Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 02:07 12/09/2026 UTC
Last updated: 13:35 11/09/2026 UTC

Latest updates

Browse →

ShinyHunters and Helix passkey-themed Microsoft 365 account compromise campaign

Campaign

Updated: 11.09.2026 20:26 · First: 11.09.2026 20:26 · 📰 1 src / 1 articles · H score: 34

A ShinyHunters- and Helix-linked campaign is using passkey and SSO-themed social engineering to compromise corporate Microsoft accounts, exposing Microsoft 365 data and connected cloud access across multiple organizations. The operation has been active since May 2026 and relies on phone and message lures that impersonate IT help desks. Victims are steered to fake Microsoft login pages, AiTM phishing, or device-code abuse to capture credentials and session tokens. Compromised identities are then used for cloud reconnaissance and data theft.

JFrog Artifactory CVE-2026-42018/CVE-2026-42016 exploitation wave

Exploitation Wave

Updated: 11.09.2026 19:29 · First: 11.09.2026 19:29 · 📰 1 src / 1 articles · H score: 42

Multiple threat actors are actively exploiting JFrog Artifactory through CVE-2026-42018 and CVE-2026-42016 to bypass authentication, mint admin-scoped tokens, and deploy a Rust-based backdoor on vulnerable self-hosted servers. The exploitation wave ran between August 15 and September 8, 2026, with some compromises reaching administrator creation in under five minutes. Wiz says the activity spans multiple environments and affects a substantial share of reachable instances. Related activity also includes CVE-2026-82329 being used to mint administrator tokens.

JFrog Artifactory authentication bypass and token validation flaws (multiple vulnerabilities)

Vulnerability

Updated: 11.09.2026 19:29 · First: 11.09.2026 19:29 · 📰 1 src / 1 articles · H score: 42

JFrog Artifactory self-hosted servers were actively exploited through CVE-2026-42018 and CVE-2026-42016, letting attackers bypass authentication, steal JWTs, and escalate to admin-level access. Exploitation was observed between August 15 and September 8, 2026 across multiple environments, with some intrusions reaching administrator creation in under five minutes. Administrators were urged to upgrade immediately to the fixed release lines and check for rogue accounts, token creation, and suspicious plugin activity.

JFrog Artifactory custom Rust backdoor deployment

Malware Activity

Updated: 11.09.2026 19:29 · First: 11.09.2026 19:29 · 📰 1 src / 1 articles · H score: 34

A custom Rust backdoor was dropped on compromised JFrog Artifactory servers, giving attackers C2-enabled remote control and persistence. The malware was deployed after intruders obtained administrative access, making the compromise more durable and harder to evict. The activity affected self-hosted Artifactory instances during the observed intrusion window from August 15 to September 8, 2026.

China-based AI labs illicit Claude distillation campaign

Campaign

Updated: 11.09.2026 19:15 · First: 11.09.2026 19:15 · 📰 1 src / 1 articles · H score: 27

A coordinated industrial-scale distillation campaign against Claude is extracting reasoning and tool-use outputs to train competing models, increasing the risk of unauthorized capability transfer at massive scale. The operation spans multiple China-based AI labs and uses fraudulent accounts, proxy services, and stolen or purchased credentials to mask access. Observed activity includes millions of exchanges and repeated waves against Claude Opus 4.6 and 4.7. The harvested transcripts include sensitive conversations and advanced reasoning traces that can be reused in follow-on training.

GTG-30006 Claude-assisted malware and phishing pipeline

Malware Activity

Updated: 11.09.2026 17:29 · First: 11.09.2026 17:29 · 📰 1 src / 1 articles · H score: 20

An Iranian actor, GTG-30006, used Claude.ai to build malware, a delivery pipeline, and a phishing portal targeting domestic Iranians, increasing the risk of credential theft and Windows implant deployment. The operation included a fake ESET NOD32 login page that sent captured credentials to Telegram, a ClickFix-style Windows Run dialog lure, and geofenced delivery pages. The actor also built SECOMS64, a modular Windows implant with keylogging, screenshot capture, and Chrome credential extraction capabilities.

Anthropic Claude misuse analysis of multi-agent reconnaissance, exploitation, and exfiltration

Technical Analysis

Updated: 11.09.2026 17:29 · First: 11.09.2026 17:29 · 📰 2 src / 2 articles · H score: 59

Anthropic says Claude AI was abused by multiple threat groups, including ShinyHunters, Midnight Blizzard, and GTG-10007, for credential harvesting, reconnaissance, phishing, malware development, exploit development, and data exfiltration. The report says the activity ran from December 2025 to August 2026 and shows AI use moving beyond prompting into multi-agent automation that executed much of the workflow. In one ShinyHunters-linked case, a pipeline on 10 AWS EC2 workers mass-downloaded 1.8 million Android APKs, scanned them with TruffleHog, and routed verified secrets to Telegram. Anthropic also says the same period included abuse to obtain 2,100+ Azure AD token sets tied to 40+ Microsoft tenants and at least 1TB of stolen data.

