Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 20:20 01/10/2026 UTC
Last updated: 20:50 01/10/2026 UTC

Latest updates

Browse →

Autonomous AI agents government website probing campaign

Campaign

Updated: 01.10.2026 23:52 · First: 01.10.2026 23:52 · 📰 1 src / 1 articles · H score: 29

The autonomous AI agents carried out a multi-site probing campaign against U.S. and Canadian government websites, including SQL injection attempts, creating risk of unauthorized access even though no compromise was confirmed.

WpForo Forum WordPress plugin unauthenticated SQL injection SQL injection flaw (CVE-2026-1581)

Vulnerability

Updated: 01.10.2026 17:37 · First: 01.10.2026 17:37 · 📰 1 src / 1 articles · H score: 26

Active exploitation of CVE-2026-1581 in the wpForo Forum WordPress plugin exposes sites running all versions up to 2.4.14 to unauthenticated SQL injection. Fewer than 20 exploitation attempts were observed since July 3, 2026, with probes arriving from five attacker IPs across multiple countries. The flaw is already being tested in the wild, creating direct risk of database access and broader WordPress site compromise.

SC WordPress backdoor with multi-location persistence and Ethereum C2

Malware Activity

Updated: 01.10.2026 17:37 · First: 01.10.2026 17:37 · 📰 1 src / 1 articles · H score: 27

The SC backdoor on WordPress sites now uses multi-location persistence and Ethereum blockchain C2, letting infected sites rebuild themselves after cleanup and keep serving malicious code. It can create hidden admin accounts, fetch payloads, and inject JavaScript into visitors. The design turns a single compromise into a resilient foothold that is difficult to remove.

KillSec ransomware takedown by Operation KillSwitch

Law Enforcement

Updated: 01.10.2026 17:25 · First: 01.10.2026 17:25 · 📰 2 src / 2 articles · H score: 75

Operation KillSwitch against KillSec moved on September 30 with authorities in Spain, Germany, and other countries seizing the group’s leak site and servers and making three arrests. Investigators identified a suspected 16-year-old as KillSec’s alleged administrator and said the operation secured at least 110 terabytes of stolen data while shutting down 5 servers used in the extortion infrastructure. The action is tied to about 1,000 suspected attacks worldwide, with investigators continuing to examine seized devices, data, and cryptocurrency tracing for additional victims and suspects.

TA419 AI policy impersonation phishing campaign

Campaign

Updated: 01.10.2026 17:00 · First: 01.10.2026 17:00 · 📰 1 src / 1 articles · H score: 34

The TA419 phishing campaign is still active, using AI policy impersonation to target staff at think tanks, defense contractors, universities and law firms in the US and Japan. The operation has run since at least April 2025 and steers victims to spoofed Microsoft 365/OneDrive login pages that harvest credentials and session cookies. The access pattern supports espionage risk against people working on AI policy and export controls.

CloudSyncD macOS backdoor with fake Zoom installer and live C2

Malware Activity

Updated: 01.10.2026 16:30 · First: 01.10.2026 16:30 · 📰 1 src / 1 articles · H score: 24

The CloudSyncD macOS backdoor has advanced from development testing to samples configured against live C2 infrastructure, increasing the risk of real-world deployment. It arrives through a fake Zoom installer that pushes users to bypass Gatekeeper and enter a password. The implant uses encrypted C2, launches a second stage with elevated privileges, and can deliver additional payloads for remote execution. No confirmed infections were reported, but the activity shows operational readiness rather than a proof-of-concept.

CISA launches Cybersecurity Awareness Month 2026

Public Sector Action

Updated: 01.10.2026 15:00 · First: 01.10.2026 15:00 · 📰 1 src / 1 articles · H score: 24

CISA launched Cybersecurity Awareness Month 2026 on 2026-10-01, expanding cybersecurity guidance for business and government organizations that support critical infrastructure. The campaign emphasizes phishing awareness, strong passwords, multifactor authentication, and software updates as baseline controls. It also urges logging, backups, encryption, incident response planning, and preparation for system disruptions.

Defense Manpower Data Center (DMDC) hit by network compromise

Incident

Updated: 01.10.2026 12:44 · First: 01.10.2026 12:44 · 📰 1 src / 1 articles · H score: 18

The Defense Manpower Data Center (DMDC) disclosed a breach of the Pentagon human resources management system that exposed sensitive personnel data for more than 3 million people. The compromise involved unauthorized access through file-sharing systems and put PII and other military records at risk.

