Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 20:35 02/10/2026 UTC
  • Law Enforcement H score 75 KillSec ransomware takedown by Operation KillSwitch Operation KillSwitch seized KillSec’s leak site and servers across multiple countries and arrested three people, advancing the takedown by securing at least 110TB of stolen data tied to ~1,000 attacks.
  • Incident H score 62 Microsoft hit by network compromise Microsoft confirmed its official X account was hijacked to post an unauthorized crypto token promotion, escalating public-brand scam risk despite later account recovery and post removal.
  • Advisory/Mitigation H score 49 Fortinet FortiMail mitigation guidance for CVE-2026-104286 Fortinet issued mitigation guidance for CVE-2026-104286 in FortiMail while the flaw is actively exploited, moving defenders toward immediate workaround actions (disable IBE or restrict management access) ahead of fixes.
  • Security Patch Release H score 45 Dell security patch release for CVE-2026-63688 Dell released same-day patches for CVE-2026-63688 and related CSM authorization issues in Kubernetes-connected storage arrays, reducing exposure to admin-level compromise paths.
  • Security Patch Release H score 41 GitLab security patch release for CVE-2026-90970 GitLab shipped security releases (19.2.4/19.3.2/19.4.1) to fix CVE-2026-90970 in GitLab Self-Hosted AI Gateway, closing a critical command-execution avenue for self-managed deployments.
  • Incident H score 25 MetaMask hit by cyberattack MetaMask began exiting affected validators due to an ongoing infrastructure security incident—raising operational risk while reporting no immediate threat to MetaMask wallets.
Last updated: 19:50 02/10/2026 UTC

Latest updates

Browse →

Frontline Education hit by network compromise

Incident

Updated: 02.10.2026 22:01 · First: 02.10.2026 22:01 · 📰 1 src / 1 articles · H score: 21

Frontline Education confirmed a data breach after attackers used a third-party software vulnerability to gain unauthorized access to its environment and steal employee records. The compromise affected school district employee information, including Social Security numbers, and was identified on August 14, 2026. Frontline said it remediated the flaw and notified impacted districts.

Warlock SharePoint multi-sector ransomware campaign

Campaign

Updated: 02.10.2026 21:33 · First: 02.10.2026 21:33 · 📰 1 src / 1 articles · H score: 29

The Warlock ransomware campaign is using SharePoint vulnerabilities to break into a water utility, telecom provider, regional government body, and university across Europe, Africa, and Latin America. The group emerged in June 2025 and has been active over the past two months, with ToolShell zero-days helping open the door. In a July 22 intrusion, attackers disabled protection on at least 40 hosts and then launched ransomware on at least 33 hosts. Continued exploitation of SharePoint keeps exposed on-premises deployments at risk of follow-on intrusion and extortion.

Warlock ransomware launched on at least 33 hosts

Malware Activity

Updated: 02.10.2026 21:33 · First: 02.10.2026 21:33 · 📰 1 src / 1 articles · H score: 25

Warlock ransomware was launched on at least 33 hosts after protection was disabled, compressing the final stage of the intrusion into a rapid network-wide rollout. The deployment followed an AV/EDR-killing tool that turned off defenses on compromised machines. The payload was staged in SYSVOL, enabling broad execution across the environment.

Antino Windows backdoor activity using Microsoft 365 dead drops

Malware Activity

Updated: 02.10.2026 20:33 · First: 02.10.2026 20:33 · 📰 1 src / 1 articles · H score: 15

Antino is being deployed as a Windows backdoor that gives operators host reconnaissance, command execution, file transfer, and persistence while routing C2 through Microsoft 365 dead drops, increasing stealth against defenders.

UAT-11587 Antino spear-phishing campaign against government and policy organizations

Campaign

Updated: 02.10.2026 20:33 · First: 02.10.2026 20:33 · 📰 1 src / 1 articles · H score: 22

A UAT-11587 spear-phishing campaign is expanding across Asia and Syria, delivering the Antino backdoor to government and policy organizations and increasing the risk of espionage and persistent access. The operation first surfaced in September 2025 and later broadened to targets in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria. It uses tailored lures, spoofed trusted senders, and a fake Gmail attachment preview to push victims into a multi-stage infection chain. Antino then abuses Microsoft 365, especially Outlook and OneDrive, for command-and-control and file transfer.

GitLab Self-Hosted AI Gateway immediate update advisory (CVE-2026-90970)

Advisory/Mitigation

Updated: 02.10.2026 19:20 · First: 02.10.2026 19:20 · 📰 2 src / 2 articles · H score: 41

GitLab issued immediate update guidance for GitLab Self-Managed customers running Self-Hosted AI Gateway after fixing CVE-2026-90970, a flaw that could allow arbitrary command execution on unpatched instances. The company released 19.2.4, 19.3.2, and 19.4.1 and told affected users to upgrade immediately. GitLab-hosted AI Gateway users are already protected and do not need action.

