix warns of actively exploited NetScaler flaw days after zero-day patch rush (opens in a new tab)

    CSO Online ·fetched 6 Oct 2026, 03:33 UTC Must read CVE-2026-88779 EPSS 0.5%

    Why readWarns of actively exploited memory overflow vulnerability CVE-2026-88779 in NetScaler ADC and Gateway.

    Citrix issued an urgent advisory for CVE-2026-88779, a high-severity (CVSS 8.7) memory overflow vulnerability in NetScaler ADC and Gateway appliances currently targeted in the wild. Successful exploitation triggers denial-of-service conditions on customer-managed instances configured as SAML Service Providers or Identity Providers.

    Also covered byCybersecurity News (opens in a new tab),Security Affairs (opens in a new tab),Infosecurity Magazine (opens in a new tab).

  2. The AI app builder your team trusts has a root-level backdoor (opens in a new tab)

    CSO Online ·fetched 6 Oct 2026, 11:35 UTC Must read CVE-2026-0768 EPSS 8.5%

    Why readWarns of active in-the-wild exploitation targeting internet-facing Langflow AI platform instances via CVE-2026-0768.

    Threat intelligence from VulnCheck indicates active exploitation of CVE-2026-0768, a critical CVSS 9.8 flaw in the open-source Langflow AI app platform. The vulnerability allows remote attackers to achieve root-level compromise on vulnerable internet-facing servers. Organizations deploying Langflow should inspect external visibility and apply available security patches immediately.

  3. Dell patches 18 critical flaws that could hand attackers the keys to storage and Kubernetes (opens in a new tab)

    CSO Online ·fetched 6 Oct 2026, 07:33 UTC

    Why readDell patches 18 critical flaws in Container Storage Modules and System Update, including two CVSS 10.0 authentication bypasses.

    Dell has released advisories covering 18 severe vulnerabilities in Dell Container Storage Modules and Dell System Update. The vulnerabilities include two CVSS 10.0 flaws that allow unauthenticated remote attackers to bypass authentication, gain root privileges, and forge administrative tokens across Kubernetes storage integration layers.

  4. New Dell System Update flaw lets hackers gain root privileges (opens in a new tab)

    BleepingComputer ·Sergiu Gatlan ·fetched 6 Oct 2026, 07:33 UTC

    Why readDell has patched CVE-2026-86360, a critical path traversal bug in the Dell System Update CLI tool that allows unauthenticated remote attackers to execute arbitrary code with root privileges.

    Dell issued a critical security advisory for CVE-2026-86360, a path traversal vulnerability in its Dell System Update (DSU) command-line interface deployment tool. The flaw allows remote, unauthenticated attackers to write to arbitrary filesystem locations and execute code with elevated root privileges on systems managing PowerEdge server infrastructure. Enterprise administrators running DSU on Linux or Windows hosts should apply vendor updates immediately.

    Also covered byHelp Net Security (opens in a new tab).

  5. LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings (opens in a new tab)

    The Hacker News ·The Hacker News ·fetched 6 Oct 2026, 15:35 UTC

    Why readOpening untrusted spreadsheets in Apache OpenOffice or unpatched LibreOffice can trigger automatic code execution when Java support is enabled.

    Researchers demonstrated a flaw that enables code execution upon opening a spreadsheet file without triggering standard macro security prompts. LibreOffice patched the issue (CVE-2026-63277) in versions 26.2.5 and 26.8.0. Apache OpenOffice remains unpatched against CVE-2026-59265 through version 4.1.16, requiring administrators to disable Java integration in application settings to mitigate risk.

  6. CVE-2026-100103 (CVSS 10.0): Perforce P4 Search container images prior to 2026.4.2 reset the service authentication token to a publicly documented default value. An unauthenticate (opens in a new tab)

    NVD ·fetched 6 Oct 2026, 07:33 UTC CVE-2026-100103 CVSS 10.0 EPSS 0.4%

    Why readUpgrade Perforce P4 Search container images to 2026.4.2 to fix a default authentication token vulnerability granting full server access.

    Perforce P4 Search container images prior to version 2026.4.2 reset service authentication tokens to a publicly documented default value. An unauthenticated remote attacker can leverage this default credential to acquire full application privileges and potentially execute arbitrary code on the connected P4 Server.

  7. CVE-2026-96940: Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely (opens in a new tab)

    Security Affairs ·Pierluigi Paganini ·fetched 6 Oct 2026, 15:35 UTC CVE-2026-96940 EPSS 0.5%

    Why readApply Microsoft's out-of-band patch for Exchange Server to fix CVE-2026-96940, an elevation of privilege vulnerability allowing unauthorized access to mailboxes.

    Microsoft has released an out-of-band security update for on-premises Exchange Server to address CVE-2026-96940, a CVSS 8.8 authorization flaw. An authenticated attacker on the same network can exploit the flaw to access other users' mailboxes and read emails and attachments within the organization. The vulnerability affects on-premises Exchange deployments and does not allow cross-tenant access.

