Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 19:35 10/10/2026 UTC
Last updated: 13:20 10/10/2026 UTC

Latest updates

Browse →

Edward Dubrovsky arrest in ShinyHunters extortion case

Law Enforcement

Updated: 10.10.2026 18:07 · First: 10.10.2026 18:07 · 📰 1 src / 1 articles · H score: 33

Edward Dubrovsky was arrested in Pennsylvania in a cybercrime case tied to extortion allegations and the ShinyHunters investigation. Court records show he appeared in the Eastern District of Pennsylvania before being transferred to the Eastern District of Texas, where the charges were filed. The docket lists conspiracy and extortion-related counts connected to threats to impair the confidentiality of information to extort money.

South Korea-based financial firms data exfiltration, late September to early October 2026

Data Leak

Updated: 08.10.2026 14:00 · First: 08.10.2026 14:00 · 📰 2 src / 2 articles · H score: 35

CrowdStrike linked a suspected China-based threat actor to a South Korean financial-sector intrusion campaign that used ARTEX and Claude AI tooling. The actor targeted multiple Korean banks, including Shinhan Bank, KB Kookmin Bank, and Hana Bank, exposing clients’ personal data and credit card information and causing system outages in some cases. Researchers also found Claude Code session histories, ARTEX configuration files, and Claude memory files in open directories, along with the likely use of DeepSeek v4.1-flash, GLM-5.3, and Grok 4.6 for additional sessions. The exposure extends the incident from access and tooling analysis into confirmed data leak impact, while South Korea’s government issued an emergency response and warned of phishing and loan-scam follow-on risk.

Shinhan Bank hit by cyberattack

Incident

Updated: 05.10.2026 17:22 · First: 05.10.2026 17:22 · 📰 2 src / 3 articles · H score: 41

A Chinese-speaking hacker used ARTEX AI and Claude agents in attacks on South Korean banks earlier this month, including Shinhan Bank, KB Kookmin Bank, and Hana Bank. CrowdStrike said the attacker left Claude Code session histories, ARTEX configuration files, and Claude memory files in open directories, and the same tooling also exposed résumé-based identification, contact, and Telegram details. The attack set caused system outages in some cases and exposed clients' personal data and credit card information. After confirming real-world abuse, the ARTEX developer made the project closed-source and stopped updates.

Criminal IP introduces AITEM AI-powered threat exposure management

Security Tool/Service

Updated: 10.10.2026 15:30 · First: 10.10.2026 15:30 · 📰 1 src / 1 articles · H score: 11

AI SPERA is introducing AITEM for Criminal IP, extending the platform from visibility-focused ASM to AI-powered threat exposure management and faster response to exposed risk. The capability is meant to prioritize and investigate exposure across external assets, OSINT, dark web data, internal infrastructure, Shadow AI, leaked data, and emerging vulnerabilities. By combining threat intelligence with real-world exploitability and attacker activity, the update aims to help security teams turn discovery into action.

Adception Google Ads and Bing redirect Claude ClickFix campaign

Campaign

Updated: 09.10.2026 23:31 · First: 09.10.2026 23:31 · 📰 1 src / 1 articles · H score: 33

A malvertising campaign is abusing Google Ads and Bing redirect chains to push fake Claude installers that try to trigger malicious command execution on macOS users. The operation uses multi-layer cloaking and a compromised WordPress site to hide the lure from scanners. The final page copies Anthropic's legitimate install flow but swaps the clipboard command for a script that fetches payload data from lake-90[.]com and executes it through zsh. Researchers track the associated toolkit as AcSig, and the ultimate payload remains unknown.

Chinese-speaking DarkSword exploitation-as-a-service operation with agent/reseller model

Threat Actor Meta

Updated: 09.10.2026 19:29 · First: 09.10.2026 19:29 · 📰 1 src / 1 articles · H score: 15

Researchers identified a Chinese-speaking DarkSword exploitation-as-a-service operation with an agent/reseller model, signaling a more organized criminal distribution ecosystem for iOS exploit-kit abuse. The platform’s control plane and recovered victim artifacts show the operation was already collecting crypto-wallet recovery phrases and scaling access across multiple hosts. That structure increases the reach and monetization efficiency of DarkSword/Coruna activity.

P7 DarkSword iOS exploit kit adds keychain and crypto-wallet theft

Malware Activity

Updated: 09.10.2026 19:29 · First: 09.10.2026 19:29 · 📰 1 src / 1 articles · H score: 16

The P7 DarkSword variant now adds keychain theft and crypto-wallet theft while also enabling two-way C2 with attacker infrastructure, increasing the risk of stolen credentials and wallet abuse on compromised iPhones. The change makes the exploit kit more capable of harvesting high-value data and managing infected devices remotely.

