Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 20:50 07/10/2026 UTC
Last updated: 15:50 07/10/2026 UTC

Latest updates

Browse →

Google hit by network compromise

Incident

Updated: 07.10.2026 21:48 · First: 07.10.2026 21:48 · 📰 2 src / 2 articles · H score: 16

The .gh, .sl, and .as ccTLD compromise led to unauthorized HTTPS certificates for Google and YouTube names, creating a risk of encrypted impersonation and private-data interception. Chrome blocked the rogue certificates with CRLSets, and the issuing CAs later revoked them. Certificate Transparency logs place issuance between September 22 and 27, 2026, with disclosure on October 6-7, 2026. Google's own systems were not breached.

MALFEX npm supply-chain malware campaign

Campaign

Updated: 07.10.2026 20:43 · First: 07.10.2026 20:43 · 📰 1 src / 1 articles · H score: 12

A long-running npm supply-chain campaign named MALFEX is pushing information stealers and remote access trojans (RATs) to compromised Windows hosts. The operation has used 12 published packages since August 2023, with 8 flagged as malicious, and the packages have already been downloaded 40,767 times. Researchers also found multiple delivery paths that load Overlord RAT, a movinlike stealer, and a downloader, showing an active package-based operation with broad opportunistic reach.

SonicWall security patch release for CVE-2026-102255

Security Patch Release

Updated: 07.10.2026 14:37 · First: 07.10.2026 14:37 · 📰 2 src / 2 articles · H score: 38

SonicWall released hotfixes for four SMA1000 appliance flaws, including CVE-2026-102255. CVE-2026-102255 is a CVSS 10.0 pre-authentication SSRF issue in the WorkPlace interface that could let a remote unauthenticated attacker reach internal functions. The hotfixes apply to SMA1000 models 6210, 7210, and 8200v running 12.4.3-03526 and older or 12.5.0-02952 and older, with fixed builds at 12.4.3-03670 and 12.5.0-03082. SonicWall reported no evidence of exploitation and no workaround.

Microsoft Outlook blocks MSIX attachments in web and Windows client

Security Tool/Service

Updated: 07.10.2026 18:44 · First: 07.10.2026 18:44 · 📰 1 src / 1 articles · H score: 14

Microsoft is adding .msix and .msixbundle to the blocked-attachment list in Outlook on the web and new Outlook for Windows, reducing a file-delivery path that attackers have used for unsafe attachments. The change rolls out to Exchange Online users in early November and reaches general availability by mid-November.

LMCache unauthenticated remote code execution (CVE-2026-105192)

Vulnerability

Updated: 07.10.2026 18:34 · First: 07.10.2026 18:34 · 📰 1 src / 1 articles · H score: 39

LMCache has a critical unauthenticated remote code execution flaw, CVE-2026-105192, that can let an attacker run code on the cache server without logging in. The issue affects LMCache 0.3.9 through 0.5.5, plus 0.5.6 release candidates and the development branch. No fixed version is available, so exposed deployments remain at risk until a patched release lands.

PoeLLM malware mining and botnet expansion against AI/LLM infrastructure

Malware Activity

Updated: 07.10.2026 18:33 · First: 07.10.2026 18:33 · 📰 1 src / 1 articles · H score: 60

The PoeLLM malware family is actively targeting exposed AI/LLM infrastructure to install cryptocurrency miners and expand a botnet, with more than 3,400 victim servers already identified. The activity has been running since April 2026 and is concentrated in the U.S. and Western Europe. Compromised hosts are reused as scanners and exploit servers, widening the pool of vulnerable systems. The malware hides its C2 address in a poem hosted in a GitHub repository.

PoeLLM cryptomining and scanning malware activity against exposed AI servers

Malware Activity

Updated: 07.10.2026 18:04 · First: 07.10.2026 18:04 · 📰 2 src / 2 articles · H score: 62

PoeLLM is a new malware family in the Canto Incognito campaign that targets exposed AI/LLM infrastructure to deploy XMRig and Iron miners and grow a botnet. Lumen Black Lotus Labs says the activity has been active since April 2026, has identified 3,400+ victim servers, and is concentrated in the U.S. and Western Europe. The malware hides its C2 inside a GitHub-hosted poem and has been seen against LiteLLM, Gotenberg, Gitea, and Ivanti Sentry. Compromised hosts are reused as scanners and exploit servers, and recent traffic suggests possible experimentation with distributed brute-force attacks.

