2026-09-29 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-09-29 14:00 UTC
Introduction In late September 2026, Mandiant Consulting and Google Threat Intelligence Group (GTIG) identified active, in-the-wild exploitation of a zero-day vulnerability (CVE-2026-88772) affecting Citrix NetScaler ADC and NetScaler Gateway appliances. We have observed evidence that organizations in North America and Europe in the government, financial services, technology, education, and legal and professional services sectors were likely impacted by this exploitation campaign, which has bee…
P30
2026-09-29 13:45 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-29 15:25 UTC
Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub. "The malicious packages abuse the 'Baileys' WhatsApp open source project to add the victims to groups without their consent," OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko said in a technical
P0
2026-09-29 13:29 UTC
Community
SANS Internet Storm Center · indexed 2026-09-29 13:45 UTC
Starting yesterday, our sensors picked up a small number of scans for "wordfence-waf.php". This particular script is used by Wordfence, a solution to protect WordPress sites. During the Wordfence install, the wordpress-waf.php file will be created in the site's root directory [1].
P0
2026-09-29 13:28 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-29 13:40 UTC
Apple patched zero-day CVE-2026-86950 in CoreGraphics, exploited in sophisticated targeted attacks against specific iOS users. Apple has released security updates for iOS, iPadOS and macOS to fix a zero-day vulnerability, tracked as CVE-2026-86950, in CoreGraphics that may have been exploited in attacks against specific individuals. The flaw is an out-of-bounds write that can lead to […]
P50
2026-09-29 13:20 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-29 13:40 UTC
The company will use the funds to expand its sales, partnerships, channels, and customer support teams. The post Reco Raises $55 Million for Agentic Security appeared first on SecurityWeek.
P0
2026-09-29 13:03 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-29 13:20 UTC
The personalized versions of ChatGPT were used to impersonate legitimate products and trick users into executing PowerShell commands. The post Hackers Use ChatGPT Custom GPTs in ClickFix Attacks appeared first on SecurityWeek.
P0
2026-09-29 13:00 UTC
Vendor Research
Cloudflare Security · Sharon Goldberg · indexed 2026-09-29 13:20 UTC
We’re building CryptoLabe, an internal AI-powered tool that discovers cryptography across our codebase, surfaces dependencies, and helps us progress toward a full post-quantum migration by 2029. Here’s what we’ve learned so far.
P0
2026-09-29 13:00 UTC
Vendor Research
Cloudflare Security · Steve Goldsmith · indexed 2026-09-29 13:20 UTC
Twelve years after launching Universal SSL, Cloudflare is applying to become a certificate authority. By combining an established root, an ACME-first approach, and Merkle Tree Certificates, we are building a post-quantum CA for the open web.
P0
2026-09-29 13:00 UTC
Vendor Research
Cloudflare Security · Mari Galicer · indexed 2026-09-29 13:20 UTC
As post-quantum signatures threaten to inflate TLS handshakes and certificate transparency logs, Merkle Tree Certificates offer a path to compact, auditable authentication. Cloudflare’s new certificate authority will support MTC issuance at scale.
P0
2026-09-29 13:00 UTC
Vendor Research
Cloudflare Security · Emilia Yoffie · indexed 2026-09-29 13:20 UTC
We are expanding access to Cloudforce One's Threat Events Platform to every Cloudflare account and introducing Threat Signals. Threat Signals automatically parses open-source threat reporting, extracts structured indicators, and connects threat context directly to your WAF rules.
P0
2026-09-29 13:00 UTC
Vendor Research
Cloudflare Security · Andrew Depke · indexed 2026-09-29 13:20 UTC
Cloudflare has added visibility into post-quantum (PQ) encryption in TLS 1.3 directly into HTTP Analytics, Log Explorer, and Logpush. Learn how to make sure your domain is protected with PQ encryption.
P0
2026-09-29 13:00 UTC
Vendor Research
Cloudflare Security · Daniele Molteni · indexed 2026-09-29 13:20 UTC
Cloudflare learns the structure of your HTTP requests and identifies deviations. You can add a positive security layer that helps reduce attack surface as AI makes it easier for attackers to generate and vary payloads.
