Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 19:05 09/10/2026 UTC
Last updated: 14:05 09/10/2026 UTC
  • Campaign H score 89 Flax Typhoon critical infrastructure intrusion and credential-harvesting campaign Joint US/UK allied alerts on Flax Typhoon expand Integrity Technology Group TTP detail (including credential harvesting, password spraying, VPN persistence, and email exfiltration) and highlight a broader critical-infrastructure targeting profile that continues to evolve.
  • Incident H score 76 IDC Frontier hit by ransomware attack IDC Frontier’s confirmation of ransomware on IDCF Cloud shut down East Japan Region 1, disrupting services for hundreds of customers and indicating the provider is actively investigating the intrusion path and exposure.
  • Data Leak H score 65 Denmark Central Population Register data breach exposing 8.8 million records Denmark’s CPR breach discloses unauthorized access to about 8.8 million people’s identity records, advancing the incident from detection to mass-impact disclosure with police investigation underway.
  • Campaign H score 89 Integrity Technology Group-linked email-theft and password-spraying campaign A new update on the Integrity Technology Group-linked email-theft campaign ties mailbox compromise to password spraying and fake-login XSS techniques, increasing urgency to harden Microsoft 365/Exchange authentication controls.
  • Vulnerability H score 54 SonicWall SMA1000 SSRF flaw (CVE-2026-102255) SonicWall’s hotfixes for the maximum-severity SMA1000 SSRF flaw (CVE-2026-102255) follow reports of honeypot-consistent exploitation attempts, raising the likelihood that exposed appliances are being targeted in the wild.
  • Security Patch Release H score 41 GitLab security patch release for CVE-2026-90970 GitLab’s emergency patch for critical command execution in self-hosted GitLab AI Gateway (CVE-2026-90970) advances mitigation by providing specific fixed versions for impacted self-managed deployments.

Latest updates

Browse →

Adception Google Ads and Bing redirect Claude ClickFix campaign

Campaign

Updated: 09.10.2026 23:31 · First: 09.10.2026 23:31 · 📰 1 src / 1 articles · H score: 33

A malvertising campaign is abusing Google Ads and Bing redirect chains to push fake Claude installers that try to trigger malicious command execution on macOS users. The operation uses multi-layer cloaking and a compromised WordPress site to hide the lure from scanners. The final page copies Anthropic's legitimate install flow but swaps the clipboard command for a script that fetches payload data from lake-90[.]com and executes it through zsh. Researchers track the associated toolkit as AcSig, and the ultimate payload remains unknown.

Chinese-speaking DarkSword exploitation-as-a-service operation with agent/reseller model

Threat Actor Meta

Updated: 09.10.2026 19:29 · First: 09.10.2026 19:29 · 📰 1 src / 1 articles · H score: 15

Researchers identified a Chinese-speaking DarkSword exploitation-as-a-service operation with an agent/reseller model, signaling a more organized criminal distribution ecosystem for iOS exploit-kit abuse. The platform’s control plane and recovered victim artifacts show the operation was already collecting crypto-wallet recovery phrases and scaling access across multiple hosts. That structure increases the reach and monetization efficiency of DarkSword/Coruna activity.

P7 DarkSword iOS exploit kit adds keychain and crypto-wallet theft

Malware Activity

Updated: 09.10.2026 19:29 · First: 09.10.2026 19:29 · 📰 1 src / 1 articles · H score: 16

The P7 DarkSword variant now adds keychain theft and crypto-wallet theft while also enabling two-way C2 with attacker infrastructure, increasing the risk of stolen credentials and wallet abuse on compromised iPhones. The change makes the exploit kit more capable of harvesting high-value data and managing infected devices remotely.

Read-only and scoped permission enforcement for AI agent tool calls

Defensive Guidance

Updated: 09.10.2026 17:01 · First: 09.10.2026 17:01 · 📰 1 src / 1 articles · H score: 16

Organizations are being urged to enforce read-only and scoped credentials at AI agent tool calls so agents cannot overreach through prompt injection, mistaken assumptions, or credential misuse. The guidance points to gateways, hooks, sandboxes, and endpoint enforcement as practical controls for blocking out-of-policy actions. It also warns that the right control depends on where the agent runs and whether the platform can actually see the request.

