Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 21:05 03/10/2026 UTC
  • Law Enforcement H score 66 Jordan detains Rey in ShinyHunters investigation Jordanian authorities detained ShinyHunters suspect Rey and the cooperation with the FBI could accelerate identifying remaining extortion-group members and devices amid ongoing pressure on the crew.
  • Incident H score 62 Microsoft hit by network compromise Microsoft’s hijacked official X account was used to post an unauthorized crypto-token promotion, advancing the risk of high-profile brand abuse and scams despite Microsoft removing the posts.
  • Advisory/Mitigation H score 49 Fortinet FortiMail mitigation guidance for CVE-2026-104286 Fortinet issued mitigation guidance for CVE-2026-104286 in FortiMail while the flaw is reportedly actively exploited, pushing administrators toward immediate workarounds before fixed builds arrive.
  • Security Patch Release H score 45 Dell security patch release for CVE-2026-63688 Dell released same-day patches for CSM vulnerabilities including CVE-2026-63688/63692 affecting Kubernetes-connected enterprise storage arrays, tightening exposure to admin-level compromise.
  • Security Patch Release H score 41 GitLab security patch release for CVE-2026-90970 GitLab patched CVE-2026-90970 in GitLab Self-Hosted AI Gateway, closing a critical command-execution path that could be abused in self-managed deployments.
  • Law Enforcement H score 37 U.S. Justice Department charges TdA-linked ATM jackpotting suspects The U.S. Justice Department charged 98 TdA-linked ATM jackpotting suspects, expanding accountability for cash-out hacking targeting U.S. banking infrastructure.
Last updated: 19:05 03/10/2026 UTC

Latest updates

Browse →

Jordan detains Rey in ShinyHunters investigation

Law Enforcement

Updated: 03.10.2026 22:09 · First: 03.10.2026 22:09 · 📰 1 src / 1 articles · H score: 66

Jordanian authorities detained Rey in a ShinyHunters cybercrime investigation, and he is now cooperating with the FBI to identify other extortion-group members. The reported detention could help investigators map the group's devices, communications, and remaining associates. It also comes as pressure intensifies on ShinyHunters after the group's attacks on major victims and related infrastructure disruptions.

MI5 Security Service Espionage Alert on CGTRI and U.K. academia

Public Sector Action

Updated: 03.10.2026 17:38 · First: 03.10.2026 17:38 · 📰 1 src / 1 articles · H score: 13

MI5 issued a Security Service Espionage Alert warning U.K. academic institutions about CGTRI/CAGT and the risk that research collaborations could support MSS espionage. The alert says more than 100 U.K.-linked academics have contributed to CGTRI-funded projects spanning AI, cybersecurity, covert communications, and steganography. MI5 urged universities to review collaborations and trace funding sources, while warning that continued cooperation could create National Security Act 2023 exposure.

Technical University of Denmark (DTU) hit by network compromise

Incident

Updated: 03.10.2026 17:35 · First: 03.10.2026 17:35 · 📰 1 src / 1 articles · H score: 16

The Technical University of Denmark (DTU) disclosed a compromised-credentials intrusion into DTUBasen, exposing personal data tied to up to 200,000 users. The accessed records span more than two decades and may include CPR numbers, names, addresses, profile photos, and next-of-kin details. DTU warned the stolen data could fuel identity fraud and more convincing phishing.

Technical University of Denmark (DTU) DTUBasen data leak exposing up to 200,000 users

Data Leak

Updated: 03.10.2026 17:35 · First: 03.10.2026 17:35 · 📰 1 src / 1 articles · H score: 15

The Technical University of Denmark (DTU) disclosed a data leak affecting information tied to up to 200,000 users, creating risk of identity fraud and more convincing phishing. Attackers used compromised credentials to access DTUBasen, DTU's identity and access management (IAM) system, and download a large amount of data. The exposed material may include CPR numbers, names, addresses, profile photos, and work-related details.

Frontline Education hit by network compromise

Incident

Updated: 02.10.2026 22:01 · First: 02.10.2026 22:01 · 📰 1 src / 1 articles · H score: 21

Frontline Education confirmed a data breach after attackers used a third-party software vulnerability to gain unauthorized access to its environment and steal employee records. The compromise affected school district employee information, including Social Security numbers, and was identified on August 14, 2026. Frontline said it remediated the flaw and notified impacted districts.

Warlock SharePoint multi-sector ransomware campaign

Campaign

Updated: 02.10.2026 21:33 · First: 02.10.2026 21:33 · 📰 1 src / 1 articles · H score: 29

The Warlock ransomware campaign is using SharePoint vulnerabilities to break into a water utility, telecom provider, regional government body, and university across Europe, Africa, and Latin America. The group emerged in June 2025 and has been active over the past two months, with ToolShell zero-days helping open the door. In a July 22 intrusion, attackers disabled protection on at least 40 hosts and then launched ransomware on at least 33 hosts. Continued exploitation of SharePoint keeps exposed on-premises deployments at risk of follow-on intrusion and extortion.

