{
    "generated_at": "2026-10-04T07:25:15+00:00",
    "count": 30,
    "articles": [
        {
            "id": 4433,
            "title": "Google Gemini could soon get full access to your Mac’s files, apps and the web",
            "url": "https://www.bleepingcomputer.com/news/google/google-gemini-could-soon-get-full-access-to-your-macs-files-apps-and-the-web/",
            "author": "Mayank Parmar",
            "summary": "Google's Gemini could soon access any file on your macOS device, open apps, browse the web, and perform actions without asking for permission every time. [...]",
            "published_at": "2026-10-03 23:12:34",
            "discovered_at": "2026-10-03 23:15:01",
            "updated_at": null,
            "priority_score": 0,
            "source": "BleepingComputer",
            "source_group": "Security Journalism",
            "categories": [
                "Apple"
            ],
            "cves": []
        },
        {
            "id": 4432,
            "title": "ShinyHunters hacker reportedly detained in Jordan, aiding FBI",
            "url": "https://www.bleepingcomputer.com/news/security/shinyhunters-hacker-reportedly-detained-in-jordan-aiding-fbi/",
            "author": "Lawrence Abrams",
            "summary": "A suspected ShinyHunters hacking group member known online as \"Rey\" has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members of the extortion group. [...]",
            "published_at": "2026-10-03 19:09:38",
            "discovered_at": "2026-10-03 19:20:04",
            "updated_at": null,
            "priority_score": 0,
            "source": "BleepingComputer",
            "source_group": "Security Journalism",
            "categories": [
                "Law Enforcement"
            ],
            "cves": []
        },
        {
            "id": 4431,
            "title": "Fake Zoom installer hides macOS backdoor CloudSyncD",
            "url": "https://securityaffairs.com/200293/malware/fake-zoom-installer-hides-macos-backdoor-cloudsyncd.html",
            "author": "Pierluigi Paganini",
            "summary": "Jamf Threat Labs details CloudSyncD, a fake macOS Zoom installer that hides a phished password using invisible zero-width Unicode characters. Jamf Threat Labs found CloudSyncD while doing routine scanning on VirusTotal, buried inside a disguised Zoom client. They first spotted it on September 15, clearly still under construction, and within two days watched it move […]",
            "published_at": "2026-10-03 15:11:16",
            "discovered_at": "2026-10-03 15:30:04",
            "updated_at": null,
            "priority_score": 0,
            "source": "Security Affairs",
            "source_group": "Other",
            "categories": [
                "Apple",
                "Malware",
                "Phishing"
            ],
            "cves": []
        },
        {
            "id": 4428,
            "title": "YARA-X 1.21.0 Release, (Sat, Oct 3rd)",
            "url": "https://isc.sans.edu/diary/rss/33392",
            "author": null,
            "summary": "YARA-X&#x26;#39;s 1.21.0 release brings 5 improvements and 4 bugfixes.&#xd;",
            "published_at": "2026-10-03 14:40:21",
            "discovered_at": "2026-10-03 14:50:02",
            "updated_at": null,
            "priority_score": 0,
            "source": "SANS Internet Storm Center",
            "source_group": "Community",
            "categories": [],
            "cves": []
        },
        {
            "id": 4429,
            "title": "MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics",
            "url": "https://thehackernews.com/2026/10/mi5-says-chinas-mss-funded-research.html",
            "author": "info@thehackernews.com (The Hacker News)",
            "summary": "The U.K.'s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering efforts on behalf of Beijing's state security service. In a \"Security Service Espionage Alert\" issued on September 30, 2026, MI5 said the \"primary purpose of the China General Technology Research Institute (CGTRI) 中国通用技术研究院 is to fund research that",
            "published_at": "2026-10-03 14:38:46",
            "discovered_at": "2026-10-03 15:25:03",
            "updated_at": null,
            "priority_score": 0,
            "source": "The Hacker News",
            "source_group": "Security Journalism",
            "categories": [
                "APT / Nation-State"
            ],
            "cves": []
        },
        {
            "id": 4430,
            "title": "Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware",
            "url": "https://thehackernews.com/2026/10/warlock-exploits-sharepoint-flaws-to.html",
            "author": "info@thehackernews.com (The Hacker News)",
            "summary": "The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. \"In the",
            "published_at": "2026-10-03 14:36:33",
            "discovered_at": "2026-10-03 15:25:03",
            "updated_at": null,
            "priority_score": 15,
            "source": "The Hacker News",