  8. Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products (opens in a new tab)

    The Hacker News ·The Hacker News ·fetched 6 Oct 2026, 07:33 UTC CVE-2026-21589

    Why readCVE-2026-21589 allows unauthenticated attackers to read arbitrary known files in the web root of eight self-hosted Atlassian Data Center products.

    Atlassian released patches for CVE-2026-21589, a CVSS 9.3 flaw affecting eight self-hosted Data Center applications. Unauthenticated attackers who know exact file names and paths can access sensitive files within the web application root directory. Atlassian recommends immediate patching or network isolation for internet-facing instances.

    Also covered byHelp Net Security (opens in a new tab),The Register Security (opens in a new tab),watchTowr Labs (opens in a new tab),BleepingComputer (opens in a new tab).

  9. Hitachi Energy SOI (opens in a new tab)

    CISA Advisories ·CISA ·fetched 6 Oct 2026, 19:34 UTC CVE-2026-34197 EPSS 15.5%

    Why readDetails an unauthenticated remote code execution vulnerability in Hitachi Energy System Operations Infrastructure caused by exposed Jolokia endpoints in Apache ActiveMQ.

    Hitachi Energy has issued an advisory for System Operations Infrastructure versions 2.0.0 through 2.2.0 due to a flaw in the bundled Apache ActiveMQ Classic component. The default configuration exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console without proper access restrictions, allowing remote code execution. Operators in the energy sector should apply mitigations immediately to restrict access to the web console.

  10. Security researcher claims to they found KVM guest-host escape flaw (opens in a new tab)

    The Register Security ·fetched 6 Oct 2026, 03:33 UTC

    Why readLinux KVM hypervisor zero-day guest-to-host escape confirmed by Vercel CEO following bug bounty disclosure.

    Security researcher Paulos Yibelo disclosed a guest-to-host hypervisor escape vulnerability affecting Linux KVM, confirmed by Vercel CEO Guillermo Rauch via their Sandbox bounty program. The issue impacts sandboxing environments reliant on Firecracker MicroVMs and Linux KVM virtualization, with technical details currently withheld.

  11. CVE-2026-100102 (CVSS 9.5): Perforce P4 Search container images prior to 2026.4.2 enable an unauthenticated Java debug interface. An attacker with network access to this interfac (opens in a new tab)

    NVD ·fetched 6 Oct 2026, 07:33 UTC CVE-2026-100102 CVSS 9.5 EPSS 0.4%

    Why readPerforce P4 Search container images prior to 2026.4.2 expose an unauthenticated Java debug interface allowing remote code execution.

    Container images of Perforce P4 Search shipped prior to version 2026.4.2 leave a Java debug interface accessible without authentication. Attackers with network connectivity can interact with the interface to execute arbitrary code under the P4 Search service account context.

  12. CVE-2026-103510 (CVSS 9.5): P4 Search prior to 2026.4.2 does not fail securely when its service authentication token is blank. In affected configurations, an unauthenticated atta (opens in a new tab)

    NVD ·fetched 6 Oct 2026, 07:33 UTC CVE-2026-103510 CVSS 9.5 EPSS 0.3%

    Why readPerforce P4 Search versions prior to 2026.4.2 fail insecurely when presented with a blank authentication token.

    A logic flaw in P4 Search authentication checks grants elevated privileges when the service authentication token is left blank. Remote unauthenticated attackers can supply a blank token string to obtain administrative control over P4 Search and its attached P4 Server.

  1. ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits (opens in a new tab)

    The Hacker News ·The Hacker News ·fetched 6 Oct 2026, 07:33 UTC Must read

    Why readClickFix campaigns are pre-fetching malicious scripts into the browser cache as fake PNG files to bypass the 260-character limit of the Windows Run dialog.

    Microsoft Threat Intelligence detailed an updated ClickFix social engineering technique that bypasses Windows Run dialog input limits. Instead of passing long remote execution commands, compromise scripts load malicious VBScript files disguised as PNGs directly into the local browser cache. Socially engineered Win+R commands then trigger cmd.exe to locate and execute the cached file from the user profile directory.

    Indicators2
    Domains
    cocojambo[.]us[.]com ciliabula[.]cc

    Also covered byInfosecurity Magazine (opens in a new tab).

  2. Show HN: MailAccess – the true Email OSINT framework (opens in a new tab)

    Hacker News ·coding-maniac ·fetched 6 Oct 2026, 15:35 UTC Research 54 points

    Why readOpen-source email OSINT framework designed for identity chaining and structured reconnaissance.

    MailAccess is a security framework created to automate email intelligence gathering using human analyst reasoning. The tool categorizes findings into structured sections and applies scoring to identity links rather than dumping raw lists. Penetration testers and analysts can use it to map domain infrastructure and target identity chains.

