Skip to content
Live intelligence · last 7 days only

Recent cyber attacks, breaches and security alerts worldwide.

Current reporting from established cyber-security publications and official agencies. The default view shows the last 72 hours; switch to 24 hours or the full 7-day window when you need it.

Automated feedLast refresh 12 minutes ago60 headlines · 19 curated sources · max age 7 days
Freshness
60 matching headlines Only items published within the last 7 days are retained. CZITAPP links to the original publisher.
CyberScoopUS
Ransomware

Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks

The FBI and Secret Service warned Fortinet users that FortiBleed, uncovered this summer, is a continuing threat. The post Alert: FortiBleed remains active campaign,…

Read original ↗
Dark ReadingGlobal
Cyber security

ClickFix Attacks Evolve to Better Hide Malicious Payloads

Threat actors are now hiding payloads by using DNS TXT records and browser cache pre-fetching, making it tougher to spot early attack stages.

Dark ReadingGlobal
Cyber security

Critical Healthcare Systems Aren't Quantum-Ready

A study of 2.5 million devices across 50 healthcare organization suggests the sector has a long way to go in getting ready for the…

CyberScoopUS
Cloud

Wiretapping change sparks big privacy fight in the Golden State

An update to a state wiretapping law will end private lawsuits over some internet tracking and surveillance, pitting businesses against privacy groups and unions.’…

The Hacker NewsGlobal
Identity

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

Cybersecurity researchers have disclosed details of a "human-operated phishing platform" that impersonates advertising products for artificial intelligence (AI) chatbots like Google Gemini, Anthropic Claude,…

The Hacker NewsGlobal
Malware

Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan

Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes…

Dark ReadingGlobal
Vulnerability

Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps

The situation illustrates a trend toward using AI and deterministic validation to identify flaws and exploitability, and provide a risk assessment.

CyberScoopUS
Vulnerability

Former NSA chief Nakasone says agency overhaul is ‘probably needed’

Paul Nakasone said the reported reorganization is likely necessary to meet faster-moving cyberthreats and competition in AI, but warned its success will rest on…

Dark ReadingGlobal
AI security

IANS' Kakolowski: How AI Is Reshaping CISO Budgets & Security Teams

In this video interview, Nick Kakolowski, senior director for CISO research at IANS, talks AI: budgets, ROI, and changes inside security teams.

Dark ReadingGlobal
Vulnerability

'BigDiskBuster' Leaves Microsoft Defender Running While Blocking Updates

Not quite an EDR-killer, but the proof-of-concept cyber technique creates a silent virus detection gap while service runs normally, no exploit required.

Microsoft Security BlogGlobal
Vulnerability

CISO perspectives on managing vulnerability risks in the age of AI

Learn how CISOs can mitigate cybersecurity risks and increase resilience in the age of AI-powered vulnerability management. The post CISO perspectives on managing vulnerability…

The RecordGlobal
Malware

Alleged ATM malware creator appears in Nebraska court after arrest

Aguirre was added to the FBI’s “Top 10 Most Wanted Fugitives” list in March, becoming the first cybercriminal added to the list.

The RecordGlobal
Data breach

South Korean officials believe AI agents were used to hack several banks

The personal data of at least 68,000 people was reportedly exposed in breaches of at least seven financial institutions, with officials saying they believe…

The RecordGlobal
Ransomware

Osaka Metropolitan University cancels classes after suspected ransomware attack

Osaka Metropolitan University said on Tuesday that the outage left its internal network, email and a range of administrative and academic systems unavailable.

SecurityWeekGlobal
Vulnerability

FBI Blames Contractor’s Missed Patch for ShinyHunters Breach

The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees. The post FBI Blames…

Security AffairsGlobal
Vulnerability

CVE-2026-96940: Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely

Microsoft released emergency updates for Exchange Server to fix CVE-2026-96940, a high-severity flaw that can let attackers gain higher privileges. Microsoft has released out-of-band…

The RecordGlobal
Cyber attack / incident

ClickFix campaign in Ukraine compromises over 100 websites to spread Lunex malware

CERT-UA found fake Cloudflare verification pages that led visitors into a now-familiar ClickFix trap. This time the goal was to infect machines with an…

SANS Internet Storm CenterGlobal
Cyber security

More RMM Tools In the Wild, (Tue, Oct 6th)

It seems that a trend started… I continue my journey discovering more RMM ("Remote Management & Monitoring") tools abused by threat actors! A few…

SecurityWeekGlobal
Malware

FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware

An alleged leader of Tren de Aragua’s ATM jackpotting activities, Canelon Aguirre was on the FBI’s top 10 most wanted list since March 2026.…

NCSCUK
Cyber attack / incident

Incident affecting ASOS customers

ASOS has said it is investigating a cyber incident and that some customer personal information may have been accessed.