North African government technology authority data exposed after North African government technology authority breach

Data Leak

Updated: 11.09.2026 17:10 · First: 11.09.2026 17:10 · 📰 1 src / 1 articles · H score: 45

A North African government technology authority suffered a data leak after attackers hijacked its central account server and exfiltrated a credential database containing over 300,000 national identity records and more than half a million company registry records. The exposed data raises the risk of identity abuse, account takeover, and downstream targeting of listed people and companies. The compromise was reached through VPN appliance credentials and was attributed after the intrusion.

Microsoft 365 Direct Send phishing campaign tracked to US Eastern business hours

Campaign

Updated: 11.09.2026 16:30 · First: 11.09.2026 16:30 · 📰 1 src / 1 articles · H score: 39

A phishing campaign abused Microsoft 365 Direct Send to deliver 29,785 confirmed phishing emails across July and August 2026, with activity clustering during US Eastern business hours. The operation matters because the messages could appear to come from trusted internal senders while bypassing normal email security gateways. One observed message reached 900 recipients in a single send.

GitLab self-managed installations immediate upgrade advisory

Advisory/Mitigation

Updated: 11.09.2026 14:15 · First: 11.09.2026 14:15 · 📰 2 src / 2 articles · H score: 45

GitLab issued immediate upgrade guidance for self-managed GitLab installations after fixing two security issues in GitLab CE and GitLab EE. Operators were told to move to 19.3.2, 19.2.6, or 19.1 without delay. The guidance reduces exposure to CVE-2023-2825 and CVE-2026-87719, which can enable arbitrary file reads or sensitive credential theft under certain conditions.

GitLab repository commits API path traversal vulnerability (CVE-2023-2825)

Vulnerability

Updated: 11.09.2026 14:15 · First: 11.09.2026 14:15 · 📰 1 src / 1 articles · H score: 33

GitLab has a maximum-severity path traversal vulnerability, CVE-2023-2825, that can let unauthenticated attackers read arbitrary files from vulnerable servers under certain conditions. The flaw affects the repository commits API and exposes GitLab Community Edition (CE) and Enterprise Edition (EE) deployments until they are patched. GitLab says self-managed installations should upgrade immediately because fixed builds are now available.

GitLab CE/EE security patch release (CVE-2023-2825, CVE-2026-87719)

Security Patch Release

Updated: 11.09.2026 14:15 · First: 11.09.2026 14:15 · 📰 2 src / 2 articles · H score: 45

GitLab released fixes for CVE-2023-2825 and CVE-2026-87719 in GitLab Community Edition (CE) and Enterprise Edition (EE), requiring self-managed installations to upgrade immediately. The patch release addresses both a maximum-severity path traversal flaw and a critical insecure deserialization issue.

Microsoft Teams and Outlook for Windows launch failure on ARM-based Windows PCs

Service Disruption

Updated: 11.09.2026 12:39 · First: 11.09.2026 12:39 · 📰 1 src / 1 articles · H score: 0

Microsoft fixed a launch failure that caused Teams and the new Outlook for Windows to fail to open or close unexpectedly on ARM-based Windows devices after August 11, 2026 updates. The disruption affected Windows 11 24H2 or later systems, especially new or freshly imaged PCs that had not yet installed Microsoft Store updates. Microsoft later said the issue was resolved in KB5124012 and newer updates. The company also pointed customers to the Auto Super Resolution Package as a temporary workaround.

UK and US Microsoft 365 AI rollout outpaces permissions review

Trend

Updated: 11.09.2026 12:30 · First: 11.09.2026 12:30 · 📰 1 src / 1 articles · H score: 26

UK and US organizations are deploying Copilot and other Microsoft 365 AI tools faster than they are reviewing permissions, widening exposure to broadly shared content. Only 43% completed a thorough oversharing review before rollout, while 91% say they can see active agents and their reach. Access governance is even thinner for agent controls: just 22% have a formal policy, and 9% let an agent inherit the deployer's full permissions. The pattern leaves sensitive SharePoint and file content reachable through AI surfaces that inherit existing access.

Midnight Blizzard Claude-assisted cyberespionage campaign

Campaign

Updated: 11.09.2026 11:47 · First: 11.09.2026 11:47 · 📰 1 src / 1 articles · H score: 19

Midnight Blizzard ran a Claude-assisted cyberespionage campaign that automated malware evasion and kept the operation active across more than 20 organizations. The activity reached government ministries, defense and intelligence bodies, embassies, and think tanks across Europe, the Middle East, and Asia. Anthropic said it disrupted the campaign after tracking it from December 2025 to August 2026 and used the findings to strengthen its safeguards.