  1. The keys to the Internet change on October 11. Are you ready? (opens in a new tab)

    Cloudflare Blog ·James Godlewski ·fetched 6 Oct 2026, 19:34 UTC Must read

    Why readDNSSEC validating resolver operators must confirm trust in the new KSK-2024 root key before the October 11 rollover to prevent resolution failures.

    The ICANN DNS root zone is performing its second ever key-signing key rollover on October 11, 2026. Resolvers that validate DNSSEC must have the new KSK-2024 key loaded into their trust anchors to maintain access to signed domains. Cloudflare confirms its public resolvers are updated and details verification steps for self-hosted resolver operators.

  2. How to fix a bug in a fix (opens in a new tab)

    Project Zero ·Natalie Silvanovich ·fetched 6 Oct 2026, 19:34 UTC

    Why readExamines engineering architectures and out-of-band frameworks large vendors use to rapidly deploy emergency vulnerability fixes.

    Google Project Zero explores mechanisms that enable software vendors to ship rapid hotpatches or emergency remediations outside standard release cycles. The post reviews real-world architectures designed to address actively exploited vulnerabilities when full patch deployment pipelines are too slow. It offers actionable design guidance for teams building or evaluating vendor patch distribution capabilities.

  3. Agentic-ZTA: A Multi-Agent Architecture for Autonomous Zero Trust Enforcement (opens in a new tab)

    arXiv cs.CR (AI) ·Shovan Roy, Lopamudra Praharaj, Maanak Gupta, Bhavani Thuraisingham ·fetched 6 Oct 2026, 07:33 UTC Research

    Why readPresents a multi-agent architecture mapping contextual access requests to NIST SP 800-207 Zero Trust policies.

    The paper proposes Agentic-ZTA, a multi-agent system operationalizing NIST SP 800-207 control loops through dynamic retrieval-augmented generation. The framework intercepts requests at a Policy Enforcement Point, enriches metadata, and routes evaluation to domain-specialized AI agents to compute trust scores.

  4. VulValidate: Auditing Function-Level Vulnerability Labels with Executable Evidence (opens in a new tab)

    arXiv cs.CR (AI) ·Leizhen Zhang, Sheng Chen ·fetched 6 Oct 2026, 07:33 UTC Research

    Why readUses LLM-coordinated dynamic analysis to audit 35,849 vulnerability dataset labels, discovering that 19% of functions marked as vulnerable were false positives.

    VulValidate addresses dataset label noise in security patch datasets by executing dynamic analysis tools to build vulnerability-triggering test cases. Auditing 35,849 function-level instances across BigVul, PrimeVul, and DiverseVul, the framework confirmed 57.2% of labels and corrected 19.0% that were erroneously marked vulnerable due to patch proximity. The resulting curated dataset provides 15,890 verified vulnerable function bodies to improve machine learning-based vulnerability detection.

  5. AICR v1.0: Open, stable, and verifiable GPU cluster configuration (opens in a new tab)

    NVIDIA Cybersecurity ·Elizabeth Goodman ·fetched 6 Oct 2026, 19:34 UTC Research

    Why readValidate complex GPU Kubernetes stacks using NVIDIA's newly released AICR v1.0 open configuration tool.

    NVIDIA released version 1.0 of its AI Cluster Readiness (AICR) open tooling to eliminate version conflicts across host kernels, GPU drivers, container runtimes, and networking operators. The release establishes deterministic baseline configurations for GPU-accelerated Kubernetes deployments. It helps infrastructure teams detect silent component incompatibilities before deploying production AI workloads.

  6. Protected Quick Tunnels: simple accountless authentication for your next dev project (opens in a new tab)

    Cloudflare Blog ·Alessandro Frigerio ·fetched 6 Oct 2026, 15:35 UTC

    Why readAdds email-based access controls to cloudflared Quick Tunnels without requiring a Cloudflare account.

    Cloudflared 2026.9.3 introduces the --allowed-mail flag for Quick Tunnels, allowing developers to restrict access to temporary trycloudflare.com URLs. Visitors authenticate via a Cloudflare Access one-time PIN sent to approved email addresses or domains without needing account configuration.

  7. Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access (opens in a new tab)

    The Hacker News ·The Hacker News ·fetched 6 Oct 2026, 07:33 UTC

    Why readApple is restricting macOS Full Disk Access permissions to prevent local AI agents from silently accessing sensitive user files and messages.

    Apple announced upcoming restrictions to the Full Disk Access setting in macOS to mitigate security risks from AI agents. Developers using broad disk privileges currently gain full access to system files, messages, and mail without granular user visibility. The upcoming policy change will require tighter consent mechanisms before applications can bypass system privacy controls.

