A recent analysis by Gambit Security revealed that an attacker used open-source AI tools like Strix, Cairn, and Hermes to compromise 27 out of 105 online retailers within five days, at an average cost of $25 per target. The campaign successfully exfiltrated 600,000 credit card details, installed card skimmers, and gained access to several major companies, demonstrating AI's growing role in automating and enhancing cybercriminal activities.
Attackers are using fake desktop applications to impersonate legitimate HR and payroll providers, tricking HR staff into granting them remote access to company systems. The deception is effective because the fake apps mimic legitimate software, with the only giveaway being that the impersonated providers do not actually offer desktop applications.
CISA has issued a warning regarding the active exploitation of critical vulnerabilities in WSO2 products, specifically an authentication bypass flaw. Hackers are reportedly leveraging this vulnerability, alongside others affecting Sharepoint and Adobe Commerce, to compromise systems.
Cryptocurrency exchange Bitget has attributed the recent $387.5 million raid on its hot wallets to North Korea. This attribution aligns with previous suspicions linking the Kim regime to sophisticated cryptocurrency theft operations.
The domain third-party[.]com is being used to distribute malware, specifically a ClickFix lure that targets Windows machines and can alter PowerShell. This domain is often used in documentation as a placeholder, posing a risk to enterprises that might inadvertently direct users to the malicious site.
Anthropic is offering up to $250 in free Claude Code credits for users to try their AI coding assistant through cloud sessions. This initiative aims to increase adoption and allow more individuals to experiment with the tool without an upfront commitment.
This article highlights several cybersecurity incidents and trends. It mentions the takeover of the Clop ransomware group's leak site, a Docker botnet specifically targeting AI keys, and the exposure of a water utility. Additionally, it touches on the BragJack attack against browser AI assistants, a flaw in TDengine affecting industrial telemetry, and an Ubuntu update overhaul.
GitLab's 'email work item' feature, intended to simplify issue creation, has a significant security flaw. The feature embeds a long-lived token in a secret email address that, if exposed, allows anyone to push code and run CI/CD jobs in protected repositories, bypassing IP restrictions. GitLab considers this intended behavior, while researchers at Aikido Security argue it presents a critical risk.
The article discusses how the rise of AI agents poses a challenge to the existing SOC 2 compliance framework. These agents can leverage human credentials and perform actions that are difficult for current controls to differentiate from legitimate human activity. Token Security highlights the need for SOC 2 to evolve to address these new security gaps related to agent identities.
This article discusses how to combat scams targeting IT workers by improving HR processes and training HR managers to recognize the latest tactics and warning signs. It also suggests that automated analysis can further enhance defenses against these threats.
Two GitHub Actions, actions-cool/issues-helper and actions-cool/maintain-one-comment, have been disabled for a second time after their repositories became accessible again. These actions were previously compromised during the Mini Shai-Hulud malware campaign in May 2026 and have resumed executing the malicious payload.
Bitget's security systems detected unauthorized transfers totaling $351 million on September 24, leading to the freezing of some attacker-linked wallet addresses. North Korea is suspected of being behind this significant cryptocurrency heist.
A new version of the PamStealer macOS malware has been identified by researchers, featuring enhanced evasion techniques. This updated variant employs a server-side decryption chain for its main payload and utilizes JavaScript for Automation (JXA) for its dropper mechanism, along with modified lure and delivery methods.
Microsoft plans to deprecate the Windows Deployment Services (WDS) server role with the next Windows Server release. WDS is used for deploying Windows operating systems over a network.
CISA has developed an election security plan that identifies significant barriers to effective cybersecurity practices, specifically highlighting challenges related to patching systems and the threat of attacks targeting voter databases. This plan was developed in response to a directive from Homeland Security Secretary Markwayne Mullin.
Ardit Kutleshi, the creator and operator of Rydox Marketplace, has pleaded guilty in a US court. The Rydox marketplace facilitated the trade of personally identifiable information (PII) and various cybercrime tools and services.
This article is a pop quiz for the CompTIA A+ 220-1201 certification exam. It provides a series of questions designed to test a user's knowledge on various IT topics covered by the certification.
