Skip to content
Live intelligence · last 7 days only

Recent cyber attacks, breaches and security alerts worldwide.

Current reporting from established cyber-security publications and official agencies. The default view shows the last 72 hours; switch to 24 hours or the full 7-day window when you need it.

Automated feedLast refresh 5 minutes ago60 headlines · 19 curated sources · max age 7 days
Freshness
60 matching headlines Only items published within the last 7 days are retained. CZITAPP links to the original publisher.
SANS Internet Storm CenterGlobal
Cyber security

ISC Stormcast For Thursday, October 8th, 2026 https://isc.sans.edu/podcastdetail/10128, (Thu, Oct 8th)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Unit 42Global
Vulnerability

Evolution of Web3 in Cloud Supply Chain Attacks

Unit 42 details how threat actors leverage Web3 infrastructure and open-source supply chain attacks to breach enterprise cloud environments The post Evolution of Web3…

Dark ReadingGlobal
Cyber attack / incident

Australian Gov't Weighs Mandatory AI Incident Reporting

In the wake of an agentic attack against its own Medicare systems, Australia's government is feeling out what regulations might look like for frontier…

Dark ReadingGlobal
Cyber security

Citizen Lab Slams Trump Administration, 'Techno-Fascist' Executives

The Citizen Lab's Ron Deibert warns the US government is pushing for pervasive surveillance and says certain technology executives are all too happy to…

Dark ReadingGlobal
AI security

Anthropic Gives Vetted Defenders Fewer Claude Guardrails

Anthropic has merged Project Glasswing into a tiered access program for its advanced cyber LLMs, including Opus, Sonnet, and Mythos.

The RecordGlobal
Data breach

US posts $10 million reward for accused Chinese ‘Hafnium’ hacker

U.S. officials say Zhang Yu was a prominent figure in the Hafnium campaign, which saw hackers breach thousands of computers and steal troves of…

CyberScoopUS
Data breach

Major rules for federal contractors handling sensitive data are nearing the finish line

The regulations on “controlled unclassified information” include security rules and requirements for reporting when they’re breached, including by cyberattacks. The post Major rules for…

Dark ReadingGlobal
AI security

OpenAI Agent Escape Causes Wikimedia Service Outage

Autonomous agents also tried to abuse other websites and services hosted by the foundation, using them as proxies for unauthorized activities.

Cisco TalosGlobal
Vulnerability

Microsoft, Adobe, Apple, and Foxit vulnerabilities

Cisco Talos’ Vulnerability Discovery & Research team recently disclosed vulnerabilities in Adobe, Apple, Foxit Reader, and Microsoft.The vulnerabilities mentioned in this blog post have…

The Hacker NewsGlobal
Data breach

Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains

Attackers compromised three country-code top-level domains (ccTLDs) and obtained unauthorized HTTPS certificates for several Google domains, Google said on October 6. Google's own systems were…

The RecordGlobal
Cyber security

$11 million plan for psychological support at Cyber Command gets fresh boost from lawmakers

Lawmakers who oversee military cyber policy as well as the Fort Meade, Maryland, hub for those agencies say an $11 million mental health program…

The RecordGlobal
Vulnerability

Arizona courts say hackers stole info on more than 1.3 million people

The investigation into the incident revealed cybercriminals were able to breach the Fines/Fees and Restitution Enforcement (FARE) Program, a statewide program that helps the…

Security AffairsGlobal
Vulnerability

SonicWall Fixes Max Severity Pre-Auth Flaw in SMA1000 Appliances

SonicWall patched a CVSS 10 pre-auth SSRF flaw in SMA1000 appliances that could let unauthenticated attackers reach internal functions. SonicWall released hotfixes for four…

The Hacker NewsGlobal
Cyber attack / incident

Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised…

CyberScoopUS
AI security

FBI, French authorities seize deepfake CSAM-for-sale websites 

Some of the material appeared to be recorded or stolen video of girls through interactions on social media sites like Snapchat, TikTok, Instagram and…

Read original ↗
The Hacker NewsGlobal
Vulnerability

SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications.…

Read original ↗
Microsoft Security BlogGlobal
Vulnerability

3 lessons from frontier AI vulnerability research

Read how How Microsoft Security's FORGE Lab is scaling vulnerability research from Windows to the Linux kernel. The post 3 lessons from frontier AI…

Read original ↗
The Hacker NewsGlobal
Vulnerability

Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on…

Read original ↗
The Hacker NewsGlobal
AI security

PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM)…

Read original ↗
CyberScoopUS
Cyber attack / incident

PoeLLM malware has assembled a sweeping botnet, taking technical cues from a poem

More than 3,400 servers have been compromised by malware that hides its infrastructure coordinates in a poem. The post PoeLLM malware has assembled a…

Read original ↗
The RecordGlobal
Cyber security

Oklahoma judge’s Flock ruling shows the power of Supreme Court’s digital evidence decision

How a recent Supreme Court decision on geofencing influenced a federal judge to toss a sheriff's Flock camera evidence in a drug trafficking case.

