Skip to main content

Cyber Intelligence

Curated cybersecurity news and threat intelligence

vulnerabilityBleepingComputer1 Oct

Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

Fortinet has issued a critical security warning for a zero-day vulnerability (CVE-2026-104286) in FortiMail that is actively being exploited in the wild. The flaw allows attackers to execute unauthorized code or commands on affected devices.

ransomwareDarkReading1 Oct

Alleged KillSec Ransomware Mastermind a 16-Year-Old

Law enforcement from multiple countries successfully disrupted the KillSec ransomware operation, which had targeted approximately 500 victims globally over a two-year period. The investigation revealed that the alleged mastermind behind the cybercrime operation is a 16-year-old minor.

breachThe Register Security1 Oct

AI agents hacked the hackers, stealing email addresses from security research org

AI agents exploited chained vulnerabilities in Zammad to breach a security research organization, stealing email addresses through session hijacking and code execution. The attack demonstrated critical flaws enabling rapid root-level escalation in the widely-used helpdesk platform.

researchBleepingComputer1 Oct

Microsoft says threat actors are ahead in the early AI race

Microsoft warns that threat actors are leveraging AI capabilities more effectively than defenders, accelerating vulnerability discovery and malware development. Security teams are struggling to match the pace of AI-enabled attacks, creating a critical defensive gap.

Microsoft
Read original
breachThe Register Security1 Oct

Suspected Chinese spies spoofed an Anthropic exec, ex-White House official in AI phishing

Chinese-linked threat actors conducted a sophisticated phishing campaign impersonating an Anthropic executive and former White House official to target AI policy influencers through a fake advisory committee invitation. The incident highlights state-sponsored efforts to infiltrate and gather intelligence on key figures in the AI policy and security space.

vulnerabilityThe Register Security1 Oct

Microsoft catches hackers exploiting Zimbra bug before disclosure

Microsoft detected attackers actively exploiting a Zimbra mail server vulnerability weeks before it was assigned a CVE identifier. The early detection demonstrates proactive threat hunting and highlights the risk of zero-day exploitation before public disclosure.

Microsoft
Read original
ransomwareBleepingComputer1 Oct

Police dismantle KillSec ransomware gang allegedly led by 16-year-old

International law enforcement conducted Operation KillSwitch against the KillSec ransomware gang, seizing their infrastructure and data leak site while making three arrests. The investigation identified a 16-year-old as the alleged administrator of the criminal organization.

ransomwareSecurityWeek1 Oct

Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader

Law enforcement successfully shut down the KillSec ransomware operation, taking control of their leak site and recovering at least 110 terabytes of stolen data from victims. Police have identified and are investigating an alleged teenage leader of the ransomware group.

vulnerabilityInfosecurity1 Oct

Critical Cisco Catalyst SD-WAN Zero-Day Under Active Exploitation

A critical zero-day vulnerability in Cisco Catalyst SD-WAN Manager is being actively exploited, allowing unauthenticated remote attackers to gain administrative access to affected systems. This vulnerability poses an immediate threat to organizations using Cisco's SD-WAN infrastructure.

regulationThe Register Security1 Oct

MI5 warns UK academics their research may have helped Chinese spies

MI5 has warned UK academic institutions that their research may have inadvertently assisted Chinese intelligence agencies and urged them to verify funding sources to comply with national security laws. The warning highlights risks of foreign espionage targeting sensitive research through academic partnerships and financing.

breachInfosecurity1 Oct

China-Linked Hackers Impersonate AI Experts to Target US Policy Insiders

China-linked threat actor TA419 conducted targeted phishing attacks against US AI policy experts by impersonating AI policymakers and economists to compromise Microsoft 365 accounts. The campaign represents a sophisticated social engineering effort targeting high-value government and policy sector individuals involved in AI governance.

vulnerabilityBleepingComputer1 Oct

Kiteworks patches max severity code injection vulnerability

Kiteworks released security updates addressing 126 vulnerabilities, including a maximum severity code injection flaw in its Email Protection Gateway solution. The patch is critical for users of the secure file-sharing platform to prevent potential exploitation.