AnyDesk Linux version 8.0.3 security patch release

Security Patch Release

Updated: 09.10.2026 15:59 · First: 09.10.2026 15:59 · 📰 1 src / 1 articles · H score: 36

AnyDesk released version 8.0.3 for AnyDesk Linux, closing a pre-authentication RCE path before the exploit became public. The June fix was treated as a generic bug fix in the changelog, with no CVE and no formal security advisory attached. Administrators should move affected Linux systems to 8.0.3 or later because the underlying flaw could expose systems to root access over direct connections.

AnyDesk Linux pre-auth RCE flaw (published exploit)

Vulnerability

Updated: 09.10.2026 15:59 · First: 09.10.2026 15:59 · 📰 1 src / 1 articles · H score: 29

A working exploit is now public for an AnyDesk Linux pre-authentication remote code execution flaw, exposing systems to root access before connection approval. AnyDesk fixed the issue in version 8.0.3 in June, but the flaw still had no CVE as of October 9. The published code targets direct TCP connections on port 7070 and shows that the bug can be weaponized even before a session is accepted. Relay-based exploitation remains unresolved.

AhsayCBS XMRig and web shell post-exploitation activity

Malware Activity

Updated: 09.10.2026 15:47 · First: 09.10.2026 15:47 · 📰 2 src / 2 articles · H score: 33

AhsayCBS post-exploitation activity is combining web shells and XMRig cryptominers after compromise. Huntress observed the activity on October 7 and said it targeted at least five organizations. Attackers chained CVE-2026-105133 for authentication bypass and CVE-2026-105134 for code execution, then dropped JSP webshells, downloaded XMRig as edge.exe, and used MicrosoftEdgeUpdateSvc plus Taskgmr.ps1 to hide mining activity.

AhsayCBS backup utility active exploitation wave (CVE-2026-105133, CVE-2026-105134)

Exploitation Wave

Updated: 09.10.2026 15:47 · First: 09.10.2026 15:47 · 📰 2 src / 2 articles · H score: 51

AhsayCBS exploitation of CVE-2026-105133 and CVE-2026-105134 is enabling authentication bypass, code execution, and post-compromise activity on exposed backup management systems. Huntress observed the wave on October 7 and said it targeted at least five organizations. Attackers chained the flaws to gain access, then deployed JSP webshells and the XMRig miner disguised as edge.exe. Huntress also said Ahsay 10.3.4 is affected, extending the exposure beyond the originally fixed version.

AhsayCBS backup utility actively exploited authentication bypass and command injection flaws (multiple vulnerabilities)

Vulnerability

Updated: 09.10.2026 15:47 · First: 09.10.2026 15:47 · 📰 2 src / 2 articles · H score: 49

CVE-2026-105133 and CVE-2026-105134 in AhsayCBS are being actively exploited, enabling attackers to bypass authentication and run arbitrary commands on exposed systems. Huntress observed the activity on October 7, 2026 and said it affected at least five organizations. Post-exploitation activity included JSP webshells, XMRig miners disguised as edge.exe, a MicrosoftEdgeUpdateSvc service running msedge.exe, and Taskgmr.ps1 used to hide mining activity.

SonicWall SMA1000 SSRF flaw (CVE-2026-102255)

Vulnerability

Updated: 07.10.2026 14:37 · First: 07.10.2026 14:37 · 📰 2 src / 3 articles · H score: 54

CVE-2026-102255 is a maximum-severity SSRF in the SonicWall SMA1000 Appliance WorkPlace interface that lets a remote unauthenticated attacker make the appliance issue requests on its behalf and reach internal functionality. SonicWall released hotfixes and fixed releases for SMA1000 6210, 7210, and 8200v after disclosing the flaw on 2026-10-06, then warned customers to install the patched builds. On 2026-10-09, a security researcher said his honeypot network saw exploitation attempts consistent with the CVE, while SonicWall had not yet flagged the issue as actively exploited in its advisory. Shadowserver separately tracks more than 400 Internet-exposed SMA1000 appliances, leaving an exposed target base for abuse.

