Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 19:50 05/10/2026 UTC
  • Public Sector Action H score 69 US Senate passes Health Care Cybersecurity and Resilience Act The US Senate passed the Health Care Cybersecurity and Resilience Act, advancing federal healthcare defense funding and incident-response planning to the House amid ongoing sector ransomware pressure.
  • Data Leak H score 65 Denmark Central Population Register data breach exposing 8.8 million records Denmark’s Central Population Register disclosed a breach exposing 8.8 million people’s personal records, escalating the scale of potential identity fraud while access has been blocked pending police investigation.
  • Security Patch Release H score 46 Citrix security patch release for CVE-2026-88779 Citrix issued emergency NetScaler ADC/Gateway updates for actively exploited CVE-2026-88779, tightening defenses by urging immediate patching and providing deny-list mitigations.
  • Vulnerability H score 46 Rejetto HFS session forgery RCE (CVE-2026-61500) Rejetto HFS CVE-2026-61500 is newly framed as a session-forgery flaw that enables admin takeover and possible RCE, reinforcing urgent patching to HFS 3.2.1 after PoC and exploitation attempts.
  • Incident H score 40 Shinhan Bank hit by cyberattack Shinhan Bank confirmed a cyberattack involving a data breach, with authorities coordinating investigations across South Korea’s banking sector and focusing on containment and customer protection.
  • Malware Activity H score 34 Cling botnet with STUN-based C2 and persistence FortiGuard reported Cling botnet enhancements using STUN-based hidden C2 and persistence across multiple IoT exploit waves, increasing stealthy remote control risk for internet-facing devices.
Last updated: 17:20 05/10/2026 UTC

Latest updates

Browse →

Rejetto HFS session forgery RCE (CVE-2026-61500)

Vulnerability

Updated: 05.10.2026 11:09 · First: 05.10.2026 11:09 · 📰 2 src / 2 articles · H score: 46

CVE-2026-61500 in Rejetto HTTP File Server (HFS) exposes 3.0.0 through 3.2.0 to session forgery, letting attackers recover a signing key from Math.random() and seize administrator access. A public Python PoC appeared in late September 2026, and VulnCheck later reported active exploitation attempts. The flaw can escalate to remote code execution through the server_code configuration feature. A fix is available in HFS 3.2.1.

Italy's Data Protection Authority (GPDP) €7 million fine and compliance order within 120 days on remediate health-data processing and anonymization failures

Regulatory/Legal Action

Updated: 05.10.2026 20:19 · First: 05.10.2026 20:19 · 📰 1 src / 1 articles · H score: 21

Italy's GPDP fined IQVIA and ordered compliance after finding GDPR violations in health-data processing that could expose and de-anonymize roughly one million patients. The authority said the company's Italian division used detailed records and unique codes that made reidentification possible over time. It also said the processing lacked an adequate legal basis and patient notice, with a 120-day deadline to fix the practices.

Microsoft Exchange Server weak authorization privilege escalation (CVE-2026-96940)

Vulnerability

Updated: 05.10.2026 19:21 · First: 05.10.2026 19:21 · 📰 1 src / 1 articles · H score: 29

A weak authorization flaw in Microsoft Exchange Server (CVE-2026-96940) lets an authenticated attacker elevate privileges and read other users' mailboxes within the same organization. Microsoft rated the issue 8.8 CVSS and released out-of-band security updates. The flaw affects on-premises Exchange Server deployments, while Exchange Online already has a service-side fix.

Denmark Central Population Register data breach exposing 8.8 million records

Data Leak

Updated: 05.10.2026 18:21 · First: 05.10.2026 18:21 · 📰 1 src / 1 articles · H score: 65

Denmark's Central Population Register (CPR) disclosed a data breach that exposed personal records for about 8.8 million registered people. The exposed data included names, physical addresses, dates of birth, marital status, and unique CPR numbers. The access abuse involved a private Danish company and brute-forcing CPR numbers to pull matching records. The breach happened in September 2026, was recognized on October 2, and the registry has since blocked the access while police investigate.

