Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 20:05 06/10/2026 UTC
Last updated: 16:35 06/10/2026 UTC

Latest updates

Browse →

Samsung Galaxy S26 zero-day exploitation security flaw

Vulnerability

Updated: 06.10.2026 22:21 · First: 06.10.2026 22:21 · 📰 1 src / 1 articles · H score: 24

Researchers twice compromised the Samsung Galaxy S26 on the first day of Pwn2Own Ireland 2026, showing active zero-day exposure on a flagship mobile target. The opening-day demos were part of a broader tally of 32 zero-days exploited in the contest. The competition gives vendors 90 days to ship updates before public disclosure.

Atlassian Data Center products path traversal (CVE-2026-21589)

Vulnerability

Updated: 06.10.2026 09:58 · First: 06.10.2026 09:58 · 📰 2 src / 2 articles · H score: 32

Atlassian disclosed CVE-2026-21589, a path traversal vulnerability in 8 self-hosted Data Center products that can let a no-login attacker read specific files in each product's web application root directory. Atlassian published fixed versions for the affected products and said cloud customers do not need to take action. The advisory also recommends temporary network-blocking mitigations until systems are upgraded.

Fake AI login phishing campaign targeting ad account managers

Campaign

Updated: 06.10.2026 18:16 · First: 06.10.2026 18:16 · 📰 2 src / 2 articles · H score: 36

A phishing campaign is using fake ChatGPT, Gemini, Claude, Perplexity, and Meta Muse ad portals to steal credentials and MFA codes from ad account managers, agency staff, media buyers, and administrators. The pages use the browser-in-the-browser (BitB) trick to imitate sign-in windows, including fake accounts.google.com and Okta flows, while a human operator can request passwords, SMS or authenticator codes, push approvals, Google prompts, or QR-code scans. Researchers said the broader operation also uses fake recruitment and refund lures, shared Next.js and Socket.IO infrastructure, and exposed earlier source code through misconfigured public GitHub repositories. The same cluster appears to move with product launches and has already produced hundreds of victim submissions in a Telegram control channel.

ClickFix compromised-website browser-cache campaign

Campaign

Updated: 06.10.2026 18:00 · First: 06.10.2026 18:00 · 📰 1 src / 1 articles · H score: 35

The ClickFix campaign is using compromised websites to pre-stage a VBScript payload in the browser cache, pushing visitors into running attacker code through Windows Run and increasing the risk of credential theft. Microsoft Threat Intelligence observed the activity on October 3, 2026 and said a fake CAPTCHA prompt was used to make users paste and execute a command. The chain avoids a fresh download at execution time by launching a file that is already on disk. That blend of social engineering and local staging makes the payload harder to detect and expands the chance of follow-on access.

Healthcare PQC readiness gap across IoMT and OT devices

Trend

Updated: 06.10.2026 15:20 · First: 06.10.2026 15:20 · 📰 1 src / 1 articles · H score: 21

A large healthcare device assessment found that most IoMT and medical OT systems cannot transition to post-quantum cryptography (PQC), increasing the risk of future harvest-now, decrypt-later attacks on patient data.

LibreOffice malicious spreadsheet code execution security flaw (CVE-2026-63277)

Vulnerability

Updated: 06.10.2026 14:57 · First: 06.10.2026 14:57 · 📰 1 src / 1 articles · H score: 29

LibreOffice fixed CVE-2026-63277, a flaw that lets a malicious spreadsheet trigger code execution when opened with Java support enabled. The affected scope covers versions before 26.2.5 or 26.8.0, and the vendor has already released updates. A published proof of concept shows the weakness can execute attacker-controlled Java code without the normal macro warning.

ASOS hit by network compromise

Incident

Updated: 06.10.2026 14:41 · First: 06.10.2026 14:41 · 📰 2 src / 2 articles · H score: 10

ASOS faced a suspected unauthorized-access incident after attackers sent a push notification to customers, raising the risk of potential customer data exposure across connected systems. The compromise was not confirmed by ASOS at publication, but the notification suggested some access may have been obtained through a Snowflake-related path. The message was treated as a possible extortion attempt aimed at pressuring ASOS over the scope of the breach claim. Customers were advised to avoid the link and reset passwords while investigators checked logs and exposure.