Read original ↗
SANS Internet Storm CenterGlobal
Vulnerability

Scans for Atlassian vulnerablity (CVE-2026-21589), (Wed, Oct 7th)

On October 5th, Atlassian published patches for multiple products to fix an "Arbitrary File Access" vulnerability [CVE-2026-21589]. An attacker can read arbitrary files in the…

Read original ↗
SecurityWeekGlobal
Data breach

Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts

Southern Company is notifying customers that their utility account information was accessed by hackers. The post Georgia Power, Alabama Power Data Breach Hits 400,000…

Read original ↗
The RecordGlobal
Critical infrastructure

Cyber experts call on CISA to create mandatory federal OT rules

The Operational Technology Cybersecurity Coalition released a white paper urging the CISA to create a new directive centered around operational technology, which is used…

Read original ↗
Security AffairsGlobal
Vulnerability

FortiBleed hit 86,000 firewalls by exploiting something nobody can patch away

FBI and Secret Service warn FortiBleed, a credential-harvesting campaign against Fortinet firewalls, has compromised 86,644 devices and is locking out admins. The FBI and…

Read original ↗
The RecordGlobal
Data breach

Senate passes healthcare cybersecurity bill after 190 million impacted by Change Healthcare breach

The Health Care Cybersecurity and Resiliency Act of 2026 was passed by unanimous consent last week, potentially expanding federal cyber requirements for healthcare organizations.

KrebsOnSecurityUS
Ransomware

ShinyHunters Extorted Boeing Spin-off Prior to Arrests

A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group ShinyHunters has been detained and is reportedly cooperating with…

Read original ↗
SecurityWeekGlobal
Ransomware

Qilin Ransomware Suspect Arrested in Japan, Extradited to Germany

The individual was detained in May and has been extradited to Germany to face hacking charges. The post Qilin Ransomware Suspect Arrested in Japan,…

Read original ↗
The RecordGlobal
Cyber attack / incident

Russian cyberattacks against UK are 'Putin Tax' costing $3.3 billion, says lawmaker

A report by a Labour MP and an academic argues that if the British public cannot see what Russian activity costs, it cannot weigh…

Security AffairsGlobal
Cyber attack / incident

CERT-UA: Fake Cloudflare Checks Deliver LunexStealer Malware

Over 100 hacked websites used fake Cloudflare checks to trick visitors into installing LunexStealer through ClickFix commands. The lure is the now-familiar ClickFix technique,…

Read original ↗
SecurityWeekGlobal
AI security

Hadrian Raises $40 Million to Expand Autonomous Offensive Security Platform

Hadrian offers an agentic offensive security platform that allows defenders to operate at the same speed as attackers. The post Hadrian Raises $40 Million…

Read original ↗
The RecordGlobal
Vulnerability

FBI, Secret Service add to warnings of FortiBleed credential stealing campaign

Users of two types of Fortinet hardware should take steps to limit their exposure to a now-global credential stealing campaign, U.S. federal law enforcement…

SecurityWeekGlobal
Ransomware

Advantest Discloses Data Breach Months After Ransomware Attack

The Japanese chip testing giant said hackers stole personal information from its servers in the February 2026 cyberattack. The post Advantest Discloses Data Breach…

Read original ↗
The Hacker NewsGlobal
AI security

The Sixth Voice of the CISO Data Shows Cyber Risk Has Moved Inside the Workflow

The 2026 findings are not just a year-over-year shift. They mark the latest point in a five-year arc where resilience, AI governance, human risk,…

Read original ↗
The Hacker NewsGlobal
Vulnerability

FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat…

Read original ↗
The Hacker NewsGlobal
Vulnerability

Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details

Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files…

Read original ↗
The Hacker NewsGlobal
Vulnerability

What Is Agentic Pentesting? What It Proves, and Where It Stops.

If you’re evaluating an agentic pentesting solution right now, you’ve probably heard the same pitch more than once: point it at a target, and…

Read original ↗
SecurityWeekGlobal
Vulnerability

Chrome 155 Update Patches 247 Vulnerabilities

Four critical-severity use-after-free defects were fixed in Chromecast, Browser, Navigation, and Track. The post Chrome 155 Update Patches 247 Vulnerabilities appeared first on SecurityWeek.

