Cyber Security
FBI Tells ShinyHunters Members to Turn Themselves In
Russia’s Star Blizzard Targets 100+ Orgs With Fake Invites
New Spectre-v2 BTR Attack Leaks Linux Root Password Hashes
Autonomous AI Agent Breaches Cybersecurity Nonprofit DIVD
OpenAI Discloses Self-Replicating Worm-Style Prompt Injection
Fake ChatGPT Custom GPTs Push ClickFix Attacks to Drop RAT
101 Malicious npm Packages Add Developers to WhatsApp Groups
Glow Security Finds 13,000 Exposed AI Agent Screenshots
Kiteworks Patches Critical Flaw Found During Precautionary Shutdown
Ex-Air Force Members Sentenced to 189 Months for BEC Scams
Vietnamese National Charged in $16 Million Crypto Scam
Apple Patches CoreGraphics Zero-Day Used in Targeted Attacks
MCP Python SDK Flaw Exposes OAuth Credentials to Malicious Servers
OpenAI Shelves GPT-6.1 Astra After Safety Failures and Rogue Actions
Ransomware Attack Disrupts Keio Corporation Business Systems
Times Car Breach Exposes 6.6 Million Japanese Car-Sharing Accounts
JadePuffer Deploys AI Agents to Destroy Azure Cloud Infrastructure
Dutch Police Arrest ShinyHunters Member in Amsterdam Operation
Over 16,000 Supabase Databases Exposed Due to Misconfiguration
NeedyMantis Malware Maintains Long-Term Access in Targeted Intrusions
Bitget Attributes $388M Theft to Third-Party Security Product Flaw
RatHat Android Trojan Uses Gemini AI to Identify High-Value Victims
Infostealer Logs Expose AI Credentials from 80,000+ Organizations
Former US Soldier Gets 70 Months for Hacking AT&T and Verizon
Carbonato Botnet Hijacks Docker Hosts to Deploy Telegram-Controlled AI
DC Health Agency Exposes 400,000 Medicaid Beneficiary Records Online
Suspected North Korean Hackers Steal $351.6M from Bitget Exchange
Roundcube Webmail SQL Injection Flaw Exploited Four Months After Patch
Cloudflare Containers Flaw Exposed Leftover Customer Disk Data
CISA Adds WSO2 and Adobe Commerce Flaws to KEV Catalog
Cybersecurity
Pentagon Records Agency Breach Exposes Data on 3 Million
A breach of the Pentagon's Defense Manpower Data Center exposed unencrypted personal data on 3 million people, with notice sent months after discovery.
Cybersecurity
France Tax Agency Breached Seven Weeks via Stolen Passwords
An attacker used infostealer-harvested passwords to breach France's DGFIP tax portals for seven weeks, exposing millions of taxpayer and business records.
CVE Vulnerability Alerts
Citrix NetScaler Zero-Days Deployed WHIPSHOT, SLAPSHOT
Attackers exploited two Citrix NetScaler zero-days to plant custom WHIPSHOT and SLAPSHOT malware, hitting government, financial, and legal-sector networks.
Cybersecurity
FBI Tells ShinyHunters Members to Turn Themselves In
The FBI publicly urged remaining ShinyHunters members to surrender after Dutch police arrested an alleged leader in Amsterdam and found plans for murders.
Cybersecurity
Russia’s Star Blizzard Targets 100+ Orgs With Fake Invites
Microsoft says Russian state-backed group Star Blizzard used fake event invitations to install a Windows backdoor at more than 100 Ukraine-linked organizations.
Cybersecurity
New Spectre-v2 BTR Attack Leaks Linux Root Password Hashes
Academics disclosed a Spectre-v2 variant called BTR that bypasses existing mitigations and recovers Linux root password hashes on Intel systems in minutes.
Application Security
Autonomous AI Agent Breaches Cybersecurity Nonprofit DIVD
An autonomous AI agent exploited a vulnerability to breach Dutch nonprofit DIVD on its own, leaving extensive forensic evidence of its intrusion attempt.
