Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 19:13 08/10/2026 UTC
Last updated: 15:05 08/10/2026 UTC

Latest updates

Browse →

IDC Frontier hit by ransomware attack

Incident

Updated: 08.10.2026 23:09 · First: 08.10.2026 23:09 · 📰 1 src / 1 articles · H score: 76

IDC Frontier confirmed a ransomware attack on IDCF Cloud that shut down East Japan Region 1, disrupting cloud services for public and private customers. The outage began on October 7 at 3:40 AM local time and prompted network and system shutdowns. IDC Frontier said the event affected 495 companies and local governments using the service. The provider isolated impacted systems, disabled management-console access, and continued investigating the intrusion route and broader security exposure.

Midnight Mimosa preinstalled Android firmware malware

Malware Activity

Updated: 08.10.2026 22:20 · First: 08.10.2026 22:20 · 📰 1 src / 1 articles · H score: 29

The Midnight Mimosa malware activity is embedded in low-cost Android firmware, giving infected phones system-level control to silently install apps, run ad fraud, and act as residential proxies. The activity has affected thousands of devices across more than 150 countries, with evidence tied to MediaTek-based phones and devices posing as major brands. Because the malware is preinstalled in the system partition, removal often requires firmware-level cleanup or ADB-based intervention.

Midnight Mimosa multi-country Android supply-chain campaign

Campaign

Updated: 08.10.2026 22:20 · First: 08.10.2026 22:20 · 📰 1 src / 1 articles · H score: 32

Midnight Mimosa spans thousands of Android devices in more than 150 countries, showing a broad supply-chain operation with sustained reach over about two years. The operation used preinstalled firmware malware to silently install apps, drive ad fraud, and turn infected phones into residential proxies. Victims were concentrated in Mexico, France, Italy, the United States, Germany, Brazil, and Spain.

Integrity Technology Group-linked email-theft and password-spraying campaign

Campaign

Updated: 08.10.2026 21:32 · First: 08.10.2026 21:32 · 📰 1 src / 1 articles · H score: 89

A multi-country email-theft campaign tied to Integrity Technology Group has targeted government, law enforcement, healthcare, and religious organizations since at least mid-January 2021, putting mailbox access and account security at risk. The operators used website scanning, password spraying against Microsoft 365 and Exchange, and fake-login XSS pages to gain entry. They then used tools to collect and exfiltrate mail through Exchange Web Services and other legitimate access paths. The same activity also included a portal that let third parties access stolen email content.

Stolen email content exposed through hacker web application

Data Leak

Updated: 08.10.2026 21:32 · First: 08.10.2026 21:32 · 📰 1 src / 1 articles · H score: 67

A hacker-operated web application is exposing stolen email content to third parties, letting outsiders read compromised mail instead of keeping it locked inside the original breach. The portal lets users view the mail of a specific account by adding arguments to a URL. The exposure is tied to Integrity Technology Group-linked hackers and extends the impact of their mailbox theft activity.

UAC-0099 campaign targeting Ukrainian government, logistics, and infrastructure entities

Campaign

Updated: 08.10.2026 18:26 · First: 08.10.2026 18:26 · 📰 1 src / 1 articles · H score: 33

The UAC-0099 campaign is now tied to a broader targeting set in Ukraine, including civilian logistics and infrastructure operators, which raises the risk to the systems that keep supply lines running. The operation has targeted government, defense, border guard, and logistics entities since at least mid-2022. It has also used ASHVEIN to collect credentials, capture screenshots, and open remote shells on victim systems. The actor's evolving tooling and widening victim set point to a persistent espionage operation with growing strategic reach.

ASHVEIN (TelemetryBrowser) .NET infostealer and RAT activity against Ukrainian government personnel

Malware Activity

Updated: 08.10.2026 18:26 · First: 08.10.2026 18:26 · 📰 1 src / 1 articles · H score: 29

The ASHVEIN (TelemetryBrowser) malware activity now includes confirmed attacks against Ukrainian government personnel, giving UAC-0099 a new .NET infostealer/RAT for credential theft and remote control. The malware steals logins from Chrome and Firefox while also supporting screenshot capture, file collection, and PowerShell remote shells. Its delivery chain uses DLL sideloading, VHD containers, and dedicated .NET droppers to expand reach and persistence. The build set was actively maintained in October 2025, showing continued development of a flexible intrusion toolset.

