Cyber Security
Cybersecurity
Pentagon Records Agency Breach Exposes Data on 3 Million
Gabby Lee
September 30, 2026
A breach of the Pentagon's Defense Manpower Data Center exposed unencrypted personal data on 3 million people, with notice sent months after discovery.
Cybersecurity
France Tax Agency Breached Seven Weeks via Stolen Passwords
Mitchell Langley
September 30, 2026
An attacker used infostealer-harvested passwords to breach France's DGFIP tax portals for seven weeks, exposing millions of taxpayer and business records.
CVE Vulnerability Alerts
Citrix NetScaler Zero-Days Deployed WHIPSHOT, SLAPSHOT
Gabby Lee
September 30, 2026
Attackers exploited two Citrix NetScaler zero-days to plant custom WHIPSHOT and SLAPSHOT malware, hitting government, financial, and legal-sector networks.
Cybersecurity
FBI Tells ShinyHunters Members to Turn Themselves In
Gabby Lee
September 30, 2026
The FBI publicly urged remaining ShinyHunters members to surrender after Dutch police arrested an alleged leader in Amsterdam and found plans for murders.
Cybersecurity
Russia’s Star Blizzard Targets 100+ Orgs With Fake Invites
Gabby Lee
September 30, 2026
Microsoft says Russian state-backed group Star Blizzard used fake event invitations to install a Windows backdoor at more than 100 Ukraine-linked organizations.
Cybersecurity
New Spectre-v2 BTR Attack Leaks Linux Root Password Hashes
Mitchell Langley
September 30, 2026
Academics disclosed a Spectre-v2 variant called BTR that bypasses existing mitigations and recovers Linux root password hashes on Intel systems in minutes.
Application Security
Autonomous AI Agent Breaches Cybersecurity Nonprofit DIVD
Gabby Lee
September 30, 2026
An autonomous AI agent exploited a vulnerability to breach Dutch nonprofit DIVD on its own, leaving extensive forensic evidence of its intrusion attempt.
Application Security
OpenAI Discloses Self-Replicating Worm-Style Prompt Injection
Mitchell Langley
September 30, 2026
OpenAI disclosed that GPT models can be manipulated into self-replicating prompt injections that spread like a worm across connected tools and channels.
Cybersecurity
Fake ChatGPT Custom GPTs Push ClickFix Attacks to Drop RAT
Gabby Lee
September 30, 2026
Threat actors use sponsored Google search ads for fake ChatGPT tools to run ClickFix attacks that trick victims into installing remote access trojan malware.
Application Security
101 Malicious npm Packages Add Developers to WhatsApp Groups
Gabby Lee
September 30, 2026
OX Security found 101 malicious npm packages in a campaign called PhantomSub that add developers to WhatsApp groups without consent after installation.
Cybersecurity
Glow Security Finds 13,000 Exposed AI Agent Screenshots
Gabby Lee
September 30, 2026
Glow Security found over 13,000 sensitive screenshots from AI coding agents publicly exposed on GitHub across 343 companies in a finding called PixelLeak.
Application Security
Kiteworks Patches Critical Flaw Found During Precautionary Shutdown
Mitchell Langley
September 30, 2026
Kiteworks discovered and patched a previously unknown critical flaw during a precautionary shutdown ordered after a federal warning of an imminent attack.
Cybersecurity
Ex-Air Force Members Sentenced to 189 Months for BEC Scams
Gabby Lee
September 30, 2026
Two former US Air Force members received a combined 189-month federal prison sentence for running a multi-year business email compromise and phishing scheme.
Cybersecurity
Vietnamese National Charged in $16 Million Crypto Scam
Gabby Lee
September 30, 2026
A Vietnamese national was charged with money laundering after a pig-butchering scam defrauded a victim out of $16 million in cryptocurrency, prosecutors say.
Application Security
Apple Patches CoreGraphics Zero-Day Used in Targeted Attacks
Gabby Lee
September 29, 2026
Apple patched CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics exploited in extremely sophisticated targeted attacks reported by Meta.
Application Security
MCP Python SDK Flaw Exposes OAuth Credentials to Malicious Servers
Mitchell Langley
September 29, 2026
Vulnerability in MCP Python SDK pre-1.30.0 allowed malicious servers to steal OAuth credentials including client secrets and authorization codes.
Cybersecurity
OpenAI Shelves GPT-6.1 Astra After Safety Failures and Rogue Actions
Mitchell Langley
September 29, 2026
OpenAI canceled GPT-6.1 Astra release after agents bypassed access controls, attacked Australian government sites, and failed alignment testing.
Cybersecurity
Ransomware Attack Disrupts Keio Corporation Business Systems
Mitchell Langley
September 29, 2026
Keio Corporation confirmed a ransomware attack disrupted business systems over the weekend. Railway operations continued but administrative functions impacted.
Cybersecurity
Times Car Breach Exposes 6.6 Million Japanese Car-Sharing Accounts
Gabby Lee
September 29, 2026
Times Car confirmed a cyberattack compromised approximately 6.6 million user accounts, representing a significant portion of Japan's car-sharing market.
Cybersecurity
JadePuffer Deploys AI Agents to Destroy Azure Cloud Infrastructure
Mitchell Langley
September 29, 2026
JadePuffer ransomware group used autonomous AI agents to delete Azure virtual machines, databases, and storage after hijacking service principals.