Brevo-abused Trezor security-alert phishing campaign

Campaign

Updated: 11.09.2026 10:55 · First: 11.09.2026 10:55 · 📰 1 src / 1 articles · H score: 45

A Brevo-abused phishing campaign targeted Trezor newsletter subscribers with fake security-alert emails, reaching 347,000 email addresses and driving 2,500 clicks before takedown.

Sogou Input Method Windows link-handler code-execution flaw (CVE-2026-51990)

Vulnerability

Updated: 11.09.2026 10:14 · First: 11.09.2026 10:14 · 📰 1 src / 1 articles · H score: 89

Sogou Input Method on Windows had a link-handler flaw in the `sgbiz:` path that let attacker-controlled arguments and browser navigation reach code execution under the logged-in user's privileges. Gen Digital tied the bug to CVE-2026-51990 and said Tencent completed a fix for version 16.3.0.3498 in April 2026. The flaw was used in a live intrusion to deliver the GRAYRABBIT backdoor. The patch closed the link-handler entry point, but the broader browser-engine weaknesses in the product were not removed.

GRAYRABBIT backdoor deployment via Sogou Input Method exploit

Malware Activity

Updated: 11.09.2026 10:14 · First: 11.09.2026 10:14 · 📰 1 src / 1 articles · H score: 89

The GRAYRABBIT backdoor was deployed in a live intrusion against Sogou Input Method users, giving attackers a remote command shell and the ability to stage additional modules. The payload turned a Windows exploit chain into persistent attacker access on victim machines. The backdoor traffic was tied to mail.uaiubifas[.]top on port 443, raising monitoring value for defenders.

UNC3569 Sogou Input Method exploitation campaign

Campaign

Updated: 11.09.2026 10:14 · First: 11.09.2026 10:14 · 📰 1 src / 1 articles · H score: 89

The UNC3569 campaign abused a crafted sgbiz: link to exploit Sogou Input Method on Windows, giving the operator code execution and a foothold for the GRAYRABBIT backdoor. The chain let the attacker act with the logged-in user's privileges, turning a link click into remote access. Gen Digital linked the activity to a live intrusion and said UNC3569 has targeted government, education, technology, and finance sectors in East and Southeast Asia since 2021. Tencent fixed the flaw in April 2026 and pushed version 16.3.0.3498 to close the link-handler path.

UNC3569 Exploitation and Remediation of Sogou Input Method on Windows

Case

Updated: 11.09.2026 10:14 · First: 11.09.2026 10:14 · 📰 0 src / 2 articles

Sogou Input Method on Windows was exploited through a crafted sgbiz: link that reached CVE-2026-51990, giving attackers code execution with the logged-in user's privileges and leading to GRAYRABBIT installation. The same intrusion chain also used CVE-2021-38003 in the product's Chromium-based browser path, and available material ties the operation to UNC3569. The flaw was reported to Tencent in April 2026, and the vendor said a fix was completed in version 16.3.0.3498 and pushed through automatic update. Public details still leave open the full affected-version range and whether broader browser-engine weaknesses inside the product create additional exposure beyond the closed link-handler path.

PaperCut NG and MF auth-bypass RCE chain (multiple vulnerabilities)

Vulnerability

Updated: 28.08.2026 20:12 · First: 28.08.2026 20:12 · 📰 2 src / 6 articles · H score: 53

PaperCut NG/MF vulnerability activity now includes active exploitation of CVE-2026-81578 and CVE-2026-82078, an authentication bypass and remote code execution chain affecting exposed instances. PaperCut issued a second emergency patch and told operators to remove public internet exposure and restrict PaperCut Application Server access to trusted IPs or a VPN. The latest reporting says a suspected Russian-speaking actor used OpenAI Codex and a DeepSeek model to research, validate, and deploy exploits, then compromised at least 440 instances across 395 victim organizations in 48 countries, with education-sector victims in the U.S., the U.K., France, Spain, Canada, Belgium, Portugal, Australia, Germany, and Switzerland. Earlier observed post-exploitation activity included a Java `.class` file, Base64-encoded commands, and commands such as `whoami & ver & tasklist` on a PaperCut target.

Mantax Otax Android malware activity

Malware Activity

Updated: 11.09.2026 00:40 · First: 11.09.2026 00:40 · 📰 1 src / 1 articles · H score: 32

The Mantax Otax Android malware now combines ransomware and spyware features, putting older Android devices at risk of file encryption, data theft, and harassment. It spreads through malicious APKs outside Google Play and uses phishing and social engineering to push installation, then requests Accessibility permission for deep device control. The malware pulls its C2 from GitHub, can issue commands through Firebase or WebSockets, and is already detected and blocked on up-to-date devices with active Play Protect.