PoeLLM cryptomining campaign targeting exposed AI services

Campaign

Updated: 07.10.2026 18:04 · First: 07.10.2026 18:04 · 📰 1 src / 1 articles · H score: 67

The PoeLLM campaign is abusing exposed AI services to turn compromised servers into scanners and exploit launchpads, expanding risk across the United States and Western Europe. It has compromised more than 2,100 servers and reached as many as 800 infected systems in a single day. Activity has been underway since at least April, and the infrastructure now relies on a GitHub-hosted poem to derive changing C2 addresses.

Dutch police arrest tied to ShinyHunters hacking investigation

Law Enforcement

Updated: 28.09.2026 22:49 · First: 28.09.2026 22:49 · 📰 4 src / 5 articles · H score: 44

Dutch police and the FBI are moving against ShinyHunters after the arrest of a 24-year-old Amsterdam man alleged to be one of the group's leaders. The suspect was arrested on September 15 and is now set to remain in pre-trial detention for at least another 90 days after a Rotterdam District Court ruling on Tuesday. Dutch police said the suspect had material on his laptop tied to possible additional crimes, and they have not ruled out more arrests. The FBI says ShinyHunters and co-conspirators have breached more than 140 organizations since last year and collected at least $70 million in extortion payments.

Atlassian Data Center products path traversal (CVE-2026-21589)

Vulnerability

Updated: 06.10.2026 09:58 · First: 06.10.2026 09:58 · 📰 2 src / 4 articles · H score: 32

Atlassian disclosed CVE-2026-21589, a path traversal vulnerability in 8 self-hosted Data Center products that can let a no-login attacker read specific files in each product's web application root directory. Atlassian published fixed versions for the affected products and said cloud customers do not need to take action. The advisory also recommends temporary network-blocking mitigations until systems are upgraded.

Proofpoint Voice of the CISO 2026 trend in AI governance, human risk, and board alignment

Trend

Updated: 07.10.2026 14:57 · First: 07.10.2026 14:57 · 📰 1 src / 1 articles · H score: 22

The 2026 Voice of the CISO findings show AI governance and human risk moving to the center of enterprise security, reshaping how 1,600 global CISOs think about resilience and control. Over 2022-2026, perceived GenAI risk rose sharply, with 78% of CISOs now treating it as a security risk. Board alignment also rebounded to 85% in 2026, but the role is still under pressure as 79% say they must manage AI-related risk without proportional new resources. The trend points to security risk shifting into the workflow, where people, data, identity, and AI-enabled tools now intersect.

SonicWall SMA1000 SSRF flaw (CVE-2026-102255)

Vulnerability

Updated: 07.10.2026 14:37 · First: 07.10.2026 14:37 · 📰 2 src / 2 articles · H score: 54

SonicWall released hotfixes for CVE-2026-102255, a maximum-severity SSRF flaw in SMA1000 appliances that can let remote unauthenticated attackers make the device issue requests on their behalf. The issue affects the SMA1000 6210, 7210, and 8200v models and creates a path to internal functionality and unauthorized operations. SonicWall said there is no evidence of exploitation in the wild so far, but it urged customers to install the fixed release version.

Google Chrome 155 security update (247 vulnerabilities)

Security Patch Release

Updated: 07.10.2026 13:51 · First: 07.10.2026 13:51 · 📰 1 src / 1 articles · H score: 16

Google rolled out a Chrome 155 security update that patches 247 vulnerabilities, including four critical use-after-free flaws across Chromecast, Browser, Navigation, and Track components. The release expands Chrome’s security baseline on Windows, macOS, and Linux while closing a large mix of high-, medium-, and low-severity defects. Google said it has no indication of exploitation in the wild.

Cybersecurity professionals report persistent password reliance and rising AI-driven phishing and deepfake targeting

Trend

Updated: 07.10.2026 13:15 · First: 07.10.2026 13:15 · 📰 1 src / 1 articles · H score: 39

Survey data from 2,000 cybersecurity professionals shows persistent reliance on usernames and passwords alongside a rise in AI-driven phishing and deepfake impersonation, increasing compromise risk across organizations. 44% said their organization faced at least one AI-driven phishing attack in the past year, and 43% reported suspicious deepfake-style impersonations aimed at executives or clients. The pattern shows a widening gap between awareness of stronger authentication and the controls actually in use.

Pwn2Own Ireland 2026 multi-product zero-day flaws security flaw

Vulnerability

Updated: 07.10.2026 12:25 · First: 07.10.2026 12:25 · 📰 1 src / 1 articles · H score: 0

On October 6, 2026, Pwn2Own Ireland 2026 produced 32 zero-day vulnerabilities across smartphones, smart home devices, printers, and AI tools. Targets included OpenAI Codex, LiteLLM, Sonos Era 300, Philips Hue Bridge Pro, Lexmark CX532adwe, Oracle Autonomous AI Database, and Garmin Index BPM. The day-one results showed working exploit chains against multiple products, including reverse shell and code execution paths. The discoveries entered responsible disclosure, leaving vendors with a limited window to ship fixes.