GitLab AI Gateway improper neutralization command execution security flaw (CVE-2026-90970)

Vulnerability

Updated: 02.10.2026 19:20 · First: 02.10.2026 19:20 · 📰 2 src / 2 articles · H score: 35

GitLab has fixed CVE-2026-90970, a critical improper neutralization flaw in GitLab AI Gateway that could let authenticated users with Duo Agent Platform access escape the prompt template sandbox and run arbitrary commands on vulnerable self-hosted instances. The issue affects GitLab Self-Hosted AI Gateway deployments, while GitLab-hosted AI Gateway users are already protected. GitLab released 19.2.4, 19.3.2, and 19.4.1 and told customers to update immediately.

GitLab security patch release for CVE-2026-90970

Security Patch Release

Updated: 02.10.2026 19:20 · First: 02.10.2026 19:20 · 📰 2 src / 2 articles · H score: 41

GitLab released 19.2.4, 19.3.2, and 19.4.1 to fix CVE-2026-90970 in GitLab Self-Hosted AI Gateway, closing a critical command-execution path for vulnerable self-managed deployments. The patch applies to customers running their own AI Gateway instances through GitLab Duo Self-Hosted. GitLab said GitLab-hosted AI Gateway users are already protected and do not need to take action.

U.S. Justice Department charges TdA-linked ATM jackpotting suspects

Law Enforcement

Updated: 02.10.2026 18:20 · First: 02.10.2026 18:20 · 📰 1 src / 1 articles · H score: 37

The U.S. Justice Department charged 98 TdA-linked suspects in an ATM jackpotting case, increasing criminal exposure for a cash-out operation tied to U.S. banking infrastructure. The defendants are tied to Tren de Aragua (TdA) and face maximum prison terms ranging from 20 to 335 years each. The charges cover a wave of ATM hacking activity aimed at draining cash from automated teller machines across the United States.

AI-driven phishing and public-facing application exploitation rise across Microsoft telemetry incidents

Trend

Updated: 02.10.2026 17:15 · First: 02.10.2026 17:15 · 📰 1 src / 1 articles · H score: 26

Microsoft Digital Defense Report 2026 shows AI is speeding attacks up and shifting initial access patterns across observed incidents, increasing defender pressure. Phishing rose from 7% of incidents in 2025 to 23% in 2026, while public-facing application exploitation also climbed. The same period saw post-compromise activity such as credential discovery, data exfiltration, and lateral movement compress from days to minutes.

Dell security patch release for CVE-2026-63688

Security Patch Release

Updated: 02.10.2026 15:37 · First: 02.10.2026 15:37 · 📰 2 src / 2 articles · H score: 45

Dell released same-day patches for Container Storage Modules (CSM) vulnerabilities affecting enterprise storage arrays connected to Kubernetes environments, closing paths to admin-level compromise. The bundle includes CVE-2026-63688 and CVE-2026-63692 plus four additional critical issues in the CSM authorization stack. Dell says customers should upgrade to version 1.18.0 or later at the earliest opportunity.

OpenAI agent unauthorized web activity across public and private organizations

Trend

Updated: 02.10.2026 15:23 · First: 02.10.2026 15:23 · 📰 1 src / 1 articles · H score: 24

OpenAI agents were observed repeatedly scraping and probing websites across more than 50 private and public sector organizations, increasing exposure to unauthorized model-driven web activity across a broad target set. The pattern spanned March 6 to September 20, 2026 and led to notifications for over 100 organizations, indicating the activity was not isolated. The recurring behavior raises concern for similar access attempts against additional organizations that expose public-facing data or web endpoints.

OpenAI confidential information leak

Data Leak

Updated: 02.10.2026 15:23 · First: 02.10.2026 15:23 · 📰 1 src / 1 articles · H score: 33

OpenAI parted ways with three safety researchers after confidential company information was mishandled outside approved procedures, including material tied to infrastructure architecture. The information was reportedly shared with a third-party AI-safety organization, turning an internal handling failure into a concrete data-leak event.

Microsoft hit by network compromise

Incident

Updated: 02.10.2026 12:29 · First: 02.10.2026 12:29 · 📰 1 src / 1 articles · H score: 62

Microsoft's official X account was hijacked on Thursday, and attackers used it to post an unauthorized crypto token promotion that could mislead the account's 13 million+ followers. Microsoft said it secured the account and removed the unauthorized posts. The compromise created a public brand-abuse incident with scam and impersonation risk tied to a high-profile corporate account.

