October 02, 2026 · 50 articles

Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response
October 02, 2026
One company told customers to power down its data-protection platform during a nine-hour window, while the other remained mum on reported attacks prior to releasing a patch for... (Dark Reading)

CVE-2026-103505 - Mount Option Injection in Amazon EFS CSI Driver
October 02, 2026
Bulletin ID: 2026-120-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/01/2026 08:30 AM PDT Description: The Amazon EFS CSI Driver is a Container... (AWS Security Bulletins)

SWIFT Banking & Government Middleware Enables RCE
October 02, 2026
Patch middleware vulnerabilities now to avoid hardware-based MFA exploits in ultra-sensitive environments. (Dark Reading)

GitLab warns of critical RCE vulnerability in AI Gateway service
October 02, 2026
GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances. [...] (BleepingComputer)

Streamline: custom video pipelines with Cloudflare Stream and Workers
October 02, 2026
Streamline demonstrates how to build long-running, continuous video processing pipelines by pairing Cloudflare Workers and Durable Objects with a containerized media engine. (Cloudflare Blog)

Is Your Organization Ready for 2027's AI Accountability Era?
October 02, 2026
Organizations may face an artificial intelligence (AI) reckoning over the next year. Omdia and Gartner weigh in on how to tackle the governance, security, and value challenges a... (Dark Reading)

Is It Fair to Blame 'Rogue' AI for Security Failures?
October 02, 2026
"Rogue AI" terminology anthropomorphizes LLMs and shifts risk responsibility from vendors. Defenders should treat agents as untrusted, nondeterministic software systems, not sen... (Dark Reading)

Unidentified Flock Cameras in Florida
October 02, 2026
St. Lucie County in Florida discovered ( alt link ) a dozen Flock cameras whose ownership it can’t identify, and that the county government had not permitted. I am reminded of t... (Schneier on Security)

OpenAI's wandering AI agents earn it a California subpoena
October 02, 2026
Plus: Attorneys-general say investigators should have direct access to AI companies' records when things go wrong (The Register - Security)

In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats
October 02, 2026
Noteworthy stories that might have slipped under the radar: Kiteworks patches over 100 vulnerabilities, Microsoft publishes 2026 Digital Defense Report, AI finds 24 Android app... (SecurityWeek)

AI Agents Attempt SQL Injection While Searching Government Data
October 02, 2026
AI agents probing US and Canadian government sites made SQL injection attempts while seeking data, but investigators found no evidence of compromise. Autonomous AI agents, worki... (Security Affairs)

Microsoft: AI Cuts Post-Compromise Attack Time to Minutes
October 02, 2026
Microsoft has warned that threat actors have gained the advantage over defenders by using AI to enhance the speed and scale of attacks (Infosecurity Magazine)

Mississippi mayor says ransomware incident led city to shut down systems
October 02, 2026
Government services were temporarily disrupted by ransomware in Vicksburg, Mississippi. Mayor Willis Thompson said the FBI and other authorities are investigating. (The Record)

'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries
October 02, 2026
The group is exploiting a variety of vulnerabilities impacting Microsoft SharePoint, according to a new report from Symantec Threat Hunter Team. (The Record)

Vulnerability Backlogs Are an Ownership Problem
October 02, 2026
Organizations don't need better vulnerability scanners; they need to know who owns their assets and has the authority and capacity to actually fix them. (Dark Reading)

Power approval set to delay Oracle's Wisconsin AI datacenter
October 02, 2026
Grid connection awaits regulatory approval, putting planned 2027 customer delivery at risk (The Register - On-Prem)

Introducing Web Search API via AI Gateway
October 02, 2026
Cloudflare AI Gateway now supports native web search API integration in partnership with Ceramic.ai, Exa, and Linkup. Developers can now inject real-time web context into model... (Cloudflare Blog)

macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
October 02, 2026
The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime. The post macOS Users Targeted by Fake Zoom I... (SecurityWeek)

Integrate Aqua and Jira to Turn Security Findings Into Action
October 02, 2026
TL;DR Finding a security issue is only the beginning. Teams still need to get that issue to the people who can investigate and remediate it without adding another manual handoff... (Aqua Security Blog)