Central Register of Persons unauthorized access data leak

Data Leak

Updated: 07.10.2026 11:20 · First: 07.10.2026 11:20 · 📰 1 src / 1 articles · H score: 70

The Central Register of Persons (CPR) exposed names, addresses and CPR numbers for about 8.8 million registered people after unauthorized access reached the database. The exposure creates a large-scale identity and privacy risk because the CPR holds core population records for Denmark. The breach occurred in September and was disclosed on October 5 after irregular behavior was detected.

Central Register of Persons (CPR) hit by network compromise

Incident

Updated: 07.10.2026 11:20 · First: 07.10.2026 11:20 · 📰 1 src / 1 articles · H score: 69

Denmark's Central Register of Persons (CPR) disclosed an unauthorized access incident that exposed names, addresses, and CPR numbers for about 8.8 million registered persons, creating a major privacy and identity-risk exposure. The access was carried out through a private Danish company's legal access to search the CPR system, turning a trusted third-party channel into the attack path. The breach occurred in September and was disclosed on October 5 after the CPR administration noticed irregular behavior on October 2.

WordPress plugin stored XSS exploitation campaign targeting WPC Product Bundles for WooCommerce and Ninja Forms

Campaign

Updated: 07.10.2026 00:00 · First: 07.10.2026 00:00 · 📰 1 src / 1 articles · H score: 29

A WordPress plugin exploitation campaign is using stored XSS in WPC Product Bundles for WooCommerce and Ninja Forms to plant backdoors and create rogue administrator accounts. The same payload was delivered across both plugins, linking the activity to one coordinated operation. The result is persistent administrative control over affected sites and elevated risk of follow-on compromise. Administrators must treat patched systems as potentially already infected if the payload executed.

WPC Product Bundles for WooCommerce stored XSS actively exploited (CVE-2026-93836)

Vulnerability

Updated: 07.10.2026 00:00 · First: 07.10.2026 00:00 · 📰 1 src / 1 articles · H score: 29

CVE-2026-93836 in WPC Product Bundles for WooCommerce is being actively exploited on WordPress sites, letting attackers plant backdoors and create rogue administrator accounts. The flaw affects version 8.6.6 and older and requires an authenticated session. Patchstack identified the activity on October 4, 2026, with exploitation continuing into October 5.

Ninja Forms stored XSS flaw (CVE-2026-94504)

Vulnerability

Updated: 07.10.2026 00:00 · First: 07.10.2026 00:00 · 📰 1 src / 1 articles · H score: 29

CVE-2026-94504 in Ninja Forms is being exploited on WordPress sites, putting older installs at risk of stored XSS, backdoors, and rogue admin accounts. The flaw affects versions 3.15.3 and older and requires an authenticated session to exploit. Attackers can inject JavaScript into form submissions, which runs when a logged-in administrator opens the content. Administrators are advised to upgrade to Ninja Forms 3.15.4 or later.

Samsung Galaxy S26 zero-day exploitation security flaw

Vulnerability

Updated: 06.10.2026 22:21 · First: 06.10.2026 22:21 · 📰 1 src / 1 articles · H score: 24

Researchers twice compromised the Samsung Galaxy S26 on the first day of Pwn2Own Ireland 2026, showing active zero-day exposure on a flagship mobile target. The opening-day demos were part of a broader tally of 32 zero-days exploited in the contest. The competition gives vendors 90 days to ship updates before public disclosure.

Fake AI login phishing campaign targeting ad account managers

Campaign

Updated: 06.10.2026 18:16 · First: 06.10.2026 18:16 · 📰 2 src / 2 articles · H score: 36

A phishing campaign is using fake ChatGPT, Gemini, Claude, Perplexity, and Meta Muse ad portals to steal credentials and MFA codes from ad account managers, agency staff, media buyers, and administrators. The pages use the browser-in-the-browser (BitB) trick to imitate sign-in windows, including fake accounts.google.com and Okta flows, while a human operator can request passwords, SMS or authenticator codes, push approvals, Google prompts, or QR-code scans. Researchers said the broader operation also uses fake recruitment and refund lures, shared Next.js and Socket.IO infrastructure, and exposed earlier source code through misconfigured public GitHub repositories. The same cluster appears to move with product launches and has already produced hundreds of victim submissions in a Telegram control channel.

