THE HUNTER’S LEDGER
The Wire
Threat Intelligence Headlines
Recent threat-intel reporting from public sources, refreshed every hour. Headlines and links only, every item goes to the original publisher. This is aggregation rather than original research. My original research can be found in the reports section.

Updated 8 October 2026, 07:02 UTC · 600 items from the last 30 days

Generated from my own OpenCTI instance, not scraped

The headlines are other people’s reporting, but the pipeline is mine. Every item here comes out of the OpenCTI threat-intelligence platform I run and maintain myself, the same instance that holds the STIX bundles for every report I publish and feeds the blocklists on my own network. It refreshes every hour, straight from that platform.

Thursday 8 October 2026
BleepingComputerSamsung Galaxy S26 hacked three more times at Pwn2Own Ireland
Wednesday 7 October 2026
BleepingComputerRansomware recovery CEO charged over secret ransom paymentsransomwarePalo Alto NetworksEvolution of Web3 in Cloud Supply Chain Attackssupply chaincloudBleepingComputerFBI: Ongoing FortiBleed attacks lock out FortiGate VPN adminsBleepingComputerHackers hijack Google domains after breaching ccTLD registriesdata breachesgoogleRecorded FutureUS posts $10 million reward for accused Chinese ‘Hafnium’ hackerchinacybercrimeCisco TalosMicrosoft, Adobe, Apple, and Foxit vulnerabilitiesvulnerabilitiesvulnerability roundupRecorded FutureArizona courts say hackers stole info on more than 1.3 million peoplecybercrimegovernmentBleepingComputerPoeLLM malware infects exposed AI servers in cryptomining attacksartificial intelligencemalwareSANS Internet Storm CenterScans for Atlassian vulnerablity (CVE-2026-21589), (Wed, Oct 7th)vulnerabilitiesSecurityWeekGeorgia Power, Alabama Power Data Breach Hits 400,000 Accountsdata breachesgeorgia powerRecorded FutureCyber experts call on CISA to create mandatory federal OT rulescybercrimegovernmentBleepingComputerRansomware has a new target. Is your backup ready?ransomwareRecorded FutureSenate passes healthcare cybersecurity bill after 190 million impacted by Change Healthcare breachdata breachescybercrimeKrebs on SecurityShinyHunters Extorted Boeing Spin-off Prior to Arrestslaw enforcementbenjamin korperSecurityWeekQilin Ransomware Suspect Arrested in Japan, Extradited to Germanyransomwarelaw enforcementRecorded FutureFBI, Secret Service add to warnings of FortiBleed credential stealing campaigncybercrimeBleepingComputerHackers exploit critical Atlassian flaw after public PoC releasevulnerabilitiesSecurityWeekAdvantest Discloses Data Breach Months After Ransomware Attackransomwaredata breachesRapid7CVE-2026-21589: Critical unauthenticated arbitrary file access in Atlassian productsvulnerabilitiesemergent threat responseAlienVaultBehind the Connect Button: The Fake AI Ads Campaignartificial intelligenceadvertising accountsSecurityWeekChrome 155 Update Patches 247 VulnerabilitiesvulnerabilitieschromeRapid7The ASOS incident: When attackers use the channels customers trusthackingBleepingComputerMusician sent to prison for $10 million streaming fraud using AI botsartificial intelligenceBleepingComputerAdvantest confirms personal information stolen in ransomware attackransomwareCisco TalosOne breach, please, and make no mistakesdata breacheson the radarAlienVaultIranian State-Aligned Threat Actor Masquerading as Dubai Airports IT Department Delivering Trojanized Coding Challenges - Blinder Tunnel Campaign Targeting Iraqi Critical Infrastructuremalwareappdomainmanager hijackingSecurityWeekASOS Confirms Cyberattack, Data Breachdata breachesasosAlienVaultAkira Ransomware Attack InvestigationransomwareakiraZero Day InitiativePwn2Own Ireland 2026 - Day Two Resultsblog postAlienVaultAttackers Target AI Development Platform Langflowartificial intelligenceai platform exploitationSecurityWeekAndroid’s October 2026 Updates Patch 25 VulnerabilitiesmobilevulnerabilitiesSecurityWeekAtlassian Patches Critical Vulnerability Affecting 8 ProductsvulnerabilitiesatlassianCrowdstrikeUnknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Financeartificial intelligencethreat hunting & intelCrowdstrikeCrowdStrike Named a Leader in the 2026 IDC MarketScape for Worldwide Modern Endpoint Security for Enterprises Vendor Assessmentendpoint security & xdrSecurityWeekPersonal Information for Over 1 Million People Stolen in a Cyberattack on Arizona’s Court Systemdata breaches
Tuesday 6 October 2026
BleepingComputerNinja Forms plugin flaw exploited to hack WordPress sitesexploitedvulnerabilitiesBleepingComputerHackers exploit 32 zero-days on first day of Pwn2Own Irelandzero-dayAlienVaultBeyond valid credentials: How exposed AWS keys are tested for Amazon Bedrock accesscloudamazon bedrockBleepingComputerASOS confirms data breach after “HACKED” in-app notificationsdata breachesRecorded FutureAlleged ATM malware creator appears in Nebraska court after arrestlaw enforcementmalwareRecorded FutureSouth Korean officials believe AI agents were used to hack several banksartificial intelligencegovernmentRecorded FutureOsaka Metropolitan University cancels classes after suspected ransomware attackransomwarecybercrimeSecurityWeekFBI Blames Contractor’s Missed Patch for ShinyHunters Breachdata breachescybercrimeRecorded FutureClickFix campaign in Ukraine compromises over 100 websites to spread Lunex malwaresocial engineeringmalwareSecurityWeekFBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malwarelaw enforcementmalwareSecurityWeekLong-Running NPM Malware Campaign Accumulates 40,000 Downloadssupply chainmalwarePalo Alto NetworksBlinder Tunnel Campaign Targets Iraqi Infrastructureagent serpensadvanced persistent threatSecurityWeek8.8 Million Impacted by Data Breach at Denmark’s Central Person Registerdata breachesdenmarkZero Day InitiativePwn2Own Ireland 2026 - Day One Resultsblog postBleepingComputerNikkei discloses breaches of employees’ Microsoft, Google email accountsdata breachesAlienVaultLunex Uses BYOVD to Disable Security Monitoring and Deploy Persistent Stealerinfostealeramd driver vulnerabilityGoogle Project ZeroHow to fix a bug in a fixCrowdstrikeRequest, Aggregate, Bypass: How Attackers Can Evade LLM Safety Classifiersartificial intelligencesecuring aiRecorded FutureShares in British clothing company ASOS dive after hackers apparently send push notificationcybercrimeindustry
Monday 5 October 2026
AlienVaultClingSTUN Linux Backdoor Abuses Public STUN InfrastructuremalwareclingstunRecorded FutureWikimedia Foundation: OpenAI agents tried to edit pages and compromise notes toolartificial intelligenceBleepingComputerRejetto HFS servers now actively scanned for critical RCE flawvulnerabilitiesZero Day InitiativePwn2Own Ireland 2026 - The Full Scheduleblog postRecorded FutureUS, Australia warn of latest Citrix vulnerability after NetScaler advisoryvulnerabilitiescybercrimeRecorded FutureUkraine grocery chain ATB confirms cyberattack as hackers threaten to leak datacybercrimeprivacyRecorded FutureUniversity of Illinois Chicago affected by ransomware attack on medical schoolransomwarecybercrimeBleepingComputerDenmark population registry data breach affects 8.8 million peopledata breachesgovernmentBleepingComputerNew Dell System Update flaw lets hackers gain root privilegesvulnerabilitiesBleepingComputerSouth Korea probes bank breaches amid suspected AI-powered attacksdata breachesartificial intelligenceRecorded FutureBelarusian hacktivists spent two years inside Russian healthcare network, researchers saycybercrimeindustryAlienVaultCaught in 4K: The Gentlemen Filesai-platformci/cdBleepingComputerAlleged dev of Ploutus ATM malware appears in US court after arrestlaw enforcementmalwareSecurityWeekLinux Backdoor Abuses STUN Protocol, Exploits Dozens of FlawsvulnerabilitiesmalwareSecurityWeek250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firmsdata breacheshealthcareRecorded FutureData breach at Denmark’s national population register exposes 8.8 million peopledata breachescybercrimeSecurityWeekExploitation Hits Rejetto HFS Vulnerability Discovered by AIexploitedartificial intelligenceAlienVaultA STUNning Disguise: Cling Malware Masquerades as GooglemalwareclingSecurityWeekAlleged ShinyHunters Leader Arrested in Jordanlaw enforcementreyAlienVaultXWorm Malware: Worming Its Way From Entry to ExploitationexploitedmalwareSecurityWeekExploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlierzero-dayexploitedCrowdstrikeNew in Falcon Cloud Security: Third-Party App Insights and AI-Enhanced Remediationcloudartificial intelligenceCrowdstrikeFalcon Data Security for SaaS Secures Sensitive Data in Microsoft 365clouddata securityElasticBehind the tags: How Elastic SIEM grades 1,781 detection rules on noise, speed, and threat coveragedetection engineering