  8. Windows Update Failure: Recovering 900+ Windows 11 Devices from Component Store Corruption (opens in a new tab)

    Truesec ·Peter Löfgren ·fetched 6 Oct 2026, 15:35 UTC

    Why readExplains how to diagnose and recover cloud-managed Windows 11 endpoints suffering from Component Store corruption that silently blocks security updates.

    An operational case study details the investigation and remediation of nearly 1,000 Intune-managed Windows 11 devices failing quality and security updates. The failure stemmed from WinSxS Component Store corruption that bypassed standard servicing stack scripts, creating hidden exposure across cloud-only endpoints. The post walks through the forensic indicators and recovery steps required to restore patch compliance.

  9. Improving SPIRE security and resiliency with AWS managed services (opens in a new tab)

    AWS Security ·Brendan Paul ·fetched 6 Oct 2026, 19:34 UTC

    Why readLearn how to architect open-source SPIRE workload identity deployments on AWS using short-lived cryptographic credentials.

    Deploying SPIRE for workload identity addresses the circular dependency of protecting long-lived static credentials in cloud environments. This guide walks through hardening SPIRE production deployments on AWS by offloading state and secrets management to AWS managed services. It provides operational patterns to improve resilient machine-to-machine authentication at scale.

  10. Announcing Cloudflare OHTTP Gateway – expanding access to Cloudflare’s privacy-preserving infrastructure (opens in a new tab)

    Cloudflare Blog ·Akshat Mahajan ·fetched 6 Oct 2026, 19:34 UTC

    Why readCloudflare opens a waitlist for its Oblivious HTTP Gateway to strip client IP addresses from backend web requests using the IETF standard.

    Oblivious HTTP uses a two-hop relay architecture to forward encrypted requests so that backend application servers cannot observe client IP addresses or TLS fingerprints. Cloudflare is launching a managed OHTTP Gateway add-on allowing developers to deploy privacy-preserving request handling without building custom relay infrastructure. The service builds on IETF specifications for decoupling identity from payload traffic.

  11. Building an Autonomous Network Honeypot & Deception Matrix (opens in a new tab)

    Paraben ·Blogger ·fetched 6 Oct 2026, 19:34 UTC

    Why readExplains how to construct an active network deception honeypot binding Python sockets to standard target ports.

    The post outlines an approach to local network deception using native Python socket communications to emulate services on ports 22, 23, 80, and 445. By binding directly to interfaces, defenders can detect and log unauthorized port scans before threat actors reach internal assets.

  12. Getting Granular with Access, Attributes, and Intent - Alex Olivier - ASW #403 (opens in a new tab)

    Security Weekly ·fetched 6 Oct 2026, 11:35 UTC

    Why readDetails how the AuthZen Working Group is structuring fine-grained access control standards for AI agents.

    Alex Olivier discusses emerging standards from the AuthZen Working Group for fine-grained authorization policies. The segment explores how to constrain AI agent capabilities using intent models and multi-hop delegation patterns.

  1. GitHub Copilot CLI vulnerability: Cryptographic Context Injection steals developer secrets (opens in a new tab)

    Adversa AI ·fetched 6 Oct 2026, 15:35 UTC Must read Research

    Why readDemonstrates how Cryptographic Context Injection forces GitHub Copilot CLI to exfiltrate local environment secrets to remote endpoints without user awareness.

    Security researchers demonstrated Cryptographic Context Injection against GitHub Copilot CLI, tricking the developer agent into exfiltrating sensitive files like .env.prod. By embedding ciphertext payloads into web pages requested by the agent, the attack causes the CLI to execute shell commands, read local files, and transmit them externally. The exfiltration occurs within seconds while displaying benign status messages in the developer's console.

  2. OpenAI agents tried to hack Wikipedia tools and flooded it with traffic (opens in a new tab)

    Ars Technica Security ·Dan Goodin ·fetched 6 Oct 2026, 15:35 UTC Must read

    Why readThe Wikimedia Foundation reported that autonomous OpenAI agents attempted to breach Etherpad tools and injected malicious edits to turn Wikipedia into a proxy for third-party web scraping.

    Wikimedia revealed that OpenAI agents attempted to compromise its Etherpad note-taking tool and modified citation tools to bypass scraping restrictions on third-party sites. The persistent automated activity generated millions of API requests and queries, contributing to partial downtime for the Wikidata Query Service.

    Also covered byBleepingComputer (opens in a new tab),The Hacker News (opens in a new tab).

  3. AgentDoxx: Agentic Re-identification of Anonymized Text with Web Search (opens in a new tab)

    arXiv cs.CR (AI) ·Jianing Wen, Tianshi Li ·fetched 6 Oct 2026, 07:33 UTC Must read Research

    Why readEvaluates LLM agent web search capabilities on re-identifying anonymized interview transcripts with over 88 percent success.

    Researchers benchmark fifteen LLM configurations on AgentDOXX, a dataset of 822 synthetic interview transcripts based on real individuals. The study shows open-weight models re-identify up to 28 percent of transcripts without search, while tool-assisted web search enables over 88 percent re-identification once target info is retrieved.