Wikimedia Foundation hit by network compromise

Incident

Updated: 06.10.2026 14:26 · First: 06.10.2026 14:26 · 📰 1 src / 1 articles · H score: 17

The Wikimedia Foundation confirmed an unauthorized bot incident against Wikimedia wikis and Etherpad, with edits, attempted tool exploitation, and heavy traffic disrupting platform integrity. The activity included sandbox wiki edits, efforts to misuse a citation tool and Etherpad as proxies for remote data retrieval, and a flood of automated API and query requests. Wikimedia said the activity may have contributed to a partial outage in early May 2026 and found no evidence of system or data compromise.

Wikimedia public APIs partial outage from automated traffic

Service Disruption

Updated: 06.10.2026 14:26 · First: 06.10.2026 14:26 · 📰 1 src / 1 articles · H score: 1

The Wikimedia Foundation's public APIs and Wikidata Query Service (WQDS) experienced a partial outage after millions of automated requests. The traffic hit Wikimedia services in early May 2026 and raised availability risk for users and editors. Wikimedia said it found no evidence of compromise from the activity.

Nikkei Google Workspace account personal-information exposure

Data Leak

Updated: 06.10.2026 12:25 · First: 06.10.2026 12:25 · 📰 1 src / 1 articles · H score: 46

Nikkei disclosed a Google Workspace account exposure that may have revealed names and email addresses for 1,646 people, creating privacy risk for employees and business partners. The account was accessed in late July and the exposure was disclosed in early August after a notification from Google. Nikkei said the affected data did not include information about readers or interviewees.

Nikkei hit by network compromise

Incident

Updated: 06.10.2026 12:25 · First: 06.10.2026 12:25 · 📰 2 src / 2 articles · H score: 48

Nikkei disclosed a compromise of two employee email accounts that let attackers send thousands of phishing emails from trusted inboxes. One Google Workspace account was accessed in late July, exposing employee and business-partner contact information and possibly the names and email addresses of 1,646 individuals. A second Microsoft 365 account was used in September to send 9,000 phishing emails to staff and interviewees, including messages with links to malicious websites on September 30. Nikkei says it reset passwords, contacted recipients, and has not confirmed additional unauthorized logins.

UK Report Fraud passkeys awareness campaign

Public Sector Action

Updated: 06.10.2026 12:15 · First: 06.10.2026 12:15 · 📰 1 src / 1 articles · H score: 27

UK’s Report Fraud service launched a new public awareness campaign urging users to adopt passkeys, responding to a sharp rise in account-takeover fraud and stolen funds. The campaign matters because it pushes a more phishing-resistant login method to reduce losses tied to email and social media hacking. It also aligns with broader public messaging from the NCSC on improving account protection.

Medical-imaging company hit by data theft breach

Incident

Updated: 06.10.2026 11:30 · First: 06.10.2026 11:30 · 📰 1 src / 1 articles · H score: 67

A medical-imaging company suffered a weeks-long intrusion after an attacker exploited an SSRF vulnerability in an unauthenticated AI medical-imaging API, resulting in 6TB of data being compromised. The intruder used the access to find internal services and hunt for credentials to internal data stores. The event reflects a sustained, multi-stage compromise rather than a brief probe, raising the risk of data theft and follow-on abuse.

Azazel-managed exposed servers holding stolen victim data

Data Leak

Updated: 06.10.2026 11:30 · First: 06.10.2026 11:30 · 📰 1 src / 1 articles · H score: 68

The exposure of two servers managed by Azazel left several terabytes of stolen victim data at risk of publication, spanning six countries and multiple sectors. The servers held material taken from logistics, insurance, pharmaceutical, AI, medical device, and government victims. Azazel also operated an independent leak site, Leakned, to publish victim data and keep extortion proceeds outside the ransomware program.

Azazel's Leakned breakaway from The Gentlemen RaaS

Threat Actor Meta

Updated: 06.10.2026 11:30 · First: 06.10.2026 11:30 · 📰 1 src / 1 articles · H score: 82

Azazel broke away from The Gentlemen RaaS by running Leakned independently and keeping extortion proceeds, undermining the group's affiliate monetization model. The breakaway activity affected over two dozen victims across six countries and shifted victim publication control outside the parent program. The victim set included logistics, insurance, pharmaceutical, AI, medical device, and government organizations. The move shows how a ransomware affiliate can turn a standard revenue-sharing arrangement into a direct extortion business.