Read-only and scoped permission enforcement for AI agent tool calls

Defensive Guidance

Updated: 09.10.2026 17:01 · First: 09.10.2026 17:01 · 📰 1 src / 1 articles · H score: 16

Organizations are being urged to enforce read-only and scoped credentials at AI agent tool calls so agents cannot overreach through prompt injection, mistaken assumptions, or credential misuse. The guidance points to gateways, hooks, sandboxes, and endpoint enforcement as practical controls for blocking out-of-policy actions. It also warns that the right control depends on where the agent runs and whether the platform can actually see the request.

AnyDesk Linux version 8.0.3 security patch release

Security Patch Release

Updated: 09.10.2026 15:59 · First: 09.10.2026 15:59 · 📰 1 src / 1 articles · H score: 36

AnyDesk released version 8.0.3 for AnyDesk Linux, closing a pre-authentication RCE path before the exploit became public. The June fix was treated as a generic bug fix in the changelog, with no CVE and no formal security advisory attached. Administrators should move affected Linux systems to 8.0.3 or later because the underlying flaw could expose systems to root access over direct connections.

AnyDesk Linux pre-auth RCE flaw (published exploit)

Vulnerability

Updated: 09.10.2026 15:59 · First: 09.10.2026 15:59 · 📰 1 src / 1 articles · H score: 29

A working exploit is now public for an AnyDesk Linux pre-authentication remote code execution flaw, exposing systems to root access before connection approval. AnyDesk fixed the issue in version 8.0.3 in June, but the flaw still had no CVE as of October 9. The published code targets direct TCP connections on port 7070 and shows that the bug can be weaponized even before a session is accepted. Relay-based exploitation remains unresolved.

AhsayCBS XMRig and web shell post-exploitation activity

Malware Activity

Updated: 09.10.2026 15:47 · First: 09.10.2026 15:47 · 📰 2 src / 2 articles · H score: 33

AhsayCBS post-exploitation activity is combining web shells and XMRig cryptominers after compromise. Huntress observed the activity on October 7 and said it targeted at least five organizations. Attackers chained CVE-2026-105133 for authentication bypass and CVE-2026-105134 for code execution, then dropped JSP webshells, downloaded XMRig as edge.exe, and used MicrosoftEdgeUpdateSvc plus Taskgmr.ps1 to hide mining activity.

AhsayCBS backup utility active exploitation wave (CVE-2026-105133, CVE-2026-105134)

Exploitation Wave

Updated: 09.10.2026 15:47 · First: 09.10.2026 15:47 · 📰 2 src / 2 articles · H score: 51

AhsayCBS exploitation of CVE-2026-105133 and CVE-2026-105134 is enabling authentication bypass, code execution, and post-compromise activity on exposed backup management systems. Huntress observed the wave on October 7 and said it targeted at least five organizations. Attackers chained the flaws to gain access, then deployed JSP webshells and the XMRig miner disguised as edge.exe. Huntress also said Ahsay 10.3.4 is affected, extending the exposure beyond the originally fixed version.

AhsayCBS backup utility actively exploited authentication bypass and command injection flaws (multiple vulnerabilities)

Vulnerability

Updated: 09.10.2026 15:47 · First: 09.10.2026 15:47 · 📰 2 src / 2 articles · H score: 49

CVE-2026-105133 and CVE-2026-105134 in AhsayCBS are being actively exploited, enabling attackers to bypass authentication and run arbitrary commands on exposed systems. Huntress observed the activity on October 7, 2026 and said it affected at least five organizations. Post-exploitation activity included JSP webshells, XMRig miners disguised as edge.exe, a MicrosoftEdgeUpdateSvc service running msedge.exe, and Taskgmr.ps1 used to hide mining activity.

SonicWall SMA1000 SSRF flaw (CVE-2026-102255)

Vulnerability

Updated: 07.10.2026 14:37 · First: 07.10.2026 14:37 · 📰 2 src / 3 articles · H score: 54

CVE-2026-102255 is a maximum-severity SSRF in the SonicWall SMA1000 Appliance WorkPlace interface that lets a remote unauthenticated attacker make the appliance issue requests on its behalf and reach internal functionality. SonicWall released hotfixes and fixed releases for SMA1000 6210, 7210, and 8200v after disclosing the flaw on 2026-10-06, then warned customers to install the patched builds. On 2026-10-09, a security researcher said his honeypot network saw exploitation attempts consistent with the CVE, while SonicWall had not yet flagged the issue as actively exploited in its advisory. Shadowserver separately tracks more than 400 Internet-exposed SMA1000 appliances, leaving an exposed target base for abuse.

