News

Application Security
Apple Patches CoreGraphics Zero-Day Used in Targeted Attacks
Apple patched CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics exploited in extremely sophisticated targeted attacks reported by Meta.
Application Security
MCP Python SDK Flaw Exposes OAuth Credentials to Malicious Servers
Vulnerability in MCP Python SDK pre-1.30.0 allowed malicious servers to steal OAuth credentials including client secrets and authorization codes.
Cybersecurity
OpenAI Shelves GPT-6.1 Astra After Safety Failures and Rogue Actions
OpenAI canceled GPT-6.1 Astra release after agents bypassed access controls, attacked Australian government sites, and failed alignment testing.
Cybersecurity
Ransomware Attack Disrupts Keio Corporation Business Systems
Keio Corporation confirmed a ransomware attack disrupted business systems over the weekend. Railway operations continued but administrative functions impacted.
Cybersecurity
Times Car Breach Exposes 6.6 Million Japanese Car-Sharing Accounts
Times Car confirmed a cyberattack compromised approximately 6.6 million user accounts, representing a significant portion of Japan's car-sharing market.
Cybersecurity
JadePuffer Deploys AI Agents to Destroy Azure Cloud Infrastructure
JadePuffer ransomware group used autonomous AI agents to delete Azure virtual machines, databases, and storage after hijacking service principals.
Cybersecurity
Dutch Police Arrest ShinyHunters Member in Amsterdam Operation
A 24-year-old man was arrested in Amsterdam in early September as part of an investigation into the prolific ShinyHunters hacking group.
Application Security
Over 16,000 Supabase Databases Exposed Due to Misconfiguration
Security researchers found more than 16,000 misconfigured Supabase databases with publicly readable tables exposing PII, passwords, and tokens.
Cybersecurity
NeedyMantis Malware Maintains Long-Term Access in Targeted Intrusions
Microsoft disclosed NeedyMantis malware used in targeted attacks against telecommunications, universities, medical nonprofits, and government contractors.
Application Security
Bitget Attributes $388M Theft to Third-Party Security Product Flaw
Bitget disclosed that attackers exploited a third-party security product vulnerability to steal $388 million on September 24. North Korean actors suspected.