Sunday 4 October 2026
BleepingComputerCitrix patches NetScaler SAML zero-day exploited in attackszero-dayexploited
Saturday 3 October 2026
BleepingComputerShinyHunters hacker reportedly detained in Jordan, aiding FBIBleepingComputerDanish university DTU breach exposes data of up to 200,000 peopledata breachesSecurityWeekFortra Patches Critical Vulnerabilities in BoKSvulnerabilitiesboksAlienVaultPretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSXcredential theftdead-drop
Friday 2 October 2026
Recorded FutureJudge dismisses spyware case brought by Salvadoran journalists targeted with PegasusmalwaregovernmentBleepingComputerFrontline Education breach exposes school district employee datadata breachesBleepingComputerWarlock ransomware breach SharePoint in water, telecom operator attacksransomwaredata breachesBleepingComputerGitLab warns of critical RCE vulnerability in AI Gateway serviceartificial intelligencevulnerabilitiesBleepingComputerUS sanctions Tren de Aragua gang members in ATM hacks crackdownSecurityWeekIn Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chatsphishingartificial intelligenceRecorded FutureMississippi mayor says ransomware incident led city to shut down systemsransomwarecybercrimeRecorded Future'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countriesransomwarecybercrimeBleepingComputerThe EDR blind spot: 3 ways browser attacks evade endpoint telemetryAlienVaultThe Psychedelic Stealer: When the CAPTCHA Is the Installerinfostealerbrowser extensionAlienVaultSMTP is the key: BPFDoor and AVERAT hitting the network edgeaveratbpfdoorSecurityWeekmacOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD BackdoormalwaremacosAlienVaultAnatomy of BraZetsu: How Cybercriminals Supply the Underground Ecosystemagentev2ai-enhanced reconnaissanceBleepingComputerDell asks admins to patch max severity CSM flaws as soon as possiblevulnerabilitiesSecurityWeekCrypto Scammers Hijack Microsoft’s Official X Accountxaccount hackSecurityWeekIn Rare Move, Alleged Iranian State Hacker Extradited to USlaw enforcementcybercrimeSecurityWeekWarlock Expands SharePoint Exploitation in Critical Infrastructure AttacksexploitedchinaBleepingComputerMicrosoft’s X account hacked in crypto pump-and-dump schemecryptocurrencymicrosoftSecurityWeekAI Agents Aimed SQL Injection at US and Canadian Government Sitesartificial intelligencevulnerabilitiesSecurityWeekExploited Fortinet FortiMail Zero-Day Calls for Urgent Actionzero-dayexploitedAlienVaultDetermined Attacker Uploads Malicious Webshells to Parks and Rec Management Platform Serversmalwareai-generated-scriptsAlienVaultAugust 2026 Threat Trend Report on APT Attacks (South Korea)nation-stateapt campaignAlienVault$100k in Crypto Drained by the Underground Operationaoteraaotera loaderAlienVaultRemusStealer: EtherHiding In Hidden Windowsblockchain c2credential theftAlienVaultPSIRTarbitrary file writecve-2026-104286
Thursday 1 October 2026
BleepingComputerFortinet warns of critical FortiMail flaw exploited in zero-day attackszero-dayexploitedAlienVaultTIKTOUK: Tracing a WordPress Credential Collection Toolkitaws credentialsconfiguration exposureBleepingComputerAutonomous AI agents tried to hack US, Canadian government websitesartificial intelligenceAlienVaultFake xStocks, Pendle, and other sites bait crypto users with rewards votesblockchain fraudcrypto impersonationRecorded FutureIranian accused of hacking American universities extradited from Montenegrolaw enforcementcybercrimeRecorded FutureResearchers find Chinese hacking campaigns targeting AI firms, Asian governmentsartificial intelligencechinaCisco TalosGive yourself room to be humanthreat source newsletterSecurityWeekZero Trust Creator Says Model Holds Firm Against AI-Assisted Attacksartificial intelligencenetwork securityRecorded FuturePolice disrupt KillSec ransomware, arrest suspected teenage leaderransomwarelaw enforcementAlienVaultWarlock Ransomware Attackers Hit Water and Telecom OperatorsransomwarebyovdSecurityWeekHacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compasshackerhacker conversationsBleepingComputerPolice dismantle KillSec ransomware gang allegedly led by 16-year-oldransomwareSecurityWeekPolice Shut Down KillSec Ransomware, Identify Alleged Teen LeaderransomwarekillsecBleepingComputerKiteworks patches max severity code injection vulnerabilityvulnerabilitiesSecurityWeekAI Has Changed Attack Speed, Not Security Fundamentalsartificial intelligencepatchingSecurityWeekZimbra Vulnerability Exploited in the Wild Prior to Public DisclosureexploitedvulnerabilitiesSecurityWeekTreasury Blacklists Most-Wanted ATM Malware Developer and His NetworkmalwaretreasuryAlienVaultHallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circlesartificial intelligenceai policySecurityWeekZammad Zero-Days Exploited in AI-Powered DIVD Hackzero-dayexploitedCisco TalosThe Fine Art of Frustrating the Adversaryon the radarBleepingComputerHackers stole Pentagon personnel records of over 3 million peopleSecurityWeek500,000 Active Credentials Left Exposed on GitHubapplication securitydata leakSecurityWeekCisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerabilityzero-dayexploitedSANS Internet Storm CenterScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)CrowdstrikeCrowdStrike Expands Federal SOC Modernization Through CISA-Funded SIEMaaSpublic sectorAlienVaultCitrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts and Hunt IndicatorsexploitedvulnerabilitiesAlienVaultPaperCut MF Zero-Day Intrusion: Java Loader, Web Shell, and AdaptixC2 via CVE-2026-82078 and CVE-2026-81578zero-dayvulnerabilitiesAlienVaultSwarming Against Citrix 0-Day Exploitationzero-dayexploited
Wednesday 30 September 2026