SonicWall security patch release for CVE-2026-102255

Security Patch Release

Updated: 07.10.2026 14:37 · First: 07.10.2026 14:37 · 📰 2 src / 3 articles · H score: 38

SonicWall released hotfixes for CVE-2026-102255 in SMA1000 appliances, a maximum-severity flaw in the Appliance WorkPlace interface on 6210, 7210, and 8200v models. The issue lets a remote unauthenticated attacker abuse the path to make the appliance issue requests on its behalf and reach internal functionality for unauthorized operations. SonicWall said it had no evidence of exploitation in the wild at advisory time, but researcher Ryan Dewhurst said his honeypot network saw activity consistent with the flaw. The exposure surface remains significant because Shadowserver tracks more than 400 SMA1000 appliances exposed online.

Oleg Korniev / YMCO guilty plea

Law Enforcement

Updated: 09.10.2026 14:14 · First: 09.10.2026 14:14 · 📰 1 src / 1 articles · H score: 29

Oleg Korniev pleaded guilty to helping run Your Mule Cashout (YMCO), a money-laundering network that moved illicit proceeds for cybercriminals and exposed U.S. victims to losses. The case in the Western District of North Carolina covers money laundering, aggravated identity theft, computer fraud, and access device theft. His plea expands criminal exposure around a long-running mule operation that used more than 15,000 money mules.

Microsoft Windows Update certificate-rotation guidance

Advisory/Mitigation

Updated: 09.10.2026 13:12 · First: 09.10.2026 13:12 · 📰 1 src / 1 articles · H score: 26

Microsoft told administrators to upgrade supported Windows versions before the Windows Update certificate rotation in May and June 2027. Unsupported devices will lose access to Windows Update services and stop receiving security updates. Microsoft also set version-specific deadlines for Windows 11 24H2 / Windows Server 2025, other supported Windows 11, Windows Server 2022, and Windows 10, and Windows Server 2019/2016. Devices updated through WSUS are not affected.

GoBalance Tor-format key-recovery actively exploited security flaw

Vulnerability

Updated: 09.10.2026 12:03 · First: 09.10.2026 12:03 · 📰 1 src / 1 articles · H score: 18

A GoBalance flaw is letting attackers recover the private key behind a site's .onion address, enabling takeover of affected dark-web sites. Searchlight Cyber said the bug sits in the signing step and can be abused from public descriptors alone, so attackers do not need server access. The issue has already been tied to takeovers of Dread and at least one other site, and a public proof-of-concept plus patch have been published. There is still no official fix, so exposed sites need to move to a new .onion address.

ICO formal investigation into Grok personal-data processing

Regulatory/Legal Action

Updated: 09.10.2026 11:00 · First: 09.10.2026 11:00 · 📰 1 src / 1 articles · H score: 16

The ICO opened formal investigations into XIUC and X.AI LLC over Grok's personal-data processing, escalating UK regulatory scrutiny of the AI system. The probe centers on whether those practices can contribute to harmful sexualized image and video content. The action raises compliance pressure around data protection, safeguards, and the handling of sensitive personal information.

ICO launches six-week call for evidence on agentic AI data-protection risks

Public Sector Action

Updated: 09.10.2026 11:00 · First: 09.10.2026 11:00 · 📰 1 src / 1 articles · H score: 16

The ICO launched a six-week call for evidence on agentic AI data-protection risks, drawing developers, deployers, and security/privacy experts into a public consultation that will shape future safeguards for autonomous systems. The process focuses on how organizations manage personal-data risks as AI systems become more autonomous, with responses due by November 20.

Citrix NetScaler ADC and NetScaler Gateway memory overflow denial-of-service flaw (CVE-2026-107406)

Vulnerability

Updated: 09.10.2026 09:53 · First: 09.10.2026 09:53 · 📰 2 src / 2 articles · H score: 33

CVE-2026-107406 is a critical memory overflow in Citrix NetScaler ADC and NetScaler Gateway that can lead to remote code execution or denial-of-service in specific SAML SP/SAML IdP configurations. Citrix says the flaw also affects Secure Private Access Hybrid deployments that use NetScaler. Fixed builds are available, and customers are being told to upgrade immediately. Citrix said it was not aware of any unmitigated exploits at publication.