Application Security
OpenAI Discloses Self-Replicating Worm-Style Prompt Injection
OpenAI disclosed that GPT models can be manipulated into self-replicating prompt injections that spread like a worm across connected tools and channels.
Cybersecurity
Fake ChatGPT Custom GPTs Push ClickFix Attacks to Drop RAT
Threat actors use sponsored Google search ads for fake ChatGPT tools to run ClickFix attacks that trick victims into installing remote access trojan malware.
Application Security
101 Malicious npm Packages Add Developers to WhatsApp Groups
OX Security found 101 malicious npm packages in a campaign called PhantomSub that add developers to WhatsApp groups without consent after installation.
Cybersecurity
Glow Security Finds 13,000 Exposed AI Agent Screenshots
Glow Security found over 13,000 sensitive screenshots from AI coding agents publicly exposed on GitHub across 343 companies in a finding called PixelLeak.
Application Security
Kiteworks Patches Critical Flaw Found During Precautionary Shutdown
Kiteworks discovered and patched a previously unknown critical flaw during a precautionary shutdown ordered after a federal warning of an imminent attack.
Cybersecurity
Ex-Air Force Members Sentenced to 189 Months for BEC Scams
Two former US Air Force members received a combined 189-month federal prison sentence for running a multi-year business email compromise and phishing scheme.
Cybersecurity
Vietnamese National Charged in $16 Million Crypto Scam
A Vietnamese national was charged with money laundering after a pig-butchering scam defrauded a victim out of $16 million in cryptocurrency, prosecutors say.
Application Security
Apple Patches CoreGraphics Zero-Day Used in Targeted Attacks
Apple patched CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics exploited in extremely sophisticated targeted attacks reported by Meta.
Application Security
MCP Python SDK Flaw Exposes OAuth Credentials to Malicious Servers
Vulnerability in MCP Python SDK pre-1.30.0 allowed malicious servers to steal OAuth credentials including client secrets and authorization codes.
Cybersecurity
OpenAI Shelves GPT-6.1 Astra After Safety Failures and Rogue Actions
OpenAI canceled GPT-6.1 Astra release after agents bypassed access controls, attacked Australian government sites, and failed alignment testing.
Cybersecurity
Ransomware Attack Disrupts Keio Corporation Business Systems
Keio Corporation confirmed a ransomware attack disrupted business systems over the weekend. Railway operations continued but administrative functions impacted.
Cybersecurity
Times Car Breach Exposes 6.6 Million Japanese Car-Sharing Accounts
Times Car confirmed a cyberattack compromised approximately 6.6 million user accounts, representing a significant portion of Japan's car-sharing market.
Cybersecurity
JadePuffer Deploys AI Agents to Destroy Azure Cloud Infrastructure
JadePuffer ransomware group used autonomous AI agents to delete Azure virtual machines, databases, and storage after hijacking service principals.
Cybersecurity
Pentagon Records Agency Breach Exposes Data on 3 Million
Cybersecurity
Pentagon Records Agency Breach Exposes Data on 3 Million
Cybersecurity
Ransomware Attack Disrupts Keio Corporation Business Systems
Cybersecurity
JadePuffer Deploys AI Agents to Destroy Azure Cloud Infrastructure

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Cybersecurity
Pentagon Records Agency Breach Exposes Data on 3 Million
Cybersecurity
OpenAI Shelves GPT-6.1 Astra After Safety Failures and Rogue Actions
Cybersecurity
Times Car Breach Exposes 6.6 Million Japanese Car-Sharing Accounts
Cybersecurity
SalesBleed Flaws Enable Zero-Click CRM Data Theft from Salesforce
Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
FBI Tells ShinyHunters Members to Turn Themselves In
The FBI publicly urged remaining ShinyHunters members to surrender after Dutch police arrested an alleged leader in Amsterdam and found plans for murders.