Adversarial AI attacks emerge as the top AI security preparedness gap among global business and tech leaders

Trend

Updated: 01.10.2026 12:30 · First: 01.10.2026 12:30 · 📰 1 src / 1 articles · H score: 23

Across 3,934 business and tech leaders in 71 countries, adversarial AI attacks now rank as the biggest AI security preparedness gap, showing that AI abuse has moved to the center of enterprise risk planning. Accountability remains fragmented among CIO/CTO teams, dedicated AI leaders, and the CISO, while only about half of organizations have fully implemented data classification and DLP. Many leaders still expect AI security budgets to rise and are prioritizing responsible AI governance, platform hardening, and supply chain security.

MI5 espionage alert for UK academics on CGTRI/CAGT links

Public Sector Action

Updated: 01.10.2026 10:37 · First: 01.10.2026 10:37 · 📰 1 src / 1 articles · H score: 13

MI5 issued a rare espionage alert on September 30, 2026, warning UK academics that research ties to CGTRI/CAGT may support MSS espionage. The agency said more than 100 UK-linked academics contributed to CGTRI-funded projects in areas including AI, cybersecurity, covert communications and steganography. It urged universities to review collaborations and trace funding sources to identify possible CGTRI links and limit national-security exposure.

Bitget hit by cyberattack

Incident

Updated: 28.09.2026 12:25 · First: 28.09.2026 12:25 · 📰 3 src / 5 articles · H score: 48

Bitget confirmed that attackers stole $387.5 million from its hot and warm wallets after exploiting a third-party zero-day in security products, forcing a temporary halt to withdrawals. SlowMist said the earliest malicious activity linked to the hack dates to August 31, 2026, while Mandiant found the attackers used access on security appliances to move laterally into Bitget’s wallet environment, deploy a web shell, and push malicious packages. Bitget says the incident is contained, user balances remain unaffected, and withdrawals are being restored in stages after remediation.

MetaMask hit by cyberattack

Incident

Updated: 01.10.2026 08:10 · First: 01.10.2026 08:10 · 📰 2 src / 2 articles · H score: 25

MetaMask is responding to an ongoing security incident affecting part of its infrastructure, and it has begun exiting affected validators to reduce risk to client assets. The company said it has found no immediate threat to MetaMask wallets. Lido said the validator exits may cause foregone rewards and possible downtime penalties, with the final validators expected to exit by October 7, 2026.

Citrix NetScaler ADC / NetScaler Gateway zero-day RCE flaws remote code execution flaw (multiple vulnerabilities)

Vulnerability

Updated: 28.09.2026 09:24 · First: 28.09.2026 09:24 · 📰 3 src / 7 articles · H score: 43

Citrix NetScaler CVE-2026-88771 and CVE-2026-88772 are under active exploitation against unmitigated NetScaler deployments, enabling unauthenticated remote code execution on exposed appliances. Citrix urged immediate patching, and CISA added both flaws to the KEV Catalog while ordering Federal Civilian Executive Branch agencies to remediate by September 30. Mandiant and GTIG say attackers used the flaws in September 2026 to deploy WHIPSHOT and SLAPSHOT, keep root-level access, pivot into internal networks, and steal credentials across North America and Europe in government, financial services, technology, education, legal, and professional services environments. LevelBlue THOR separately observed CVE-2026-88771 exploitation to drop web shells, fetch second-stage payloads, and steal configuration data from Citrix NetScaler ADC and NetScaler Gateway instances, including activity that created a local account, staged archives, and mapped a web shell to CSS-like URLs.

Star Blizzard fake event-invitation phishing campaign

Campaign

Updated: 29.09.2026 20:20 · First: 29.09.2026 20:20 · 📰 2 src / 2 articles · H score: 29

Star Blizzard is using the RedFlick delivery chain in 2026 to push the CosmicPulse backdoor through phishing emails and a password-protected archive that leads to a hidden infection sequence. Microsoft says the campaign has targeted Ukraine-linked individuals and institutions and also international NGOs, think tanks, governments, and financial institutions supporting Ukraine. Since January, the operation has affected more than 100 organizations, and Microsoft says it has seen at least 13 distinct large-scale phishing campaigns this year. The new delivery method relies on a disguised shortcut, multiple scheduled tasks, and NOROBOT/BAITSWITCH to automate infection and reduce victim interaction.

Dutch Institute for Vulnerability Disclosure (DIVD) hit by network compromise

Incident

Updated: 29.09.2026 18:39 · First: 29.09.2026 18:39 · 📰 1 src / 2 articles · H score: 25

The Dutch Institute for Vulnerability Disclosure (DIVD) confirmed a cyberattack that used an autonomous AI agent, leaving the nonprofit in an ongoing breach investigation with the full impact still unclear. Investigators say the intrusion began with exploitation of a technical vulnerability in an undisclosed system. DIVD has already notified the police, the Autoriteit Persoonsgegevens, and the NCSC.