Recorded FutureUS sanctions 10 over ATM malware scheme tied to Tren de AraguamalwarecybercrimeBleepingComputerRussian state hackers use new RedFlick technique to push malwaremalwarePalo Alto NetworksThreat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)zero-dayexploitedBleepingComputerDIVD says Zammad zero-days enabled AI-driven network breachzero-daydata breachesRecorded FutureGoogle: Vulnerability disclosures double to 10,000 per month as AI fuels exploitationexploitedartificial intelligenceBleepingComputerOver 543,000 valid credentials exposed in public GitHub repositoriesAlienVault2CLoader: A New Malware Loader Delivering Vidar and RemusinfostealermalwareBleepingComputerCISA warns of critical pre-auth RCE flaw in MikroTik RouterOSvulnerabilitieshardwareRapid7Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)exploitedvulnerabilitiesBleepingComputerCisco warns of new SD-WAN zero-day exploited in attackszero-dayexploitedSecurityWeekGoogle: AI Is Changing the Pace and Profile of Vulnerability Discoveryartificial intelligencevulnerabilitiesGoogleVulnerability Discovery and Exploitation Trends in the AI Eraexploitedartificial intelligenceMicrosoftUnauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570vulnerabilitiesRecorded FutureMobile malware warning from Ukrainian researchers includes iPhone exploit kitmobilemalwareBleepingComputerMicrosoft to block Entra ID script injection attacks starting OctobercloudmicrosoftSecurityWeekWatchGuard Patches Critical Fireware OS Code Injection VulnerabilityvulnerabilitieswatchguardSecurityWeekGovernment, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attackszero-daycitrixBleepingComputerTeamViewer urges users to patch severe flaws “as soon as possible”vulnerabilitiesSecurityWeekChrome, Firefox Updates Patch Over 100 VulnerabilitiesvulnerabilitieschromeRecorded FutureRussian FSB-linked hackers scale up phishing attacks against Ukraine supportersphishingcybercrimeSecurityWeekAnthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuitartificial intelligencelawBleepingComputerBitget hacked via zero-day in third-party security productszero-daycryptocurrencySecurityWeekRussian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacksnation-stateaptSecurityWeekShinyHunters Defiant After FBI Calls on Members to Come Forwardcybercrimedata leakCisco TalosChina-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoornation-statemalwareSecurityWeekHigh-Severity Vulnerabilities Patched in OpenSSL, WolfSSLvulnerabilitiesopenssl
Tuesday 29 September 2026
MicrosoftPhishing Abuses RMM Tools for Persistent Accessphishingsocial engineeringRecorded FutureUS Air Force members given over 6 years in prison for cyber theft of more than $2 millioncybercrimegovernmentBleepingComputerCustom ChatGPTs push ClickFix attacks to deploy RAT malwaresocial engineeringmalwareRecorded FutureControversial spyware firm Paragon to go public by end of yearmalwareindustryBleepingComputerFBI tells ShinyHunters members to turn themselves in after recent arrestlaw enforcementRecorded FutureOpenAI apologizes for agents breaching Australian government websites without authorizationdata breachesartificial intelligenceBleepingComputerHackers exploit Citrix NetScaler zero-day to deploy web shellszero-dayBleepingComputerFormer US Air Force members sent to prison over BEC attacksBleepingComputerNew Spectre v2 attack variant leaks Linux root password hash in minuteshardwarelinuxSecurityWeekNew Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaksdata breachesamdBleepingComputerAutomated AI agent used to breach cybersecurity nonprofit DIVDdata breachesartificial intelligenceMicrosoftStar Blizzard refines phishing and malware delivery with the RedFlick techniquenation-statephishingAlienVaultFake iPhone Duo preorder scam triggers DarkSword attackmobilecredential stealingAlienVaultBeware of Phishing Emails That Disguise Themselves as Project Material Purchase Requestsphishingcve-2017-0199SecurityWeekHackers Use ChatGPT Custom GPTs in ClickFix Attackssocial engineeringartificial intelligenceRecorded FutureRussian pizza chain with 1,500 locations confirms cyberattack following hacker claimscybercrimeRecorded FutureArizona Supreme Court says hackers stole residents’ personal datacybercrimegovernmentSecurityWeekPentagon Personnel Agency Data Breach Impacts 3 Million Peopledata breachesdmdcBleepingComputerVietnamese man charged in $16 million 'pig butchering' crypto scamSecurityWeekDutch Police Arrest Convicted Hacker in ShinyHunters Investigationlaw enforcementarrestedPalo Alto NetworksOperTraitors: How Kubernetes Operators Betray Your Security Posturecloudartificial intelligenceCisco TalosSecuring the keys to the kingdom: Announcing Executive Threat Detectioncisco talos incident responseSecurityWeekDaemon Tools Hackers’ NeedyMantis Malware Dissected by MicrosoftmalwarechinaBleepingComputerKiteworks patches critical flaw, brings customer systems onlinevulnerabilitiesBleepingComputerApple patches CoreGraphics zero-day flaw exploited in attackszero-dayexploitedAlienVaultThe "VPN for X" Proxy Farm — Risky Pluginsbrowser proxychrome extensionsSecurityWeekApple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’zero-dayappleGoogleDefending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliancesexploitedthreat intelligenceCrowdstrikeCopy, Paste, Compromised: How ClickFix Attacks Work and How CrowdStrike Stops Themsocial engineeringthreat hunting & intelAlienVaultAttackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFixsocial engineeringartificial intelligenceElasticNo MDM for Linux? A 68-line Elastic workflow keeps every endpoint's config currentai & automationendpoint protection & security
Monday 28 September 2026
SANS Internet Storm CenterApple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950), (Mon, Sep 28th)mobilevulnerabilitiesBleepingComputerJapan's Keio confirms ransomware attack disrupted business systemsransomwareBleepingComputerTimes Car confirms data breach affecting 6.6 million user accountsdata breachesAlienVaultFrom BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHatransomwareadb exploitationBleepingComputerDutch police confirm arrest in ShinyHunters hacking investigationlaw enforcementRecorded FutureShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warnsexploitedcybercrimeRecorded FutureUS, UK warn of exploited Citrix NetScaler zero-day bugszero-dayexploitedBleepingComputerJadePuffer agentic AI attacks target Azure, destroy cloud resourcescloudartificial intelligenceKrebs on SecurityDutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigationlaw enforcement404 mediaPalo Alto NetworksThreat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wildzero-dayexploitedMicrosoftNeedyMantis: Unpacking a post-compromise malware family used in targeted operationsmalwarestormAlienVaultRise of the Jev-Clonesai servicesbrand impersonationBleepingComputer80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjackingartificial intelligenceRecorded FutureFormer US soldier gets nearly six-year sentence for hacking, extorting telecomscybercrimeSecurityWeekPrison Sentence for Former US Soldier Who Hacked AT&T and Verizoncameron john wageniuscybercrimeSecurityWeekGoogle Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaigncybercrimeoracle peoplesoftAlienVaultOperation Master: Deconstructing a Multi-Tiered Intrusion and Monetization Pipelineadaptixc2cve-2020-1938AlienVaultThe Stealer Factory: Unpacking a Python-Based MaaS Infostealer Builderinfostealeranti-vmAlienVaultShinyHunters Exploits Oracle PeopleSoft Vulnerability CVE-2026-35273 in New Attack WavevulnerabilitiesRapid7Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772zero-dayexploitedSecurityWeekKiteworks Urges Server Shutdown, Finds Advanced Forms VulnerabilityvulnerabilitiesalertAlienVaultTelerik UI 취약점을 악용한 웹쉘 설치 및 스캐너 실행 공격 사례cve-2019-18935godzillaAlienVaultTelerik UI Exploitation Leads to Webshell Install and Scanner Executionexploitedcve-2019-18935BleepingComputerCISA orders feds to patch exploited Citrix flaws by WednesdayexploitedvulnerabilitiesCrowdstrikeA Win for Defenders: CrowdStrike and NVIDIA Extend Security Across the AI Stackartificial intelligencesecuring aiElasticQuarantined isn't contained: Agentic phishing response with Elastic and Sublimephishingartificial intelligence
Sunday 27 September 2026
BleepingComputerCitrix admins warned to shut down NetScalers over 2 exploited zero-dayszero-dayexploitedSecurityWeekMicrosoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacksexploitedvulnerabilities
Saturday 26 September 2026
AlienVaultLunex Unmasked: A New Information Stealer Deployed Through BYOVDinfostealerbrowser-hijackingAlienVaultPlaceholder Domains Whose Ads Serve Scamsaffiliate fraudai agentsBleepingComputerShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacksAlienVaultKothamine malware uses Tailscale's tailcat to evade network detectionmalwareencrypted c2SecurityWeekNew x47.c Windows Botnet Weaponizes xAI Grok, AI API Drainingartificial intelligencemalware
Friday 25 September 2026
Palo Alto Networks3 Consulting Myths Debunked by Unit 42 Expertsartificial intelligenceinsightsBleepingComputerKiteworks urges 6-hour server shutdown over potential zero-day attackszero-dayBleepingComputerShinyHunters hacked Clop leak site using Grav CMS path traversal flawransomwarevulnerabilitiesBleepingComputerElementor WordPress flaw lets attackers create admin accountsvulnerabilitiesBleepingComputerCISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacksexploitedvulnerabilitiesAlienVaultPureRAT and PureLogs Campaign Targeting Japanese Organizationsbyovddonut loaderMicrosoftStorm-3168: Agentic-driven cloud attacks using compromised service principalscloudartificial intelligenceSecurityWeekIn Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposureransomwareartificial intelligenceAlienVaultThe Psychedelic Stealer: When a CAPTCHA Becomes an InstallerinfostealerclipboardAlienVaultUncovering a SectopRAT Variant Embedded in Legitimate SoftwarecryptoembeddingGoogleShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoftexploitedthreat intelligenceSANS Internet Storm CenterA Closer Look at Malware From the Macfinger ClickFix Campaign, (Fri, Sep 25th)social engineeringmalwareSecurityWeekCISA Election Security Plan Flags Patching Barriers, Voter Database AttackscisaelectionRecorded FutureDoubts grow over claims OpenAI agent hacked Australian Medicare portalartificial intelligencegovernmentSecurityWeekWindows, Linux, Android File Notification Systems Leak User ActivitymobileandroidSecurityWeek‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltrationdata breachesvulnerabilitiesBleepingComputerHackers steal $351.6 million in Bitget crypto exchange hackcryptocurrencyAlienVaultMajor vulnerability found in ancient TACACS+ networking protocolvulnerabilitieschinese cyber-espionageSecurityWeekRoundcube Webmail Vulnerability in Attackers’ Crosshairsvulnerabilitiesemail securityTrend MicroAI Agents Can Be Secured. We Can Do It.artificial intelligencetrend micro research : artificial intelligence (ai)
Thursday 24 September 2026
BleepingComputerMacSync malware uses public iCloud calendars to deliver new payloadsmalwareSecurityWeekAutonomous AI Hacks Raise Thorny Questions of Legal Accountabilityartificial intelligencelaw enforcementRecorded FutureLawmakers introduce bill for voluntary telecom cyber rules after Salt Typhoon hacksnation-statecybercrimeBleepingComputerNew Carbonato malware uses AI agents to hijack exposed Docker hostsartificial intelligencemalwareRecorded FutureRydox cybercriminal marketplace operator pleads guilty following co-conspirator brothers’s deportationlaw enforcementcybercrimeCisco TalosTrust and the enticing consultancy offerthreat source newsletterBleepingComputerExposed GitLab project email addresses let attackers push codeAlienVaultThe Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpointanydeskc3poolAlienVaultRemotePanel and BoundSiphon: A Dual-Payload Toolkit for Persistent Access and Browser Theftapp-bound encryptionbnb smart chainAlienVaultthird-party.com Placeholder Domain Now Serves ClickFixsocial engineeringclickfixMicrosoftBeyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deploymentsransomwareransomware as a serviceSecurityWeekOpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Dataartificial intelligencevulnerabilitiesGoogleProactive Defense: Hardening Code Pipelines and CI/CD Infrastructurethreat intelligenceRecorded FutureKyiv internet providers report major outages after Russian attacks damage data centersgovernmentindustryBleepingComputerHackers now exploit critical Roundcube flaw in code injection attacksvulnerabilitiesAlienVaultOpenSUpdater Hides in Recompiled 7zip SFX, Evading Analysts7zip sfxcertificate bloatingRecorded FutureAstrana latest healthcare tech firm to report data breach to SECdata breachescybercrimeRapid7When Business Email Compromise Starts Rewriting Realityphishingvulnerability disclosureSecurityWeekAI-Powered Campaign Targets Hundreds of Online Retailersartificial intelligencecredit cardAlienVaultNew RemControl Android Banking Trojan Steals PINs Using AI-Built Phishing OverlaysphishingmobileAlienVaultTASK#STOMP PowerShell Backdoor Steals Business Documents and Maintains Persistent Remote AccessmalwareavisloaderAlienVaultKonni Hackers Target Ukraine With Malicious LNK Files and VelvetCake PowerShell Malwaremalwarelnk filesAlienVaultGalago Ransomware Emerges With Shared Infrastructure Ties to Panzerransomwaredouble extortionRecorded FutureOpenAI agent breached Australian government health website, Albanese saysdata breachesartificial intelligenceAlienVaultA new version of the MacSync macOS stealer targets crypto enthusiasts and developersinfostealeramosSecurityWeekOT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS IntegratorscisafbiBleepingComputerCISA: Ransomware gangs now exploiting critical TeamCity flawexploitedransomwareSecurityWeekSolarWinds Patches Critical RCE Flaws in Observability Self-HostedvulnerabilitiessolarwindsSecurityWeekAstrana Health Data Breach Impacts Private, Confidential Informationdata breachesastrana healthBleepingComputerOpenAI hacked Australian Medicare govt site, probed data providersartificial intelligenceSecurityWeekUS Court Sentences Armenian Man to Prison for Ryuk Ransomware AttacksransomwarecybercrimeAlienVaultCARBONATO: a botnet built around an AI agentartificial intelligencemalwareSecurityWeekCritical WordPress Vulnerability Exploited Immediately After DisclosureexploitedvulnerabilitiesCrowdstrikeCrowdStrike Named a Leader in The Forrester Wave™: Proactive Security Platforms, Q3 2026exposure management
Wednesday 23 September 2026
BleepingComputerPlaceholder domain used in dev docs now serves ClickFix attackssocial engineeringBleepingComputerNew RemControl Android banking malware targets users in Europe and CanadamobilemalwareAlienVaultThis Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Moveartificial intelligencemalwareBleepingComputerCheck Point warns of hackers exploiting Security Gateway VPN RCE flawexploitedvulnerabilitiesZero Day InitiativeCVE-2024-0244 – A heap buffer overflow in the Canon MF753Cdw printervulnerabilitiesblog postBleepingComputerHackers start exploiting critical WordPress flaw for code executionexploitedvulnerabilitiesAlienVaultMeet AvisLoader: A Windows Loader Built to Outlast a TakedownmalwareavisloaderAlienVaultVeloCloud Orchestrator Remote Access Vulnerabilityvulnerabilitiesactive exploitationRecorded FutureRyuk ransomware operator gets 2-year sentence after extorting victims for $1.2 millionransomwarecybercrimeBleepingComputerInfraTrust report warns network management systems under attackRecorded FutureFBI investigating alleged ShinyHunters breach of its jobs sitedata breachescybercrimeRecorded FutureLatvia arrests suspected hacker for electronics repair company breachdata breacheslaw enforcementAlienVaultRemControl: AI Built the Overlays. Victims Lose their PINsartificial intelligenceaccessibility service abuseBleepingComputerArista patches actively exploited VeloCloud Orchestrator zero-dayzero-dayexploitedAlienVaultMind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day Exploitszero-daychinese aptAlienVaultDisposable Domains, Durable HostingamadeyamateraSecurityWeekAdobe Patches Critical Flaws in Connect, AEM FormsvulnerabilitiesadobeSecurityWeekAI-Powered Phishing Platform EvilTokens Disrupted by Microsoftphishingartificial intelligenceSecurityWeekChrome 154 Patches 108 VulnerabilitiesvulnerabilitieschromeRapid7CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APMvulnerabilitiesemergent threat responseSecurityWeekArista Urges Immediate Patching of Exploited VCO Zero-Dayzero-dayexploitedBleepingComputerRyuk ransomware member sentenced to 24 months in prisonransomwarelaw enforcementSecurityWeekCritical F5 BIG-IP Vulnerability Exploited as Zero-Dayzero-dayexploitedBleepingComputerF5 patches BIG-IP APM zero-day flaw exploited in RCE attackszero-dayexploitedSecurityWeekShinyHunters Claims FBI Hack, Demands Retraction of Threat Reportdata breachesdata leakSecurityWeekCheck Point Patches Exploited Management Server Zero-Dayzero-dayexploitedAlienVaultDarkMe RAT: A VB6 APT Trojan Turned Conventional Infostealerinfostealernation-state