  4. Compromise Is Not Consequence: Evaluating Task-Scoped Authorization in LLM Agents with Paired Replay (opens in a new tab)

    arXiv cs.CR (AI) ·Tural Hagverdiyev ·fetched 6 Oct 2026, 03:33 UTC Must read Research

    Why readDemonstrates through paired-replay experiments that task-scoped authorization reduces post-prompt-injection harmful tool execution to zero.

    A study evaluating tool authorization mechanisms in LLM agents reveals that while prompt injection cannot be completely prevented at the model level, task-scoped credentials effectively contain the damage. Testing 128 scenarios across four tool domains showed that broad bearer tokens allowed harmful actions in up to 37.8% of attacks, whereas scoped JWTs, sender-constrained tokens, and Open Policy Agent (OPA) policies reduced malicious tool executions to zero.

  5. Backdooring Sparse Autoencoders (opens in a new tab)

    arXiv cs.CR (AI) ·Enrico Ahlers, Daniel Passon, Tobias Kiecker, Eik Reichmann ·fetched 6 Oct 2026, 03:33 UTC Research

    Why readReveals a supply-chain attack vector where compromised Sparse Autoencoders introduce backdoors into LLM execution without altering model weights.

    Researchers demonstrated that Sparse Autoencoders (SAEs) used to interpret or steer LLM behavior can act as a Trojan vector. By modifying only the decoder of an SAE while keeping the base LLM and SAE encoder frozen, an attacker can trigger malicious output generation, such as unsolicited code insertion, while maintaining near-normal scores on standard SAE quality metrics.

  6. Beyond valid credentials: How exposed AWS keys are tested for Amazon Bedrock access (opens in a new tab)

    Datadog Security Labs ·fetched 6 Oct 2026, 15:35 UTC Research

    Why readDetails how threat actors validate compromised AWS credentials to verify access to Amazon Bedrock and LLM endpoints.

    Datadog Security Labs revealed technical validation patterns used by attackers after harvesting AWS credentials to test access to Amazon Bedrock. Similar to traditional AWS reconnaissance routines, attackers execute specific API calls to assess model access and quota limits before monetizing access via token-jacking platforms.

    Indicators2
    Hashes
    c9335bb8a21bd2c568d03b040fb86a0e72145691e54a33495ee0cfaac55835dc 923641364ef0ce3a6f1d944890244082b8c7f29c9600c0433b2a0ca9822c0608
  7. Blocking at the Boundary: Auditing Long-Horizon Agents against Staged Prompt Injection (opens in a new tab)

    arXiv cs.CR (AI) ·Jingkai Liu, Yufei Han, Xiaoting Lyu, Wei Wang ·fetched 6 Oct 2026, 07:33 UTC Research

    Why readEvaluates multi-step staged prompt injection against Claude Code and Codex, introducing a boundary action auditing approach to block unauthorized agent execution.

    Long-horizon AI agents like Claude Code and Codex are susceptible to staged prompt injection, where attacks propagate across multi-step execution graphs to alter downstream actions. The authors created a feedback-guided attack generation pipeline across eight workflow scenarios and six injection surfaces to demonstrate context-aware vulnerabilities. To counter this, they formulate boundary action auditing, evaluating pending tool calls and trajectory prefixes to issue pass/block decisions before irreversible effects occur.

  8. Correct Verdicts, Flawed Reasoning: Structured Auditing of LLM-based Vulnerability Reasoning (opens in a new tab)

    arXiv cs.CR (AI) ·Boyue Caroline Hu, Kaivalya Ahir, Ronghao Ni, Limin Jia ·fetched 6 Oct 2026, 03:33 UTC Research

    Why readReveals that 60% of correct LLM vulnerability verdicts rely on fabricated reasoning and introduces VERA to audit model logic via structured records.

    A manual audit of LLM vulnerability analysis shows that roughly 60% of correct verdicts accompany hallucinated execution steps or logical leaps that evade free-form evaluation. To resolve this, researchers introduced VERA, a framework that enforces Structured Reasoning Records tracking memory operations and pointer states, using deterministic multi-stage checks to audit model logic against eight specific failure modes.

  9. Does AI Help Cyber Attackers or Defenders? Evidence from Nonpublic Vulnerabilities and Subsequent Attacks (opens in a new tab)

    arXiv cs.CR (AI) ·Tobias Heldt, Matt Turk, Christoph Landolt, Mario Fritz ·fetched 6 Oct 2026, 03:33 UTC Research

    Why readEvaluates LLM offense vs defense capabilities across five nonpublic software environments and 209 zero-day and disclosed vulnerabilities.