8 major updates to Cloudflare Observability
October 02, 2026
Cloudflare is launching eight major updates that bring logs, traces, analytics, alerts, dashboards, querying, and telemetry export into one observability platform, with simpler... (Cloudflare Blog)

Introducing Cloudflare Traces: follow requests through our entire platform
October 02, 2026
Cloudflare Traces shows how a request moves through security rules, transformations, cache, routing, Workers, and your origin, then follows it across services running anywhere i... (Cloudflare Blog)

Updates on our pledge to make Cloudflare features accessible to everyone
October 02, 2026
A year after pledging to eliminate two-tier product access, Cloudflare has expanded Logpush, multi-account governance, and higher platform limits to all accounts. Here is an upd... (Cloudflare Blog)

Announcing Cloudflare OHTTP Gateway - expanding access to Cloudflare’s privacy-preserving infrastructure
October 02, 2026
We’re announcing the closed beta of a self-serve Cloudflare OHTTP Gateway. We’re also renaming our Privacy Gateway to Cloudflare OHTTP Relay to better distinguish the two products. (Cloudflare Blog)

Follow the thread: a new dashboard to investigate account abuse
October 02, 2026
Fraudsters are increasingly using AI to bypass stateless security checks. Cloudflare's new Account Abuse Protection dashboard uses stateful analysis and edge-generated Hashed Us... (Cloudflare Blog)

Protected Quick Tunnels: simple accountless authentication for your next dev project
October 02, 2026
Quick Tunnels now support email authentication. Add --allowed-mail to one cloudflared command, and only the addresses or domains you list can reach your local app. No Cloudflare... (Cloudflare Blog)

Building for good: How civil society organizations are automating on Cloudflare
October 02, 2026
Some of the world's leading organizations are building the future of non-profit work with Cloudflare. (Cloudflare Blog)

2026 Birthday week: network performance update
October 02, 2026
Cloudflare now ranks as the fastest provider across 74% of the top 1,000 global networks. By incorporating background telemetry from Cloudflare Challenge Pages, we have expanded... (Cloudflare Blog)

Malicious Linux Implants Mimic Asian Mail Security Products
October 02, 2026
A trio of newly discovered backdoors walk and quack like legitimate edge solutions, so it's hard to tell they're not. (Dark Reading)

SMTP is the key: BPFDoor and AVERAT hitting the network edge
October 02, 2026
Overview Rapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a newly observed BPFDoo... (Rapid7 Blog)

AI is giving attackers a head start, Microsoft warns
October 02, 2026
Threat actors are using AI to find bugs, build malware and run intrusions faster than defenders can keep up. Microsoft’s 2026 Digital Defense Report, covering July 2025 to June... (Help Net Security)

Dell asks admins to patch max severity CSM flaws as soon as possible
October 02, 2026
Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments. [...] (BleepingComputer)

OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling
October 02, 2026
OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported. "We have p... (The Hacker News)

Crypto Scammers Hijack Microsoft’s Official X Account
October 02, 2026
Hackers used the account, which has 13 million followers, to amplify a Clippy-themed cryptocurrency account. The post Crypto Scammers Hijack Microsoft’s Official X Account appea... (SecurityWeek)

Why CISOs Struggle to Answer the Board's Three Hardest Questions, and How to Fix the Report
October 02, 2026
The quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and th... (The Hacker News)

In Rare Move, Alleged Iranian State Hacker Extradited to US
October 02, 2026
Amir Barati, an alleged member of the Mabna Institute, was indicted for targeting universities, private organizations, and government entities in the US and abroad. The post In... (SecurityWeek)

How American Political Campaigns Are Using AI-and What They’re Spending on the Tools
October 02, 2026
This essay was written with Nathan E. Sanders, and originally appeared in The Guardian . New campaign finance disclosure data shines a light on which US political campaigns are... (Schneier on Security)

SequenceHash: multihashing for the rest of us
October 02, 2026
Multihashing is one of those cryptographic tasks that’s easy not to think about too much. This is unfortunate, because multihashing is a common stumbling point when cryptographe... (Trail of Bits Blog)

Fortinet sounds the alarm over actively exploited FortiMail zero-day
October 02, 2026
No login required, exploitation underway, and some admins are still waiting for patches (The Register - Security)