ClingSTUN Linux proxy backdoor abusing IoT devices

Malware Activity

Updated: 05.10.2026 17:30 · First: 05.10.2026 17:30 · 📰 1 src / 1 articles · H score: 31

The ClingSTUN Linux proxy backdoor is turning unpatched internet-facing IoT devices into remotely controlled proxy nodes, expanding covert infrastructure for abuse. The malware was tracked across three periods with different download servers and an expanding set of entry points. Its earliest observed wave relied on CVE-2022-36553 in Hytec Inter routers. Later activity added more flaws and used public STUN servers to keep infected systems reachable.

Cling botnet with STUN-based C2 and persistence

Malware Activity

Updated: 05.10.2026 14:46 · First: 05.10.2026 14:46 · 📰 2 src / 2 articles · H score: 34

The Cling malware activity now includes STUN-based back-connect proxying that uses public STUN servers to keep infected systems reachable as remotely controlled proxy nodes. FortiGuard Labs said the campaign, published October 5, progressed through multiple waves of exploitation against internet-facing IoT devices, including CVE-2022-36553, CVE-2025-34035, and CVE-2024-23625, before expanding to a list of 24 vulnerabilities in the third period. The malware also copies itself, modifies boot scripts for persistence, hides behind process information from init, and supports remote command execution. FortiGuard further noted that the STUN traffic can resemble normal VoIP and WebRTC activity, making the proxy nodes harder to spot.

Shinhan Bank hit by cyberattack

Incident

Updated: 05.10.2026 17:22 · First: 05.10.2026 17:22 · 📰 1 src / 1 articles · H score: 40

A confirmed data breach at Shinhan Bank and related cyber incidents at KB Kookmin Bank and Hana Bank exposed risk across South Korea's banking sector. Authorities launched on-site investigations and coordinated incident information with KISA after receiving reports. Local reporting said Shinhan may have leaked details on 25,000 customers, while Kookmin may have exposed credit card information for 119,000 clients. The response now centers on containment, customer protection, and tighter checks on externally accessible systems.

BPFDoor, BPF Rekoobe, and AVERAT Linux backdoor activity against telecom and network-edge appliances

Malware Activity

Updated: 05.10.2026 17:00 · First: 05.10.2026 17:00 · 📰 1 src / 1 articles · H score: 22

BPFDoor, BPF Rekoobe, and AVERAT Linux backdoors were tracked against telecom and network-edge appliances in South Korea and Taiwan, raising the risk of stealthy compromise on devices that handle core communications traffic. The tooling hides by making sessions look like SMTP on TCP port 25 and by posing as legitimate services. It also adds deeper access features such as file transfer, shell sessions, and proxy/port-forwarding channels.

Tenfold Community Edition adds shared-content governance and event auditing for small organizations

Security Tool/Service

Updated: 05.10.2026 16:33 · First: 05.10.2026 16:33 · 📰 1 src / 1 articles · H score: 11

tenfold Community Edition added shared content governance and event auditing, giving organizations under 150 users stronger visibility into Microsoft 365 access and identity activity. The update brings access reviews for shared files and helps teams catch oversharing, stale access, login spikes, and new admin accounts earlier. The free tier now carries more of the controls normally needed to monitor and reduce identity risk.

Citrix security patch release for CVE-2026-88779

Security Patch Release

Updated: 05.10.2026 00:58 · First: 05.10.2026 00:58 · 📰 3 src / 3 articles · H score: 46

Citrix released emergency NetScaler updates for CVE-2026-88779, closing an actively exploited flaw across NetScaler ADC, NetScaler Gateway, and affected FIPS deployments. The vendor shipped 14.1-73.41 and 13.1-64.28, and told customers to install the updates immediately. Global Deny Lists were also provided as a supplementary block list for known malicious IPs.