FBI employee and applicant data leak claim

Data Leak

Updated: 22.09.2026 22:13 · First: 22.09.2026 22:13 · 📰 5 src / 8 articles · H score: 95

ShinyHunters publicly claimed it breached FBI jobs systems through an Oracle PeopleSoft flaw, stole 2TB to 3TB of data, and exposed information tied to FBI employees and job applicants from services including Criminal Justice (CJ), HR, and Medlink. The FBI said it is investigating the unauthorized-activity claims affecting FBIjobs.gov, and the access and leak claims remain unverified in the supplied context. Later reporting said Mandiant and the Google Threat Intelligence Group (GTIG) confirmed mass exploitation of CVE-2026-35273 in Oracle PeopleSoft across dozens of systems in higher education, technology, healthcare, agriculture, transportation, and government. The same exploit thread was linked to a URL-encoding bypass against WAF rules and to renewed abuse of unpatched PeopleSoft servers.

ClickFix fake CAPTCHA and browser-update campaign

Campaign

Updated: 06.10.2026 08:22 · First: 06.10.2026 08:22 · 📰 1 src / 1 articles · H score: 47

The ClickFix campaign has become a scalable social-engineering operation that uses compromised websites, phishing kits, and malvertising to push victims into running attacker commands. The lure set has broadened to include fake CAPTCHA, browser-update, and other troubleshooting prompts that make the command look routine. The expanding infrastructure and reusable lure kits increase the campaign’s reach and make it harder to block using old indicators.

Rejetto HFS session forgery RCE (CVE-2026-61500)

Vulnerability

Updated: 05.10.2026 11:09 · First: 05.10.2026 11:09 · 📰 2 src / 2 articles · H score: 46

CVE-2026-61500 in Rejetto HTTP File Server (HFS) exposes 3.0.0 through 3.2.0 to session forgery, letting attackers recover a signing key from Math.random() and seize administrator access. A public Python PoC appeared in late September 2026, and VulnCheck later reported active exploitation attempts. The flaw can escalate to remote code execution through the server_code configuration feature. A fix is available in HFS 3.2.1.

Italy's Data Protection Authority (GPDP) €7 million fine and compliance order within 120 days on remediate health-data processing and anonymization failures

Regulatory/Legal Action

Updated: 05.10.2026 20:19 · First: 05.10.2026 20:19 · 📰 1 src / 1 articles · H score: 21

Italy's GPDP fined IQVIA and ordered compliance after finding GDPR violations in health-data processing that could expose and de-anonymize roughly one million patients. The authority said the company's Italian division used detailed records and unique codes that made reidentification possible over time. It also said the processing lacked an adequate legal basis and patient notice, with a 120-day deadline to fix the practices.

Microsoft Exchange Server weak authorization privilege escalation (CVE-2026-96940)

Vulnerability

Updated: 05.10.2026 19:21 · First: 05.10.2026 19:21 · 📰 1 src / 1 articles · H score: 29

A weak authorization flaw in Microsoft Exchange Server (CVE-2026-96940) lets an authenticated attacker elevate privileges and read other users' mailboxes within the same organization. Microsoft rated the issue 8.8 CVSS and released out-of-band security updates. The flaw affects on-premises Exchange Server deployments, while Exchange Online already has a service-side fix.

Denmark Central Population Register data breach exposing 8.8 million records

Data Leak

Updated: 05.10.2026 18:21 · First: 05.10.2026 18:21 · 📰 2 src / 2 articles · H score: 65

Denmark's Central Population Register (CPR) disclosed a data breach that exposed personal records for about 8.8 million registered people. The exposed data included names, physical addresses, dates of birth, marital status, and unique CPR numbers. The access abuse involved a private Danish company and brute-forcing CPR numbers to pull matching records. The breach happened in September 2026, was recognized on October 2, and the registry has since blocked the access while police investigate.

ClingSTUN Linux proxy backdoor abusing IoT devices

Malware Activity

Updated: 05.10.2026 17:30 · First: 05.10.2026 17:30 · 📰 1 src / 1 articles · H score: 31

The ClingSTUN Linux proxy backdoor is turning unpatched internet-facing IoT devices into remotely controlled proxy nodes, expanding covert infrastructure for abuse. The malware was tracked across three periods with different download servers and an expanding set of entry points. Its earliest observed wave relied on CVE-2022-36553 in Hytec Inter routers. Later activity added more flaws and used public STUN servers to keep infected systems reachable.

Cling botnet with STUN-based C2 and persistence

Malware Activity

Updated: 05.10.2026 14:46 · First: 05.10.2026 14:46 · 📰 2 src / 2 articles · H score: 34

The Cling malware activity now includes STUN-based back-connect proxying that uses public STUN servers to keep infected systems reachable as remotely controlled proxy nodes. FortiGuard Labs said the campaign, published October 5, progressed through multiple waves of exploitation against internet-facing IoT devices, including CVE-2022-36553, CVE-2025-34035, and CVE-2024-23625, before expanding to a list of 24 vulnerabilities in the third period. The malware also copies itself, modifies boot scripts for persistence, hides behind process information from init, and supports remote command execution. FortiGuard further noted that the STUN traffic can resemble normal VoIP and WebRTC activity, making the proxy nodes harder to spot.