Cybersecurity
Ransomware Attack Disrupts Keio Corporation Business Systems
Mitchell Langley
September 29, 2026
Cybersecurity
JadePuffer Deploys AI Agents to Destroy Azure Cloud Infrastructure
Mitchell Langley
September 29, 2026
TOP CYBERSECURITY HEADLINES
Cybersecurity
FBI Tells ShinyHunters Members to Turn Themselves In
Application Security
Autonomous AI Agent Breaches Cybersecurity Nonprofit DIVD
This Week’s Security Spotlight
Cybersecurity
OpenAI Shelves GPT-6.1 Astra After Safety Failures and Rogue Actions
Mitchell Langley
September 29, 2026
Cybersecurity
Times Car Breach Exposes 6.6 Million Japanese Car-Sharing Accounts
Gabby Lee
September 29, 2026
Cybersecurity
SalesBleed Flaws Enable Zero-Click CRM Data Theft from Salesforce
Andrew Doyle
September 25, 2026
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Featured Videos
Podcasts
Cyber Security News
- All
- Application Security
- Blog
- CVE Vulnerability Alerts
- Cybersecurity
- Cybersecurity Newsletter
- Data Security
- Endpoint Security
- Identity and Access Management
- Information Security
- Network Security
- News
- Phishing
- Podcasts
- Product Reviews
- Ransomware
- Ransomware Victims
- Resources
- Security Spotlight
- Sponsored
- Threat Actors
- Threat Actors
- Threat Detection Tools
FBI Tells ShinyHunters Members to Turn Themselves In
September 30, 2026
The FBI publicly urged remaining ShinyHunters members to surrender after Dutch police arrested an alleged leader in Amsterdam and found plans for murders.
Russia’s Star Blizzard Targets 100+ Orgs With Fake Invites
September 30, 2026
Microsoft says Russian state-backed group Star Blizzard used fake event invitations to install a Windows backdoor at more than 100 Ukraine-linked organizations.
New Spectre-v2 BTR Attack Leaks Linux Root Password Hashes
September 30, 2026
Academics disclosed a Spectre-v2 variant called BTR that bypasses existing mitigations and recovers Linux root password hashes on Intel systems in minutes.
Autonomous AI Agent Breaches Cybersecurity Nonprofit DIVD
September 30, 2026
An autonomous AI agent exploited a vulnerability to breach Dutch nonprofit DIVD on its own, leaving extensive forensic evidence of its intrusion attempt.
OpenAI Discloses Self-Replicating Worm-Style Prompt Injection
September 30, 2026
OpenAI disclosed that GPT models can be manipulated into self-replicating prompt injections that spread like a worm across connected tools and channels.
Fake ChatGPT Custom GPTs Push ClickFix Attacks to Drop RAT
September 30, 2026
Threat actors use sponsored Google search ads for fake ChatGPT tools to run ClickFix attacks that trick victims into installing remote access trojan malware.
101 Malicious npm Packages Add Developers to WhatsApp Groups
September 30, 2026
OX Security found 101 malicious npm packages in a campaign called PhantomSub that add developers to WhatsApp groups without consent after installation.
Glow Security Finds 13,000 Exposed AI Agent Screenshots
September 30, 2026
Glow Security found over 13,000 sensitive screenshots from AI coding agents publicly exposed on GitHub across 343 companies in a finding called PixelLeak.
Kiteworks Patches Critical Flaw Found During Precautionary Shutdown
September 30, 2026
Kiteworks discovered and patched a previously unknown critical flaw during a precautionary shutdown ordered after a federal warning of an imminent attack.
Ex-Air Force Members Sentenced to 189 Months for BEC Scams
September 30, 2026
Two former US Air Force members received a combined 189-month federal prison sentence for running a multi-year business email compromise and phishing scheme.
Vietnamese National Charged in $16 Million Crypto Scam
September 30, 2026
A Vietnamese national was charged with money laundering after a pig-butchering scam defrauded a victim out of $16 million in cryptocurrency, prosecutors say.
Apple Patches CoreGraphics Zero-Day Used in Targeted Attacks
September 29, 2026
Apple patched CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics exploited in extremely sophisticated targeted attacks reported by Meta.
MCP Python SDK Flaw Exposes OAuth Credentials to Malicious Servers
September 29, 2026
Vulnerability in MCP Python SDK pre-1.30.0 allowed malicious servers to steal OAuth credentials including client secrets and authorization codes.
OpenAI Shelves GPT-6.1 Astra After Safety Failures and Rogue Actions
September 29, 2026
OpenAI canceled GPT-6.1 Astra release after agents bypassed access controls, attacked Australian government sites, and failed alignment testing.
Ransomware Attack Disrupts Keio Corporation Business Systems
September 29, 2026
Keio Corporation confirmed a ransomware attack disrupted business systems over the weekend. Railway operations continued but administrative functions impacted.
Times Car Breach Exposes 6.6 Million Japanese Car-Sharing Accounts
September 29, 2026
Times Car confirmed a cyberattack compromised approximately 6.6 million user accounts, representing a significant portion of Japan's car-sharing market.
JadePuffer Deploys AI Agents to Destroy Azure Cloud Infrastructure
September 29, 2026
JadePuffer ransomware group used autonomous AI agents to delete Azure virtual machines, databases, and storage after hijacking service principals.
Dutch Police Arrest ShinyHunters Member in Amsterdam Operation
September 29, 2026
A 24-year-old man was arrested in Amsterdam in early September as part of an investigation into the prolific ShinyHunters hacking group.
Over 16,000 Supabase Databases Exposed Due to Misconfiguration
September 29, 2026
Security researchers found more than 16,000 misconfigured Supabase databases with publicly readable tables exposing PII, passwords, and tokens.
NeedyMantis Malware Maintains Long-Term Access in Targeted Intrusions
September 29, 2026
Microsoft disclosed NeedyMantis malware used in targeted attacks against telecommunications, universities, medical nonprofits, and government contractors.





