            "source_group": "Security Journalism",
            "categories": [
                "Cloud Security",
                "Microsoft",
                "Ransomware",
                "Threat Actors"
            ],
            "cves": []
        },
        {
            "id": 4427,
            "title": "Danish university DTU breach exposes data of up to 200,000 people",
            "url": "https://www.bleepingcomputer.com/news/security/danish-university-dtu-breach-exposes-data-of-up-to-200-000-people/",
            "author": "Ionut Ilascu",
            "summary": "The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data. [...]",
            "published_at": "2026-10-03 14:35:20",
            "discovered_at": "2026-10-03 14:45:02",
            "updated_at": null,
            "priority_score": 0,
            "source": "BleepingComputer",
            "source_group": "Security Journalism",
            "categories": [],
            "cves": []
        },
        {
            "id": 4426,
            "title": "doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures",
            "url": "https://www.securityweek.com/doxx-net-raises-38-million-to-prevent-ai-agent-on-the-internet-misadventures/",
            "author": "Kevin Townsend",
            "summary": "doxx.net’s new ADN platform prevents agentic misadventure while the agent is operating under the user’s authority. The post doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures appeared first on SecurityWeek.",
            "published_at": "2026-10-03 11:45:00",
            "discovered_at": "2026-10-03 12:00:03",
            "updated_at": null,
            "priority_score": 0,
            "source": "Security Week",
            "source_group": "Security Journalism",
            "categories": [
                "AI Security"
            ],
            "cves": []
        },
        {
            "id": 4425,
            "title": "Fortra Patches Critical Vulnerabilities in BoKS",
            "url": "https://www.securityweek.com/fortra-patches-critical-vulnerabilities-in-boks/",
            "author": "Ionut Arghire",
            "summary": "The bugs could lead to authentication bypass, shell command execution, and memory corruption. The post Fortra Patches Critical Vulnerabilities in BoKS appeared first on SecurityWeek.",
            "published_at": "2026-10-03 11:34:00",
            "discovered_at": "2026-10-03 11:40:03",
            "updated_at": null,
            "priority_score": 10,
            "source": "Security Week",
            "source_group": "Security Journalism",
            "categories": [],
            "cves": []
        },
        {
            "id": 4424,
            "title": "The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations",
            "url": "https://thehackernews.com/2026/10/the-state-of-cybersecurity-in-2026key.html",
            "author": "info@thehackernews.com (The Hacker News)",
            "summary": "Featuring: Cybersecurity is being reshaped by the expansion of cloud infrastructure, AI, distributed systems, and increasingly complex digital environments. As organizations manage more identities, devices, data, and internet-facing infrastructure, security is shifting toward continuous visibility, control, and the ability to respond to risk at scale. This report examines how core areas of",
            "published_at": "2026-10-03 11:00:00",
            "discovered_at": "2026-10-03 11:10:06",
            "updated_at": null,
            "priority_score": 0,
            "source": "The Hacker News",
            "source_group": "Security Journalism",
            "categories": [],
            "cves": []
        },
        {
            "id": 4423,
            "title": "CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed",
            "url": "https://securityaffairs.com/200283/hacking/cve-2026-90970-critical-gitlab-ai-gateway-flaw-fixed.html",
            "author": "Pierluigi Paganini",
            "summary": "GitLab fixes critical AI Gateway flaw that could let authenticated Duo users escape a prompt sandbox and execute commands on self-hosted gateways. GitLab has released patches for a critical vulnerability in its AI Gateway, tracked as CVE-2026-90970 (CVSS score of 9.9), that could allow an authenticated user with access to the Duo Agent Platform to […]",
            "published_at": "2026-10-03 10:43:39",
            "discovered_at": "2026-10-03 11:00:04",
            "updated_at": null,
            "priority_score": 15,
            "source": "Security Affairs",
            "source_group": "Other",
            "categories": [
                "Vulnerabilities"
            ],
            "cves": [
                "CVE-2026-90970"
            ]
        },
        {
            "id": 4422,
            "title": "Antino Backdoor Lets China-Linked UAT-11587 Turn Microsoft 365 Into a C2 Channel",
            "url": "https://securityaffairs.com/200264/apt/antino-backdoor-uses-your-inbox-as-its-control-panel.html",
            "author": "Pierluigi Paganini",