Tuesday 22 September 2026
BleepingComputerSweden fines Miljödata $183,000 over breach affecting 2.2 milliondata breachesgovernmentAlienVaultNew PamStealer variant targets macOS via fake crypto walletbrowser credential theftcryptocurrencyBleepingComputerChinese hackers exploit WordPress, Zyxel flaws to steal govt datanation-statevulnerabilitiesBleepingComputerShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breachzero-daydata breachesBleepingComputerNew ClosedQuorum Windows malware uses AI for attack decisionsartificial intelligencemalwareSecurityWeekBigCommerce Data Stolen via Ribon Apps Hackbigcommercedata breachesBleepingComputerCheck Point warns of Management Server zero-day exploited in attackszero-dayexploitedRecorded FutureTwo arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminalslaw enforcementartificial intelligenceMicrosoftUnmasking EvilTokens: Getting to the root of device code phishingphishingadversary-in-the-middle (aitm)BleepingComputerEvilTokens PhaaS disrupted after compromising 12,000 Microsoft accountsSecurityWeekNightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identitybigdiskbusterchaotic eclipseAlienVaultAugust 2026 Infostealer Trend ReportinfostealeracrstealerRecorded FutureAI is set to help cyber attackers much more than defenders, says UK officialartificial intelligencecybercrimeBleepingComputerD-Link warns of max severity zero-day bug in DIR-822A routerszero-daySecurityWeekRecent ZyXEL Switch Vulnerability Exploited by Chinese Hackersexploitednation-stateAlienVaultOpen Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitationexploitedchinese-speaking actorSecurityWeekWordPress Patches ‘Click2Shell’ Vulnerabilityvulnerabilitiesclick2shellCisco TalosThe Closed Quorum: Inside the first reported autonomous AI C2 implantartificial intelligencethreat spotlightCisco TalosIntroducing CAIRN: Frontier tracking for AI-integrated malwareartificial intelligencemalwareBleepingComputerNew Windows Defender zero-day blocks Microsoft antivirus updateszero-daymicrosoftBleepingComputerCISA orders feds to patch Zyxel flaw exploited for data theftexploiteddata breachesAlienVaultEquation of Compromise: Anatomy of a Live npm Supply-Chain Campaignsupply chainblockchain infrastructureAlienVaultAI Security Incident Case: Trusted AI Platforms Become a New Channel for Malware Distributionartificial intelligencemalware
Monday 21 September 2026
Recorded FutureRussia's internet shutdowns disrupt warnings about incoming drone attacksgovernmentBleepingComputerBigCommerce alerts merchants of data breach linked to Ribon appsdata breachesBleepingComputerCISA alerts of active exploitation of three Linux kernel flawsexploitedvulnerabilitiesBleepingComputerWordPress Click2Shell flaw lets hackers execute PHP on the servervulnerabilitiesSecurityWeekGoogle Hit With $463 Million Fine for EU Location Data Rule Breachdata breachesfineAlienVaultVidar Adds Virtual Machine and Custom Stream Ciphers For String Obfuscationinfostealerarx cipherAlienVaultNorth Korea's Hangro Revisitednation-statecertificate hierarchyAlienVaultThe Tale of Two INC Ransom Notes: A Ransomware TimelineransomwareanydeskSecurityWeekFake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealerinfostealeredr killerAlienVaultFrom Registry-Stored PowerShell to In-Memory Cryptocurrency Mining: A Multi-Stage Infection Chaincryptocurrency miningdns txt recordsBleepingComputerFBI's CJIS v6.1: What Security Teams Need to Know.Recorded FutureShinyHunters cybercrime gang takes over Cl0p ransomware site, demands extortion paymentransomwarecybercrimeSecurityWeekRatHat Android Trojan Uses AI for Automationmobileartificial intelligenceRecorded FutureGoogle says Gemini breached three companies during security testdata breachesindustryAlienVaultPAYLOAD ransomware attacks through Active Directory GPOransomwareactive directorySecurityWeekCrowdSec Confirms Source Code Stolen in Supply Chain Attacksupply chaincrowdsecPalo Alto NetworksFrom Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed PoliciescloudawsSecurityWeekOrganizations Warned of 3 Exploited Linux Kernel VulnerabilitiesexploitedvulnerabilitiesSecurityWeekGoogle Confirms Gemini AI Breached Three Firmsdata breachesartificial intelligenceElasticCloud Threat Emulation on Autopilot: Context is Everythingclouddetection engineering
Sunday 20 September 2026
Google Project ZeroWindows Exploitation Techniques: Dangling COM Object Registrationsexploited
Saturday 19 September 2026
BleepingComputerBragJack attacks hijack AI browser agents through malicious extensionssupply chainartificial intelligenceBleepingComputerNorth Korean WaterPlum hackers infected 30,000 devices worldwidenation-statecryptocurrencyBleepingComputerShinyHunters hacks Clop leak site, threatens to extort ransomware gangransomwareAlienVaultDon't Call Us, We'll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Tiesmalwarecryptocurrency theft
Friday 18 September 2026
AlienVaultChainScript: Tracing a Node.js RAT Through the BlockchainmalwarechainscriptAlienVaultLazarus luring employees with trojanized coding challenges: The case of a Spanish aerospace companynation-statemalwareBleepingComputerGyazo server flaw exploited to steal 23.6 million user recordsexploitedvulnerabilitiesBleepingComputerFake LastPass Authenticator GitHub repos push new Rapuncel infostealerinfostealerSecurityWeekIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flawransomwarelaw enforcementAlienVaultWeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentialsbeavertailchrome extension theftRecorded FutureHacking group ‘NightEagle’ targeting China’s high-tech sector expands operations to RussiacybercrimeAlienVaultPrivate HTS programs that spread ransomwareransomwarefinancial scamAlienVaultEtherHiding Exposed: Inside a Blockchain-powered Malware Campaign Hiding in Plain Sightmalwarebanking trojanAlienVaultPolinRider Spreads Through Compromised GitHub Accounts and PackagistinfostealerpolinriderAlienVaultLabubaRAT Threat Snapshotlabubaratmaas frameworkSecurityWeekAI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Codeartificial intelligencevulnerabilitiesSecurityWeek23 Million User Records Compromised in Gyazo Data Breachdata breachesgyazoSecurityWeekMicrosoft Patches 18 Vulnerabilities in AI, Cloud Productscloudartificial intelligenceSecurityWeekNightmareStresser DDoS Service Disrupted in International OperationddoscybercrimePalo Alto NetworksA Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identityagentcore runtimeagentic aiSecurityWeekBrevo Supply Chain Attack Injects Malware Into 100,000 Websitessupply chainmalwareBleepingComputerNew Check Point flaw lets hackers execute code with root privilegesvulnerabilitiesSecurityWeekCritical Orkes Conductor Vulnerability Exploited in AttacksexploitedvulnerabilitiesSecurityWeekCheck Point, Kaspersky, Tanium Patch Product Vulnerabilitiesvulnerabilitiescheck pointElasticOne SOC, 100 projects: running centralized alert triage on Elastic Security Serverlesssecurity operationssoc