.Gh (Ghana) ccTLD registry hit by cyberattack

Incident

Updated: 08.10.2026 17:30 · First: 08.10.2026 17:30 · 📰 1 src / 1 articles · H score: 26

The .gh, .sl and .as ccTLD registries were compromised, letting attackers alter authoritative DNS records and obtain unauthorized HTTPS certificates for Google domains and other organizations. The incident put domains under those namespaces at risk and weakened certificate trust beyond the registries themselves.

China-based ARTEX AI-enabled campaign against South Korean financial organizations

Campaign

Updated: 08.10.2026 14:00 · First: 08.10.2026 14:00 · 📰 2 src / 2 articles · H score: 39

CrowdStrike said a suspected China-based threat actor used ARTEX and Anthropic’s Claude AI in a targeted campaign against South Korean financial organizations from late September to early October 2026. The activity led to data exfiltration, and the actor used ARTEX to discover vulnerabilities and compromise specific services. CrowdStrike also linked the operator to efforts to find Korean Telegram data sales groups, while assessing the attacker as a Chinese speaker with financial motivation. South Korea’s Financial Services Commission warned customers of the hacked companies about possible phishing attacks and loan scams.

ASOS hit by network compromise

Incident

Updated: 06.10.2026 14:41 · First: 06.10.2026 14:41 · 📰 2 src / 5 articles · H score: 10

ASOS is investigating unauthorized activity involving third-party platforms it uses to communicate with customers after a Telegram-linked notification appeared to come from the incident. ASOS said it took immediate action to restrict access to the notification platforms and is working with internal and external advisers plus relevant authorities. The company said names and contact details may have been accessed, while payment-card information and account passwords were not believed impacted, and its website, app, and operations were reported as normal. Analysts said the access appears more consistent with a SaaS platform compromise than confirmed database theft, and no sample or dump has been provided to verify broader data claims.

MATCHBOIL downloader evolution by UAC-0099

Malware Activity

Updated: 08.10.2026 16:00 · First: 08.10.2026 16:00 · 📰 1 src / 1 articles · H score: 20

UAC-0099 has steadily upgraded MATCHBOIL, a C# downloader used against Ukrainian organizations, increasing obfuscation, adding sandbox checks, and changing execution and persistence behavior. The activity matters because the malware has been observed across transportation, manufacturing, and energy and continued through June 2026.

Microsoft Teams adds third-party deepfake detection and impersonation protection for meetings

Security Tool/Service

Updated: 08.10.2026 15:08 · First: 08.10.2026 15:08 · 📰 1 src / 1 articles · H score: 11

Microsoft Teams is adding third-party deepfake detection and impersonation protection to meetings, expanding in-call defenses against synthetic media and deceptive identities. The features are in development now and are slated for general availability in November after a worldwide rollout. Once deployed, Teams will surface detection signals, warnings, and meeting controls from supported providers to help users respond during live meetings.

CISA, FBI, and NSA joint advisory on Integrity Tech-enabled critical infrastructure targeting

Public Sector Action

Updated: 08.10.2026 15:00 · First: 08.10.2026 15:00 · 📰 1 src / 1 articles · H score: 29

CISA, the FBI, the NSA, and international partners issued a joint Cybersecurity Advisory warning that Integrity Technology Group (Integrity Tech) is enabling threat actors to target critical infrastructure sectors worldwide. The activity uses large-scale botnets, VPN infrastructure, and living off the land techniques, with observed operations in North America, Southeast Asia, and Africa. Defenders are being told to review the guidance, hunt for compromise, and patch the listed known exploited CVEs.

South Korea-based financial firms data exfiltration, late September to early October 2026

Data Leak

Updated: 08.10.2026 14:00 · First: 08.10.2026 14:00 · 📰 1 src / 1 articles · H score: 35

Sensitive data was exfiltrated from multiple South Korea-based financial firms during a late September to early October 2026 intrusion campaign, confirming a leak from a regulated sector. The activity involved ARTEX and Claude AI as part of the offensive workflow. The exposure raises immediate risk of downstream fraud, phishing, and resale of stolen information.

Wazza phishkit campaign targeting banking, manufacturing, and government organizations

Campaign

Updated: 08.10.2026 13:30 · First: 08.10.2026 13:30 · 📰 1 src / 1 articles · H score: 33

The Wazza phishing campaign is targeting banking, manufacturing, and government organizations across the US, Europe, and Australia, and it is using multi-stage routing to hide the final lure. The kit screens visitors and automated traffic before serving an Adobe-themed Device Code phishing page. That evasive delivery pattern raises the chance that initial links will look benign until they are detonated in the right environment.

