Cyber Security
Cybersecurity
Attackers Hijack Three Country TLDs to Forge Google Certificates
Andrew Doyle
October 8, 2026
Google says attackers compromised the .gh, .sl and .as registries, altered DNS records and obtained fraudulent HTTPS certificates for Google and other domains.
CVE Vulnerability Alerts
SonicWall Patches CVSS 10.0 Pre-Auth SSRF in SMA1000 Appliances
Gabby Lee
October 8, 2026
SonicWall fixed four SMA1000 flaws, led by CVE-2026-102255, a CVSS 10.0 unauthenticated SSRF in the WorkPlace portal. No exploitation has been reported.
Application Security
Unpatched LMCache Flaw Allows Unauthenticated Remote Code Execution
Mitchell Langley
October 8, 2026
JFrog disclosed CVE-2026-105192, a CVSS 9.8 pickle deserialization flaw in LMCache that lets one network message run code. No patched version exists yet.
Cybersecurity
PoeLLM Malware Hides C2 Addresses in GitHub Poems, Infects 3,000+
Andrew Doyle
October 8, 2026
Lumen's Black Lotus Labs says PoeLLM malware infected over 3,000 servers, hiding C2 addresses in poems on GitHub to mine cryptocurrency on AI infrastructure.
Cybersecurity
FBI, Secret Service: FortiBleed Attackers Lock Victims Out of Fortinet
Andrew Doyle
October 8, 2026
An FBI and Secret Service advisory says a Russian initial access broker is using stolen credentials to lock organizations out of Fortinet FortiGate devices.
Application Security
Tensorlake npm Package Compromised to Spread Shai-Hulud Worm
Gabby Lee
October 8, 2026
Socket and StepSecurity say tensorlake npm version 0.5.144 carried the Shai-Hulud worm, which steals tokens and keys and punishes revoked GitHub tokens.
Cybersecurity
MonsterCloud Owner Charged With Secretly Paying Ransoms, $19M Billed
Andrew Doyle
October 8, 2026
Federal prosecutors charged MonsterCloud owner Zohar Pinhasi with wire fraud, alleging he billed victims over $19 million while secretly paying ransom gangs.
Cybersecurity
US Offers $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks
Mitchell Langley
October 8, 2026
The State Department's Rewards for Justice program offers up to $10 million for information on Zhang Yu, a Chinese national indicted over the HAFNIUM hacks.
Cybersecurity
Georgia Power, Alabama Power Portal Breach Hits 400,000 Accounts
Andrew Doyle
October 8, 2026
An unauthorized party accessed the Georgia Power and Alabama Power customer portal, exposing about 400,000 accounts, including partial SSNs and contact data.
Application Security
Chrome 155 Patches 247 Vulnerabilities, Including Four Critical
Mitchell Langley
October 8, 2026
Google released Chrome 155 with fixes for 247 vulnerabilities, four of them critical use-after-free flaws. Google reports no in-the-wild exploitation.
Cybersecurity
Four US States Sue TP-Link Over China Risks and Security Claims
Andrew Doyle
October 8, 2026
Florida, Iowa, Montana and Nebraska sued router maker TP-Link, alleging misleading security claims and concealed China ties. TP-Link calls the claims baseless.
Application Security
Atlassian CVE-2026-21589 Exploited Within Two Hours of PoC Details
Gabby Lee
October 8, 2026
Attackers probed Atlassian Data Center flaw CVE-2026-21589 within two hours of watchTowr publishing details; Previdian logged 15 attempts from three IPs.
Application Security
Adversa AI: Encrypted Instructions Can Make Copilot CLI Leak Secrets
Mitchell Langley
October 8, 2026
Adversa AI says encrypted prompt injections on web pages can trick GitHub Copilot CLI into leaking .env secrets. GitHub declined to call it a vulnerability.
Cybersecurity
ASOS Confirms Breach After Hackers Hijack App Push Notifications
Andrew Doyle
October 7, 2026
ASOS confirmed a breach after attackers sent a fake push alert claiming a Snowflake hack; names and contact details may be exposed, but not card ...