NetScaler ADC and NetScaler Gateway memory buffer flaw (CVE-2026-88779, actively exploited)

Vulnerability

Updated: 05.10.2026 00:58 · First: 05.10.2026 00:58 · 📰 3 src / 3 articles · H score: 36

Citrix disclosed CVE-2026-88779, a memory buffer flaw in NetScaler ADC and NetScaler Gateway that is being used in zero-day attacks. The issue affects SAML authentication paths and can cause denial of service on unmitigated deployments. Citrix said researchers are also investigating whether the flaw can be pushed to remote code execution. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog.

US Senate passes Health Care Cybersecurity and Resilience Act

Public Sector Action

Updated: 05.10.2026 13:42 · First: 05.10.2026 13:42 · 📰 1 src / 1 articles · H score: 69

The US Senate passed the bipartisan Health Care Cybersecurity and Resilience Act, moving the healthcare cybersecurity bill to the US House. The measure would create a federal resilience framework for healthcare institutions with grants, training, and tighter HHS/CISA coordination. It also aims to strengthen defenses for rural providers and require a cybersecurity incident response plan. The action targets a sector facing repeated ransomware and breach pressure.

Apple macOS Full Disk Access access-control tightening

Advisory/Mitigation

Updated: 05.10.2026 13:38 · First: 05.10.2026 13:38 · 📰 1 src / 1 articles · H score: 20

Apple is tightening Full Disk Access in macOS, requiring an explicit user action before apps can gain broad access to files, mail, messages, browsing history, and other private data. The mitigation reduces the risk that AI agents or other apps can quietly bypass privacy protections and read or write sensitive system content. Apple said the change is meant to make users clearly understand the risk before granting that level of access, and the rollout date is still unknown.

OpenAI ChatGPT app for Mac unauthorized access vulnerability (CVE-2026-100754)

Vulnerability

Updated: 05.10.2026 13:38 · First: 05.10.2026 13:38 · 📰 1 src / 1 articles · H score: 1

CVE-2026-100754 exposed OpenAI's ChatGPT app for Mac to unauthorized takeover, putting stored chat logs and other app data at risk. The flaw could let an attacker take over the AI assistant and reach data stored by the app. The vulnerability broadened the risk for Mac users who relied on the app to hold sensitive conversations and related content.

Meta Muse Mac hidden dictation endpoint security flaw

Vulnerability

Updated: 22.09.2026 09:33 · First: 22.09.2026 09:33 · 📰 1 src / 2 articles · H score: 37

Meta's Muse assistant for Mac has a now-patched flaw that let an unprivileged local process redirect dictation traffic, capture dictated audio and prompts, inject trusted prompts, and abuse the app's access. Security researcher Patrick Wardle also tied the issue to the undocumented endo_voyager_dictation_endpoint setting, which could be changed by a program running as the logged-in user. The exposure sits within the broader risk Apple highlighted for Full Disk Access on macOS, where apps with elevated privacy permissions can reach files, mail, messages, and browsing history. Apple said it plans to tighten FDA controls so that this kind of access is granted only with explicit user action.

Google OSS VRP suspension after automated AI submissions flooded the program

Security Tool/Service

Updated: 05.10.2026 13:30 · First: 05.10.2026 13:30 · 📰 1 src / 1 articles · H score: 11

Google has suspended its Open Source Vulnerability Rewards Program (OSS VRP) until 2027, disrupting a vulnerability-reporting channel for its open-source projects. The pause follows a significant rise in automated submissions that were mostly invalid, reducing the program’s usefulness for researchers. Google says existing reports and supply-chain reports are not affected, and the program will be reformatted before a Q1 2027 update.

UK schools cyber-resilience improvement trend across 2023-24 to 2025-26

Trend

Updated: 05.10.2026 12:30 · First: 05.10.2026 12:30 · 📰 1 src / 1 articles · H score: 22

UK schools are seeing fewer cyber incidents and faster recovery, with the share reporting an incident falling from 34% in 2023-24 to 27% in 2025-26. At the same time, 66% of schools can now recover immediately, up from 55%, indicating a sector-wide resilience gain that reduces disruption to teaching and administration.