Kiteworks
Read original
researchInfosecurity1 Oct

CloudSyncD MacOS Backdoor Hides Behind Fake Zoom Installer

CloudSyncD is a macOS backdoor that disguises itself as a fake Zoom installer to steal passwords and establish a two-stage malware infection on affected systems. This threat represents a significant social engineering attack targeting Mac users through a trusted application mimic.

ransomwareDarkReading1 Oct

Warlock Ransomware Hits Large Spanish, Portuguese Orgs

A Chinese-linked threat actor known as Warlock ransomware has attacked large organizations in Spain and Portugal, displaying characteristics of both cybercriminal gangs and state-associated APT groups. The group, active for approximately one year, targets organizations in geographically unexpected locations.

vulnerabilitySecurityWeek1 Oct

Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure

CVE-2026-73570, a Zimbra vulnerability, is being actively exploited in the wild before its public disclosure. The flaw can be triggered via specially crafted emails without requiring user interaction.

breachGraham Cluley1 Oct

ShinyHunters suspect arrested, and is now investigated over alleged murder plots

A 24-year-old alleged key member of the ShinyHunters cybercrime group has been arrested in the Netherlands. The suspect is also under investigation for allegedly attempting to arrange two murders, adding serious criminal charges beyond cyber offenses.

regulationSecurityWeek1 Oct

Treasury Blacklists Most-Wanted ATM Malware Developer and His Network

The US Treasury Department has blacklisted a prominent ATM malware developer and his network as part of ongoing enforcement actions against Tren de Aragua, a criminal organization involved in ATM jackpotting schemes. This government action represents a significant step in disrupting financially motivated cybercriminal operations targeting financial infrastructure.

vulnerabilitySecurityWeek1 Oct

Zammad Zero-Days Exploited in AI-Powered DIVD Hack

Multiple zero-day vulnerabilities in Zammad were exploited and chained together to achieve session hijacking, remote code execution, and privilege escalation to root level. The DIVD (Dutch Institute for Vulnerability Disclosure) discovered and disclosed these critical flaws in the ticketing system.

breachBleepingComputer1 Oct

Hackers stole Pentagon personnel records of over 3 million people

Hackers breached the Pentagon's Defense Manpower Data Center (DMDC) in October 2025, stealing personal data of over 3 million military service members. The Pentagon is notifying affected personnel of the compromise of their information in the human resources management system.

breachSecurityWeek1 Oct

500,000 Active Credentials Left Exposed on GitHub

Approximately 500,000 active credentials were exposed on GitHub, with 200,000 of those exposed after GitHub enabled push protections by default. This incident highlights the ongoing risk of developers inadvertently committing sensitive authentication credentials to public repositories.

vulnerabilitySecurityWeek1 Oct

Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability

Cisco has released a patch for an exploited zero-day vulnerability in Catalyst SD-WAN that allows remote, unauthenticated attackers to gain administrative access to vulnerable appliances. This critical flaw poses significant risk to organizations using Cisco's SD-WAN infrastructure.

productSecurityWeek1 Oct

Google Launches Gemini 4 Argon With Guardrail-Free Access for Vetted Defenders

Google has launched Gemini 4 Argon, a frontier AI model with guardrail-free access for vetted security defenders. The model has demonstrated the ability to identify critical vulnerabilities in widely-used hospital software.

otherInfosecurity1 Oct

MI5 Warns Over 100 Academics Helped China's Espionage Plans

MI5 has warned that over 100 UK academics have been contributing to China's General Technology Research Institute, potentially aiding Chinese espionage efforts. This represents a significant national security concern regarding intellectual property theft and foreign intelligence gathering.

breachBleepingComputer1 Oct

Metamask discloses security incident affecting its infrastructure

MetaMask, a major cryptocurrency wallet provider, disclosed an ongoing security incident affecting its infrastructure. The incident impacts some of the company's infrastructure systems, though specific details about the scope and nature of the compromise were not provided in the announcement.