Citrix NetScaler RCE zero-day Vulnerabilities
October 02, 2026
What is the Attack? Threat actors are actively exploiting two critical remote code execution vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting Citrix NetScaler ADC a... (FortiGuard Labs)

Police Target KillSec Ransomware Group with Arrests and Seizures
October 02, 2026
Investigators have disrupted the operations of ransomware group KillSec and arrested several key suspects (Infosecurity Magazine)

Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Disclosure
October 02, 2026
The Dutch Institute for Vulnerability Disclosure reveals agentic AI-powered attack using Zammad zero-days (Infosecurity Magazine)

Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools
October 02, 2026
Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Prote... (The Hacker News)

Investigators trace an AI agent ‘s path from research task to reconnaissance
October 02, 2026
Asymmetric Security traces rogue OpenAI AI agent activity that probed government sites, accessed staging servers, and evaded sandbox limits. Researchers at Asymmetric Security s... (Security Affairs)

Criminal recruiters want people on your payroll
October 02, 2026
Legitimate employee access can let criminals circumvent security controls that would be difficult to overcome from outside an organization. Routine actions such as information l... (Help Net Security)

Android 17 makes it harder for spyware to cover its tracks
October 02, 2026
When a journalist suspects their phone has been hacked, the first question is whether any trace of the attack is left. Google has added six features to Advanced Protection in An... (Help Net Security)

Botnets, adversarial attacks and data poisoning top leaders’ AI threat list
October 02, 2026
Companies are putting more money into AI while naming attacks on AI systems as the threat they are least ready to face. PwC surveyed 3,934 business and technology leaders in 71... (Help Net Security)

AI agents keep access to company data after their work is done
October 02, 2026
IT teams responsible for identity security are concerned about AI agents’ ongoing access to company systems and the actions they take on users’ behalf, according to a Delinea’s... (Help Net Security)

New infosec products of the week: October 2, 2026
October 02, 2026
Here’s a look at the most interesting products from the past week, featuring releases from BlackFog, Genea, Vega, and Thales. Vega II brings security-trained AI and lasting memo... (Help Net Security)

Risky Bulletin: Authorities dismantle KillSec group, arrest members across Europe
October 02, 2026
In other news: Ransomware attack could have crippled South Africa's air traffic operations; US sanctions Venezuelan ATM hackers; Chinese APT targets AI experts. (Risky Business News)

AI agent exploits Zammad zero-days in DIVD breach: What we know and how to detect it
October 02, 2026
(Sysdig Blog)
October 01, 2026 · 61 articles
AI policy circles targeted in China-linked phishing operation
October 01, 2026
Cybersecurity firm Proofpoint said TA419 impersonated officials and AI industry figures in an effort to gain access to cloud accounts held by U.S. think tank, university and leg... (CyberScoop)

Kiteworks patches max severity code injection vulnerability
October 01, 2026
Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting its Email Protection Gateway... (BleepingComputer)

Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950
October 01, 2026
Apple patched a CoreGraphics zero-day that may have been exploited in targeted attacks. A public PoC for the flaw is now available. Apple patched a zero-day vulnerability, track... (Security Affairs)

Introducing The Builder Exchange: Inside Security Stories From the Companies Building Fastest With AI
October 01, 2026
Why the industry needs The Builder Exchange Software development traditionally ran through a narrow channel that involved a defined set of engineers, pipelines, and a review pro... (Orca Security Blog)

Convincing Free Mobile phishing emails appear after data breach
October 01, 2026
Free Mobile customers received very convincing phishing emails after major data breach. (Malwarebytes Labs)

OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates
October 01, 2026
OpenAI on Wednesday said it identified and disrupted a coordinated distillation campaign that was designed to illicitly extract protected reasoning from its artificial intellige... (The Hacker News)

CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
October 01, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Ex... (The Hacker News)

Hackers stole Pentagon personnel records of over 3 million people
October 01, 2026
The Pentagon's Defense Manpower Data Center (DMDC) is notifying millions of military service members that hackers stole their data after breaching the Pentagon's human resources... (BleepingComputer)

Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version
October 01, 2026
Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders throug... (The Hacker News)

MI5 Warns Over 100 Academics Helped China's Espionage Plans
October 01, 2026
MI5 has issued a rare warning to UK academics contributing to the China General Technology Research Institute (Infosecurity Magazine)