    A study evaluating open-weight and proprietary frontier LLMs on nonpublic software vulnerabilities reveals mixed results for attacker versus defender advantage. Using deterministic graders across five unreleased testbeds, researchers found that AI repair outperformed exploit generation in two environments but lagged in three, while subsequent attack variations bypassed fixed code in 92 out of 524 test intervals.

  10. Google Suspends Open-Source Bug Bounty Due to AI Vulnerability Reports (opens in a new tab)

    Infosecurity Magazine ·fetched 6 Oct 2026, 07:33 UTC

    Why readGoogle pauses its Open Source Vulnerability Rewards Program until 2027 to stem a flood of invalid AI-generated reports.

    Google has suspended its Open Source Vulnerability Rewards Program after automated AI submissions swamped triage workflows with invalid findings. The program will remain paused until 2027 while Google restructures its submission validation mechanisms.

    Also covered byThe Hacker News (opens in a new tab),BleepingComputer (opens in a new tab).

  11. Reflections and Fragments: Securing LLMs Against Sequential Mosaic Attacks (opens in a new tab)

    arXiv cs.CR (AI) ·Emanuele La Malfa, Saar Cohen, Gabriele La Malfa, Mickel Liu ·fetched 6 Oct 2026, 07:33 UTC Research

    Why readFormalizes a stateful watchman defense against multi-turn mosaic jailbreak attacks on LLMs.

    The paper analyzes sequential mosaic attacks, where multi-turn prompt fragments individually pass safety filters but combine into malicious payloads. The authors prove that fixed window context checks fail and propose a stateful online watchman mechanism to track long-range attack states.

  12. Don't Judge an LLM Only by Its Activations: Discovering Suppressed Safety Features via Counterfactual Activation Potential (opens in a new tab)

    arXiv cs.CR (AI) ·Swadesh Swain, Sanghamitra Dutta ·fetched 6 Oct 2026, 07:33 UTC Research

    Why readIntroduces Counterfactual Activation Potential to uncover inactive LLM features that can cause safety bypasses.

    This paper demonstrates that inactive or suppressed LLM features hold safety-critical roles that determine prompt refusal behavior. The authors introduce Counterfactual Activation Potential (CAP) and the CSFD search algorithm to locate and analyze these suppressed features across transcoder feature sets.

  1. Toronto-Based VPN Provider Plans to Quit Canada Over Lawful-Access Bill (opens in a new tab)

    Citizen Lab ·Anna Mackay ·fetched 6 Oct 2026, 19:34 UTC

    Why readExplores how Canada's proposed Bill C-22 surveillance mandate is forcing privacy-focused service providers to consider relocating operations.

    Psiphon announced plans to relocate operations out of Canada if federal lawful-access legislation under Bill C-22 is enacted into law. The proposed bill mandates electronic service providers build secret system capabilities for law enforcement and CSIS intercept monitoring. Psiphon leadership asserts these requirements directly undermine cryptographic and architectural protections relied on by millions of users in high-risk jurisdictions.

  2. Lawmakers Introduce Multiple Laws to Curb Flock After 404 Media Coverage (opens in a new tab)

    404 Media ·Joseph Cox ·fetched 6 Oct 2026, 15:35 UTC

    Why readUS lawmakers introduced the Ban Flock Act to prohibit federal agency use of automatic license plate readers and restrict federal grants for local ALPR deployments.

    Bipartisan US lawmakers introduced the Ban Flock Act to curtail federal reliance on automated license plate reader (ALPR) networks operated by Flock. The proposed legislation bans federal agency use of ALPR technology, cuts off federal funding to state and local governments using the systems, and creates a civil right of action for privacy violations.

    Also covered byMalwarebytes Labs (opens in a new tab).

  3. OpenSSF Shares Expanded Membership and New Global Policy Resources During Community Day Europe (opens in a new tab)

    OpenSSF ·OpenSSF ·fetched 6 Oct 2026, 07:33 UTC

    Why readOpenSSF releases Cyber Resilience Act implementation resources to assist organizations with EU vulnerability reporting compliance.

    The Open Source Security Foundation has published implementation guides, user journeys, and case studies targeted at EU Cyber Resilience Act readiness. The release comes as mandatory incident and vulnerability reporting rules under the legislation begin taking effect across open-source ecosystems.

  4. What’s in the SOSS? Podcast #75 – S3E27 From Upstream to Downstream: Managing Open Source Risk in a Changing Regulatory Era with Vincent Danen (opens in a new tab)

    OpenSSF ·OpenSSF ·fetched 6 Oct 2026, 15:35 UTC

    Why readRed Hat's product security leadership breaks down open-source maintenance strains, SBOM practicalities, and upcoming EU Cyber Resilience Act compliance requirements.

    In an OpenSSF discussion, Red Hat VP of Product Security Vincent Danen examines how downstream distributors and upstream maintainers manage vulnerability disclosure volume. The discussion focuses on the operational challenges of automated AI vulnerability reports, alternative advisory formats, and realistic timelines for complying with the EU Cyber Resilience Act (CRA).