            "summary": "Cisco Talos details UAT-11587, a China-linked group using the Antino backdoor and Microsoft 365 as cover to spy on Asian governments. Cisco Talos has been tracking a cluster of espionage activity since September 2025 that it calls UAT-11587, and by July 2026 the group had hit at least 16 government and policy organizations across eight […]",
            "published_at": "2026-10-03 09:26:04",
            "discovered_at": "2026-10-03 10:00:04",
            "updated_at": null,
            "priority_score": 0,
            "source": "Security Affairs",
            "source_group": "Other",
            "categories": [
                "APT / Nation-State",
                "Malware",
                "Microsoft"
            ],
            "cves": []
        },
        {
            "id": 4275,
            "title": "Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability",
            "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU?vs_f=Cisco%20Security%20Advisory%26vs_cat%3DSecurity%20Intelligence%26vs_type%3DRSS%26vs_p%3DCisco%20Catalyst%20SD-WAN%20Manager%20API%20Authentication%20Bypass%20Vulnerability%26vs_k%3D1",
            "author": null,
            "summary": "A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. Live Protect Shield Cisco has released a Live Protect shield for CVE-2026-76504 to provide temporary security coverage to allow time for software upgrade planning, including preserving any information that customers may require for governance or compliance purposes. This shield offers only temporary partial protection. The only way to remediate this vulnerability is to upgrade to the first fixed software release, as noted in the Fixed Releases section of this advisory. Cisco strongly recommends prioritizing system upgrades and scheduling them as soon as possible to ensure remediation. Before deploying the shield, read the following information: Side Effects/Limitation: If this shield is applied A legitimate user with URI encoding might not be able to login to SDWAN Manager. For more information about Live Protect for Cisco Catalyst SD-WAN, see https://www.cisco.com/c/en/us/td/docs/routers/sdwan/26x-later/network-monitoring/network-monitoring-guide/live-protect-for-cisco-catalyst-sd-wan.html. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU Security Impact Rating: Critical CVE: CVE-2026-76504",
            "published_at": "2026-10-02 23:18:42",
            "discovered_at": "2026-09-30 13:10:02",
            "updated_at": "2026-10-03 00:50:01",
            "priority_score": 15,
            "source": "Cisco Security Advisories",
            "source_group": "Vendor Research",
            "categories": [
                "Network Security",
                "Vulnerabilities"
            ],
            "cves": [
                "CVE-2026-76504"
            ]
        },
        {
            "id": 4419,
            "title": "U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog",
            "url": "https://securityaffairs.com/200248/security/u-s-cisa-adds-zammad-gmbh-zammad-flaws-to-its-known-exploited-vulnerabilities-catalog.html",
            "author": "Pierluigi Paganini",
            "summary": "U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: The first flaw, CVE-2026-102489, is a session hijacking vulnerability in Zammad that can lead to remote code execution as the […]",
            "published_at": "2026-10-02 22:46:18",
            "discovered_at": "2026-10-02 23:35:03",
            "updated_at": null,
            "priority_score": 50,
            "source": "Security Affairs",
            "source_group": "Other",
            "categories": [
                "Cloud Security",
                "Vulnerabilities"
            ],
            "cves": [
                "CVE-2026-102489"
            ]
        },
        {
            "id": 4418,
            "title": "Judge dismisses spyware case brought by Salvadoran journalists targeted with Pegasus",
            "url": "https://therecord.media/judge-dismisses-spyware-case-brought-by-salvadoran-journalists",
            "author": null,
            "summary": "The plaintiffs, who all worked for the independent and Salvadoran news outlet El Faro, failed to convince the court that their case had jurisdiction in California, according to the judge’s order.",
            "published_at": "2026-10-02 20:30:00",
            "discovered_at": "2026-10-02 20:45:04",
            "updated_at": null,
            "priority_score": 0,
            "source": "The Record",
            "source_group": "Security Journalism",
            "categories": [],
            "cves": []
        },
        {
            "id": 4416,
            "title": "CVE-2026-104019 - OS command injection in the Studio Space startup script in Amazon SageMaker Distribution",
            "url": "https://aws.amazon.com/security/security-bulletins/rss/2026-125-aws/",
            "author": "aws@amazon.com",