Application Security
Ninja Forms, WPC Product Bundles XSS Flaws Used to Backdoor Sites
Mitchell Langley
October 7, 2026
Attackers are exploiting stored XSS flaws in Ninja Forms and WPC Product Bundles to install a fake plugin with four persistence mechanisms on WordPress.
CVE Vulnerability Alerts
Pwn2Own Ireland 2026 Day One: 32 Zero-Days, $388,500 in Payouts
Gabby Lee
October 7, 2026
Researchers demonstrated 32 unique zero-day exploits on day one of Pwn2Own Ireland 2026, earning $388,500 against phones, routers, printers and AI platforms.
Application Security
Attackers Scan for Rejetto HFS Session-Forgery Flaw CVE-2026-61500
Mitchell Langley
October 7, 2026
Scanning has begun for CVE-2026-61500 in Rejetto HFS, a flaw that lets attackers forge admin cookies and reach remote code execution on versions 3.0.0-3.2.0.
CVE Vulnerability Alerts
Dell Patches Root-Level Flaw CVE-2026-86360 in System Update Tool
Andrew Doyle
October 7, 2026
Dell fixed a critical path traversal, CVE-2026-86360, in its System Update CLI that lets unauthenticated remote attackers run code as root, plus four more bugs.
CVE Vulnerability Alerts
Android October 2026 Update Patches 25 Flaws, Seven Rated Critical
Mitchell Langley
October 7, 2026
Google's Android security bulletin for patch level 2026-10-01 fixes 25 vulnerabilities, seven of them critical, with no in-the-wild exploitation reported.
Application Security
LibreOffice, OpenOffice Flaws Run Code From Spreadsheets Silently
Andrew Doyle
October 7, 2026
CVE-2026-63277 in LibreOffice and CVE-2026-59265 in Apache OpenOffice let malicious spreadsheets run code through JDBC drivers with no macro warning shown.
Cybersecurity
Attackers Hijack Three Country TLDs to Forge Google Certificates
Andrew Doyle
October 8, 2026
Cybersecurity
Georgia Power, Alabama Power Portal Breach Hits 400,000 Accounts
Andrew Doyle
October 8, 2026
Cybersecurity
MonsterCloud Owner Charged With Secretly Paying Ransoms, $19M Billed
Andrew Doyle
October 8, 2026
TOP CYBERSECURITY HEADLINES
This Week’s Security Spotlight
Application Security
Atlassian CVE-2026-21589 Exploited Within Two Hours of PoC Details
Gabby Lee
October 8, 2026
CVE Vulnerability Alerts
Dell Patches Root-Level Flaw CVE-2026-86360 in System Update Tool
Andrew Doyle
October 7, 2026
CVE Vulnerability Alerts
Android October 2026 Update Patches 25 Flaws, Seven Rated Critical
Mitchell Langley
October 7, 2026
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Featured Videos
Podcasts
Cyber Security News
- All
- Application Security
- Blog
- CVE Vulnerability Alerts
- Cybersecurity
- Cybersecurity Newsletter
- Data Security
- Endpoint Security
- Identity and Access Management
- Information Security
- Network Security
- News
- Phishing
- Podcasts
- Product Reviews
- Ransomware
- Ransomware Victims
- Resources
- Security Spotlight
- Sponsored
- Threat Actors
- Threat Actors
- Threat Detection Tools
PoeLLM Malware Hides C2 Addresses in GitHub Poems, Infects 3,000+
October 8, 2026
Lumen's Black Lotus Labs says PoeLLM malware infected over 3,000 servers, hiding C2 addresses in poems on GitHub to mine cryptocurrency on AI infrastructure.
FBI, Secret Service: FortiBleed Attackers Lock Victims Out of Fortinet
October 8, 2026
An FBI and Secret Service advisory says a Russian initial access broker is using stolen credentials to lock organizations out of Fortinet FortiGate devices.
Tensorlake npm Package Compromised to Spread Shai-Hulud Worm
October 8, 2026
Socket and StepSecurity say tensorlake npm version 0.5.144 carried the Shai-Hulud worm, which steals tokens and keys and punishes revoked GitHub tokens.