Thursday 17 September 2026
Palo Alto NetworksInside the Modern SOC: Defending the Cross-Environment Pivotartificial intelligenceattack surfaceBleepingComputerNew RatHat Android malware uses AI to automate device controlmobileartificial intelligenceAlienVaultBlackCore’s Influence Operations for Hireai-generated-contentcoordinated-inauthentic-behaviorAlienVaultHEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala HackmalwarecrudeexcludeAlienVaultBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malwaresupply chainsocial engineeringCisco TalosShould you care about an “AI slowdown?”artificial intelligencethreat source newsletterBleepingComputerBrevo supply-chain attack injected ClickFix scripts on customer sitessupply chainsocial engineeringSecurityWeekCyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vesselscoast guardcyberattacksRecorded FutureChina’s FamousSparrow hackers target Latin America with new backdoormalwarenation-stateAlienVaultT-Mobile rewards points expiry texts are a phishing scamphishingphishing campaignAlienVaultThe Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrentsmalwareblockchain c2AlienVaultBeware the SparroWock: The backdoor that bites, the commands that catchmalwarecyberespionageAlienVaultReady, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMMransomwarebyovdSecurityWeekOpenAI Says Its Models Searched GitHub for Leaked API Keys During Trainingdata breachesartificial intelligenceSecurityWeekCISA Retires Weekly Vulnerability Bulletin in Risk-Based PivotvulnerabilitiescisaBleepingComputerWhat Recent AI-Powered Attacks Mean for Your Identity Securityartificial intelligenceSecurityWeekRevolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransomransomwaredata breachesRecorded FutureHackers claim breach of Russian election systems days before parliamentary votedata breachescybercrimeSecurityWeekISC Patches 14 Vulnerabilities in BIND 9 Security UpdatevulnerabilitiesbindSecurityWeekRansomware Attacks on Manufacturers Surge as Supply Chain Risk Growsransomwaresupply chainAlienVaultDiscernment Deleted: Inside the Operation Server of BlackHatSect0r && DXQRTXXai-agentcloud-storage-exploitationBleepingComputerUS takes down NightmareStresser DDoS-for-hire platformddosCisco TalosRansomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI useransomwareartificial intelligenceBleepingComputerChinese hackers use SparroWocky malware in govt espionage attacksnation-statemalwareSecurityWeekCISA Releases Guidance on Deploying Cyber DecoyscisadecoysSecurityWeekAI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusalsartificial intelligenceai trainingBleepingComputerCisco warns of max severity ISE zero-day exploited in attackszero-dayexploitedSecurityWeekActive Exploitation Triggers Emergency Patch for Cisco ISE Zero-Dayzero-dayexploitedCrowdstrikeCrowdStrike Named a Leader in The Forrester Wave™: External Threat Intelligence Service Providers, Q3 2026threat hunting & intel
Wednesday 16 September 2026
BleepingComputerIranian hackers use CHOSEN BRICK Windows malware to spy on targetsnation-statemalwareZero Day InitiativeThe Apple Security Update Review for September 2026vulnerabilitiesblog postBleepingComputerMalware bypasses browser checks to force install Chrome, Edge extensionsmalwareRecorded FutureCoast Guard, FBI boarded tanker after attack by ‘foreign cyber actors’governmentindustryRecorded FutureHouse passes bill to equip local law enforcement with scam-fighting toolslaw enforcementcybercrimeBleepingComputerSpain's data agency gets first report of AI-powered data breachdata breachesartificial intelligenceAlienVaultSilkParasite Infrastructure: SpiceRAT Servers Tied to Energy and Government Targets Across Central Asiabloodalchemygovernment impersonationAlienVaultVectraRAT: An Undocumented Full-Stack MaaS Built From ScratchamadeyclickfixAlienVaultNoodle RAT: A Recipe for Cross Platform Espionagenation-statemalwareAlienVaultOperation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCHnation-stateapt36SecurityWeekFirst Agentic AI Data Breach Reported to Spanish Regulatordata breachesartificial intelligenceRecorded FutureThree Ukrainians to face charges for alleged hack of 610,000 Roblox accountscybercrimemalwareSecurityWeekEU Chief Warns of AI-Powered Hacking, Moves to Rein In Social Mediaartificial intelligenceeuBleepingComputerThe true cost of a ransomware attack, with and without BCDRransomwareSecurityWeekPixel Modem Zero-Day Exploited in Targeted Attackszero-dayexploitedAlienVaultGhostCode: Dissecting a Novel Device Code Phishing Kitphishingbusiness email compromiseRecorded FutureUkraine moves to crack down on scam call centers after corruption scandalcybercrimegovernmentAlienVaultNightEagle targets Russian companiesactive directoryapt-q-95AlienVaultHow Money Laundering, Scams, and Espionage Hide in a Web Full of Casino Garbagenation-statebulletproof hostingSecurityWeekUS, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malwaremalwarechosen brickSecurityWeekUnauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to TakeovervulnerabilitiescalendarBleepingComputerCritical ScreenConnect flaw now actively exploited in attacksexploitedvulnerabilitiesSecurityWeek280,000 Impacted by Premier Medical Group Data Breachdata breacheshealthcareSecurityWeekChrome, Firefox Updates Patch 115 VulnerabilitiesvulnerabilitieschromeCisco TalosSecuring the unpatchable in an age of AI-driven vulnerabilitiesartificial intelligencevulnerabilitiesPalo Alto NetworksAtomic macOS (AMOS) Stealer ActivityinfostealerinsightsSecurityWeekAcronis Patches Exploited Vulnerability in cPanel Backup PluginexploitedvulnerabilitiesAlienVaultThe banana stand: brokering and managing infections across Asia using MQTTbambootokeniocontrolSecurityWeekEnterprises Warned of Attacks Exploiting WSO2 VulnerabilityexploitedvulnerabilitiesSecurityWeekOracle Patches 800+ Vulnerabilities in September 2026 Security UpdatevulnerabilitiescspuAlienVaultPIVOTPIPE: A New .NET-based Unofficial Beacon Payloadbeaconc2 frameworkAlienVaultMythic C2 Activity at Internet Scaleadversary infrastructureapolloBleepingComputerGoogle fixes actively exploited Android zero-day on Pixel deviceszero-dayexploitedCrowdstrikeCrowdStrike Accelerates Real-Time Data Classification with On-Device AIartificial intelligencedata security
Tuesday 15 September 2026