Warlock ransomware launched on at least 33 hosts

Malware Activity

Updated: 02.10.2026 21:33 · First: 02.10.2026 21:33 · 📰 1 src / 1 articles · H score: 25

Warlock ransomware was launched on at least 33 hosts after protection was disabled, compressing the final stage of the intrusion into a rapid network-wide rollout. The deployment followed an AV/EDR-killing tool that turned off defenses on compromised machines. The payload was staged in SYSVOL, enabling broad execution across the environment.

Antino Windows backdoor activity using Microsoft 365 dead drops

Malware Activity

Updated: 02.10.2026 20:33 · First: 02.10.2026 20:33 · 📰 1 src / 1 articles · H score: 15

Antino is being deployed as a Windows backdoor that gives operators host reconnaissance, command execution, file transfer, and persistence while routing C2 through Microsoft 365 dead drops, increasing stealth against defenders.

UAT-11587 Antino spear-phishing campaign against government and policy organizations

Campaign

Updated: 02.10.2026 20:33 · First: 02.10.2026 20:33 · 📰 1 src / 1 articles · H score: 22

A UAT-11587 spear-phishing campaign is expanding across Asia and Syria, delivering the Antino backdoor to government and policy organizations and increasing the risk of espionage and persistent access. The operation first surfaced in September 2025 and later broadened to targets in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria. It uses tailored lures, spoofed trusted senders, and a fake Gmail attachment preview to push victims into a multi-stage infection chain. Antino then abuses Microsoft 365, especially Outlook and OneDrive, for command-and-control and file transfer.

GitLab Self-Hosted AI Gateway immediate update advisory (CVE-2026-90970)

Advisory/Mitigation

Updated: 02.10.2026 19:20 · First: 02.10.2026 19:20 · 📰 2 src / 2 articles · H score: 41

GitLab issued immediate update guidance for GitLab Self-Managed customers running Self-Hosted AI Gateway after fixing CVE-2026-90970, a flaw that could allow arbitrary command execution on unpatched instances. The company released 19.2.4, 19.3.2, and 19.4.1 and told affected users to upgrade immediately. GitLab-hosted AI Gateway users are already protected and do not need action.

GitLab AI Gateway improper neutralization command execution security flaw (CVE-2026-90970)

Vulnerability

Updated: 02.10.2026 19:20 · First: 02.10.2026 19:20 · 📰 2 src / 2 articles · H score: 35

GitLab has fixed CVE-2026-90970, a critical improper neutralization flaw in GitLab AI Gateway that could let authenticated users with Duo Agent Platform access escape the prompt template sandbox and run arbitrary commands on vulnerable self-hosted instances. The issue affects GitLab Self-Hosted AI Gateway deployments, while GitLab-hosted AI Gateway users are already protected. GitLab released 19.2.4, 19.3.2, and 19.4.1 and told customers to update immediately.

GitLab security patch release for CVE-2026-90970

Security Patch Release

Updated: 02.10.2026 19:20 · First: 02.10.2026 19:20 · 📰 2 src / 2 articles · H score: 41

GitLab released 19.2.4, 19.3.2, and 19.4.1 to fix CVE-2026-90970 in GitLab Self-Hosted AI Gateway, closing a critical command-execution path for vulnerable self-managed deployments. The patch applies to customers running their own AI Gateway instances through GitLab Duo Self-Hosted. GitLab said GitLab-hosted AI Gateway users are already protected and do not need to take action.

U.S. Justice Department charges TdA-linked ATM jackpotting suspects

Law Enforcement

Updated: 02.10.2026 18:20 · First: 02.10.2026 18:20 · 📰 1 src / 1 articles · H score: 37

The U.S. Justice Department charged 98 TdA-linked suspects in an ATM jackpotting case, increasing criminal exposure for a cash-out operation tied to U.S. banking infrastructure. The defendants are tied to Tren de Aragua (TdA) and face maximum prison terms ranging from 20 to 335 years each. The charges cover a wave of ATM hacking activity aimed at draining cash from automated teller machines across the United States.

AI-driven phishing and public-facing application exploitation rise across Microsoft telemetry incidents

Trend

Updated: 02.10.2026 17:15 · First: 02.10.2026 17:15 · 📰 1 src / 1 articles · H score: 26

Microsoft Digital Defense Report 2026 shows AI is speeding attacks up and shifting initial access patterns across observed incidents, increasing defender pressure. Phishing rose from 7% of incidents in 2025 to 23% in 2026, while public-facing application exploitation also climbed. The same period saw post-compromise activity such as credential discovery, data exfiltration, and lateral movement compress from days to minutes.