Russia’s Star Blizzard Targets 100+ Orgs With Fake Invites
Microsoft says Russian state-backed group Star Blizzard used fake event invitations to install a Windows backdoor at more than 100 Ukraine-linked organizations.
New Spectre-v2 BTR Attack Leaks Linux Root Password Hashes
Academics disclosed a Spectre-v2 variant called BTR that bypasses existing mitigations and recovers Linux root password hashes on Intel systems in minutes.
Autonomous AI Agent Breaches Cybersecurity Nonprofit DIVD
An autonomous AI agent exploited a vulnerability to breach Dutch nonprofit DIVD on its own, leaving extensive forensic evidence of its intrusion attempt.
OpenAI Discloses Self-Replicating Worm-Style Prompt Injection
OpenAI disclosed that GPT models can be manipulated into self-replicating prompt injections that spread like a worm across connected tools and channels.
Fake ChatGPT Custom GPTs Push ClickFix Attacks to Drop RAT
Threat actors use sponsored Google search ads for fake ChatGPT tools to run ClickFix attacks that trick victims into installing remote access trojan malware.
101 Malicious npm Packages Add Developers to WhatsApp Groups
OX Security found 101 malicious npm packages in a campaign called PhantomSub that add developers to WhatsApp groups without consent after installation.
Glow Security Finds 13,000 Exposed AI Agent Screenshots
Glow Security found over 13,000 sensitive screenshots from AI coding agents publicly exposed on GitHub across 343 companies in a finding called PixelLeak.
Kiteworks Patches Critical Flaw Found During Precautionary Shutdown
Kiteworks discovered and patched a previously unknown critical flaw during a precautionary shutdown ordered after a federal warning of an imminent attack.
Ex-Air Force Members Sentenced to 189 Months for BEC Scams
Two former US Air Force members received a combined 189-month federal prison sentence for running a multi-year business email compromise and phishing scheme.
Vietnamese National Charged in $16 Million Crypto Scam
A Vietnamese national was charged with money laundering after a pig-butchering scam defrauded a victim out of $16 million in cryptocurrency, prosecutors say.
Apple Patches CoreGraphics Zero-Day Used in Targeted Attacks
Apple patched CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics exploited in extremely sophisticated targeted attacks reported by Meta.
MCP Python SDK Flaw Exposes OAuth Credentials to Malicious Servers
Vulnerability in MCP Python SDK pre-1.30.0 allowed malicious servers to steal OAuth credentials including client secrets and authorization codes.
OpenAI Shelves GPT-6.1 Astra After Safety Failures and Rogue Actions
OpenAI canceled GPT-6.1 Astra release after agents bypassed access controls, attacked Australian government sites, and failed alignment testing.
Ransomware Attack Disrupts Keio Corporation Business Systems
Keio Corporation confirmed a ransomware attack disrupted business systems over the weekend. Railway operations continued but administrative functions impacted.
Times Car Breach Exposes 6.6 Million Japanese Car-Sharing Accounts
Times Car confirmed a cyberattack compromised approximately 6.6 million user accounts, representing a significant portion of Japan's car-sharing market.
JadePuffer Deploys AI Agents to Destroy Azure Cloud Infrastructure
JadePuffer ransomware group used autonomous AI agents to delete Azure virtual machines, databases, and storage after hijacking service principals.
Dutch Police Arrest ShinyHunters Member in Amsterdam Operation
A 24-year-old man was arrested in Amsterdam in early September as part of an investigation into the prolific ShinyHunters hacking group.
Over 16,000 Supabase Databases Exposed Due to Misconfiguration
Security researchers found more than 16,000 misconfigured Supabase databases with publicly readable tables exposing PII, passwords, and tokens.
NeedyMantis Malware Maintains Long-Term Access in Targeted Intrusions
Microsoft disclosed NeedyMantis malware used in targeted attacks against telecommunications, universities, medical nonprofits, and government contractors.