            "summary": "Bulletin ID: 2026-125-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/02/2026 13:00 PM PDT Description: Amazon SageMaker Unified Studio is an AWS service that unifies data, analytics, and AI development. It lets you find and access your organization's data and act on it with integrated, purpose-built tools. We identified CVE-2026-104019, an issue with the startup of SageMaker Spaces in SageMaker Unified Studio. The startup script in a SageMaker Space performs a network validation against all the available SageMaker connections in a project. Under certain conditions, improper sanitization of connection details during this validation could allow arbitrary code to be executed in the Space of another project member. In projects with the Trusted Identity Propagation feature enabled, this issue could result in a user with project contributor permissions (or higher) gaining access to another member's temporary execution role credentials and calling downstream trusted identity propagation-enabled AWS services on their behalf. We implemented a fix to all supported SageMaker Distribution versions to sanitize connection details during the startup validation process. The fix is deployed globally and will apply to all Spaces automatically on the next startup. Impacted versions: - 2.8.x - 2.13.x: all versions affected, no fix (end of support) - 2.14.x: < 2.14.12, fixed in 2.14.12 - 3.3.x - 3.8.x: all versions affected, no fix (end of support) - 3.9.x: < 3.9.12, fixed in 3.9.12 - 4.0.x: < 4.0.11, fixed in 4.0.11 - 4.1.x: < 4.1.11, fixed in 4.1.11 - 4.2.x: < 4.2.8, fixed in 4.2.8 - 4.3.x: < 4.3.5, fixed in 4.3.5 - 4.4.x: < 4.4.3, fixed in 4.4.3 - 4.5.x: not affected - < 2.8.0 and < 3.3.0: not affected Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.",
            "published_at": "2026-10-02 20:25:48",
            "discovered_at": "2026-10-02 20:40:05",
            "updated_at": null,
            "priority_score": 5,
            "source": "AWS Security Bulletins",
            "source_group": "Vendor Research",
            "categories": [
                "Cloud Security",
                "Vulnerabilities"
            ],
            "cves": [
                "CVE-2026-104019"
            ]
        },
        {
            "id": 4417,
            "title": "RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail",
            "url": "https://www.darkreading.com/cybersecurity-operations/remotethreat-bets-security-teams-need-to-test-what-happens-after-defenses-fail",
            "author": "Arielle Waldman",
            "summary": "The offensive cyber operations startup looks to evolve red teaming beyond traditional methods to simulate attackers' increasingly advanced capabilities.",
            "published_at": "2026-10-02 20:18:37",
            "discovered_at": "2026-10-02 20:45:03",
            "updated_at": null,
            "priority_score": 0,
            "source": "Dark Reading",
            "source_group": "Security Journalism",
            "categories": [],
            "cves": []
        },
        {
            "id": 4415,
            "title": "Bipartisan backlash to ALPRs grows as two high-profile bills are introduced",
            "url": "https://therecord.media/alpr-legislation-hawley-sanders-merkley-aoc",
            "author": null,
            "summary": "Republican Sen. Josh Hawley has new legislation on limiting automated license plate readers (ALPRs), while Democratic Sens. Bernie Sanders and Jeff Merkley, with Rep. Alexandria Ocasio-Cortez, have teed up a broader bill.",
            "published_at": "2026-10-02 19:30:00",
            "discovered_at": "2026-10-02 19:45:07",
            "updated_at": null,
            "priority_score": 0,
            "source": "The Record",
            "source_group": "Security Journalism",
            "categories": [],
            "cves": []
        },
        {
            "id": 4414,
            "title": "CVE-2026-103956, CVE-2026-103957, and CVE-2026-103958 - Issues in Loom for AWS",
            "url": "https://aws.amazon.com/security/security-bulletins/rss/2026-124-aws/",
            "author": "aws@amazon.com",
            "summary": "Bulletin ID: 2026-124-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/02/2026 12:00 PM PDT Description: Loom is an AWS Labs open-source AI agent orchestration platform. We have identified and addressed three issues in Loom for AWS, described below. We recommend upgrading to the latest version (1.7.0) and ensuring any forked or derivative code is patched to incorporate the new fixes. - CVE-2026-103956 ‐ Authentication bypass in Loom for AWS (CWE-306, CWE-1188) An issue in the authentication dependency in Loom for AWS versions",
            "published_at": "2026-10-02 19:21:29",
            "discovered_at": "2026-10-02 19:25:03",
            "updated_at": null,
            "priority_score": 15,
            "source": "AWS Security Bulletins",
            "source_group": "Vendor Research",
            "categories": [
                "AI Security",
                "Cloud Security",
                "Vulnerabilities"
            ],
            "cves": [
                "CVE-2026-103956",