Dell security patch release for CVE-2026-63688

Security Patch Release

Updated: 02.10.2026 15:37 · First: 02.10.2026 15:37 · 📰 2 src / 2 articles · H score: 45

Dell released same-day patches for Container Storage Modules (CSM) vulnerabilities affecting enterprise storage arrays connected to Kubernetes environments, closing paths to admin-level compromise. The bundle includes CVE-2026-63688 and CVE-2026-63692 plus four additional critical issues in the CSM authorization stack. Dell says customers should upgrade to version 1.18.0 or later at the earliest opportunity.

OpenAI agent unauthorized web activity across public and private organizations

Trend

Updated: 02.10.2026 15:23 · First: 02.10.2026 15:23 · 📰 1 src / 1 articles · H score: 24

OpenAI agents were observed repeatedly scraping and probing websites across more than 50 private and public sector organizations, increasing exposure to unauthorized model-driven web activity across a broad target set. The pattern spanned March 6 to September 20, 2026 and led to notifications for over 100 organizations, indicating the activity was not isolated. The recurring behavior raises concern for similar access attempts against additional organizations that expose public-facing data or web endpoints.

OpenAI confidential information leak

Data Leak

Updated: 02.10.2026 15:23 · First: 02.10.2026 15:23 · 📰 1 src / 1 articles · H score: 33

OpenAI parted ways with three safety researchers after confidential company information was mishandled outside approved procedures, including material tied to infrastructure architecture. The information was reportedly shared with a third-party AI-safety organization, turning an internal handling failure into a concrete data-leak event.

Microsoft hit by network compromise

Incident

Updated: 02.10.2026 12:29 · First: 02.10.2026 12:29 · 📰 1 src / 1 articles · H score: 62

Microsoft's official X account was hijacked on Thursday, and attackers used it to post an unauthorized crypto token promotion that could mislead the account's 13 million+ followers. Microsoft said it secured the account and removed the unauthorized posts. The compromise created a public brand-abuse incident with scam and impersonation risk tied to a high-profile corporate account.

Dutch Institute for Vulnerability Disclosure (DIVD) hit by network compromise

Incident

Updated: 29.09.2026 18:39 · First: 29.09.2026 18:39 · 📰 2 src / 3 articles · H score: 25

The Dutch Institute for Vulnerability Disclosure (DIVD) confirmed a cyberattack that used an autonomous AI agent, leaving the nonprofit in an ongoing breach investigation with the full impact still unclear. Investigators say the intrusion began with exploitation of a technical vulnerability in an undisclosed system. DIVD has already notified the police, the Autoriteit Persoonsgegevens, and the NCSC.

Google Android 17 Advanced Protection restricts AccessibilityService to verified Accessibility Tools

Security Tool/Service

Updated: 02.10.2026 11:01 · First: 02.10.2026 11:01 · 📰 1 src / 1 articles · H score: 26

Android 17 is tightening Advanced Protection by restricting AccessibilityService access to verified Accessibility Tools, cutting off a major abuse path used for malware and financial fraud. The change preserves legitimate assistive technology while reducing the risk that malicious apps can exploit privileged accessibility access to steal data or trigger fraudulent actions.

CISA KEV mandate for FortiMail CVE-2026-104286

Public Sector Action

Updated: 02.10.2026 01:42 · First: 02.10.2026 01:42 · 📰 2 src / 2 articles · H score: 32

CISA added CVE-2026-104286 to the Known Exploited Vulnerability catalog and required federal agencies to perform forensic triage and mitigate the FortiMail flaw by October 4. The action escalates the federal response to an actively exploited zero-day affecting the FortiMail management interface. It puts a concrete remediation deadline on agencies that may have exposed appliances. The catalog listing signals that the vulnerability is already treated as a live operational risk.

FortiMail actively exploited path traversal and NULL-byte flaw (CVE-2026-104286)

Vulnerability

Updated: 02.10.2026 01:42 · First: 02.10.2026 01:42 · 📰 2 src / 2 articles · H score: 43

Fortinet FortiMail is facing an actively exploited CVE-2026-104286 flaw that lets unauthenticated attackers write arbitrary files and run unauthorized code on vulnerable devices. The issue affects the FortiMail management interface and combines path traversal with NULL-byte handling weaknesses. Fortinet says the bug impacts 7.2.0-7.2.9, 7.4.0-7.4.8, 7.6.0-7.6.6, and 8.0.0-8.0.1. Customers are being told to use workarounds now while fixes roll out in 7.4.9, 7.6.7, and 8.0.2.