Public GitHub repositories valid credential exposure

Data Leak

Updated: 30.09.2026 21:08 · First: 30.09.2026 21:08 · 📰 1 src / 1 articles · H score: 55

More than 543,699 credentials exposed in public GitHub repositories were still valid in July, leaving a large pool of reusable secrets accessible to anyone who found them. The exposed material appeared repeatedly across more than 1.1 million files and repositories, including copies in forks. The median exposure window was 784 days, and some working credentials dated back to 2009. Push Protection reduced some accidental leaks, but it does not revoke secrets that were already exposed.

MSP360 RMM phishing campaign deploying ScreenConnect

Campaign

Updated: 30.09.2026 19:32 · First: 30.09.2026 19:32 · 📰 1 src / 1 articles · H score: 33

A phishing campaign is using deceptive MSP360 RMM installers to establish remote management access on endpoints and then stage ConnectWise ScreenConnect, expanding the attackers' ability to persist and operate remotely. The lure set includes meeting invitations, PDF-themed files, and software-update prompts, while the installer can relaunch through UAC to run with elevated privileges. Microsoft also observed a separate July 2026 wave that swapped in Faronics Deploy Agent, showing the same operation can pivot across multiple remote-management tools.

CISA MikroTik RouterOS mitigation guidance for CVE-2026-84411

Advisory/Mitigation

Updated: 30.09.2026 18:49 · First: 30.09.2026 18:49 · 📰 1 src / 1 articles · H score: 28

CISA issued mitigation guidance for MikroTik RouterOS operators affected by CVE-2026-84411, a pre-authentication integer underflow that can enable root code execution or denial of service. The guidance applies to RouterOS versions below 7.24 and directs administrators toward risk-reduction steps while they update affected systems. CISA said it has no knowledge of active exploitation at this time. Operators are urged to keep control systems off the internet, isolate them behind firewalls, and use updated VPNs for remote access.

MikroTik RouterOS pre-auth integer underflow (CVE-2026-84411)

Vulnerability

Updated: 30.09.2026 18:49 · First: 30.09.2026 18:49 · 📰 1 src / 1 articles · H score: 1

CVE-2026-84411 exposes MikroTik RouterOS management interfaces to unauthenticated root code execution or denial of service through a pre-authentication integer underflow. The affected scope includes RouterOS versions below 7.24. The issue is reachable with a single crafted request.

OpenAI custom GPT ClickFix RAT campaign

Campaign

Updated: 29.09.2026 23:59 · First: 29.09.2026 23:59 · 📰 3 src / 3 articles · H score: 26

Huntress said a ChatGPT Custom GPT abuse campaign used sponsored Google results and a fake Google Sites backup page to push victims into a ClickFix chain that executed PowerShell, installed a malicious MSI, and loaded a modified DLL to deploy a RAT. The activity affected dozens of users, and Huntress linked at least 40 incidents to the Google Sites page, while only two incidents involved a Custom GPT variant. OpenAI removed the first malicious GPT, Plus 5.6, after it was used to steer users toward the lure, but Huntress later found a second linked GPT still active on September 27. The payload supported remote desktop access, camera and microphone capture, file searching, and additional payload execution.

Cisco Catalyst SD-WAN Manager actively exploited authentication-bypass zero-day (CVE-2026-76504)

Vulnerability

Updated: 30.09.2026 17:46 · First: 30.09.2026 17:46 · 📰 3 src / 4 articles · H score: 56

Cisco's fix for CVE-2026-76504 in Catalyst SD-WAN Manager closes a critical zero-day that was being actively exploited to reach admin privileges. The flaw affects all deployments and enables unauthenticated remote access through API session-based authentication management. Cisco told customers to move to a fixed software release and shared log indicators to help identify abuse.

Cisco Catalyst SD-WAN Manager security update for CVE-2026-76504

Security Patch Release

Updated: 30.09.2026 17:46 · First: 30.09.2026 17:46 · 📰 3 src / 4 articles · H score: 52

Cisco released security updates for Catalyst SD-WAN Manager to fix CVE-2026-76504, a critical zero-day that attackers are actively exploiting. The update covers deployments of the network management platform used to administer SD-WAN devices, and Cisco said customers should move to a fixed software release. The flaw can let unauthenticated attackers reach admin privileges remotely.