Read original ↗
The Hacker NewsGlobal
Cloud

LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings

A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown.…

Read original ↗
SecurityWeekGlobal
AI security

Apple to Tighten Full Disk Access Controls in macOS Amid AI Risks

Citing growing risks posed by more capable and autonomous AI agents, Apple will introduce additional controls. The post Apple to Tighten Full Disk Access…

Read original ↗
SANS Internet Storm CenterGlobal
Cyber security

ISC Stormcast For Tuesday, October 6th, 2026 https://isc.sans.edu/podcastdetail/10124, (Tue, Oct 6th)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Read original ↗
CyberScoopUS
Cyber attack / incident

Here’s how experts think CISA should tell agencies to protect OT

Government auditors say federal agencies haven’t met mandated security steps for operational technology, which hackers targeted in water sector attacks this summer. The post…

Read original ↗
The Hacker NewsGlobal
Vulnerability

Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies

The Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to…

Read original ↗
The Hacker NewsGlobal
Vulnerability

Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers

In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools…

Read original ↗
SecurityWeekGlobal
Cyber security

Cybersecurity M&A Roundup: 39 Deals Announced in September 2026

Significant cybersecurity M&A deals announced by Dragos, IBM, Palo Alto Networks, Kiteworks, and Upwind. The post Cybersecurity M&A Roundup: 39 Deals Announced in September…

Read original ↗
SecurityWeekGlobal
Malware

Long-Running NPM Malware Campaign Accumulates 40,000 Downloads

Since August 2023, attackers have published eight malicious packages as part of the MALFEX supply chain campaign. The post Long-Running NPM Malware Campaign Accumulates…

Read original ↗
Unit 42Global
Critical infrastructure

Blinder Tunnel Campaign Targets Iraqi Infrastructure

Analysis of Blinder Tunnel, an Iran-nexus campaign using fake Dubai Airports recruitment lures and GitHub C2 malware to target critical infrastructure. The post Blinder…

Read original ↗
SecurityWeekGlobal
Data breach

8.8 Million Impacted by Data Breach at Denmark’s Central Person Register

Hackers abused a company’s lawful access to the CPR system to steal the personal information of registered citizens. The post 8.8 Million Impacted by…

Read original ↗
Security AffairsGlobal
Vulnerability

FBI Drops Accenture Contractor After Sensitive Data Breach

Accenture lost an FBI contract after a missed security patch exposed sensitive employee data, raising serious concerns over operational security. The FBI pulled an…

Read original ↗
The Hacker NewsGlobal
Vulnerability

Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports

Google has stopped accepting product vulnerability reports through its bug bounty program for its open-source software. The change, in effect since October 1, means…

Read original ↗
SecurityWeekGlobal
Cyber security

Social Engineering Detection Moves Into the Live Conversation

Companies are pouring time and dollars into security awareness training, but little evidence shows it actually works against social engineering. The post Social Engineering…

Read original ↗
Security AffairsGlobal
Vulnerability

Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root Access

Dell warns that a critical DSU flaw lets attackers run code as root. Customers should patch affected PowerEdge systems as soon as possible. Dell…

Read original ↗
The Hacker NewsGlobal
Vulnerability

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files…

Read original ↗
The Hacker NewsGlobal
Vulnerability

FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the theft…

Read original ↗
Security AffairsGlobal
Vulnerability

ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure

Fortinet details ClingSTUN, a Linux backdoor exploiting unpatched IoT devices and abusing public STUN servers to route traffic past NAT. FortiGuard Labs researchers spotted…

Read original ↗
The Hacker NewsGlobal
Cyber security

Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account

Unauthorized parties have gained access to the names, addresses, and personal identification numbers of about 8.8 million people, living and dead, in Denmark's national…

Read original ↗
The Hacker NewsGlobal
Cyber attack / incident

ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits

A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser's cache.…

Read original ↗
The RecordGlobal
Cyber attack / incident

Shares in British clothing company ASOS dive after hackers apparently send push notification

Several mysteries surround what appeared to be an unauthorized push notification sent to customers of London-based clothing company ASOS.