Wazza phishkit multi-stage routing delivery

Malware Activity

Updated: 08.10.2026 13:30 · First: 08.10.2026 13:30 · 📰 1 src / 1 articles · H score: 22

The Wazza phishkit now hides its phishing page behind multi-stage routing, session tokens, and browser telemetry checks, making the lure harder to reproduce and detect. It screens automated traffic before showing an Adobe-themed Device Code page to targeted organizations across the US, Europe, and Australia. Defenders get a smaller initial signal and a more evasive delivery chain to investigate.

Raheim Hamilton sentenced in Empire Market cybercrime case

Law Enforcement

Updated: 08.10.2026 13:29 · First: 08.10.2026 13:29 · 📰 1 src / 1 articles · H score: 49

A court sentenced Raheim Hamilton to 40 years in prison for helping run Empire Market, a cybercrime marketplace tied to $430 million in illegal transactions. The sentence raises the criminal cost for the dark-web operation’s leadership and reinforces the severity of its drug, fraud, and tooling sales. The case also includes major forfeiture and seizure components tied to the same investigation.

Atlassian Data Center products path traversal (CVE-2026-21589)

Vulnerability

Updated: 06.10.2026 09:58 · First: 06.10.2026 09:58 · 📰 3 src / 5 articles · H score: 32

Atlassian disclosed CVE-2026-21589, a path traversal vulnerability in 8 self-hosted Data Center products that can let a no-login attacker read specific files in each product's web application root directory. Atlassian published fixed versions for the affected products and said cloud customers do not need to take action. The advisory also recommends temporary network-blocking mitigations until systems are upgraded.

Europol and US GAO issue PQC migration reports

Public Sector Action

Updated: 08.10.2026 12:30 · First: 08.10.2026 12:30 · 📰 1 src / 1 articles · H score: 17

Europol and the US GAO released reports urging faster post-quantum cryptography (PQC) preparation as CRQCs could eventually break widely used encryption. The guidance pushes organizations and federal agencies to inventory vulnerable cryptography, plan funding, and test PQC migration. The reports also elevate near-term defensive steps, including tighter protocol choices and reducing long-term exposure of sensitive data.

U.S. State Department Rewards for Justice reward for Zhang Yu

Public Sector Action

Updated: 08.10.2026 10:42 · First: 08.10.2026 10:42 · 📰 1 src / 1 articles · H score: 55

The U.S. State Department offered up to $10 million for information leading to the identification or location of Zhang Yu, escalating the official search for a suspect tied to HAFNIUM. The reward is being run through Rewards for Justice and is linked to the 2021 Microsoft Exchange Server attacks. The offer underscores an active U.S. government effort to surface information on a charged cyber-related target who remains at large.

Zohar Pinhasi indicted in MonsterCloud ransom-payment fraud case

Law Enforcement

Updated: 08.10.2026 02:04 · First: 08.10.2026 02:04 · 📰 2 src / 2 articles · H score: 35

Federal prosecutors indicted and arraigned Zohar Pinhasi in a wire fraud conspiracy case tied to alleged secret ransom payments, exposing a cyber-remediation business accused of profiting from ransomware victims. The case centers on MonsterCloud and allegations that it misled customers while paying attackers for decryptors from June 2018 to June 2023. The charged conduct in Brooklyn and the Eastern District of New York could bring major criminal exposure for a ransomware-recovery operation and its operator.

Google hit by network compromise

Incident

Updated: 07.10.2026 21:48 · First: 07.10.2026 21:48 · 📰 2 src / 2 articles · H score: 16

The .gh, .sl, and .as ccTLD compromise led to unauthorized HTTPS certificates for Google and YouTube names, creating a risk of encrypted impersonation and private-data interception. Chrome blocked the rogue certificates with CRLSets, and the issuing CAs later revoked them. Certificate Transparency logs place issuance between September 22 and 27, 2026, with disclosure on October 6-7, 2026. Google's own systems were not breached.

MALFEX npm supply-chain malware campaign

Campaign

Updated: 07.10.2026 20:43 · First: 07.10.2026 20:43 · 📰 1 src / 1 articles · H score: 12

A long-running npm supply-chain campaign named MALFEX is pushing information stealers and remote access trojans (RATs) to compromised Windows hosts. The operation has used 12 published packages since August 2023, with 8 flagged as malicious, and the packages have already been downloaded 40,767 times. Researchers also found multiple delivery paths that load Overlord RAT, a movinlike stealer, and a downloader, showing an active package-based operation with broad opportunistic reach.