regulationSecurityWeek30 Sept

FTC is Investigating OpenAI and Anthropic Over Possible Risks to Consumers

The FTC has launched an investigation into OpenAI and Anthropic regarding potential risks to consumers from their AI systems. The investigation represents regulatory scrutiny of major AI companies and their impact on consumer safety.

vulnerabilityDarkReading30 Sept

Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure

Threat actors are exploiting custom GPTs on ChatGPT by abusing legitimate OpenAI and Google domains to deliver remote access trojans (RATs) to unsuspecting users. This social engineering campaign follows the ClickFix attack pattern, using trusted platforms as lures for malware distribution.

researchBleepingComputer30 Sept

Russian state hackers use new RedFlick technique to push malware

Russian state-sponsored actor Star Blizzard has deployed a new malware installation technique called RedFlick to distribute its CosmicPulse backdoor. This represents an evolution in the threat actor's tactics and demonstrates ongoing sophisticated espionage operations by Russian state-backed groups.

vulnerabilityBleepingComputer30 Sept

DIVD says Zammad zero-days enabled AI-driven network breach

The Dutch Institute for Vulnerability Disclosure (DIVD) disclosed that its network breach was facilitated by exploitation of two zero-day vulnerabilities in the open-source Zammad ticketing system. The vulnerabilities were leveraged in an AI-driven attack against the organization's infrastructure.

vulnerabilityThe Register Security30 Sept

16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows

A 16-year-old security researcher discovered a vulnerability in Microsoft systems that granted admin access to databases containing 17.3 trillion rows of data. The finding highlights the value of external security research and responsible disclosure in identifying critical access control issues.

Microsoft
Read original
breachBleepingComputer30 Sept

Over 543,000 valid credentials exposed in public GitHub repositories

Over 543,000 valid credentials were discovered exposed in public GitHub repositories in July, representing a significant security risk despite GitHub's built-in protections. The incident highlights the ongoing challenge of preventing accidental leaks of sensitive authentication data in code repositories.

vulnerabilityBleepingComputer30 Sept

CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS

CISA has issued a warning about a critical pre-authentication remote code execution vulnerability in MikroTik RouterOS that could allow attackers to execute arbitrary code or cause denial-of-service attacks. This vulnerability affects widely-deployed networking equipment and requires immediate attention from affected organizations.

researchDarkReading30 Sept

Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net

Russian APT actor Star Blizzard has adopted a new phishing tactic called "RedFlick" to target Ukrainian-linked organizations including NGOs, think tanks, and journalists. The campaign aims to deploy the CosmicPulse backdoor, representing an evolution in the threat actor's attack methodology.

vulnerabilityBleepingComputer30 Sept

Cisco warns of new SD-WAN zero-day exploited in attacks

Cisco has released security updates to address a critical zero-day vulnerability (CVE-2026-76504) in Catalyst SD-WAN Manager that is actively being exploited by attackers. The flaw allows attackers to escalate privileges to administrator level.

researchSecurityWeek30 Sept

Google: AI Is Changing the Pace and Profile of Vulnerability Discovery

Google's research indicates that AI is accelerating vulnerability discovery and finding different types of vulnerabilities than traditional methods, with discovered vulnerabilities more likely to enable remote code execution. This finding highlights changing threat landscapes as AI tools become more prevalent in security research.

researchInfosecurity30 Sept

AI-Found Vulnerabilities More Likely to Enable RCE, Google Says

Google research indicates that AI-discovered vulnerabilities have a higher propensity for enabling remote code execution compared to other vulnerability types. The findings highlight increasing trends in both disclosure and active exploitation of these AI-identified security flaws.

vulnerabilitySecurityWeek30 Sept

WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

WatchGuard has released patches addressing 15 vulnerabilities in Fireware OS, including critical code execution, denial of service, authorization bypass, and path traversal bugs. This proactive patching effort helps secure WatchGuard firewall deployments against multiple attack vectors.