Frontline Education hit by network compromise

Incident

Updated: 02.10.2026 22:01 · First: 02.10.2026 22:01 · 📰 2 src / 2 articles · H score: 21

Frontline Education confirmed a data breach after attackers used a third-party software vulnerability to gain unauthorized access to its environment and steal employee records. The compromise affected school district employee information, including Social Security numbers, and was identified on August 14, 2026. Frontline said it remediated the flaw and notified impacted districts.

Google OSS VRP pauses product vulnerability submissions after AI-generated report surge

Security Tool/Service

Updated: 05.10.2026 11:27 · First: 05.10.2026 11:27 · 📰 1 src / 1 articles · H score: 12

Google temporarily suspended OSS VRP product vulnerability submissions, pausing part of its open-source bug bounty intake after a surge of AI-generated automated reports overwhelmed the program. The change leaves supply chain reports and outstanding reports open, limiting the interruption to product vulnerability submissions. Google said it will readjust the OSS VRP and provide an update in Q1 2027.

TA419 AI policy impersonation phishing campaign

Campaign

Updated: 01.10.2026 17:00 · First: 01.10.2026 17:00 · 📰 2 src / 2 articles · H score: 36

TA419 is a China-nexus espionage campaign that used credential phishing against AI policy experts at U.S. think tanks, universities, and legal sector organizations, with additional targeting of defense contractors and Japan-linked institutions. The lures impersonated economists, AI policymakers, Lynne Parker, Heidi Crebo-Rediker, and an Anthropic employee, including a February 2026 message with the subject “Request for Feedback on Military Integration of Claude.” Recipients who responded were pushed through shortened URLs and multi-stage redirects to a spoofed OneDrive sign-in page. The page used Frameless BitB and an adversary-in-the-middle (AitM) proxy to relay Microsoft 365 logins, capture passwords, MFA codes, and session cookies, and keep the sign-in appearing successful. Proofpoint says the activity has run since at least April 2025 and likely supports Chinese intelligence collection on U.S. AI policy and export-control issues.

Jordan detains Rey in ShinyHunters investigation

Law Enforcement

Updated: 03.10.2026 22:09 · First: 03.10.2026 22:09 · 📰 2 src / 2 articles · H score: 53

Jordanian authorities reportedly detained Rey — identified as Saif al-Din Khader — in Jordan on September 29, 2026, and he is said to be cooperating with the FBI to identify other ShinyHunters members. The reported cooperation could help investigators map the group’s devices and digital communications and accelerate further arrests. The case sits inside a broader ShinyHunters crackdown that Reuters says includes pressure on the group after recent actions and disruptions tied to its online infrastructure.

MI5 Security Service Espionage Alert on CGTRI and U.K. academia

Public Sector Action

Updated: 03.10.2026 17:38 · First: 03.10.2026 17:38 · 📰 1 src / 1 articles · H score: 13

MI5 issued a Security Service Espionage Alert warning U.K. academic institutions about CGTRI/CAGT and the risk that research collaborations could support MSS espionage. The alert says more than 100 U.K.-linked academics have contributed to CGTRI-funded projects spanning AI, cybersecurity, covert communications, and steganography. MI5 urged universities to review collaborations and trace funding sources, while warning that continued cooperation could create National Security Act 2023 exposure.

Technical University of Denmark (DTU) hit by network compromise

Incident

Updated: 03.10.2026 17:35 · First: 03.10.2026 17:35 · 📰 1 src / 1 articles · H score: 16

The Technical University of Denmark (DTU) disclosed a compromised-credentials intrusion into DTUBasen, exposing personal data tied to up to 200,000 users. The accessed records span more than two decades and may include CPR numbers, names, addresses, profile photos, and next-of-kin details. DTU warned the stolen data could fuel identity fraud and more convincing phishing.