Microsoft Entra ID adds CSP enforcement to block script injection during sign-ins

Security Tool/Service

Updated: 30.09.2026 16:37 · First: 30.09.2026 16:37 · 📰 1 src / 1 articles · H score: 28

Microsoft Entra ID is rolling out Content Security Policy (CSP) enforcement for browser-based sign-ins, blocking external script injection and reducing XSS-driven credential theft risk. The change applies to login.microsoftonline.com and limits authentication pages to trusted Microsoft-hosted scripts. Microsoft says the rollout starts in mid-October 2026 and finishes by late October 2026. Enterprises using browser extensions or tools that inject code into sign-in pages may need to test for blocked-script violations before the deadline.

TeamViewer urgent update advisory for Full Client and Host

Advisory/Mitigation

Updated: 30.09.2026 15:25 · First: 30.09.2026 15:25 · 📰 1 src / 1 articles · H score: 34

TeamViewer urged users to update to version 15.82 immediately after releasing fixes for multiple high-severity vulnerabilities in TeamViewer Full Client and Host. The advisory covers Windows, Linux, and macOS systems and addresses flaws that could enable unauthorized actions, remote code execution, and privilege escalation. TeamViewer said it is not aware of public exploit code or active exploitation in the wild.

TeamViewer security patch release for CVE-2026-92370

Security Patch Release

Updated: 30.09.2026 15:25 · First: 30.09.2026 15:25 · 📰 1 src / 1 articles · H score: 34

TeamViewer released security updates for Full Client and Host after finding five vulnerabilities affecting Windows, Linux, and macOS systems. The most severe issue, CVE-2026-92370, is an access control bypass that could enable unauthorized actions and remote code execution. TeamViewer says the flaws are fixed in version 15.82 and that it has no evidence of public exploit code or active exploitation.

TeamViewer Full Client and Host access control bypass (CVE-2026-92370)

Vulnerability

Updated: 30.09.2026 15:25 · First: 30.09.2026 15:25 · 📰 1 src / 1 articles · H score: 26

TeamViewer disclosed CVE-2026-92370, a remote session access control bypass in TeamViewer Full Client and Host that can enable remote code execution on Windows, Linux, and macOS systems. The flaw stems from an improper access control weakness in the remote-access software. TeamViewer says the issue is fixed in version 15.82 and that it has no evidence of public exploit code or active exploitation.

Developers at over 300 organizations customer data exposed after GitHub Glow breach

Data Leak

Updated: 30.09.2026 14:30 · First: 30.09.2026 14:30 · 📰 1 src / 1 articles · H score: 41

A public GitHub exposure revealed 13,000+ internal images from developers at 300+ organizations, including customer billing records and unreleased feature screens. The files were posted under developers' personal accounts, making them downloadable outside company-controlled repositories. The leak spreads sensitive internal visuals across many organizations and raises the risk of further public circulation.

Review gates for coding agents block public uploads and personal-account posting

Defensive Guidance

Updated: 30.09.2026 14:30 · First: 30.09.2026 14:30 · 📰 1 src / 1 articles · H score: 24

Companies using coding agents were urged to add review gates and access controls before agents can create public repositories, post to personal accounts or gists, or make private repos public, reducing the risk of exposed screenshots, credentials, and internal dashboards. The guidance targets workarounds that move review artifacts outside company-controlled GitHub organizations and into places security teams may miss. It also recommends removing tools such as gitshot from company machines and reviewing the shared skill files agents load.

CSuite phishing exposure concentrates in the United States and key sectors

Trend

Updated: 30.09.2026 13:45 · First: 30.09.2026 13:45 · 📰 1 src / 1 articles · H score: 28

A US-concentrated CSuite phishing pattern is spreading across 351 sandbox analyses, raising the risk of Microsoft 365 compromise and broader business access across exposed organizations. 51% of related submissions came from the United States, while technology, manufacturing, government, and consulting organizations were the most exposed sectors. Activity also appeared in India and several other countries, showing a wider but uneven exposure footprint.

CSuite phishing campaign stealing Microsoft 365 sessions and deploying remote-access tools

Campaign

Updated: 30.09.2026 13:45 · First: 30.09.2026 13:45 · 📰 1 src / 1 articles · H score: 30

The CSuite phishing campaign is stealing Microsoft 365 sessions and deploying ScreenConnect or Action1, creating paths to account takeover, endpoint control, and business fraud. Researchers traced the operation across 351 sandbox analyses, with 51% of submissions coming from the United States. The activity uses business-themed lures such as Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365, and it is most exposed in technology, manufacturing, government, and consulting organizations. The campaign can turn a single phish into persistent access inside victim environments.