New Spectre v2 attack variant leaks Linux root password hash in minutes
A new Spectre v2 attack variant called Branch Target Reuse (BTR) can recover root password hashes from Intel computers running Linux in just a few minutes. A BTR attack exploits stale information in a processor’s branch predictor after a just-in-time (JIT) engine reuses memory for new code. By manipulating this leftover information, an attacker can […]
Automated AI agent used to breach cybersecurity nonprofit DIVD
The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyberattack that the organization described as “loud and very, very messy.” Evidence uncovered during the ongoing investigation indicates the attacker exploited a vulnerability, but the attack’s purpose and impact remain unclear at this stage. DIVD is a nonprofit organization of volunteer security researchers that scans […]
Vietnamese man charged in $16 million ‘pig butchering’ crypto scam
A Vietnamese national was charged with money laundering for his role in a massive “pig butchering” scam, which defrauded a victim out of $16 million worth of cryptocurrency. 37-year-old Trung Nguyen Van entered the United States through the San Ysidro, California / Mexico pedestrian border entry point on September 22 and was arrested before boarding […]
Kiteworks patches critical flaw, brings customer systems online
American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability. Formerly known as Accellion, it operates a Private Content Network (PCN) that integrates enterprise email, file sharing, Managed File Transfer (MFT), APIs, and web forms into a single platform. Kiteworks provides services to thousands of […]
Apple patches CoreGraphics zero-day flaw exploited in attacks
Apple released security updates to fix a zero-day vulnerability exploited in “extremely sophisticated” targeted attacks on iOS devices. Tracked as CVE-2026-86950, this flaw stems from an out-of-bounds write weakness discovered by Meta Product Security in CoreGraphics, a framework used for two-dimensional vector graphics, image rendering, and text drawing across iOS, macOS, iPadOS, watchOS, and tvOS. […]
Japan’s Keio confirms ransomware attack disrupted business systems
Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems. Following a system failure in the early hours of Saturday, the company confirmed the attack and shut down its network to prevent additional damage. The company said […]
Times Car confirms data breach affecting 6.6 million user accounts
Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. The company announced the incident on September 25, saying that a third party had accessed its systems at the beginning of the month. Times Car took action to block the unauthorized access on […]
Dutch police confirm arrest in ShinyHunters hacking investigation
Dutch police have confirmed that a 24-year-old Amsterdam man arrested earlier this month was detained as part of an investigation into the ShinyHunters hacking group. “It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters,” the Politie Landelijke Opsporing en Interventies said Monday. Police […]
Over 16,000 Supabase databases expose PII, passwords, auth tokens
Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens. Based on the analysis of table schemas, researchers at cyber risk management company UpGuard believe that a very small set of the exposed information includes credit card data. Supabase is an open-source development platform built around […]
JadePuffer agentic AI attacks target Azure, destroy cloud resources
The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components. The malware emerged in July, with researchers at cloud security company Sysdig highlighting that it uses AI agents to automate the entire attack chain, from reconnaissance, credential theft, and lateral movement to persistence and data […]