Flax Typhoon critical infrastructure intrusion and credential-harvesting campaign

Campaign

Updated: 09.10.2026 09:39 · First: 09.10.2026 09:39 · 📰 2 src / 2 articles · H score: 89

Flax Typhoon is a long-running intrusion and credential-harvesting campaign tied to Integrity Technology Group that has targeted U.S. and foreign critical infrastructure and other victim networks. By mid-January 2021, the operation was already using Python- and Go-based utilities and XSS credential harvesting to break into networks and cloud services, then extending access into Microsoft 365 Cloud environments. The latest joint alert from the US, UK and allied countries adds detail on Integrity Technology Group TTPs, including open source scanning tools, EBurst password spraying, SoftEther VPN persistence, and email exfiltration from on-premises and cloud systems. The US also seized several domains tied to Microscan and FishHub in a disruption action against the organization and associated threat activity.

FBI seizes Flax Typhoon hacking-tool domains

Law Enforcement

Updated: 09.10.2026 00:42 · First: 09.10.2026 00:42 · 📰 1 src / 1 articles · H score: 67

The FBI seized seven domains tied to Flax Typhoon's MicroScan and FishHub hacking tools, disrupting infrastructure used in breaches against critical infrastructure and other organizations worldwide.

MicroScan and FishHub tool activity used for scanning, phishing, and exfiltration

Malware Activity

Updated: 09.10.2026 00:42 · First: 09.10.2026 00:42 · 📰 1 src / 1 articles · H score: 68

MicroScan and FishHub were used to support vulnerability scanning, spear-phishing, and data exfiltration, expanding intrusion reach against critical infrastructure and other organizations worldwide. The tools were tied to a broader Flax Typhoon operation and infrastructure later disrupted by domain seizures. The activity also included follow-on malware delivery and unauthorized access to already compromised networks.

IDC Frontier hit by ransomware attack

Incident

Updated: 08.10.2026 23:09 · First: 08.10.2026 23:09 · 📰 1 src / 1 articles · H score: 76

IDC Frontier confirmed a ransomware attack on IDCF Cloud that shut down East Japan Region 1, disrupting cloud services for public and private customers. The outage began on October 7 at 3:40 AM local time and prompted network and system shutdowns. IDC Frontier said the event affected 495 companies and local governments using the service. The provider isolated impacted systems, disabled management-console access, and continued investigating the intrusion route and broader security exposure.

Midnight Mimosa preinstalled Android firmware malware

Malware Activity

Updated: 08.10.2026 22:20 · First: 08.10.2026 22:20 · 📰 1 src / 1 articles · H score: 29

The Midnight Mimosa malware activity is embedded in low-cost Android firmware, giving infected phones system-level control to silently install apps, run ad fraud, and act as residential proxies. The activity has affected thousands of devices across more than 150 countries, with evidence tied to MediaTek-based phones and devices posing as major brands. Because the malware is preinstalled in the system partition, removal often requires firmware-level cleanup or ADB-based intervention.

Midnight Mimosa multi-country Android supply-chain campaign

Campaign

Updated: 08.10.2026 22:20 · First: 08.10.2026 22:20 · 📰 1 src / 1 articles · H score: 32

Midnight Mimosa spans thousands of Android devices in more than 150 countries, showing a broad supply-chain operation with sustained reach over about two years. The operation used preinstalled firmware malware to silently install apps, drive ad fraud, and turn infected phones into residential proxies. Victims were concentrated in Mexico, France, Italy, the United States, Germany, Brazil, and Spain.