CISA has added two new vulnerabilities, CVE-2026-65660 (Microsoft SharePoint Code Injection) and CVE-2026-67279 (Mikrotik RouterOS Improper Enforcement of Behavioral Workflow), to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. These additions underscore the importance of CISA's Binding Operational Directive (BOD) 26-04, which mandates FCEB agencies to prioritize remediation of these high-risk vulnerabilities.
A Kosovar national has pleaded guilty to operating Rydox, an illegal online marketplace that trafficked in stolen personal information, login credentials, and credit card details. The administrator faces up to 22 years in prison for their role in facilitating cybercriminal activities.
Attackers are leveraging AI to make failed attacks cheaper and easier to retry. This shift means that Security Operations Centers (SOCs) will likely face more persistent and iterative attacks, requiring new strategies to manage and respond to alerts. The change is described as quieter but already visible in the cybersecurity landscape.
Anthropic's recent report details various misuses of their AI model, Claude. These misuses include AI agents conducting reconnaissance, exploitation, data theft, and propaganda production, with human oversight for target selection and goal setting. The report highlights attackers leveraging AI to industrialize credential theft, cloud compromise, phishing, vulnerability research, and sensitive data extraction.
Researchers have discovered that file-change notification systems in Windows, Linux, and Android can inadvertently leak sensitive user activity. This leaked information includes details such as keystroke timing, browsing habits, and even media events on applications like WhatsApp.
Cryptocurrency exchange Bitget has reported that suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets. The incident was identified on September 24, 2026, when unauthorized transfers were detected in a limited number of hot wallets.
Microsoft has acknowledged that recent Windows updates, specifically the August 2026 preview updates and subsequent releases, are causing desktop loading problems for some users. These issues can manifest as black screens, impacting the user experience.
A pre-authentication SQL injection vulnerability in the Roundcube Webmail virtuser_query plugin, identified as CVE-2026-48842, is being actively exploited in the wild. The Canadian Centre for Cyber Security has issued a warning about this flaw, which affects versions prior to 1.6.16 and 1.7.1. The vulnerability is due to an issue with the preg_replace() function.
Privacy International (PI) has responded to the UK Department for Science, Innovation & Technology regarding data regulation in the era of AI and other data-intensive technologies. The response emphasizes the need for robust data protection measures to safeguard individuals' privacy.
Three vulnerabilities dubbed 'SalesBleed' have been discovered in Salesforce Agentforce. These flaws allowed attackers to compromise trusted agents, leading to data theft and the execution of phishing attacks.
Cryptocurrency exchange Bitget has disclosed that hackers, suspected to be from North Korea, have stolen $351.6 million from its hot and warm wallets. The incident highlights ongoing threats to digital asset platforms.
Flock Safety's interconnected camera and license plate reader systems offer potential benefits for law enforcement in solving crimes. However, concerns are growing about the misuse of the sensitive personal location data these systems collect. The article argues for stronger controls and debate on balancing public safety with privacy expectations.
European nations are experiencing an increase in hybrid warfare tactics, including cyber sabotage, disinformation campaigns, and drone attacks. These activities are particularly concentrated in countries providing support to Ukraine.
Roundcube Webmail is facing exploitation of a critical SQL injection vulnerability, tracked as CVE-2026-48842. This bug can be exploited by attackers without requiring any authentication.
This article provides an in-depth analysis of malware associated with the Macfinger ClickFix campaign. It details the specific types of malware and their functionalities observed during this campaign.
Cloudflare has fixed a flaw in its Containers service that allowed one customer's container to potentially access residual disk data left behind by other customers' containers on the same server. The vulnerability meant data from previous workloads, not live ones, could be exposed, though Cloudflare stated an attacker could not select whose data they accessed.
CISA has added two critical vulnerabilities, one in WSO2 API Control Plane and another in Adobe Commerce and Magento, to its Known Exploited Vulnerabilities (KEV) catalog. These additions are based on evidence that both flaws are currently being actively exploited in the wild.