SonicWall security patch release for CVE-2026-102255

Security Patch Release

Updated: 07.10.2026 14:37 · First: 07.10.2026 14:37 · 📰 2 src / 3 articles · H score: 38

SonicWall released hotfixes for CVE-2026-102255 in SMA1000 appliances, a maximum-severity flaw in the Appliance WorkPlace interface on 6210, 7210, and 8200v models. The issue lets a remote unauthenticated attacker abuse the path to make the appliance issue requests on its behalf and reach internal functionality for unauthorized operations. SonicWall said it had no evidence of exploitation in the wild at advisory time, but researcher Ryan Dewhurst said his honeypot network saw activity consistent with the flaw. The exposure surface remains significant because Shadowserver tracks more than 400 SMA1000 appliances exposed online.

Oleg Korniev / YMCO guilty plea

Law Enforcement

Updated: 09.10.2026 14:14 · First: 09.10.2026 14:14 · 📰 1 src / 1 articles · H score: 29

Oleg Korniev pleaded guilty to helping run Your Mule Cashout (YMCO), a money-laundering network that moved illicit proceeds for cybercriminals and exposed U.S. victims to losses. The case in the Western District of North Carolina covers money laundering, aggravated identity theft, computer fraud, and access device theft. His plea expands criminal exposure around a long-running mule operation that used more than 15,000 money mules.

Microsoft Windows Update certificate-rotation guidance

Advisory/Mitigation

Updated: 09.10.2026 13:12 · First: 09.10.2026 13:12 · 📰 1 src / 1 articles · H score: 26

Microsoft told administrators to upgrade supported Windows versions before the Windows Update certificate rotation in May and June 2027. Unsupported devices will lose access to Windows Update services and stop receiving security updates. Microsoft also set version-specific deadlines for Windows 11 24H2 / Windows Server 2025, other supported Windows 11, Windows Server 2022, and Windows 10, and Windows Server 2019/2016. Devices updated through WSUS are not affected.

GoBalance Tor-format key-recovery actively exploited security flaw

Vulnerability

Updated: 09.10.2026 12:03 · First: 09.10.2026 12:03 · 📰 1 src / 1 articles · H score: 18

A GoBalance flaw is letting attackers recover the private key behind a site's .onion address, enabling takeover of affected dark-web sites. Searchlight Cyber said the bug sits in the signing step and can be abused from public descriptors alone, so attackers do not need server access. The issue has already been tied to takeovers of Dread and at least one other site, and a public proof-of-concept plus patch have been published. There is still no official fix, so exposed sites need to move to a new .onion address.

ICO formal investigation into Grok personal-data processing

Regulatory/Legal Action

Updated: 09.10.2026 11:00 · First: 09.10.2026 11:00 · 📰 1 src / 1 articles · H score: 16

The ICO opened formal investigations into XIUC and X.AI LLC over Grok's personal-data processing, escalating UK regulatory scrutiny of the AI system. The probe centers on whether those practices can contribute to harmful sexualized image and video content. The action raises compliance pressure around data protection, safeguards, and the handling of sensitive personal information.

ICO launches six-week call for evidence on agentic AI data-protection risks

Public Sector Action

Updated: 09.10.2026 11:00 · First: 09.10.2026 11:00 · 📰 1 src / 1 articles · H score: 16

The ICO launched a six-week call for evidence on agentic AI data-protection risks, drawing developers, deployers, and security/privacy experts into a public consultation that will shape future safeguards for autonomous systems. The process focuses on how organizations manage personal-data risks as AI systems become more autonomous, with responses due by November 20.

Citrix NetScaler ADC and NetScaler Gateway memory overflow denial-of-service flaw (CVE-2026-107406)

Vulnerability

Updated: 09.10.2026 09:53 · First: 09.10.2026 09:53 · 📰 2 src / 2 articles · H score: 33

CVE-2026-107406 is a critical memory overflow in Citrix NetScaler ADC and NetScaler Gateway that can lead to remote code execution or denial-of-service in specific SAML SP/SAML IdP configurations. Citrix says the flaw also affects Secure Private Access Hybrid deployments that use NetScaler. Fixed builds are available, and customers are being told to upgrade immediately. Citrix said it was not aware of any unmitigated exploits at publication.

Flax Typhoon critical infrastructure intrusion and credential-harvesting campaign

Campaign

Updated: 09.10.2026 09:39 · First: 09.10.2026 09:39 · 📰 2 src / 2 articles · H score: 89

Flax Typhoon is a long-running intrusion and credential-harvesting campaign tied to Integrity Technology Group that has targeted U.S. and foreign critical infrastructure and other victim networks. By mid-January 2021, the operation was already using Python- and Go-based utilities and XSS credential harvesting to break into networks and cloud services, then extending access into Microsoft 365 Cloud environments. The latest joint alert from the US, UK and allied countries adds detail on Integrity Technology Group TTPs, including open source scanning tools, EBurst password spraying, SoftEther VPN persistence, and email exfiltration from on-premises and cloud systems. The US also seized several domains tied to Microscan and FishHub in a disruption action against the organization and associated threat activity.