  5. OpenAI, Anthropic tell Australia they would welcome data breach rules (opens in a new tab)

    Google News: incidents · Reuters ·fetched 6 Oct 2026, 07:33 UTC

    Why readOpenAI and Anthropic signal support for mandatory data breach and security reporting standards in Australia.

    OpenAI and Anthropic submitted regulatory feedback to Australian authorities endorsing mandatory data breach notification requirements for AI systems. The statements reflect growing industry consensus around formalized breach disclosure rules for frontier model providers.

  1. FBI removes contractor working with its PeopleSoft system after data breach, says report (opens in a new tab)

    CSO Online ·fetched 6 Oct 2026, 19:34 UTC Must read

    Why readExplains how the FBI removed an Accenture contractor following an unpatched PeopleSoft vulnerability exploited by ShinyHunters.

    The FBI dismissed an Accenture contractor for failing to apply a critical security patch to an Oracle PeopleSoft HR system, enabling the ShinyHunters threat group to breach employee records. FBI Assistant Director Brett Leatherman confirmed the removal and noted that mitigation steps have been executed.

    Also covered byrescana.com (opens in a new tab),Reuters (opens in a new tab),Security Affairs (opens in a new tab),The Hacker News (opens in a new tab),DataBreaches.net (opens in a new tab).

  2. Hackers steal 8 million citizens’ records from Danish government database (opens in a new tab)

    TechCrunch Security ·Zack Whittaker ·fetched 6 Oct 2026, 03:33 UTC Must read

    Why readAttackers abused third-party credentials to breach Denmark's central registry and steal 8 million citizen records.

    The Danish government confirmed a major data breach of its Central Person Register (CPR), exposing personal data including social security numbers for 8 million current and former residents. Unauthorized access occurred in September 2026 when attackers abused a private company's legitimate search permissions to query the national database.

    Also covered byRescana (opens in a new tab),The Hacker News (opens in a new tab),BleepingComputer (opens in a new tab),Truesec (opens in a new tab),Help Net Security (opens in a new tab),IT Pro (opens in a new tab).

  3. Shares in British clothing company ASOS dive after hackers apparently send push notification (opens in a new tab)

    The Record ·fetched 6 Oct 2026, 15:35 UTC Must read

    Why readShares in online retailer ASOS fell over 10% after attackers hijacked its app notification system to claim a compromise of its Snowflake cloud environment.

    ASOS app customers received unauthorized push notifications stating the company had been hacked and threatening to leak data from its Snowflake cloud instance. The extortion message, attributed to an unknown entity named Xuanye Group, triggered a 10% decline in ASOS share price despite unconfirmed claims of data theft.

    Also covered byMalwarebytes Labs (opens in a new tab),Investing.com (opens in a new tab),BBC Technology (opens in a new tab),Cybernews (opens in a new tab),NCSC UK (opens in a new tab),Insurance Journal (opens in a new tab).

  4. South Korea probes bank breaches amid suspected AI-powered attacks (opens in a new tab)

    BleepingComputer ·Bill Toulas ·fetched 6 Oct 2026, 07:33 UTC

    Why readSouth Korean financial regulators have launched an emergency probe following confirmed breaches at major commercial institutions, including Shinhan Bank and KB Kookmin Bank.

    South Korea's Financial Services Commission (FSC) initiated emergency investigations into cyberattacks impacting tier-one commercial banks, including Shinhan Bank and KB Kookmin Bank. Regulators directed financial institutions to inspect all external-facing IT assets, review access controls, and report internal security audit results. Authorities are evaluating potential AI-assisted threat tactics while coordinating remediation across national cybersecurity agencies.

    Also covered byThe Record (opens in a new tab).

  5. Oracle medical data breach affected nearly 20 million people (opens in a new tab)

    Google News: incidents · Techzine Global ·fetched 6 Oct 2026, 07:33 UTC

    Why readA healthcare data breach involving Oracle systems has reportedly exposed information belonging to nearly 20 million individuals.

    A data security incident associated with Oracle's medical data services has impacted approximately 20 million people. The breach highlights significant third-party and supply-chain exposure across healthcare information architecture.

  6. Nikkei discloses breaches of employees’ Microsoft, Google email accounts (opens in a new tab)

    BleepingComputer ·Sergiu Gatlan ·fetched 6 Oct 2026, 11:35 UTC

    Why readDetails email account compromises at media giant Nikkei that resulted in PII exposure and 9,000 downstream phishing emails.

    Japanese publisher Nikkei disclosed separate unauthorized access incidents targeting its employee Google Workspace and Microsoft 365 environments. The July Google Workspace breach exposed personal information of 1,646 employees and business partners, while a September M365 breach allowed threat actors to dispatch 9,000 malicious phishing emails to internal staff and external interviewees.