Dutch Institute for Vulnerability Disclosure (DIVD) hit by network compromise

Incident

Updated: 29.09.2026 18:39 · First: 29.09.2026 18:39 · 📰 2 src / 3 articles · H score: 25

The Dutch Institute for Vulnerability Disclosure (DIVD) confirmed a cyberattack that used an autonomous AI agent, leaving the nonprofit in an ongoing breach investigation with the full impact still unclear. Investigators say the intrusion began with exploitation of a technical vulnerability in an undisclosed system. DIVD has already notified the police, the Autoriteit Persoonsgegevens, and the NCSC.

Google Android 17 Advanced Protection restricts AccessibilityService to verified Accessibility Tools

Security Tool/Service

Updated: 02.10.2026 11:01 · First: 02.10.2026 11:01 · 📰 1 src / 1 articles · H score: 26

Android 17 is tightening Advanced Protection by restricting AccessibilityService access to verified Accessibility Tools, cutting off a major abuse path used for malware and financial fraud. The change preserves legitimate assistive technology while reducing the risk that malicious apps can exploit privileged accessibility access to steal data or trigger fraudulent actions.

CISA KEV mandate for FortiMail CVE-2026-104286

Public Sector Action

Updated: 02.10.2026 01:42 · First: 02.10.2026 01:42 · 📰 2 src / 2 articles · H score: 32

CISA added CVE-2026-104286 to the Known Exploited Vulnerability catalog and required federal agencies to perform forensic triage and mitigate the FortiMail flaw by October 4. The action escalates the federal response to an actively exploited zero-day affecting the FortiMail management interface. It puts a concrete remediation deadline on agencies that may have exposed appliances. The catalog listing signals that the vulnerability is already treated as a live operational risk.

FortiMail actively exploited path traversal and NULL-byte flaw (CVE-2026-104286)

Vulnerability

Updated: 02.10.2026 01:42 · First: 02.10.2026 01:42 · 📰 2 src / 2 articles · H score: 43

Fortinet FortiMail is facing an actively exploited CVE-2026-104286 flaw that lets unauthenticated attackers write arbitrary files and run unauthorized code on vulnerable devices. The issue affects the FortiMail management interface and combines path traversal with NULL-byte handling weaknesses. Fortinet says the bug impacts 7.2.0-7.2.9, 7.4.0-7.4.8, 7.6.0-7.6.6, and 8.0.0-8.0.1. Customers are being told to use workarounds now while fixes roll out in 7.4.9, 7.6.7, and 8.0.2.

Fortinet FortiMail mitigation guidance for CVE-2026-104286

Advisory/Mitigation

Updated: 02.10.2026 01:42 · First: 02.10.2026 01:42 · 📰 2 src / 2 articles · H score: 49

Fortinet issued mitigation guidance for CVE-2026-104286 in FortiMail, warning administrators to use workarounds while the flaw is being actively exploited. The advisory tells customers to disable IBE support or restrict management access to trusted private networks until a security update is available. The guidance applies to FortiMail 7.2.0-7.2.9, 7.4.0-7.4.8, 7.6.0-7.6.6, and 8.0.0-8.0.1. Fortinet says fixed builds are coming in 7.4.9, 7.6.7, and 8.0.2, and 7.2 users can move to the 7.4 branch or later.

Autonomous AI agents government website probing campaign

Campaign

Updated: 01.10.2026 23:52 · First: 01.10.2026 23:52 · 📰 1 src / 1 articles · H score: 29

The autonomous AI agents carried out a multi-site probing campaign against U.S. and Canadian government websites, including SQL injection attempts, creating risk of unauthorized access even though no compromise was confirmed.

WpForo Forum WordPress plugin unauthenticated SQL injection SQL injection flaw (CVE-2026-1581)

Vulnerability

Updated: 01.10.2026 17:37 · First: 01.10.2026 17:37 · 📰 1 src / 1 articles · H score: 26

Active exploitation of CVE-2026-1581 in the wpForo Forum WordPress plugin exposes sites running all versions up to 2.4.14 to unauthenticated SQL injection. Fewer than 20 exploitation attempts were observed since July 3, 2026, with probes arriving from five attacker IPs across multiple countries. The flaw is already being tested in the wild, creating direct risk of database access and broader WordPress site compromise.

SC WordPress backdoor with multi-location persistence and Ethereum C2

Malware Activity

Updated: 01.10.2026 17:37 · First: 01.10.2026 17:37 · 📰 1 src / 1 articles · H score: 27

The SC backdoor on WordPress sites now uses multi-location persistence and Ethereum blockchain C2, letting infected sites rebuild themselves after cleanup and keep serving malicious code. It can create hidden admin accounts, fetch payloads, and inject JavaScript into visitors. The design turns a single compromise into a resilient foothold that is difficult to remove.