P0
2026-09-29 12:34 UTC
Security Journalism
The Record · indexed 2026-09-29 12:45 UTC
According to Dodo Pizza, the potentially compromised information included customers’ names, addresses, email addresses, phone numbers, dates of birth and order details.
P0
2026-09-29 12:27 UTC
Security Journalism
The Record · indexed 2026-09-29 12:45 UTC
A spokesperson for the court system told Recorded Future News that the incident did not involve ransomware and the hackers have not issued ransom demands for the stolen data as of Monday.
P15
2026-09-29 12:25 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-29 12:40 UTC
The data breach affects the Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense. The post Pentagon Personnel Agency Data Breach Impacts 3 Million People appeared first on SecurityWeek.
P0
2026-09-29 12:00 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-09-29 12:00 UTC
Rig provides an identity dependencies graph to distinguish between legitimate users and rogue AI agents The post Rig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity Risks appeared first on SecurityWeek.
P0
2026-09-29 11:41 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-29 11:50 UTC
A Vietnamese national was charged with money laundering for his role in a massive "pig butchering" scam, which defrauded a victim out of $16 million worth of cryptocurrency. [...]
P0
2026-09-29 11:30 UTC
Security Journalism
Security Week · Steve Durbin · indexed 2026-09-29 11:40 UTC
- AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. The post Four Cyber Threats Harboring Big Plans for the Future appeared first on SecurityWeek.
P0
2026-09-29 11:15 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-29 11:20 UTC
The GPT-6.1 Astra model was slated to debut in ChatGPT and Codex in October, but it fell short of expectations. The post OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training appeared first on SecurityWeek.
P0
2026-09-29 11:01 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-29 11:20 UTC
Pepijn van der Stap was convicted in 2023 for hacking multiple organizations, stealing their data, and extorting them. The post Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation appeared first on SecurityWeek.
P0
2026-09-29 10:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Lior Yakim · indexed 2026-09-29 10:20 UTC
We introduce OperTraitor, a tool to audit privileges of Kubernetes operators, identify excessive RBAC risks, and secure non-human identities. The post OperTraitors: How Kubernetes Operators Betray Your Security Posture appeared first on Unit 42.
P0
2026-09-29 10:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · Craig Jackson · indexed 2026-09-29 10:30 UTC
This new proactive service joins the suite of retainer offerings to provide dedicated, intelligence-led hunting specifically for your organization’s most high-value IT assets.
P0
2026-09-29 09:46 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-29 10:00 UTC
The malware framework uses a modular architecture and a custom executable file format for long-term persistence. The post Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft appeared first on SecurityWeek.
P0
2026-09-29 09:04 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-29 09:10 UTC
American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability. [...]
P10
2026-09-29 09:00 UTC
Other
ESET · indexed 2026-09-30 13:30 UTC
Con artists are targeting timeshare owners who want out – and some victims are hit twice
P0
2026-09-29 08:35 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-29 09:50 UTC
Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. "It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters," the Politie Landelijke Opsporing en Interventies said in an X post Monday. Police said the individual is expected to appear before the
P0
2026-09-29 07:33 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-29 07:45 UTC
Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices. [...]
P50
2026-09-29 07:30 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-29 08:10 UTC
Dutch police confirm the arrest of a 24-year-old Amsterdam man as part of an investigation into the ShinyHunters hacking group. Dutch police confirmed this week that a 24-year-old man from Amsterdam was arrested earlier this month as part of an investigation into the cybercrime group ShinyHunters. The suspect appears before Rotterdam District Court today, September […]
P0
2026-09-29 06:27 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-29 07:10 UTC
UK AISI finds GPT-6 Astra launches unsanctioned supply-chain attacks in simulations far more than earlier OpenAI models, even when told not to. The UK’s AI Security Institute tested GPT-6 Astra before its public release, and the results, published September 28, aren’t subtle. When given a routine cybersecurity evaluation, the model went off script and attacked […]
P0
2026-09-29 06:18 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-29 06:30 UTC
Apple released iOS and macOS updates to patch a zero-day vulnerability (CVE-2026-86950) reported by Meta’s product security team. The post Apple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’ appeared first on SecurityWeek.
P30