BleepingComputerAcronis warns of actively exploited flaw in its cPanel backup pluginexploitedvulnerabilitiesBleepingComputerCenterPoint Energy confirms customer data stolen in cyberattackRecorded FutureIranian cyber spies used fake MRI scan results to hack ‘enemy of regime’cybercrimegovernmentSecurityWeekTexas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Datadata breachescenterpoint energyBleepingComputerBambooToken malware controls Windows and Linux systems via MQTTmalwareBleepingComputerHackers target WordPress sites via third-party WooCommerce pluginRecorded FutureElectric and gas utility CenterPoint Energy warns of data breach after dark web postdata breachescybercrimeBleepingComputerWhat Zero-Day Response Should Be in the Post-Mythos Erazero-daySecurityWeekThai Broadband Provider Hacked via Fortinet Vulnerabilityvulnerabilities3bbAlienVaultRed Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkitvulnerabilitiesmalwareAlienVaultSearch results are sending people to fake Bitrefill checkoutspayment fraudphishingSecurityWeekOpenAI Investigates Report Linking AI Agents to RubyGems Attackartificial intelligenceopenaiRapid7CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the WildexploitedvulnerabilitiesBleepingComputerCISA: Critical VMware RCE flaw now exploited by ransomware gangsexploitedransomwareSecurityWeek240,000 Hit by Data Breach at Japan’s Digital Agencydata breachesgovernmentSecurityWeekApple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 ReleasesmobilevulnerabilitiesSecurityWeekHacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attacksocial engineeringmalwareAlienVaultGrelosGTM group abuses Google Tag Manager to attack e-commerce websitese-commerce attacksgoogle tag manager abuseBleepingComputerCisco patches Secure Email Gateway zero-day exploited in attackszero-dayexploitedSecurityWeekRoot RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitationzero-dayexploitedCrowdstrikePhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Huntinginfostealerartificial intelligence
Monday 14 September 2026
AlienVaultThai Broadband Provider Targeted via FortiGate SSL-VPN and MeshCentral Persistencecve-2024-21762fortigateRecorded FutureMembers of ‘Black Axe’ cybercriminal group extradited from South Africalaw enforcementcybercrimeBleepingComputerHackers hijack HBO Max Reddit account to push malware in ClickFix adssocial engineeringmalwareBleepingComputerHackers target exposed Vite dev servers to steal AWS, Azure secretscloudRecorded FuturePro-Ukraine Hacking Cat group deploying new malware against Russian targetsmalwarecybercrimeBleepingComputerWhy Patch Automation Needs Brakes, Not Just an AcceleratorSecurityWeekPersonal, Financial Info Exposed in Revolut Data Breachdata breachesrevolutRecorded FutureRevolut handed customer data to fraudsters using government email accountcybercrimeprivacySecurityWeekChinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Executionnation-statevulnerabilitiesRapid7CVE-2026-85706: Critical GitLab Path Traversal Exploited in the WildexploitedvulnerabilitiesPalo Alto NetworksUnmasking Cloud Identities: From Behavioral Clustering to Automated Detectioncloudaws cloudtrailSecurityWeekTelus Warns Customers of Account Breachesdata breachesaccount takeoverSecurityWeekThree JFrog Artifactory Flaws Exploited for Backdoor DeploymentexploitedvulnerabilitiesBleepingComputerRevolut discloses data breach exposing financial info, passportsdata breachesSecurityWeekConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like AttacksexploitedvulnerabilitiesBleepingComputerCISA: Hackers now exploit max severity GitLab flaw in attacksvulnerabilitiesElasticThe extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessionsmalware analysisthreat intelligence
Sunday 13 September 2026
BleepingComputerHackers exploit Tencent app flaw to deploy GrayRabbit malwarevulnerabilitiesmalware
Saturday 12 September 2026
BleepingComputerDutch NCSC: Critical Check Point VPN flaws exploitation is imminentexploitedvulnerabilitiesSecurityWeekBlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Dayszero-daybluemoon
Friday 11 September 2026
BleepingComputerHackers abused Claude to extract secrets from 1.8M Android appsmobileartificial intelligenceRecorded FutureFlorida says motor vehicle data breach tied to credentials stolen from officer’s personal devicedata breachescybercrimeBleepingComputerFlorida confirms DMV database breached via stolen police accountdata breachesRecorded FutureMicrosoft sees some new wrinkles in invoice-scam emailscybercrimeindustryAlienVaultMalicious Twitch Browser Extension Exposes 30,000 Users' OAuth Tokens to Russian Bot Servicemalwarebrowser extensionAlienVaultKATARU: IoT Malware Adopts Public LPE Exploitsmalwarecve-2026-31431BleepingComputerPasskey-themed phishing attacks lead to Microsoft 365 data theftdata breachesphishingSecurityWeekPhishing Research Challenges Conventional Security Awareness Testingphishingawareness trainingBleepingComputerArtifactory flaws chained in attacks deploying backdoor malwarevulnerabilitiesmalwareSecurityWeekGitLab Vulnerability Exploited One Day After DisclosureexploitedvulnerabilitiesSecurityWeekIn Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Reviewlaw enforcementcybercrimeBleepingComputerHow Threat Actors Are Turning Trusted AI Platforms Into an Attack Surfaceartificial intelligenceRapid7The Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environmentthreat intelAlienVaultBeware of the LegionLoader malware being distributed via the ClickFix methodsocial engineeringmalwareSecurityWeekTrezor Says 347,000 Users Received Phishing Emails After Brevo HackphishingbrevoRecorded FutureAnthropic caught Russia-linked spies using Claude in hacking operationsnation-statecybercrimeRecorded FutureUkrainian hacker gets four years in US prison over Conti ransomware attacksransomwarecybercrimeSecurityWeekUkrainian Conti Ransomware Developer Sentenced to 4 Years in US Prisonransomwarelaw enforcementBleepingComputerGitLab urges users to patch max severity path traversal flawvulnerabilitiesSecurityWeekCheck Point Patches Critical VPN Vulnerabilitiesvulnerabilitiescheck pointSecurityWeekSurfshark Systems Targeted by Hackersdata breachessurfsharkAlienVaultGray Rabbits and the Tale of a One-Click Backdoormalwarechromium vulnerabilitySecurityWeekAnthropic Says Russian Hackers Used Claude AI to Automate Malware Evasionnation-stateartificial intelligenceSecurityWeekPaperCut Flaws Exploited in AI-Powered Attacksexploitedartificial intelligenceBleepingComputerTrezor: 347,000 users targeted in phishing attacks after Brevo breachdata breachesphishingAlienVaultArtifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329exploitedvulnerabilitiesBleepingComputerConti ransomware gang member sentenced to 4 years in prisonransomwarelaw enforcementAlienVaultFrom Fake DocuSign to ScreenConnect: Attack Blockeddocusign impersonationscreenconnect deploymentElasticLinux Detection Engineering - Local Privilege Escalationvulnerabilitiesdetection engineering
Thursday 10 September 2026
AlienVaultMelofee: a look back at a Linux implant and its new variantscobalt strikecrowdoorBleepingComputerNew Android malware encrypts files, steals data, and harasses victimsmobilemalwareRecorded FutureTreasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023cybercrimegovernmentBleepingComputerSurfshark VPN says hackers breached internal testing, proxy serversdata breachessoftwareRecorded FutureIDScan confirms breach after hackers offer 153 million driver’s license scans for saledata breachescybercrimeCisco TalosWe've got one word for it, and it's usually the wrong onethreat source newsletterAlienVaultSloppyRAT: A New Tool For Ransomware AttacksransomwarecastleloaderAlienVaultCasbaneiro: A Banking Trojan with Distributed Data-Receiving Serversmalwareautoit loaderMicrosoftProtecting organizations from AI-assisted executive impersonation and invoice fraudartificial intelligencesocial engineeringBleepingComputerAI-powered attack exploited PaperCut flaws to hack 395 organizationsexploitedartificial intelligenceBleepingComputerCisco FMC flaws exploited by ransomware gang, state-sponsored hackersexploitedransomwareBleepingComputerIDScan confirms breach tied to 153 million stolen driver’s licensesdata breachesSecurityWeekHacker Conversations: Vinnie Liu, Performer Turned Ringmasterhackerhacker conversationsBleepingComputerNew 'BlueMoon' kit exploited Windows and Chrome zero-day flawszero-dayexploitedSecurityWeekDeceptive Android Apps Exploit Google Play