07 Oct, 2026

Google halts open-source bug bounty program amid AI spam surge

Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports. The company’s OSS VRP incentivizes security researchers to responsibly disclose security flaws across open-source projects maintained by Google, including Golang, Angular, Bazel, Protocol Buffers, Fuchsia, and critical third-party dependencies, as well as repository settings […]

3 mins read

Citrix patches NetScaler SAML zero-day exploited in attacks

Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution. The vulnerability is a memory buffer flaw affecting NetScaler ADC and NetScaler Gateway appliances using SAML authentication with Gateway or AAA […]

5 mins read

Anthropic asks Claude users to share voice data for AI model training

Anthropic has started asking Claude users to voluntarily share their voice conversations to help train and improve its AI models. The new prompt appears when using Claude’s voice features and explicitly asks users to allow Anthropic to use their voice data for AI training. “Allow us to use your voice data to improve our AI […]

1 min read

Google Gemini could soon get full access to your Mac’s files, apps and the web

Google’s Gemini could soon access any file on your macOS device, open apps, browse the web, and perform actions without asking for permission every time. As spotted by TestingCatalog on X, Google is testing desktop control for Gemini, and there are references to a new hidden “Additional sandbox options” setting in the Gemini Desktop app. […]

2 mins read

ShinyHunters hacker reportedly detained in Jordan, aiding FBI

A suspected ShinyHunters hacking group member known online as “Rey” has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members of the extortion group. According to Reuters, Jordanian authorities detained Rey, identified as Saif al-Din Khader, this week, with two sources saying he was taken into custody on […]

6 mins read

Danish university DTU breach exposes data of up to 200,000 people

The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data. ​The university says the attacker used compromised credentials to log into DTUBasen, its identity and access management (IAM) system, allowing access […]

3 mins read

Frontline Education breach exposes school district employee data

Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers. Frontline Education is an edtech company that provides administration and workforce management software and services used by school districts. Last night, a […]

2 mins read

Warlock ransomware breach SharePoint in water, telecom operator attacks

The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access. ​Over the past two months, the threat actor appears to have focused on countries speaking Portuguese and Spanish across Europe, Africa, and Latin America. The gang emerged in […]

3 mins read

GitLab warns of critical RCE vulnerability in AI Gateway service

GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances. AI Gateway is a service that gives access to AI-native GitLab Duo features. While GitLab operates its own cloud-based AI Gateway instance used by GitLab.com, GitLab Self-Managed, and GitLab Dedicated, users can also […]

2 mins read

US sanctions Tren de Aragua gang members in ATM hacks crackdown

The U.S. Treasury Department has sanctioned eight members of the Venezuelan gang Tren de Aragua (TdA) for their role in the theft of millions of dollars in ATM jackpotting attacks across the United States. In jackpotting attacks, criminals deploy malware (e.g., ATMii, ATMitch, GreenDispenser, Alice, RIPPER, Skimer, SUCEFUL, and Ploutus) on bank and credit union […]

2 mins read