                "CVE-2026-103957",
                "CVE-2026-103958"
            ]
        },
        {
            "id": 138,
            "title": "Cisco IOS XE Software Security Hardening Release: August 2026",
            "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ?vs_f=Cisco%20Security%20Advisory%26vs_cat%3DSecurity%20Intelligence%26vs_type%3DRSS%26vs_p%3DCisco%20IOS%20XE%20Software%20Security%20Hardening%20Release%3A%20August%202026%26vs_k%3D1",
            "author": null,
            "summary": "As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures identifier (CVE ID). Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ Security Impact Rating: Critical CVE: CVE-2026-20267,CVE-2026-20268,CVE-2026-20269,CVE-2026-20270,CVE-2026-20271,CVE-2026-20272,CVE-2026-20273",
            "published_at": "2026-10-02 19:21:28",
            "discovered_at": "2026-08-15 14:33:28",
            "updated_at": "2026-10-02 19:45:02",
            "priority_score": 30,
            "source": "Cisco Security Advisories",
            "source_group": "Vendor Research",
            "categories": [
                "Apple",
                "Vulnerabilities"
            ],
            "cves": [
                "CVE-2026-20267",
                "CVE-2026-20268",
                "CVE-2026-20269",
                "CVE-2026-20270",
                "CVE-2026-20271",
                "CVE-2026-20272",
                "CVE-2026-20273"
            ]
        },
        {
            "id": 4413,
            "title": "Frontline Education breach exposes school district employee data",
            "url": "https://www.bleepingcomputer.com/news/security/frontline-education-data-breach-impacts-school-district-employees/",
            "author": "Lawrence Abrams",
            "summary": "Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers. [...]",
            "published_at": "2026-10-02 19:01:40",
            "discovered_at": "2026-10-02 19:15:02",
            "updated_at": null,
            "priority_score": 0,
            "source": "BleepingComputer",
            "source_group": "Security Journalism",
            "categories": [
                "Data Breaches",
                "Vulnerabilities"
            ],
            "cves": []
        },
        {
            "id": 4412,
            "title": "Warlock ransomware breach SharePoint in water, telecom operator attacks",
            "url": "https://www.bleepingcomputer.com/news/security/warlock-ransomware-breach-sharepoint-in-water-telecom-operator-attacks/",
            "author": "Ionut Ilascu",
            "summary": "The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access. [...]",
            "published_at": "2026-10-02 18:33:01",
            "discovered_at": "2026-10-02 18:35:02",
            "updated_at": null,
            "priority_score": 15,
            "source": "BleepingComputer",
            "source_group": "Security Journalism",
            "categories": [
                "Microsoft",
                "Ransomware"
            ],
            "cves": []
        },
        {
            "id": 4409,
            "title": "GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers",
            "url": "https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html",
            "author": "info@thehackernews.com (The Hacker News)",
            "summary": "A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory. The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act. The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1. The flaw",
            "published_at": "2026-10-02 17:33:31",
            "discovered_at": "2026-10-02 17:45:03",
            "updated_at": null,
            "priority_score": 10,
            "source": "The Hacker News",
            "source_group": "Security Journalism",
            "categories": [],
            "cves": []
        },
        {
            "id": 4410,
            "title": "Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign",
            "url": "https://thehackernews.com/2026/10/antino-backdoor-uses-outlook-and.html",
            "author": "info@thehackernews.com (The Hacker News)",
            "summary": "Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster",
            "published_at": "2026-10-02 17:33:16",
            "discovered_at": "2026-10-02 17:45:03",
            "updated_at": null,
            "priority_score": 0,
            "source": "The Hacker News",
            "source_group": "Security Journalism",
            "categories": [
                "APT / Nation-State",
                "Malware",
                "Threat Actors"
            ],
            "cves": []
        },
        {
            "id": 4411,
            "title": "Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes",
            "url": "https://thehackernews.com/2026/10/dell-csm-flaws-enable-unauthenticated.html",
            "author": "info@thehackernews.com (The Hacker News)",
