07 Oct, 2026

Custom ChatGPTs push ClickFix attacks to deploy RAT malware

Custom variants of OpenAI’s ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware. The threat actor is abusing the legitimate feature in the AI platform that lets users create a version of ChatGPT tailored for a specific task that combines instructions, extra knowledge, and […]

3 mins read

FBI tells ShinyHunters members to turn themselves in after recent arrest

The FBI is warning members of the ShinyHunters extortion group to turn themselves in after Dutch police arrested a man the bureau described as one of the group’s alleged leaders. “Today, our partners at the Dutch National Police announced the arrest of one of the alleged leaders of ShinyHunters, a group linked to cyberattacks in […]

4 mins read

Hackers exploit Citrix NetScaler zero-day to deploy web shells

Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks. Mandiant says the attacks began in at least early September and are believed to have impacted organizations in North America and Europe across the government, financial services, […]

7 mins read

Former US Air Force members sent to prison over BEC attacks

Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. According to court documents, 25-year-old Chijioke Timothy Odimegwu and 26-year-old Harafat Mogaji carried out these attacks while stationed at Dover […]

2 mins read

Windows 11 2026 Update released, here’s everything you need to know

Microsoft has started rolling out the Windows 11 2026 Update (26H2) to everyone, and while it’s this year’s big annual feature update, you probably won’t notice a massive difference after installing it. That’s because Windows 11 24H2, 25H2, and 26H2 are all based on the same servicing branch, and Microsoft has already been gradually shipping […]

2 mins read

New Spectre v2 attack variant leaks Linux root password hash in minutes

A new Spectre v2 attack variant called Branch Target Reuse (BTR) can recover root password hashes from Intel computers running Linux in just a few minutes. A BTR attack exploits stale information in a processor’s branch predictor after a just-in-time (JIT) engine reuses memory for new code. By manipulating this leftover information, an attacker can […]

4 mins read

Automated AI agent used to breach cybersecurity nonprofit DIVD

The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyberattack that the organization described as “loud and very, very messy.” Evidence uncovered during the ongoing investigation indicates the attacker exploited a vulnerability, but the attack’s purpose and impact remain unclear at this stage. DIVD is a nonprofit organization of volunteer security researchers that scans […]

2 mins read

Vietnamese man charged in $16 million ‘pig butchering’ crypto scam

A Vietnamese national was charged with money laundering for his role in a massive “pig butchering” scam, which defrauded a victim out of $16 million worth of cryptocurrency. 37-year-old Trung Nguyen Van entered the United States through the San Ysidro, California / Mexico pedestrian border entry point on September 22 and was arrested before boarding […]

2 mins read

Kiteworks patches critical flaw, brings customer systems online

American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability. Formerly known as Accellion, it operates a Private Content Network (PCN) that integrates enterprise email, file sharing, Managed File Transfer (MFT), APIs, and web forms into a single platform. Kiteworks provides services to thousands of […]

3 mins read

Apple patches CoreGraphics zero-day flaw exploited in attacks

Apple released security updates to fix a zero-day vulnerability exploited in “extremely sophisticated” targeted attacks on iOS devices. Tracked as CVE-2026-86950, this flaw stems from an out-of-bounds write weakness discovered by Meta Product Security in CoreGraphics, a framework used for two-dimensional vector graphics, image rendering, and text drawing across iOS, macOS, iPadOS, watchOS, and tvOS. […]

2 mins read