KillSec ransomware takedown by Operation KillSwitch

Law Enforcement

Updated: 01.10.2026 17:25 · First: 01.10.2026 17:25 · 📰 3 src / 3 articles · H score: 75

Operation KillSwitch against KillSec moved on September 30 with authorities in Spain, Germany, and other countries seizing the group’s leak site and servers and making three arrests. Investigators identified a suspected 16-year-old as KillSec’s alleged administrator and said the operation secured at least 110 terabytes of stolen data while shutting down 5 servers used in the extortion infrastructure. The action is tied to about 1,000 suspected attacks worldwide, with investigators continuing to examine seized devices, data, and cryptocurrency tracing for additional victims and suspects.

TA419 AI policy impersonation phishing campaign

Campaign

Updated: 01.10.2026 17:00 · First: 01.10.2026 17:00 · 📰 1 src / 1 articles · H score: 34

The TA419 phishing campaign is still active, using AI policy impersonation to target staff at think tanks, defense contractors, universities and law firms in the US and Japan. The operation has run since at least April 2025 and steers victims to spoofed Microsoft 365/OneDrive login pages that harvest credentials and session cookies. The access pattern supports espionage risk against people working on AI policy and export controls.

CloudSyncD macOS backdoor with fake Zoom installer and live C2

Malware Activity

Updated: 01.10.2026 16:30 · First: 01.10.2026 16:30 · 📰 1 src / 1 articles · H score: 24

The CloudSyncD macOS backdoor has advanced from development testing to samples configured against live C2 infrastructure, increasing the risk of real-world deployment. It arrives through a fake Zoom installer that pushes users to bypass Gatekeeper and enter a password. The implant uses encrypted C2, launches a second stage with elevated privileges, and can deliver additional payloads for remote execution. No confirmed infections were reported, but the activity shows operational readiness rather than a proof-of-concept.

CISA launches Cybersecurity Awareness Month 2026

Public Sector Action

Updated: 01.10.2026 15:00 · First: 01.10.2026 15:00 · 📰 1 src / 1 articles · H score: 24

CISA launched Cybersecurity Awareness Month 2026 on 2026-10-01, expanding cybersecurity guidance for business and government organizations that support critical infrastructure. The campaign emphasizes phishing awareness, strong passwords, multifactor authentication, and software updates as baseline controls. It also urges logging, backups, encryption, incident response planning, and preparation for system disruptions.

Defense Manpower Data Center (DMDC) hit by network compromise

Incident

Updated: 01.10.2026 12:44 · First: 01.10.2026 12:44 · 📰 1 src / 1 articles · H score: 18

The Defense Manpower Data Center (DMDC) disclosed a breach of the Pentagon human resources management system that exposed sensitive personnel data for more than 3 million people. The compromise involved unauthorized access through file-sharing systems and put PII and other military records at risk.

Adversarial AI attacks emerge as the top AI security preparedness gap among global business and tech leaders

Trend

Updated: 01.10.2026 12:30 · First: 01.10.2026 12:30 · 📰 1 src / 1 articles · H score: 23

Across 3,934 business and tech leaders in 71 countries, adversarial AI attacks now rank as the biggest AI security preparedness gap, showing that AI abuse has moved to the center of enterprise risk planning. Accountability remains fragmented among CIO/CTO teams, dedicated AI leaders, and the CISO, while only about half of organizations have fully implemented data classification and DLP. Many leaders still expect AI security budgets to rise and are prioritizing responsible AI governance, platform hardening, and supply chain security.

MI5 espionage alert for UK academics on CGTRI/CAGT links

Public Sector Action

Updated: 01.10.2026 10:37 · First: 01.10.2026 10:37 · 📰 1 src / 1 articles · H score: 13

MI5 issued a rare espionage alert on September 30, 2026, warning UK academics that research ties to CGTRI/CAGT may support MSS espionage. The agency said more than 100 UK-linked academics contributed to CGTRI-funded projects in areas including AI, cybersecurity, covert communications and steganography. It urged universities to review collaborations and trace funding sources to identify possible CGTRI links and limit national-security exposure.

Bitget hit by cyberattack

Incident

Updated: 28.09.2026 12:25 · First: 28.09.2026 12:25 · 📰 3 src / 5 articles · H score: 48

Bitget confirmed that attackers stole $387.5 million from its hot and warm wallets after exploiting a third-party zero-day in security products, forcing a temporary halt to withdrawals. SlowMist said the earliest malicious activity linked to the hack dates to August 31, 2026, while Mandiant found the attackers used access on security appliances to move laterally into Bitget’s wallet environment, deploy a web shell, and push malicious packages. Bitget says the incident is contained, user balances remain unaffected, and withdrawals are being restored in stages after remediation.