general
20 articles
Ransomware remediation company owner charged with defrauding victims
Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between What Your Developers Declare and What’s Actu...
Leaked chats show Russian extortion gang sending ‘agents’ into US law firms
In leaked chats, members track dozens of victims, haggle over multimillion-dollar payments and direct operatives based in the United States whom they call “a...
Security Awareness Training Isn’t Dead, but It Needs a Rethink
All enterprises conduct security awareness training for their employees. But whether this has tangible benefits is debatable.
Attackers Hijack Three ccTLDs to Obtain Google Certificates
Attackers compromised .gh, .
ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms
Cybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence (A...
Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication
Threat actors have started targeting CVE-2026-21589, a critical vulnerability in Atlassian’s self-hosted Data Center products. The post Attackers Target Crit...
OAuth grants pile up faster than you can review them. Here's how to keep up.
OAuth grants create data highways between SaaS apps, AI agents, and other tools. And, they are multiplying faster than any security team can review them.
Hackers target two South Korean megachurches, potentially exposing congregant data
Two of South Korea's largest Protestant churches are investigating cyberattacks that may have exposed sensitive information about hundreds of thousands of me...
MonsterCloud Owner Charged With Secretly Paying Ransomware Demands
MonsterCloud owner Zohar Pinhasi allegedly paid ransomware demands behind clients’ backs, then charged them millions for the supposed recovery. Zohar Pinhasi...
ASOS Confirms Data Breach Linked to Stolen Employee Credentials
The ASOS hack comes from the compromise of agentic marketing platform Simon AI, said the attackers
Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware
A threat actor published a malicious version of the tensorlake npm package on October 8, 2026, embedding a new variant of the self-replicating Shai-Hulud sup...
Uranium crypto exchange hacker convicted for stealing $53 million
A Maryland man was found guilty of stealing more than $53 million after hacking the decentralized crypto exchange Uranium Finance twice in April 2021. [.
PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that can expose active users’ session cookies and ...
Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process deployments by exploiting unsa...
Russia-Aligned UAC-0099 Evolves MATCHBOIL Malware
Russia-aligned UAC-0099 has steadily upgraded its MATCHBOIL downloader since 2024
Thousands of cheap Android phones shipped with ad-fraud malware
"It’s on the phone before the owner switches it on for the first time, and it can’t be uninstalled," researchers at Bitdefender said about ad fraud malware f...
Authorities seize sites selling hacked, stolen intimate images of 17,000 women and girls
The FBI and French law enforcement have seized two websites that sold hacked and stolen sexually explicit images and videos of young women and girls, and arr...
US Seeks Alleged Chinese Hafnium Hacker With $10 Million Reward
Zhang Yu was charged alongside Xu Zewei, who was extradited from Italy to the US in April 2026. The post US Seeks Alleged Chinese Hafnium Hacker With $10 Mil...