SonicWall security patch release for CVE-2026-102255

Security Patch Release

Updated: 07.10.2026 14:37 · First: 07.10.2026 14:37 · 📰 2 src / 2 articles · H score: 38

SonicWall released hotfixes for four SMA1000 appliance flaws, including CVE-2026-102255. CVE-2026-102255 is a CVSS 10.0 pre-authentication SSRF issue in the WorkPlace interface that could let a remote unauthenticated attacker reach internal functions. The hotfixes apply to SMA1000 models 6210, 7210, and 8200v running 12.4.3-03526 and older or 12.5.0-02952 and older, with fixed builds at 12.4.3-03670 and 12.5.0-03082. SonicWall reported no evidence of exploitation and no workaround.

Microsoft Outlook blocks MSIX attachments in web and Windows client

Security Tool/Service

Updated: 07.10.2026 18:44 · First: 07.10.2026 18:44 · 📰 1 src / 1 articles · H score: 14

Microsoft is adding .msix and .msixbundle to the blocked-attachment list in Outlook on the web and new Outlook for Windows, reducing a file-delivery path that attackers have used for unsafe attachments. The change rolls out to Exchange Online users in early November and reaches general availability by mid-November.

LMCache unauthenticated remote code execution (CVE-2026-105192)

Vulnerability

Updated: 07.10.2026 18:34 · First: 07.10.2026 18:34 · 📰 1 src / 1 articles · H score: 39

LMCache has a critical unauthenticated remote code execution flaw, CVE-2026-105192, that can let an attacker run code on the cache server without logging in. The issue affects LMCache 0.3.9 through 0.5.5, plus 0.5.6 release candidates and the development branch. No fixed version is available, so exposed deployments remain at risk until a patched release lands.

PoeLLM malware mining and botnet expansion against AI/LLM infrastructure

Malware Activity

Updated: 07.10.2026 18:33 · First: 07.10.2026 18:33 · 📰 1 src / 1 articles · H score: 60

The PoeLLM malware family is actively targeting exposed AI/LLM infrastructure to install cryptocurrency miners and expand a botnet, with more than 3,400 victim servers already identified. The activity has been running since April 2026 and is concentrated in the U.S. and Western Europe. Compromised hosts are reused as scanners and exploit servers, widening the pool of vulnerable systems. The malware hides its C2 address in a poem hosted in a GitHub repository.

PoeLLM cryptomining and scanning malware activity against exposed AI servers

Malware Activity

Updated: 07.10.2026 18:04 · First: 07.10.2026 18:04 · 📰 2 src / 2 articles · H score: 62

PoeLLM is a new malware family in the Canto Incognito campaign that targets exposed AI/LLM infrastructure to deploy XMRig and Iron miners and grow a botnet. Lumen Black Lotus Labs says the activity has been active since April 2026, has identified 3,400+ victim servers, and is concentrated in the U.S. and Western Europe. The malware hides its C2 inside a GitHub-hosted poem and has been seen against LiteLLM, Gotenberg, Gitea, and Ivanti Sentry. Compromised hosts are reused as scanners and exploit servers, and recent traffic suggests possible experimentation with distributed brute-force attacks.

PoeLLM cryptomining campaign targeting exposed AI services

Campaign

Updated: 07.10.2026 18:04 · First: 07.10.2026 18:04 · 📰 1 src / 1 articles · H score: 67

The PoeLLM campaign is abusing exposed AI services to turn compromised servers into scanners and exploit launchpads, expanding risk across the United States and Western Europe. It has compromised more than 2,100 servers and reached as many as 800 infected systems in a single day. Activity has been underway since at least April, and the infrastructure now relies on a GitHub-hosted poem to derive changing C2 addresses.

Dutch police arrest tied to ShinyHunters hacking investigation

Law Enforcement

Updated: 28.09.2026 22:49 · First: 28.09.2026 22:49 · 📰 4 src / 5 articles · H score: 44

Dutch police and the FBI are moving against ShinyHunters after the arrest of a 24-year-old Amsterdam man alleged to be one of the group's leaders. The suspect was arrested on September 15 and is now set to remain in pre-trial detention for at least another 90 days after a Rotterdam District Court ruling on Tuesday. Dutch police said the suspect had material on his laptop tied to possible additional crimes, and they have not ruled out more arrests. The FBI says ShinyHunters and co-conspirators have breached more than 140 organizations since last year and collected at least $70 million in extortion payments.