Read original ↗
SecurityWeekGlobal
AI security

Anthropic Introduces 3-Tier Cyber Verification Program for AI Access

Anthropic is integrating the CVP and Project Glasswing into a single offering, with three levels of access to its most capable AI models. The…

Read original ↗
Security AffairsGlobal
Vulnerability

Anthropic Creates Three Tiers for Claude Cyber Access

Anthropic created three access tiers for Claude’s offensive security use, matching cyber capabilities and safeguards to the user’s level of trust. Anthropic is trying…

Read original ↗
Cisco TalosGlobal
Data breach

One breach, please, and make no mistakes

The cybersecurity community has seen examples of autonomous agents, built inside AI labs, attacking public infrastructure. How you prepare for agentic threats is what…

Read original ↗
SecurityWeekGlobal
Data breach

ASOS Confirms Cyberattack, Data Breach

Hackers compromised a third-party communication platform and sent rogue notifications to ASOS users. The post ASOS Confirms Cyberattack, Data Breach appeared first on SecurityWeek.

Read original ↗
The Hacker NewsGlobal
Vulnerability

Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws

Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards…

Read original ↗
SecurityWeekGlobal
AI security

Wikimedia Says Rogue OpenAI Agents Tried to Turn Its Tools Into Proxies

Wikimedia looked into whether its own websites had seen activity like that disclosed by other organizations The post Wikimedia Says Rogue OpenAI Agents Tried…

Read original ↗
CERT-EUEU
Vulnerability

2026-015: Critical Vulnerability in Multiple Atlassian Products

On 5 October 2026, Atlassian published a security advisory addressing a critical arbitrary file access vulnerability. It affects Bitbucket Data Center, Confluence Data Center,…

Read original ↗
Security AffairsGlobal
AI security

Wikimedia Finds Unauthorized OpenAI Agent Activity on Wikipedia

Wikimedia found unauthorized OpenAI agent activity on its platforms, including unapproved edits, proxy attempts and millions of automated API requests. Wikimedia ran its own…

Read original ↗
The Hacker NewsGlobal
Cyber attack / incident

100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer

The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve…

Read original ↗
SecurityWeekGlobal
Vulnerability

Android’s October 2026 Updates Patch 25 Vulnerabilities

The patches resolve a critical vulnerability in Android’s System component that could lead to privilege escalation. The post Android’s October 2026 Updates Patch 25…

Read original ↗
SecurityWeekGlobal
Vulnerability

Atlassian Patches Critical Vulnerability Affecting 8 Products

Unauthenticated attackers could exploit the flaw to access specific files in the web application root directory. The post Atlassian Patches Critical Vulnerability Affecting 8…

Read original ↗
SANS Internet Storm CenterGlobal
Cyber security

ISC Stormcast For Wednesday, October 7th, 2026 https://isc.sans.edu/podcastdetail/10126, (Wed, Oct 7th)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

SecurityWeekGlobal
Cyber attack / incident

Personal Information for Over 1 Million People Stolen in a Cyberattack on Arizona’s Court System

The Arizona Supreme Court said the information was copied for people dating back as far as 30 years. The post Personal Information for Over…

Read original ↗
CyberScoopUS
Ransomware

Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks

The FBI and Secret Service warned Fortinet users that FortiBleed, uncovered this summer, is a continuing threat. The post Alert: FortiBleed remains active campaign,…

Dark ReadingGlobal
Cyber security

ClickFix Attacks Evolve to Better Hide Malicious Payloads

Threat actors are now hiding payloads by using DNS TXT records and browser cache pre-fetching, making it tougher to spot early attack stages.

Dark ReadingGlobal
Cyber security

Critical Healthcare Systems Aren't Quantum-Ready

A study of 2.5 million devices across 50 healthcare organizations suggests the sector has a long way to go in getting ready for the…

CyberScoopUS
Cloud

Wiretapping change sparks big privacy fight in the Golden State

An update to a state wiretapping law will end private lawsuits over some internet tracking and surveillance, pitting businesses against privacy groups and unions.’…

The Hacker NewsGlobal
Identity

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

Cybersecurity researchers have disclosed details of a "human-operated phishing platform" that impersonates advertising products for artificial intelligence (AI) chatbots like Google Gemini, Anthropic Claude,…

The Hacker NewsGlobal
Malware

Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan

Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes…

Dark ReadingGlobal
Vulnerability

Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps

The situation illustrates a trend toward using AI and deterministic validation to identify flaws and exploitability, and provide a risk assessment.

CyberScoopUS
Vulnerability

Former NSA chief Nakasone says agency overhaul is ‘probably needed’

Paul Nakasone said the reported reorganization is likely necessary to meet faster-moving cyberthreats and competition in AI, but warned its success will rest on…

Dark ReadingGlobal
AI security

IANS' Kakolowski: How AI Is Reshaping CISO Budgets & Security Teams

In this video interview, Nick Kakolowski, senior director for CISO research at IANS, talks AI: budgets, ROI, and changes inside security teams.