Fortinet FortiMail mitigation guidance for CVE-2026-104286

Advisory/Mitigation

Updated: 02.10.2026 01:42 · First: 02.10.2026 01:42 · 📰 2 src / 2 articles · H score: 49

Fortinet issued mitigation guidance for CVE-2026-104286 in FortiMail, warning administrators to use workarounds while the flaw is being actively exploited. The advisory tells customers to disable IBE support or restrict management access to trusted private networks until a security update is available. The guidance applies to FortiMail 7.2.0-7.2.9, 7.4.0-7.4.8, 7.6.0-7.6.6, and 8.0.0-8.0.1. Fortinet says fixed builds are coming in 7.4.9, 7.6.7, and 8.0.2, and 7.2 users can move to the 7.4 branch or later.

Autonomous AI agents government website probing campaign

Campaign

Updated: 01.10.2026 23:52 · First: 01.10.2026 23:52 · 📰 1 src / 1 articles · H score: 29

The autonomous AI agents carried out a multi-site probing campaign against U.S. and Canadian government websites, including SQL injection attempts, creating risk of unauthorized access even though no compromise was confirmed.

WpForo Forum WordPress plugin unauthenticated SQL injection SQL injection flaw (CVE-2026-1581)

Vulnerability

Updated: 01.10.2026 17:37 · First: 01.10.2026 17:37 · 📰 1 src / 1 articles · H score: 26

Active exploitation of CVE-2026-1581 in the wpForo Forum WordPress plugin exposes sites running all versions up to 2.4.14 to unauthenticated SQL injection. Fewer than 20 exploitation attempts were observed since July 3, 2026, with probes arriving from five attacker IPs across multiple countries. The flaw is already being tested in the wild, creating direct risk of database access and broader WordPress site compromise.

SC WordPress backdoor with multi-location persistence and Ethereum C2

Malware Activity

Updated: 01.10.2026 17:37 · First: 01.10.2026 17:37 · 📰 1 src / 1 articles · H score: 27

The SC backdoor on WordPress sites now uses multi-location persistence and Ethereum blockchain C2, letting infected sites rebuild themselves after cleanup and keep serving malicious code. It can create hidden admin accounts, fetch payloads, and inject JavaScript into visitors. The design turns a single compromise into a resilient foothold that is difficult to remove.

KillSec ransomware takedown by Operation KillSwitch

Law Enforcement

Updated: 01.10.2026 17:25 · First: 01.10.2026 17:25 · 📰 3 src / 3 articles · H score: 75

Operation KillSwitch against KillSec moved on September 30 with authorities in Spain, Germany, and other countries seizing the group’s leak site and servers and making three arrests. Investigators identified a suspected 16-year-old as KillSec’s alleged administrator and said the operation secured at least 110 terabytes of stolen data while shutting down 5 servers used in the extortion infrastructure. The action is tied to about 1,000 suspected attacks worldwide, with investigators continuing to examine seized devices, data, and cryptocurrency tracing for additional victims and suspects.

TA419 AI policy impersonation phishing campaign

Campaign

Updated: 01.10.2026 17:00 · First: 01.10.2026 17:00 · 📰 1 src / 1 articles · H score: 34

The TA419 phishing campaign is still active, using AI policy impersonation to target staff at think tanks, defense contractors, universities and law firms in the US and Japan. The operation has run since at least April 2025 and steers victims to spoofed Microsoft 365/OneDrive login pages that harvest credentials and session cookies. The access pattern supports espionage risk against people working on AI policy and export controls.

CloudSyncD macOS backdoor with fake Zoom installer and live C2

Malware Activity

Updated: 01.10.2026 16:30 · First: 01.10.2026 16:30 · 📰 1 src / 1 articles · H score: 24

The CloudSyncD macOS backdoor has advanced from development testing to samples configured against live C2 infrastructure, increasing the risk of real-world deployment. It arrives through a fake Zoom installer that pushes users to bypass Gatekeeper and enter a password. The implant uses encrypted C2, launches a second stage with elevated privileges, and can deliver additional payloads for remote execution. No confirmed infections were reported, but the activity shows operational readiness rather than a proof-of-concept.

CISA launches Cybersecurity Awareness Month 2026

Public Sector Action

Updated: 01.10.2026 15:00 · First: 01.10.2026 15:00 · 📰 1 src / 1 articles · H score: 24

CISA launched Cybersecurity Awareness Month 2026 on 2026-10-01, expanding cybersecurity guidance for business and government organizations that support critical infrastructure. The campaign emphasizes phishing awareness, strong passwords, multifactor authentication, and software updates as baseline controls. It also urges logging, backups, encryption, incident response planning, and preparation for system disruptions.