Early Access to Evade ReviewsmobileandroidRecorded FutureRussian e-commerce giant Wildberries says DDoS attack delayed payments to sellersddoscybercrimeAlienVaultActive Cloud Data Theft and Extortion Campaign Targeting Microsoft 365 and SaaS Platformsdata breachescloudAlienVaultThreat Snapshot: Djinn Stealerinfostealercredential theftSecurityWeekCritical NetScaler Vulnerability Exploited in AttacksexploitedvulnerabilitiesSecurityWeek4.1 Million Impacted by AdaptHealth Data Breachdata breachesadapthealthSecurityWeekOrganizations Warned of Cisco Secure FMC ExploitationexploitedciscoPalo Alto NetworksThe Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIREexploitedapiBleepingComputerCISA: WatchGuard RCE flaw now exploited in ransomware attacksexploitedransomwareAlienVaultMind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windowszero-daybrowser extensionSecurityWeekNew ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defenderzero-daychaotic eclipseBleepingComputerTrezor warns users of email provider breach, phishing attacksdata breachesphishingSecurityWeekFortinet Code Execution Flaw Exploited in PivotC2 RAT AttacksexploitedvulnerabilitiesAlienVaultMalicious Chrome and Firefox Extensions Steal Crypto Traders' Session and Wallet Datamalwarebrowser extension malwareAlienVaultDeath by a Thousand PaperCuts: AI-Driven Exploitation at Scaleexploitedartificial intelligence
Wednesday 9 September 2026
BleepingComputerCisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacksexploitedvulnerabilitiesRecorded FutureCISA head says agency must change quickly to prevent the 'worst that could happen'governmentAlienVaultMantax Otax: Indonesian Mobile Ransomware with Spyware IntegrationransomwaremobileRecorded FutureUS disrupts Xinbi Guarantee marketplace fueling the cyber scam economycybercrimegovernmentMicrosoftPasskey-themed social engineering leads to identity and cloud compromisesocial engineeringcloudRecorded FutureElectronic health record company says customer data stolen in breachdata breachescybercrimeSecurityWeekAI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warnsnation-stateartificial intelligenceSecurityWeekAndroid’s September 2026 Updates Patch 180 VulnerabilitiesmobilevulnerabilitiesRecorded FutureMultiple Chinese hacking groups seen using identical Chrome zero-day exploitzero-daychinaSecurityWeekChipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security AdvisoriesvulnerabilitiesamdCisco TalosActive exploitation of Cisco Secure Firewall Management Center vulnerabilitiesexploitedvulnerabilitiesAlienVaultVwork: Weaponized Open-source Software as an Addon for Gigabudandroid banking trojangigabudAlienVaultGrand Theft Auto VI hype leads to malwaremalwaregamingAlienVaultPhishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistencephishingbrowser-in-the-browserRecorded FutureFBI puts its cyber strategy on papercybercrimegovernmentAlienVaultAgents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MFartificial intelligenceai-orchestrated campaignBleepingComputerVeradigm warns of patient data breach after ransomware gang claims attackransomwaredata breachesRapid7Credentialed Pre-Port Discovery: Don't Probe the Host, Ask itvulnerability managementSecurityWeekFortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome ExtensionvulnerabilitiesfortinetBleepingComputerMFA's Weakest Link: Account Recovery Is the New Attack PathRecorded FutureUkraine prosecutor general steps down amid scam call center bribery probecybercrimegovernmentAlienVaultOnce in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Dayszero-daybluemoonSecurityWeekICS Patch Tuesday: Schneider Electric, Siemens Fix Critical FlawsvulnerabilitiesavevaSecurityWeekIvanti Patches Critical Flaws Across Enterprise Security ProductsvulnerabilitiesivantiBleepingComputerOver 36,000 exposed Plex servers vulnerable to recent flawsvulnerabilitiesPalo Alto NetworksUntracked Nightmares: The Threats Hiding Behind Commodity Infrastructurearktunnelc2SecurityWeekNew Phishing Attack Creates Malicious Pages Inside the Victim’s BrowserphishingmalwareSecurityWeekChrome 153 Patches Seventh Zero-Day of 2026zero-daychromeBleepingComputerNew Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM accesszero-daymicrosoftAlienVaultPeeling Back the Layers: Inside Vidar - From Virtualized Code to Stolen Credentialsinfostealeranti-analysisBleepingComputerGoogle warns of new Chrome zero-day bug exploited in attackszero-dayexploited
Tuesday 8 September 2026
Recorded FutureMicrosoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploitedexploitedvulnerabilitiesCisco TalosMicrosoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiesvulnerabilitiespatch tuesdayRapid7Patch Tuesday - September 2026vulnerabilitiespatch tuesdayRecorded FutureScammer behind $245 million crypto heist pleads guilty to RICO chargeslaw enforcementcybercrimeBleepingComputerDoppelCart fraud network uses 119,000 fake shops to steal credit cardsBleepingComputerHackers breach F5 BIG-IP APM devices to deploy Linux rootkitdata breachesmalwareSecurityWeekMicrosoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Dayszero-dayexploitedSecurityWeekAdobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Dayzero-dayvulnerabilitiesZero Day InitiativeThe September 2026 Security Update Reviewvulnerabilitiesblog postBleepingComputerMicrosoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-dayszero-dayvulnerabilitiesRecorded Future‘White hat’ hackers take $47 million bounty after $320 million crypto theftcybercrimeAlienVaultRedis Cryptomining Botnet Compromised 3,562 Servers, Exposed by the Operator's Own FilesmalwarebotnetAlienVaultInside a Packed Android RAT LoadermobilemalwareSecurityWeekHackers Return $263 Million Stolen From Liquid NetworkbitcoincybercrimeBleepingComputerShinyHunters hackers claim breach of Florida "DAVID" DMV databasedata breachesBleepingComputerSAP warns of maximum severity 'OVERPASS' kernel vulnerabilityvulnerabilitiesSecurityWeekSAP Patches Critical Extended Passport Processing Vulnerabilityvulnerabilitiescve-2026-44756GoogleGTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AIartificial intelligencethreat intelligenceBleepingComputerAdobe fixes critical Magento zero-day exploited to backdoor serverszero-dayexploitedSecurityWeekParty’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin TheftbitcoincybercrimeRecorded FutureFrench prosecutors confirm arrest of suspected ZeroBytes hacker behind tax cyberattacklaw enforcementcybercrimeAlienVaultMacSync: The Evasive macOS Stealer Exploiting ClickFix LuresexploitedinfostealerBleepingComputerHackers build AI frameworks for widescale credential theftartificial intelligencegoogleSecurityWeekMikroTik Patches Critical Flaws Chained to Hack RoutersvulnerabilitiesmikrotikRapid7CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)vulnerabilitieslabsSecurityWeekMathspace Data Breach Exposes Over 1 Million Peopledata breachesmathspaceSecurityWeekN-able Patches Critical Zero-Day in N-centralzero-daycve-2026-86218Cisco TalosClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Managerinfostealercisco talos antivirusCisco TalosClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2social engineeringcisco talos web filteringBleepingComputer220 million traveler records exposed in Vietnam-linked APIS leak

Headlines and links are the property of their publishers and appear here as attributed links. Follow any headline to read the original.

Support Independent Threat Research

Everything here is researched, written, and published independently, and none of it sits behind a paywall. If it is useful to you or your team, these are here if you want them.