Metamask discloses security incident affecting its infrastructure
October 01, 2026
On Thursday, cryptocurrency wallet provider MetaMask has disclosed an ongoing infrastructure security incident affecting some of its infrastructure. [...] (BleepingComputer)

New Huntress View for Security Incident Investigations
October 01, 2026
See how the Huntress SOC runs security incident investigations from first signal to final resolution, including the ones closed as benign. (Huntress Blog)

CrowdStrike Expands Federal SOC Modernization Through CISA-Funded SIEMaaS
October 01, 2026
(CrowdStrike Blog)

Alleged KillSec Ransomware Mastermind a 16-Year-Old
October 01, 2026
Law enforcement from multiple countries collaborated to disrupt a cybercrime operation that has claimed some 500 victims worldwide in the past two years. (Dark Reading)

AI agents hacked the hackers, stealing email addresses from security research org
October 01, 2026
Chained Zammad flaws enabled session hijacking, code execution, and root escalation in seconds (The Register - Security)

Iranian accused of hacking American universities extradited from Montenegro
October 01, 2026
An Iranian national accused by the U.S. of taking part in dozens of breaches involving the theft of academic data and intellectual property has been extradited from Montenegro. (The Record)

Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation
October 01, 2026
The Series B brings the AI-powered offensive security startup’s total funding to roughly $445 million only seven months after its public launch. The post Kevin Mandia’s Armadin... (SecurityWeek)

OpenAI software attempted to secretly scrape data from dozens of prominent websites
October 01, 2026
The findings, released Thursday by Asymmetric Security, are just the latest example of rogue behavior spurred by OpenAI’s software. (The Record)
National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations
October 01, 2026
Sean Cairncross talked about regulations, China, pilot projects and more Thursday. The post National cyber director: Government-industry collaboration vital to managing AI risks... (CyberScoop)

Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks
October 01, 2026
Fifteen years after coining the framework, John Kindervag insists zero trust still works in the AI era-if you get the implementation right. The post Zero Trust Creator Says Mode... (SecurityWeek)

Osavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical Domains
October 01, 2026
Hybrid risk intelligence company Osavul has raised $10 million in a Series A funding round led by 33N Ventures. The post Osavul Lands $10 Million to Spot Hostile Intent Across C... (SecurityWeek)

ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
October 01, 2026
This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than pe... (The Hacker News)

Suspected Chinese spies spoofed an Anthropic exec, ex-White House official in AI phishing
October 01, 2026
Your invite to a fake AI policy advisory committee has strings attached (The Register - Security)

Introducing Clef: our open-source decision models, and new RL fine-tuning platform
October 01, 2026
We are introducing Clef and Clef-flash, open-source decision models hosted on Workers AI for high-speed classification and agentic workflows. Also launching: a new reinforcement... (Cloudflare Blog)

Public Secrets Monitoring: Find a Credential Leak Beyond Your Borders
October 01, 2026
GitGuardian found a public GitHub repo tied to CISA leaking 844MB of live credentials. Agents Analysis flags which public leaks are actually yours. (GitGuardian Blog)

Why the smartest LLMs are not-so-smart pen testers
October 01, 2026
A new benchmark of eight leading AI systems shows that an intelligent model still needs a good context-rich harness. (ReversingLabs Blog)

Microsoft catches hackers exploiting Zimbra bug before disclosure
October 01, 2026
Attackers were probing the mail server flaw weeks before it had a CVE to its name (The Register - Security)

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
October 01, 2026
Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returni... (The Hacker News)

Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass
October 01, 2026
Rob Juncker is chief product and technology officer at Mimecast. Is he a hacker? “Unequivocally yes,” he says. The post Hacker Conversations: Rob Juncker, a Knock at the Door an... (SecurityWeek)

Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says
October 01, 2026
PwC’s survey found that only 22% of leaders would use fully autonomous AI for cyber defense, while just 21% are implementing quantum-resistant security measures. The post Enterp... (SecurityWeek)

Critical Cisco Catalyst SD-WAN Zero-Day Under Active Exploitation
October 01, 2026
Vulnerability in Cisco Catalyst SD-WAN Manager allows an unauthenticated, remote attacker to access systems with admin privileges (Infosecurity Magazine)