FBI seizes Flax Typhoon hacking-tool domains

Law Enforcement

Updated: 09.10.2026 00:42 · First: 09.10.2026 00:42 · 📰 1 src / 1 articles · H score: 67

The FBI seized seven domains tied to Flax Typhoon's MicroScan and FishHub hacking tools, disrupting infrastructure used in breaches against critical infrastructure and other organizations worldwide.

MicroScan and FishHub tool activity used for scanning, phishing, and exfiltration

Malware Activity

Updated: 09.10.2026 00:42 · First: 09.10.2026 00:42 · 📰 1 src / 1 articles · H score: 68

MicroScan and FishHub were used to support vulnerability scanning, spear-phishing, and data exfiltration, expanding intrusion reach against critical infrastructure and other organizations worldwide. The tools were tied to a broader Flax Typhoon operation and infrastructure later disrupted by domain seizures. The activity also included follow-on malware delivery and unauthorized access to already compromised networks.

IDC Frontier hit by ransomware attack

Incident

Updated: 08.10.2026 23:09 · First: 08.10.2026 23:09 · 📰 1 src / 1 articles · H score: 76

IDC Frontier confirmed a ransomware attack on IDCF Cloud that shut down East Japan Region 1, disrupting cloud services for public and private customers. The outage began on October 7 at 3:40 AM local time and prompted network and system shutdowns. IDC Frontier said the event affected 495 companies and local governments using the service. The provider isolated impacted systems, disabled management-console access, and continued investigating the intrusion route and broader security exposure.

Midnight Mimosa preinstalled Android firmware malware

Malware Activity

Updated: 08.10.2026 22:20 · First: 08.10.2026 22:20 · 📰 1 src / 1 articles · H score: 29

The Midnight Mimosa malware activity is embedded in low-cost Android firmware, giving infected phones system-level control to silently install apps, run ad fraud, and act as residential proxies. The activity has affected thousands of devices across more than 150 countries, with evidence tied to MediaTek-based phones and devices posing as major brands. Because the malware is preinstalled in the system partition, removal often requires firmware-level cleanup or ADB-based intervention.

Midnight Mimosa multi-country Android supply-chain campaign

Campaign

Updated: 08.10.2026 22:20 · First: 08.10.2026 22:20 · 📰 1 src / 1 articles · H score: 32

Midnight Mimosa spans thousands of Android devices in more than 150 countries, showing a broad supply-chain operation with sustained reach over about two years. The operation used preinstalled firmware malware to silently install apps, drive ad fraud, and turn infected phones into residential proxies. Victims were concentrated in Mexico, France, Italy, the United States, Germany, Brazil, and Spain.

Integrity Technology Group-linked email-theft and password-spraying campaign

Campaign

Updated: 08.10.2026 21:32 · First: 08.10.2026 21:32 · 📰 1 src / 1 articles · H score: 89

A multi-country email-theft campaign tied to Integrity Technology Group has targeted government, law enforcement, healthcare, and religious organizations since at least mid-January 2021, putting mailbox access and account security at risk. The operators used website scanning, password spraying against Microsoft 365 and Exchange, and fake-login XSS pages to gain entry. They then used tools to collect and exfiltrate mail through Exchange Web Services and other legitimate access paths. The same activity also included a portal that let third parties access stolen email content.

Stolen email content exposed through hacker web application

Data Leak

Updated: 08.10.2026 21:32 · First: 08.10.2026 21:32 · 📰 1 src / 1 articles · H score: 67

A hacker-operated web application is exposing stolen email content to third parties, letting outsiders read compromised mail instead of keeping it locked inside the original breach. The portal lets users view the mail of a specific account by adding arguments to a URL. The exposure is tied to Integrity Technology Group-linked hackers and extends the impact of their mailbox theft activity.

UAC-0099 campaign targeting Ukrainian government, logistics, and infrastructure entities

Campaign

Updated: 08.10.2026 18:26 · First: 08.10.2026 18:26 · 📰 1 src / 1 articles · H score: 33

The UAC-0099 campaign is now tied to a broader targeting set in Ukraine, including civilian logistics and infrastructure operators, which raises the risk to the systems that keep supply lines running. The operation has targeted government, defense, border guard, and logistics entities since at least mid-2022. It has also used ASHVEIN to collect credentials, capture screenshots, and open remote shells on victim systems. The actor's evolving tooling and widening victim set point to a persistent espionage operation with growing strategic reach.