Integrity Technology Group-linked email-theft and password-spraying campaign

Campaign

Updated: 08.10.2026 21:32 · First: 08.10.2026 21:32 · 📰 1 src / 1 articles · H score: 89

A multi-country email-theft campaign tied to Integrity Technology Group has targeted government, law enforcement, healthcare, and religious organizations since at least mid-January 2021, putting mailbox access and account security at risk. The operators used website scanning, password spraying against Microsoft 365 and Exchange, and fake-login XSS pages to gain entry. They then used tools to collect and exfiltrate mail through Exchange Web Services and other legitimate access paths. The same activity also included a portal that let third parties access stolen email content.

Stolen email content exposed through hacker web application

Data Leak

Updated: 08.10.2026 21:32 · First: 08.10.2026 21:32 · 📰 1 src / 1 articles · H score: 67

A hacker-operated web application is exposing stolen email content to third parties, letting outsiders read compromised mail instead of keeping it locked inside the original breach. The portal lets users view the mail of a specific account by adding arguments to a URL. The exposure is tied to Integrity Technology Group-linked hackers and extends the impact of their mailbox theft activity.

UAC-0099 campaign targeting Ukrainian government, logistics, and infrastructure entities

Campaign

Updated: 08.10.2026 18:26 · First: 08.10.2026 18:26 · 📰 1 src / 1 articles · H score: 33

The UAC-0099 campaign is now tied to a broader targeting set in Ukraine, including civilian logistics and infrastructure operators, which raises the risk to the systems that keep supply lines running. The operation has targeted government, defense, border guard, and logistics entities since at least mid-2022. It has also used ASHVEIN to collect credentials, capture screenshots, and open remote shells on victim systems. The actor's evolving tooling and widening victim set point to a persistent espionage operation with growing strategic reach.

ASHVEIN (TelemetryBrowser) .NET infostealer and RAT activity against Ukrainian government personnel

Malware Activity

Updated: 08.10.2026 18:26 · First: 08.10.2026 18:26 · 📰 1 src / 1 articles · H score: 29

The ASHVEIN (TelemetryBrowser) malware activity now includes confirmed attacks against Ukrainian government personnel, giving UAC-0099 a new .NET infostealer/RAT for credential theft and remote control. The malware steals logins from Chrome and Firefox while also supporting screenshot capture, file collection, and PowerShell remote shells. Its delivery chain uses DLL sideloading, VHD containers, and dedicated .NET droppers to expand reach and persistence. The build set was actively maintained in October 2025, showing continued development of a flexible intrusion toolset.

.Gh (Ghana) ccTLD registry hit by cyberattack

Incident

Updated: 08.10.2026 17:30 · First: 08.10.2026 17:30 · 📰 1 src / 1 articles · H score: 26

The .gh, .sl and .as ccTLD registries were compromised, letting attackers alter authoritative DNS records and obtain unauthorized HTTPS certificates for Google domains and other organizations. The incident put domains under those namespaces at risk and weakened certificate trust beyond the registries themselves.

China-based ARTEX AI-enabled campaign against South Korean financial organizations

Campaign

Updated: 08.10.2026 14:00 · First: 08.10.2026 14:00 · 📰 2 src / 2 articles · H score: 39

CrowdStrike said a suspected China-based threat actor used ARTEX and Anthropic’s Claude AI in a targeted campaign against South Korean financial organizations from late September to early October 2026. The activity led to data exfiltration, and the actor used ARTEX to discover vulnerabilities and compromise specific services. CrowdStrike also linked the operator to efforts to find Korean Telegram data sales groups, while assessing the attacker as a Chinese speaker with financial motivation. South Korea’s Financial Services Commission warned customers of the hacked companies about possible phishing attacks and loan scams.

ASOS hit by network compromise

Incident

Updated: 06.10.2026 14:41 · First: 06.10.2026 14:41 · 📰 2 src / 5 articles · H score: 10

ASOS is investigating unauthorized activity involving third-party platforms it uses to communicate with customers after a Telegram-linked notification appeared to come from the incident. ASOS said it took immediate action to restrict access to the notification platforms and is working with internal and external advisers plus relevant authorities. The company said names and contact details may have been accessed, while payment-card information and account passwords were not believed impacted, and its website, app, and operations were reported as normal. Analysts said the access appears more consistent with a SaaS platform compromise than confirmed database theft, and no sample or dump has been provided to verify broader data claims.