A significant vulnerability has been discovered in the TACACS+ networking protocol, an older system still in use for network device authentication. This bulletin also touches upon unrelated cybersecurity news regarding OpenAI's involvement in an Australian Medicare website hack, providing Ukraine with access to an unspecified system, and the UK's plan to create an anti-disinformation center.
Intigriti's Bug Bytes newsletter for September 2026 highlights various hacking achievements and tools. Features include compromising major platforms like OpenAI, Slack, and Meta through a vulnerable image library, hacking OpenAI employee accounts, and breaching Google's GFile for a substantial reward. The newsletter also introduces CrowdRecon, a crowd-led reconnaissance tool, and mentions performance improvements in Turbo Intruder.
A critical code injection vulnerability, CVE-2026-65660, has been identified in Microsoft SharePoint. This flaw allows authorized attackers to execute arbitrary code remotely, posing a significant risk. Organizations are urged to apply vendor-provided mitigations and adhere to CISA's guidance on prioritizing security updates.
MikroTik RouterOS has a vulnerability (CVE-2026-67279) that allows unauthenticated clients to open a session and send exec requests, potentially chaining to exploit CVE-2026-86060 for unauthenticated exploitation. Affected stakeholders must apply vendor mitigations and comply with CISA's BOD 26-04 guidance for prioritizing security updates.
A threat actor utilized three open-source agents, costing an average of just $25 per scan, to breach over 25 organizations, including a Fortune 500 hospitality company and a major US airline. This indicates a shift towards more accessible and cost-effective attack methods.
A security researcher created a detailed map of Flock surveillance camera locations, revealing more than any previous effort. Flock is now attempting to have this map taken down.
A new vulnerability dubbed 'Salesbleed' allows threat actors to exploit Salesforce agents to inject malicious content into internal Slack communications. This could enable sophisticated phishing attacks by smuggling arbitrary instructions from the web into trusted internal channels.
A new variant of the MacSync malware, designed for macOS systems, has been identified that utilizes public iCloud calendar events for distributing its latest payloads. This method allows attackers to embed malicious links or information within seemingly innocuous calendar invitations to compromise users.
The article discusses the complex legal and accountability issues surrounding autonomous AI systems that conduct cyberattacks. It highlights the possibility of lawsuits and the significant challenges any criminal investigations would face in assigning blame.
The remote access Trojan (RAT) known as SectopRAT has resurfaced, employing a new tactic of hiding within legitimate applications. This resurgence highlights the importance for organizations to monitor application behavior rather than solely relying on trust.
WordPress has released version 7.1.2 to patch a critical severity vulnerability (CVE-2026-87902) that allows unauthenticated attackers remote code execution. The vulnerability exploits how page templates are resolved, enabling attackers to include and execute malicious PHP files if specific server and theme conditions are met. Attacks in the wild have already been reported, and users are urged to update immediately, as the fix affects many older versions.
DraftKings is employing AI and machine learning to identify and target customers who are most likely to place losing bets, then luring them back with promotions. This practice amplifies the harms of online behavioral advertising by exploiting vulnerable individuals for profit. The company's use of AI necessitates extensive data collection, further fueling surveillance.
A new botnet malware named Carbonato is exploiting exposed Docker hosts to deploy the Hermes Agent AI framework. This allows attackers to gain control of compromised systems and leverage them for malicious activities.
A vulnerability dubbed 'SalesBleed' has been discovered in Salesforce's Agentforce, potentially allowing for zero-click data theft from CRM systems and anonymous phishing attacks. The flaws could lead to "very unexpected consequences" for organizations using the platform.
Red Siege, a sponsor of the Wild West Hackin' Fest (WWHF), is returning to Deadwood for the 2026 event. They will be offering training and talks as part of their involvement.
Researchers have discovered two unpatched vulnerabilities in OnePlus devices running OxygenOS that allow installed Android apps to gain root access without requiring any special permissions. This chaining of flaws effectively grants a malicious app the highest level of control over the device, and OnePlus has acknowledged that these issues affect a wide range of their devices as well as OPPO devices.