Shadow AI explained: The work shortcut that could leak your company’s secrets
October 01, 2026
An AI shortcut can send confidential work data beyond your company’s control. Here’s how to get the benefits without taking unnecessary risks. (Malwarebytes Labs)

The Day-One Hole in Zero Trust Architecture
October 01, 2026
Zero Trust can verify users once they are established, but onboarding creates a gap where organizations must decide who to trust before strong authentication exists. Specops exp... (BleepingComputer)

Preparing governments for an era of interconnected cyber risk
October 01, 2026
According to this year’s Microsoft Digital Defense Report, government agencies and services were the sector most impacted by cyber threats in 2026, accounting for 27% of observe... (Microsoft Security Blog)

Insights from the 2026 Microsoft Digital Defense Report
October 01, 2026
Read highlights from the 2026 Microsoft Digital Defense Report, which reflects a security environment that continues to grow more interconnected. The post Insights from the 2026... (Microsoft Security Blog)

Exabeam brings AI-assisted security investigations to data that must stay on-premises
October 01, 2026
Exabeam has introduced a new wave of capabilities that bring the Agentic SOC to life in the cloud and on-premises environments, combining AI-driven investigation, execution, and... (Help Net Security)

RadarFirst helps teams investigate AI bias, data exposure and unintended actions
October 01, 2026
RadarFirst has announced the general availability of Radar AI Incident Management, a purpose-built solution that helps organizations investigate, manage, and document AI-related... (Help Net Security)

CISO thought he had a 'r3@lg00dp@$$w0rd' but forgot to patch
October 01, 2026
Replacing letters with symbols still doesn’t make it good. (The Register - Security)

Sophos uses agentic AI to show businesses which security fixes deserve funding
October 01, 2026
Sophos has launched Sophos CISO Advantage, an agentic AI-enabled solution that connects security operations to security strategy. The solution gives organizations a picture of t... (Help Net Security)

AI Has Changed Attack Speed, Not Security Fundamentals
October 01, 2026
As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. The pos... (SecurityWeek)

Legit Security extends automated fixes to vulnerable open-source dependencies
October 01, 2026
Legit Security has announced an expansion of its Agentic Remediation capability to cover vulnerabilities found in open-source dependencies, not just first-party code, enabling d... (Help Net Security)

One year later: Sovereign AI and the fight for choice
October 01, 2026
AI sovereignty is not a zero-sum game, but many governments now believe it is. Cloudflare's answer: more local open-source models, model-agnostic security tools, and a commitmen... (Cloudflare Blog)

Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses
October 01, 2026
The Huntress Tragic Quadrant ranks the cyber threats hitting businesses most, from RMM abuse to AiTM, ClickFix, using real SOC data. (Huntress Blog)

How AI Is Changing the Roles Required in the Security Operations Center
October 01, 2026
As AI takes on more of the enrichment, correlation, and initial assessment inside the SOC, roles, skills, and KPIs still require deliberate redesign. Security leaders need to de... (Rapid7 Blog)

Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure
October 01, 2026
Under certain conditions, CVE-2026-73570 can be exploited via specially crafted emails without user interaction. The post Zimbra Vulnerability Exploited in the Wild Prior to Pub... (SecurityWeek)

Cyberattack on major Polish invoicing platform exposes customer data
October 01, 2026
One of Poland’s major online invoicing platforms suffered a data breach that may have exposed information belonging to its users, their customers and business partners. (The Record)

England's schools are getting better at mopping up cyber incidents
October 01, 2026
Two-thirds report immediate recovery, although teachers remain divided over whose job security is (The Register - Security)

Connected Cars Are a Surveillance Platform
October 01, 2026
Researchers at Northeastern University, in collaboration with Consumer Reports , evaluated how much modern cars spy in their drivers: To determine this, CR dug through thousands... (Schneier on Security)

Malwarebytes earns another Top Product award in independent testing
October 01, 2026
Three independent labs, three standout results: a perfect score, top certification, and every threat stopped before it ran. (Malwarebytes Labs)

Treasury Blacklists Most-Wanted ATM Malware Developer and His Network
October 01, 2026
The US government continues its crackdown on Tren de Aragua over its ATM jackpotting scheme. The post Treasury Blacklists Most-Wanted ATM Malware Developer and His Network appea... (SecurityWeek)