            "summary": "Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems. The vulnerabilities are listed below - CVE-2026-63688 (CVSS score: 10.0) - A missing authentication for critical function vulnerability in the csm-authorization-storage gRPC server that an",
            "published_at": "2026-10-02 17:02:12",
            "discovered_at": "2026-10-02 17:45:03",
            "updated_at": null,
            "priority_score": 5,
            "source": "The Hacker News",
            "source_group": "Security Journalism",
            "categories": [
                "Cloud Security",
                "Vulnerabilities"
            ],
            "cves": [
                "CVE-2026-63688"
            ]
        },
        {
            "id": 4408,
            "title": "Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response",
            "url": "https://www.darkreading.com/cybersecurity-operations/kiteworks-citrix-incidents-challenges-zero-day-response",
            "author": "Robert Lemos",
            "summary": "One company told customers to power down its data-protection platform during a nine-hour window, while the other remained mum on reported attacks prior to releasing a patch for its product.",
            "published_at": "2026-10-02 16:56:30",
            "discovered_at": "2026-10-02 17:15:03",
            "updated_at": null,
            "priority_score": 25,
            "source": "Dark Reading",
            "source_group": "Security Journalism",
            "categories": [
                "Vulnerabilities"
            ],
            "cves": []
        },
        {
            "id": 4407,
            "title": "CVE-2026-103505 - Mount Option Injection in Amazon EFS CSI Driver",
            "url": "https://aws.amazon.com/security/security-bulletins/rss/2026-120-aws/",
            "author": "aws@amazon.com",
            "summary": "Bulletin ID: 2026-120-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/01/2026 08:30 AM PDT Description: The Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. We identified CVE-2026-103505, where an actor with PersistentVolume creation privileges can inject additional mount options through the mounttargetipmap volumeAttribute. Appending comma-separated values to a value inside that JSON map causes the mount utility to parse them as separate mount options. Impacted versions: >= v3.1.0 AND",
            "published_at": "2026-10-02 16:38:11",
            "discovered_at": "2026-10-02 16:50:03",
            "updated_at": null,
            "priority_score": 5,
            "source": "AWS Security Bulletins",
            "source_group": "Vendor Research",
            "categories": [
                "Cloud Security",
                "Vulnerabilities"
            ],
            "cves": [
                "CVE-2026-103505"
            ]
        },
        {
            "id": 4405,
            "title": "SWIFT Banking & Government Middleware Enables RCE",
            "url": "https://www.darkreading.com/cybersecurity-operations/swift-banking-govt-middleware-rce",
            "author": "Nate Nelson",
            "summary": "Patch middleware vulnerabilities now to avoid hardware-based MFA exploits in ultra-sensitive environments.",
            "published_at": "2026-10-02 16:27:54",
            "discovered_at": "2026-10-02 16:30:12",
            "updated_at": null,
            "priority_score": 15,
            "source": "Dark Reading",
            "source_group": "Security Journalism",
            "categories": [
                "Vulnerabilities"
            ],
            "cves": []
        },
        {
            "id": 4406,
            "title": "GitLab warns of critical RCE vulnerability in AI Gateway service",
            "url": "https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/",
            "author": "Sergiu Gatlan",
            "summary": "GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances. [...]",
            "published_at": "2026-10-02 16:20:05",
            "discovered_at": "2026-10-02 16:35:03",
            "updated_at": null,
            "priority_score": 15,
            "source": "BleepingComputer",
            "source_group": "Security Journalism",
            "categories": [
                "Vulnerabilities"
            ],
            "cves": []
        },
        {
            "id": 4404,
            "title": "Is Your Organization Ready for 2027's AI Accountability Era?",
            "url": "https://www.darkreading.com/cybersecurity-operations/is-your-organization-ready-for-2027-s-ai-accountability-era-",
            "author": "Arielle Waldman",
            "summary": "Organizations may face an artificial intelligence (AI) reckoning over the next year. Omdia and Gartner weigh in on how to tackle the governance, security, and value challenges ahead.",
            "published_at": "2026-10-02 16:01:22",
            "discovered_at": "2026-10-02 16:15:03",
            "updated_at": null,
            "priority_score": 0,
            "source": "Dark Reading",
            "source_group": "Security Journalism",
            "categories": [
                "AI Security"
            ],
            "cves": []
        }
    ]
}