WatchGuard
Read original
vulnerabilitySecurityWeek30 Sept

Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks

Multiple security firms have confirmed exploitation of two NetScaler zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in ongoing attacks targeting government and financial organizations. The attacks have been occurring over a period of weeks, indicating active and sustained threat activity.

vulnerabilityBleepingComputer30 Sept

TeamViewer urges users to patch severe flaws “as soon as possible”

TeamViewer has issued an urgent warning to users to immediately patch high-severity vulnerabilities affecting its client and host software. The remote access software company is urging customers to apply patches as soon as possible to mitigate security risks.

vulnerabilitySecurityWeek30 Sept

Chrome, Firefox Updates Patch Over 100 Vulnerabilities

Chrome and Firefox have released updates addressing over 100 vulnerabilities, some of which could enable remote code execution and sandbox escape attacks. Users are advised to update their browsers immediately to mitigate these critical security risks.

researchInfosecurity30 Sept

Attackers Combine ChatGPT Feature Abuse With ClickFix to Deliver Trojan Malware

Cybersecurity researchers at Huntress have identified an active campaign combining ChatGPT feature abuse with ClickFix techniques to deliver trojan malware to users searching for ChatGPT on Google. This attack leverages social engineering and legitimate service vulnerabilities to distribute potent malware to unsuspecting victims.

regulationSecurityWeek30 Sept

Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit

Anthropic has raised concerns about liability risks associated with autonomous AI agents, while OpenAI faces a hacking-related lawsuit, highlighting emerging legal questions about responsibility for AI agent actions. The issue marks a shift from theoretical AI safety discussions to real courtroom battles over accountability.

breachBleepingComputer30 Sept

Bitget hacked via zero-day in third-party security products

Cryptocurrency exchange Bitget suffered a major breach resulting in $387.5 million in stolen funds, with attackers exploiting a zero-day vulnerability in third-party security products. The incident highlights risks associated with dependencies on third-party security software.

researchSecurityWeek30 Sept

Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks

Russian state-sponsored APT group Star Blizzard has been conducting large-scale phishing campaigns using a 'RedFlick' infection chain to deploy the CosmicPulse backdoor malware. This represents a significant escalation in their attack operations and poses a threat to targeted organizations.

breachGraham Cluley30 Sept

Pentagon personnel database breach exposes personal data of millions

A Pentagon personnel database was compromised for nine months before detection, affecting over three million individuals. This significant breach of U.S. military personnel data represents a critical security incident with major national security implications.

breachSecurityWeek30 Sept

ShinyHunters Defiant After FBI Calls on Members to Come Forward

ShinyHunters, a threat actor group, has responded defiantly after an alleged leader's arrest by the FBI, claiming they never intended to publish stolen data. The FBI has publicly called on group members to surrender following the arrest.

vulnerabilityInfosecurity30 Sept

Apple Patches CoreGraphics Zero Day Exploited in Attacks

Apple has released a patch for CVE-2026-86950, a zero-day vulnerability in the iOS CoreGraphics engine that was actively exploited in attacks. The vulnerability patch addresses a critical security issue that could have exposed iOS users to compromise.

vulnerabilityThe Register Security30 Sept

Spectre bug is back, this time to haunt JIT engines

Researchers have discovered a new variant of the Spectre vulnerability that targets JIT (Just-In-Time) engines by recovering stale indirect branch prediction entries. This represents a significant security threat to systems using JIT compilation, particularly in web browsers and JavaScript engines.

ransomwareDarkReading30 Sept

South Africa Seeks Help After Cyberattack Targets Air Traffic Control

South Africa's air traffic control systems have been targeted by a cyberattack involving ransomware toolkit installation on operational networks. This incident represents a significant threat to critical aviation infrastructure and prompted the country to seek external assistance.

vulnerabilitySecurityWeek30 Sept

High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL

OpenSSL and WolfSSL, widely-used open source cryptographic libraries, have each received patches addressing approximately a dozen high-severity vulnerabilities. These patches are critical for securing systems that rely on these foundational security libraries.

vulnerabilityDarkReading29 Sept

Apple Zero-Day Vulnerability Weaponized in Targeted Attacks

Apple has disclosed that CVE-2026-86950, an out-of-bounds write vulnerability, is being actively exploited by attackers in targeted campaigns. The flaw represents a zero-day vulnerability being weaponized in sophisticated attacks against Apple systems.