Read original ↗
CyberScoopUS
Vulnerability

Citrix discloses third actively exploited NetScaler zero-day in less than a week

The vendor was much quicker and consistent in its response to the latest defect, and researchers consider the impact relatively low compared to the…

Read original ↗
The RecordGlobal
Vulnerability

Wikimedia Foundation: OpenAI agents tried to edit pages and compromise notes tool

Beyond the potential misuses of its services, Wikimedia said activity by AI agents can be a drain on web platforms that are already operating…

Read original ↗
Dark ReadingGlobal
Vulnerability

ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes

The Linux backdoor exploits 24 known flaws to compromise IoT devices and uses legitimate public STUN servers to obscure communications.

The RecordGlobal
Vulnerability

Alleged ShinyHunters member reportedly detained in Jordan, assisting law enforcement

Saif ‌al-Din Khader is cooperating with the FBI, reports said, as the bureau responds to a massive breach that exposed employee data.

Read original ↗
Security AffairsGlobal
Vulnerability

Anthropic Mythos Found A Bug in Rejetto HFS. Attackers Are Now Exploiting It.

AI-assisted research uncovered a critical Rejetto HFS flaw that enables authentication bypass and remote code execution, now exploited in the wild. A Rejetto HFS…

The RecordGlobal
Vulnerability

US, Australia warn of latest Citrix vulnerability after NetScaler advisory

Citrix confirmed late on Friday that it was “tracking a newly observed issue” related to some customer-managed NetScaler deployments but claimed the problem was…

Read original ↗
The RecordGlobal
Ransomware

Ukraine grocery chain ATB confirms cyberattack as hackers threaten to leak data

Ukraine’s largest grocery store chain, ATB, confirmed that it was hit by a cyberattack after hackers posted an extortion demand on its website.

Read original ↗
The Hacker NewsGlobal
Vulnerability

Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes

Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under…

Dark ReadingGlobal
Cyber attack / incident

Chinese Hackers Impersonate US Officials for AI Cyber Espionage

An emerging threat group known as TA419 established seemingly legitimate professional relationships with AI policy experts working for US think tanks, universities, and legal…

The RecordGlobal
Ransomware

University of Illinois Chicago affected by ransomware attack on medical school

A ransomware attack that affected the University of Illinois Chicago (UIC) College of Medicine resulted in the theft of some information from its servers.

Read original ↗
SecurityWeekGlobal
Vulnerability

Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports

Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP). The post Google Narrows Open Source…

The Hacker NewsGlobal
Ransomware

⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests

A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the…

Check Point ResearchGlobal
Data breach

5th October – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 5th October, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Arizona’s…

The RecordGlobal
Nation-state

Belarusian hacktivists spent two years inside Russian healthcare network, researchers say

Russian cybersecurity researchers attributed a quiet two-year espionage campaign to the Belarusian Cyber Partisans, a group better known for public attacks against governments and…

Security AffairsGlobal
Data breach

Denmark ’s Population Registry Breached, 8.8 Million Affected

Hackers accessed names, addresses and CPR numbers of 8.8 million people in Denmark through a third-party company with legal registry access. A hacker broke…

The RecordGlobal
Vulnerability

Japanese media group Nikkei discloses intrusions targeting employees and users

The Japanese media giant Nikkei disclosed a cyber incident involving an employee email account that may have compromised journalistic sources.

The RecordGlobal
Vulnerability

Japanese media group Nikkei discloses cyberattack targeting journalistic sources

The Japanese media giant Nikkei disclosed a cyber incident involving an employee email account that may have compromised journalistic sources.

Security AffairsGlobal
Vulnerability

U.S. CISA adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency…

Dark ReadingGlobal
Cyber security

Need for Speed: AI-Driven Attacks Are Changing Security Strategies

AI-powered attacks are fast, relentless, and automated. How security teams can keep up is top of mind, according to the latest Dark Reading reader…

SecurityWeekGlobal
Vulnerability

Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

ClingSTUN operates as a back-connect proxy backdoor, sets up persistence, and contains exploits for self-propagation. The post Linux Backdoor Abuses STUN Protocol, Exploits Dozens…