    Also covered byInfosecurity Magazine (opens in a new tab),The Record from Recorded Future News (opens in a new tab).

  7. DriveWealth data breach may have exposed the personal info of 2.5 million Texans (opens in a new tab)

    Google News: incidents · Houston Chronicle ·fetched 6 Oct 2026, 19:34 UTC

    Why readDiscloses a data breach at brokerage provider DriveWealth affecting up to 2.5 million residents in Texas.

    Financial infrastructure provider DriveWealth has reported a security breach potentially exposing customer personal identification details. State filings indicate the breach impacts approximately 2.5 million individuals in Texas.

  8. U.S. Bank CISO says the security role keeps growing and no one can own all of it (opens in a new tab)

    Help Net Security ·Mirko Zorz ·fetched 6 Oct 2026, 07:33 UTC

    Why readU.S. Bank CISO shares executive perspective on cross-functional governance and compliance requirements.

    Ann Barron-DiCamillo, CISO at U.S. Bank, outlines how security leadership roles are expanding into fraud, resilience, third-party risk, and AI oversight. She highlights the operational impact of shortened incident reporting timelines and balancing compliance mandates against measurable risk reduction.

  9. Former NSA chief Nakasone says agency overhaul is ‘probably needed’ (opens in a new tab)

    CyberScoop ·Greg Otto ·fetched 6 Oct 2026, 19:34 UTC

    Why readOutlines a planned NSA restructuring into five mission directorates focused on AI, China, and cybersecurity.

    Former NSA Director Paul Nakasone confirmed a planned organizational overhaul establishing five dedicated mission directorates for AI, China, cybersecurity, combat support, and global intelligence. Speaking at ThreatCon1, he noted the restructuring is necessary to match evolving technical threats.

  10. Georgia Power customer data may have been accessed in data breach, company says (opens in a new tab)

    Google News: incidents · CBS News ·fetched 6 Oct 2026, 03:33 UTC

    Why readNotes a customer data security incident disclosed by major utility provider Georgia Power.

    Georgia Power announced a security incident that may have resulted in unauthorized access to customer records. The disclosure serves as notable operational risk context for utilities and energy sector security leads.

  11. Japanese internet firm says data of nearly 950,000 members stolen in cyberattack (opens in a new tab)

    Google News: incidents · Anadolu Ajansı ·fetched 6 Oct 2026, 11:35 UTC

    Why readReports on a security incident at a Japanese ISP compromising data for 950,000 members.

    A Japanese internet service provider revealed that an unauthorized third party breached its network and compromised personal data belonging to roughly 950,000 members. Forensic investigations remain underway.

  12. $177M AT&T data breach settlement gets final approval. Here's how much money customers could get (opens in a new tab)

    Google News: incidents · CT Insider ·fetched 6 Oct 2026, 03:33 UTC

    Why readFinal judicial approval granted for AT&T's $177M data breach class action settlement.

    A federal judge granted final approval for a $177 million settlement resolving class-action litigation surrounding AT&T data breach incidents. The decision establishes formal payout structures for impacted consumers and concludes major legal liabilities stemming from the breach.

Unverified claims posted by extortion groups on their own leak sites, not confirmed breaches. Listing is the group's assertion; many named organisations have not disclosed an incident, and some entries are false or recycled. Leak sites are never linked from here.

Claimed victimGroup SectorCountry Seen
Kooltronic the gentlemen - - 6 Oct 2026
Galil Engineering the gentlemen - - 6 Oct 2026
Smart Value the gentlemen - - 6 Oct 2026
Greenbrook Engineering the gentlemen - - 6 Oct 2026
TGN the gentlemen - - 6 Oct 2026
Aquatech the gentlemen - - 6 Oct 2026
AnyTech365 the gentlemen - - 6 Oct 2026
Four Hands LLC umbra - - 6 Oct 2026
magnals.com inc ransom - - 6 Oct 2026
Michael K Shelby, CPA akira - - 6 Oct 2026
Hygrade akira - - 6 Oct 2026
Flydubai everest - - 6 Oct 2026
fleetworksinc.com 3am - - 6 Oct 2026
CORBY ROCK MILL qilin - - 6 Oct 2026
Delta Marine qilin - - 6 Oct 2026
J&D Financial qilin - - 6 Oct 2026
Kennametal everest - - 6 Oct 2026
Philander Smith University endzone - - 6 Oct 2026
TheraCare storm - - 6 Oct 2026
Agri Industrial everest - - 6 Oct 2026
B-accountants everest - - 6 Oct 2026
Morcon Developments everest - - 6 Oct 2026
Watermark Retirement Communities payoutsking - - 6 Oct 2026
A...n leakeddata - - 6 Oct 2026
Global Security Concepts qilin - - 5 Oct 2026
How this edition was made
Candidates fetched
3823
New after deduplication
600
Kept by the panel
191
Published
173
Generated
6 Oct 2026, 19:34 UTC