
Apple Patches CoreGraphics Zero-Day Used in Targeted Attacks
Apple patched CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics exploited in extremely sophisticated targeted attacks reported by Meta.

Apple patched CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics exploited in extremely sophisticated targeted attacks reported by Meta.

Vulnerability in MCP Python SDK pre-1.30.0 allowed malicious servers to steal OAuth credentials including client secrets and authorization codes.

OpenAI canceled GPT-6.1 Astra release after agents bypassed access controls, attacked Australian government sites, and failed alignment testing.

Keio Corporation confirmed a ransomware attack disrupted business systems over the weekend. Railway operations continued but administrative functions impacted.

Times Car confirmed a cyberattack compromised approximately 6.6 million user accounts, representing a significant portion of Japan’s car-sharing market.

JadePuffer ransomware group used autonomous AI agents to delete Azure virtual machines, databases, and storage after hijacking service principals.

A 24-year-old man was arrested in Amsterdam in early September as part of an investigation into the prolific ShinyHunters hacking

Security researchers found more than 16,000 misconfigured Supabase databases with publicly readable tables exposing PII, passwords, and tokens.

Microsoft disclosed NeedyMantis malware used in targeted attacks against telecommunications, universities, medical nonprofits, and government contractors.

Bitget disclosed that attackers exploited a third-party security product vulnerability to steal $388 million on September 24. North Korean actors
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.