MonsterCloud Owner Charged With Secretly Paying Ransoms, $19M Billed
October 8, 2026
Federal prosecutors charged MonsterCloud owner Zohar Pinhasi with wire fraud, alleging he billed victims over $19 million while secretly paying ransom gangs.
US Offers $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks
October 8, 2026
The State Department's Rewards for Justice program offers up to $10 million for information on Zhang Yu, a Chinese national indicted over the HAFNIUM hacks.
Georgia Power, Alabama Power Portal Breach Hits 400,000 Accounts
October 8, 2026
An unauthorized party accessed the Georgia Power and Alabama Power customer portal, exposing about 400,000 accounts, including partial SSNs and contact data.
Chrome 155 Patches 247 Vulnerabilities, Including Four Critical
October 8, 2026
Google released Chrome 155 with fixes for 247 vulnerabilities, four of them critical use-after-free flaws. Google reports no in-the-wild exploitation.
Four US States Sue TP-Link Over China Risks and Security Claims
October 8, 2026
Florida, Iowa, Montana and Nebraska sued router maker TP-Link, alleging misleading security claims and concealed China ties. TP-Link calls the claims baseless.
Atlassian CVE-2026-21589 Exploited Within Two Hours of PoC Details
October 8, 2026
Attackers probed Atlassian Data Center flaw CVE-2026-21589 within two hours of watchTowr publishing details; Previdian logged 15 attempts from three IPs.
Adversa AI: Encrypted Instructions Can Make Copilot CLI Leak Secrets
October 8, 2026
Adversa AI says encrypted prompt injections on web pages can trick GitHub Copilot CLI into leaking .env secrets. GitHub declined to call it a vulnerability.
ASOS Confirms Breach After Hackers Hijack App Push Notifications
October 7, 2026
ASOS confirmed a breach after attackers sent a fake push alert claiming a Snowflake hack; names and contact details may be exposed, but not card ...
Ninja Forms, WPC Product Bundles XSS Flaws Used to Backdoor Sites
October 7, 2026
Attackers are exploiting stored XSS flaws in Ninja Forms and WPC Product Bundles to install a fake plugin with four persistence mechanisms on WordPress.
Pwn2Own Ireland 2026 Day One: 32 Zero-Days, $388,500 in Payouts
October 7, 2026
Researchers demonstrated 32 unique zero-day exploits on day one of Pwn2Own Ireland 2026, earning $388,500 against phones, routers, printers and AI platforms.
Attackers Scan for Rejetto HFS Session-Forgery Flaw CVE-2026-61500
October 7, 2026
Scanning has begun for CVE-2026-61500 in Rejetto HFS, a flaw that lets attackers forge admin cookies and reach remote code execution on versions 3.0.0-3.2.0.
Dell Patches Root-Level Flaw CVE-2026-86360 in System Update Tool
October 7, 2026
Dell fixed a critical path traversal, CVE-2026-86360, in its System Update CLI that lets unauthenticated remote attackers run code as root, plus four more bugs.
Android October 2026 Update Patches 25 Flaws, Seven Rated Critical
October 7, 2026
Google's Android security bulletin for patch level 2026-10-01 fixes 25 vulnerabilities, seven of them critical, with no in-the-wild exploitation reported.
LibreOffice, OpenOffice Flaws Run Code From Spreadsheets Silently
October 7, 2026
CVE-2026-63277 in LibreOffice and CVE-2026-59265 in Apache OpenOffice let malicious spreadsheets run code through JDBC drivers with no macro warning shown.
Gentlemen Ransomware Affiliate Used MCP as Command Channel
October 7, 2026
CloudSEK found Gentlemen RaaS affiliate Azazel using Model Context Protocol as a command channel in live intrusions that hit 24-plus victims in six countries.
UIC College of Medicine Hit by Booba Ransomware, 344 GB Claimed
October 7, 2026
The University of Illinois Chicago says data was taken from College of Medicine servers; the Booba ransomware gang claims 344 GB stolen from the school.
Denmark CPR Breach Exposes Data of 8.8 Million People
October 6, 2026
Attackers abused a private firm's lawful lookup rights to pull names, addresses and CPR numbers of 8.8 million people from Denmark's Central Person Register.






