Technical University of Denmark (DTU) DTUBasen data leak exposing up to 200,000 users

Data Leak

Updated: 03.10.2026 17:35 · First: 03.10.2026 17:35 · 📰 1 src / 1 articles · H score: 15

The Technical University of Denmark (DTU) disclosed a data leak affecting information tied to up to 200,000 users, creating risk of identity fraud and more convincing phishing. Attackers used compromised credentials to access DTUBasen, DTU's identity and access management (IAM) system, and download a large amount of data. The exposed material may include CPR numbers, names, addresses, profile photos, and work-related details.

Warlock SharePoint multi-sector ransomware campaign

Campaign

Updated: 02.10.2026 21:33 · First: 02.10.2026 21:33 · 📰 1 src / 1 articles · H score: 29

The Warlock ransomware campaign is using SharePoint vulnerabilities to break into a water utility, telecom provider, regional government body, and university across Europe, Africa, and Latin America. The group emerged in June 2025 and has been active over the past two months, with ToolShell zero-days helping open the door. In a July 22 intrusion, attackers disabled protection on at least 40 hosts and then launched ransomware on at least 33 hosts. Continued exploitation of SharePoint keeps exposed on-premises deployments at risk of follow-on intrusion and extortion.

Warlock ransomware launched on at least 33 hosts

Malware Activity

Updated: 02.10.2026 21:33 · First: 02.10.2026 21:33 · 📰 1 src / 1 articles · H score: 25

Warlock ransomware was launched on at least 33 hosts after protection was disabled, compressing the final stage of the intrusion into a rapid network-wide rollout. The deployment followed an AV/EDR-killing tool that turned off defenses on compromised machines. The payload was staged in SYSVOL, enabling broad execution across the environment.

Antino Windows backdoor activity using Microsoft 365 dead drops

Malware Activity

Updated: 02.10.2026 20:33 · First: 02.10.2026 20:33 · 📰 1 src / 1 articles · H score: 15

Antino is being deployed as a Windows backdoor that gives operators host reconnaissance, command execution, file transfer, and persistence while routing C2 through Microsoft 365 dead drops, increasing stealth against defenders.

UAT-11587 Antino spear-phishing campaign against government and policy organizations

Campaign

Updated: 02.10.2026 20:33 · First: 02.10.2026 20:33 · 📰 1 src / 1 articles · H score: 22

A UAT-11587 spear-phishing campaign is expanding across Asia and Syria, delivering the Antino backdoor to government and policy organizations and increasing the risk of espionage and persistent access. The operation first surfaced in September 2025 and later broadened to targets in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria. It uses tailored lures, spoofed trusted senders, and a fake Gmail attachment preview to push victims into a multi-stage infection chain. Antino then abuses Microsoft 365, especially Outlook and OneDrive, for command-and-control and file transfer.

GitLab Self-Hosted AI Gateway immediate update advisory (CVE-2026-90970)

Advisory/Mitigation

Updated: 02.10.2026 19:20 · First: 02.10.2026 19:20 · 📰 2 src / 2 articles · H score: 41

GitLab issued immediate update guidance for GitLab Self-Managed customers running Self-Hosted AI Gateway after fixing CVE-2026-90970, a flaw that could allow arbitrary command execution on unpatched instances. The company released 19.2.4, 19.3.2, and 19.4.1 and told affected users to upgrade immediately. GitLab-hosted AI Gateway users are already protected and do not need action.

GitLab AI Gateway improper neutralization command execution security flaw (CVE-2026-90970)

Vulnerability

Updated: 02.10.2026 19:20 · First: 02.10.2026 19:20 · 📰 2 src / 2 articles · H score: 35

GitLab has fixed CVE-2026-90970, a critical improper neutralization flaw in GitLab AI Gateway that could let authenticated users with Duo Agent Platform access escape the prompt template sandbox and run arbitrary commands on vulnerable self-hosted instances. The issue affects GitLab Self-Hosted AI Gateway deployments, while GitLab-hosted AI Gateway users are already protected. GitLab released 19.2.4, 19.3.2, and 19.4.1 and told customers to update immediately.