ClickFix compromised-website browser-cache campaign

Campaign

Updated: 06.10.2026 18:00 · First: 06.10.2026 18:00 · 📰 1 src / 1 articles · H score: 35

The ClickFix campaign is using compromised websites to pre-stage a VBScript payload in the browser cache, pushing visitors into running attacker code through Windows Run and increasing the risk of credential theft. Microsoft Threat Intelligence observed the activity on October 3, 2026 and said a fake CAPTCHA prompt was used to make users paste and execute a command. The chain avoids a fresh download at execution time by launching a file that is already on disk. That blend of social engineering and local staging makes the payload harder to detect and expands the chance of follow-on access.

Healthcare PQC readiness gap across IoMT and OT devices

Trend

Updated: 06.10.2026 15:20 · First: 06.10.2026 15:20 · 📰 1 src / 1 articles · H score: 21

A large healthcare device assessment found that most IoMT and medical OT systems cannot transition to post-quantum cryptography (PQC), increasing the risk of future harvest-now, decrypt-later attacks on patient data.

LibreOffice malicious spreadsheet code execution security flaw (CVE-2026-63277)

Vulnerability

Updated: 06.10.2026 14:57 · First: 06.10.2026 14:57 · 📰 1 src / 1 articles · H score: 29

LibreOffice fixed CVE-2026-63277, a flaw that lets a malicious spreadsheet trigger code execution when opened with Java support enabled. The affected scope covers versions before 26.2.5 or 26.8.0, and the vendor has already released updates. A published proof of concept shows the weakness can execute attacker-controlled Java code without the normal macro warning.

ASOS hit by network compromise

Incident

Updated: 06.10.2026 14:41 · First: 06.10.2026 14:41 · 📰 2 src / 3 articles · H score: 10

ASOS is investigating unauthorized activity involving third-party platforms it uses to communicate with customers after a Telegram-linked notification appeared to come from the incident. ASOS said it took immediate action to restrict access to the notification platforms and is working with internal and external advisers plus relevant authorities. The company said names and contact details may have been accessed, while payment-card information and account passwords were not believed impacted, and its website, app, and operations were reported as normal. Analysts said the access appears more consistent with a SaaS platform compromise than confirmed database theft, and no sample or dump has been provided to verify broader data claims.

Wikimedia Foundation hit by network compromise

Incident

Updated: 06.10.2026 14:26 · First: 06.10.2026 14:26 · 📰 1 src / 1 articles · H score: 17

The Wikimedia Foundation confirmed an unauthorized bot incident against Wikimedia wikis and Etherpad, with edits, attempted tool exploitation, and heavy traffic disrupting platform integrity. The activity included sandbox wiki edits, efforts to misuse a citation tool and Etherpad as proxies for remote data retrieval, and a flood of automated API and query requests. Wikimedia said the activity may have contributed to a partial outage in early May 2026 and found no evidence of system or data compromise.

Wikimedia public APIs partial outage from automated traffic

Service Disruption

Updated: 06.10.2026 14:26 · First: 06.10.2026 14:26 · 📰 1 src / 1 articles · H score: 1

The Wikimedia Foundation's public APIs and Wikidata Query Service (WQDS) experienced a partial outage after millions of automated requests. The traffic hit Wikimedia services in early May 2026 and raised availability risk for users and editors. Wikimedia said it found no evidence of compromise from the activity.

Nikkei Google Workspace account personal-information exposure

Data Leak

Updated: 06.10.2026 12:25 · First: 06.10.2026 12:25 · 📰 1 src / 1 articles · H score: 46

Nikkei disclosed a Google Workspace account exposure that may have revealed names and email addresses for 1,646 people, creating privacy risk for employees and business partners. The account was accessed in late July and the exposure was disclosed in early August after a notification from Google. Nikkei said the affected data did not include information about readers or interviewees.

Nikkei hit by network compromise

Incident

Updated: 06.10.2026 12:25 · First: 06.10.2026 12:25 · 📰 2 src / 2 articles · H score: 48

Nikkei disclosed a compromise of two employee email accounts that let attackers send thousands of phishing emails from trusted inboxes. One Google Workspace account was accessed in late July, exposing employee and business-partner contact information and possibly the names and email addresses of 1,646 individuals. A second Microsoft 365 account was used in September to send 9,000 phishing emails to staff and interviewees, including messages with links to malicious websites on September 30. Nikkei says it reset passwords, contacted recipients, and has not confirmed additional unauthorized logins.