Shinhan Bank hit by cyberattack

Incident

Updated: 05.10.2026 17:22 · First: 05.10.2026 17:22 · 📰 1 src / 1 articles · H score: 40

A confirmed data breach at Shinhan Bank and related cyber incidents at KB Kookmin Bank and Hana Bank exposed risk across South Korea's banking sector. Authorities launched on-site investigations and coordinated incident information with KISA after receiving reports. Local reporting said Shinhan may have leaked details on 25,000 customers, while Kookmin may have exposed credit card information for 119,000 clients. The response now centers on containment, customer protection, and tighter checks on externally accessible systems.

BPFDoor, BPF Rekoobe, and AVERAT Linux backdoor activity against telecom and network-edge appliances

Malware Activity

Updated: 05.10.2026 17:00 · First: 05.10.2026 17:00 · 📰 2 src / 2 articles · H score: 23

Rapid7 identified BPFDoor, BPF Rekoobe, and AVERAT Linux backdoors targeting telecom and network-edge appliances in South Korea and Taiwan. The activity disguises traffic as SMTP on TCP port 25 and impersonates legitimate services such as SpamSniper and ShareTech to reduce detection. AVERAT uses a dropper, checks in every 600 to 699 seconds, and supports file transfer, shell sessions, and proxy/port-forwarding channels. The broader set of samples shows continued adaptation after prior public disclosures, including process-name spoofing and trigger delivery wrapped in HTTPS POST requests.

Tenfold Community Edition adds shared-content governance and event auditing for small organizations

Security Tool/Service

Updated: 05.10.2026 16:33 · First: 05.10.2026 16:33 · 📰 1 src / 1 articles · H score: 11

tenfold Community Edition added shared content governance and event auditing, giving organizations under 150 users stronger visibility into Microsoft 365 access and identity activity. The update brings access reviews for shared files and helps teams catch oversharing, stale access, login spikes, and new admin accounts earlier. The free tier now carries more of the controls normally needed to monitor and reduce identity risk.

Citrix security patch release for CVE-2026-88779

Security Patch Release

Updated: 05.10.2026 00:58 · First: 05.10.2026 00:58 · 📰 3 src / 3 articles · H score: 46

Citrix released emergency NetScaler updates for CVE-2026-88779, closing an actively exploited flaw across NetScaler ADC, NetScaler Gateway, and affected FIPS deployments. The vendor shipped 14.1-73.41 and 13.1-64.28, and told customers to install the updates immediately. Global Deny Lists were also provided as a supplementary block list for known malicious IPs.

NetScaler ADC and NetScaler Gateway memory buffer flaw (CVE-2026-88779, actively exploited)

Vulnerability

Updated: 05.10.2026 00:58 · First: 05.10.2026 00:58 · 📰 3 src / 3 articles · H score: 36

Citrix disclosed CVE-2026-88779, a memory buffer flaw in NetScaler ADC and NetScaler Gateway that is being used in zero-day attacks. The issue affects SAML authentication paths and can cause denial of service on unmitigated deployments. Citrix said researchers are also investigating whether the flaw can be pushed to remote code execution. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog.

US Senate passes Health Care Cybersecurity and Resilience Act

Public Sector Action

Updated: 05.10.2026 13:42 · First: 05.10.2026 13:42 · 📰 1 src / 1 articles · H score: 69

The US Senate passed the bipartisan Health Care Cybersecurity and Resilience Act, moving the healthcare cybersecurity bill to the US House. The measure would create a federal resilience framework for healthcare institutions with grants, training, and tighter HHS/CISA coordination. It also aims to strengthen defenses for rural providers and require a cybersecurity incident response plan. The action targets a sector facing repeated ransomware and breach pressure.

Apple macOS Full Disk Access access-control tightening

Advisory/Mitigation

Updated: 05.10.2026 13:38 · First: 05.10.2026 13:38 · 📰 1 src / 1 articles · H score: 20

Apple is tightening Full Disk Access in macOS, requiring an explicit user action before apps can gain broad access to files, mail, messages, browsing history, and other private data. The mitigation reduces the risk that AI agents or other apps can quietly bypass privacy protections and read or write sensitive system content. Apple said the change is meant to make users clearly understand the risk before granting that level of access, and the rollout date is still unknown.