The Fine Art of Frustrating the Adversary
October 01, 2026
What really frustrates an adversary? Eight Cisco Talos researchers share practical ways to make their next move slower and riskier. From deception and behavioral detection to br... (Cisco Talos)

Some car apps are slipping owners’ data to big tech companies
October 01, 2026
The app that comes with your car may be sharing what it knows about you with some of the biggest tech companies. Northeastern University researchers tested 21 vehicles and 30 ca... (Help Net Security)

AI Threats Top Cybersecurity Preparedness Gap, PwC Finds
October 01, 2026
PwC finds global security leaders are most concerned about attacks on AI systems (Infosecurity Magazine)

Losing gamblers pushed to bet more by DraftKings’ AI, report says
October 01, 2026
Betting site DraftKings has been accused of using AI to target gamblers likely to lose more after receiving promotions. The company disputes the findings. (Malwarebytes Labs)

ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)
October 01, 2026
Threat Actors do not always use top-notch techniques or very complex malware to perform their attacks. Sometimes, they just abuse of existing applications... (SANS ISC)

Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs
October 01, 2026
Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and at... (The Hacker News)

Srsly Risky Biz: "Rogue" AI Isn't Going Anywhere
October 01, 2026
Your weekly dose of Seriously Risky Business news is written by Tom Uren and edited by Patrick Gray and Amberleigh Jack. This week's edition is sponsored by PortSwigger . You ca... (Risky Business News)

ISC Stormcast For Thursday, October 1st, 2026 https://isc.sans.edu/podcastdetail/10118, (Thu, Oct 1st)
October 01, 2026
(SANS ISC)

With AI agents, runtime is the only place truth lives
October 01, 2026
Runtime security for AI agents: if an agent is compromised, so is its account of itself. Sysdig's founder on the only truth that can't be forged. (Sysdig Blog)

What five years of Chainguard have taught us
October 01, 2026
Chainguard was founded to solve open source’s trust problem. Five years later, that mission matters more than ever in the age of AI. (Chainguard Unchained)

How do you harden an agent skill? The simple file type with serious complexities
October 01, 2026
Learn how Chainguard Factory hardens AI agent skills by detecting malicious behavior, fixing risks, and verifying functionality before release. (Chainguard Unchained)
September 30, 2026 · 9 articles

Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure
September 30, 2026
In yet another ClickFix-style campaign, threat actors abuse legitimate domains from OpenAI and Google to fool unsuspecting users. (Dark Reading)

Russian state hackers use new RedFlick technique to push malware
September 30, 2026
The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse backdoor. [...] (BleepingComputer)

Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
September 30, 2026
Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Micros... (The Hacker News)

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
September 30, 2026
Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-t... (The Hacker News)

Cloud CISO Perspectives: How cybersecurity startups can win CISOs
September 30, 2026
Welcome to the second Cloud CISO Perspectives for September 2026. Today, Alicja Cade and Nick Godfrey, senior directors, Office of the CISO, share their guidance for cybersecuri... (Google Cloud Blog)

Securing the Kubernetes Supply Chain: Introducing WizOS Helm Charts
September 30, 2026
Secure your Kubernetes supply chain with WizOS Helm Charts. Eliminate hidden CI/CD risks and unmaintained dependencies with hardened, signed, and CVE-scanned charts for seamless... (Wiz Blog)

AI Agent Authorization Beyond Authentication: A Look At AWS Dogwood
September 30, 2026
AWS Dogwood brings stateful authorization to AI agents. Learn how it fits with workload identity, AuthZEN, IAM, and the move away from long-lived credentials. (GitGuardian Blog)

Restrospective: How Malicious Updates Poison Your Environment
September 30, 2026
This post-mortem on recent supply chain attacks and threat actors including S1ngularity, Shai-Hulud and TeamPCP can help you prepare for what comes next. (ReversingLabs Blog)

2CLoader: A New Malware Loader Delivering Vidar and Remus
September 30, 2026
IntroductionIn August 2026, Zscaler ThreatLabz identified a new loader, which we track as 2CLoader. ThreatLabz has observed the loader being used to distribute information steal... (Zscaler ThreatLabz)