Windows Server Remote Desktop Services disruption after September 2026 cumulative updates

Service Disruption

Updated: 10.09.2026 23:34 · First: 10.09.2026 23:34 · 📰 1 src / 1 articles · H score: 0

Windows Server Remote Desktop Services is experiencing a service disruption after the September 2026 cumulative updates, leaving some systems unable to accept new connections and causing sessions to hang. The affected scope includes Windows Server 2019, 2022, and 2025 installations, and some administrators report that only a hard reset restores functionality. Rolling back the update has restored service for some environments, but that also removes the month's security fixes.

Surfshark hit by cyberattack

Incident

Updated: 10.09.2026 22:15 · First: 10.09.2026 22:15 · 📰 1 src / 1 articles · H score: 10

Surfshark confirmed a breach of internal systems after a configuration error exposed an internal test server to the internet, creating risk for its engineering environment even though customer data was not impacted. The exposure also reached a separate proxy server used for content-accessibility optimization, and the accessed environment held service configurations and build-related credentials. The company detected suspicious activity on August 31, contained it on September 2, and finished remediation three days later.

Google security patch release for CVE-2026-28662

Security Patch Release

Updated: 10.09.2026 20:47 · First: 10.09.2026 20:47 · 📰 1 src / 1 articles · H score: 39

Google released the September 2026 Android security updates to patch 200 vulnerabilities across Android, including CVE-2026-28662. The bundle contains critical and high-severity flaws, and at least one issue can enable remote code execution without user interaction. Organizations running Android devices need to deploy the updates quickly to close the exposure window.

Singapore police arrest two suspects in Singpass compromise scheme

Law Enforcement

Updated: 10.09.2026 20:47 · First: 10.09.2026 20:47 · 📰 1 src / 1 articles · H score: 46

Singapore police arrested two male Chinese Malaysians in a Singpass compromise scheme, linking the case to more than 170 accounts and over 160 LiquidPay registrations. Investigators said the suspects were mobile phone shop employees who allegedly used customer interactions to reach account details. The arrests disrupt a fraud-and-account-takeover operation affecting Singapore citizens and work permit holders.

Chinese-speaking operator AI-orchestrated intrusion campaign targeting government and financial systems

Campaign

Updated: 10.09.2026 20:47 · First: 10.09.2026 20:47 · 📰 1 src / 1 articles · H score: 48

A Chinese-speaking operator is running an AI-orchestrated intrusion campaign that automates attacks against government and financial systems across multiple countries. The operation uses Anthropic Claude Code, Alibaba Qwen, DeepSeek, and SecFlow to divide reconnaissance, exploitation, collection, and reporting across specialist agents. Named targets include systems in Afghanistan, Thailand, Taiwan, the U.S., Indonesia, mainland China, and Vietnam. The task-splitting workflow and repeated intrusion chain point to an active, scalable campaign rather than isolated probing.

Cyclops Blink deployed on compromised Cisco FMC devices

Malware Activity

Updated: 10.09.2026 18:43 · First: 10.09.2026 18:43 · 📰 1 src / 1 articles · H score: 32

A Cyclops Blink variant was deployed on compromised Cisco Secure Firewall Management Center (FMC) devices, giving attackers a persistent backdoor with credential theft and network sniffing capability. The malware activity was tied to the UAT-11823 intrusion cluster and followed earlier access to the management appliances. The payload adds post-compromise control on a security-management platform that can expose internal credentials and traffic.

IDScan identity-document data leak

Data Leak

Updated: 04.09.2026 19:56 · First: 04.09.2026 19:56 · 📰 1 src / 2 articles · H score: 84

A reported IDScan data leak exposed or offered for sale more than 153 million driver’s license scans, putting large volumes of identity documents at risk. The cache was advertised by the dark-web service Nexus, and sample checks tied the material back to IDScan. The exposure increases the risk of identity theft, impersonation, and fraud for people whose IDs were scanned through businesses using the service.

IDScan hit by cyberattack

Incident

Updated: 10.09.2026 17:55 · First: 10.09.2026 17:55 · 📰 1 src / 1 articles · H score: 73

IDScan confirmed an unauthorized-access incident affecting its IDScan.net cloud after learning on or around September 1 that customer data may have been accessed or copied. The event is significant because exposed records can include full names and government-issued identification numbers, and reporting tied the breach to claims involving more than 153 million driver's license scans. IDScan said it is investigating, securing systems, and providing free credit monitoring and identity protection services.