{"items":[{"id":"298d890b9a3cb8a1","title":"Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure","link":"https://www.darkreading.com/cyberattacks-data-breaches/malicious-custom-gpts-chatgpt-rat-delivery-lure","source":"Dark Reading","summary":"In yet another ClickFix-style campaign, threat actors abuse legitimate domains from OpenAI and Google to fool unsuspecting users.","publishedAt":"2026-09-30T21:25:47.000Z","timestamp":1790803547000,"tags":["apt","ai-sec"],"category":"apt","categoryLabel":"APT / THREAT ACTOR","severity":"info","keywordMatches":2,"technologies":[],"enrichment":null},{"id":"cb10f964c9d055b6","title":"Trump, Tech Giants Strike Voluntary AI Safety Accord","link":"https://www.darkreading.com/cyber-risk/trump-tech-giants-strike-voluntary-ai-safety-accord","source":"Dark Reading","summary":"The new White House Accord on so-called \"Super Intelligence\" calls on companies to implement greater controls and oversight over AI safety.","publishedAt":"2026-09-30T20:51:15.000Z","timestamp":1790801475000,"tags":[],"category":"uncategorized","categoryLabel":"UNSORTED","severity":"info","keywordMatches":0,"technologies":[],"enrichment":null},{"id":"2d28f457acee0ed7","title":"Russian state hackers use new RedFlick technique to push malware","link":"https://www.bleepingcomputer.com/news/security/russian-state-hackers-use-new-redflick-technique-to-push-malware/","source":"BleepingComputer","summary":"The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed \"RedFlick\" to deploy its signature CosmicPulse backdoor. [...]","publishedAt":"2026-09-30T20:34:01.000Z","timestamp":1790800441000,"tags":["malware"],"category":"malware","categoryLabel":"MALWARE","severity":"info","keywordMatches":2,"technologies":[],"enrichment":null},{"id":"3776ad1cae04a940","title":"DIVD says Zammad zero-days enabled AI-driven network breach","link":"https://www.bleepingcomputer.com/news/security/divd-says-zammad-zero-days-enabled-ai-driven-network-breach/","source":"BleepingComputer","summary":"The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. [...]","publishedAt":"2026-09-30T19:49:15.000Z","timestamp":1790797755000,"tags":["vulns","intel"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":5,"technologies":[],"enrichment":null},{"id":"2cf02acd767adc09","title":"As AI Reshapes the SOC Career Ladder, Satisfaction Rises for 91%, but Entry Gets Harder for Nearly Half","link":"https://www.darkreading.com/cybersecurity-careers/ai-reshapes-soc-career-ladder","source":"Dark Reading","summary":"New Swimlane research underscores a paradox: While AI detection and response is essential to giving defenders an edge, one in four security pros say AI limits their skill development.","publishedAt":"2026-09-30T18:56:56.000Z","timestamp":1790794616000,"tags":[],"category":"uncategorized","categoryLabel":"UNSORTED","severity":"info","keywordMatches":0,"technologies":[],"enrichment":null},{"id":"2ebaae643cd392ce","title":"Over 543,000 valid credentials exposed in public GitHub repositories","link":"https://www.bleepingcomputer.com/news/security/over-543-000-valid-credentials-exposed-in-public-github-repositories/","source":"BleepingComputer","summary":"More than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platform's security measures to prevent accidental leaks of sensitive data. [...]","publishedAt":"2026-09-30T18:08:34.000Z","timestamp":1790791714000,"tags":["intel","kubernetes"],"category":"intel","categoryLabel":"THREAT INTEL","severity":"info","keywordMatches":2,"technologies":[],"enrichment":null},{"id":"fe95a2c38cafc897","title":"Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets","link":"https://thehackernews.com/2026/09/attackers-exploit-zimbra-flaw-to-deploy.html","source":"The Hacker News","summary":"Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team. The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated operating system command injection flaw t…","publishedAt":"2026-09-30T16:46:29.000Z","timestamp":1790786789000,"tags":["vulns","apt"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":3,"technologies":[],"enrichment":null},{"id":"cb2af8d2a0d2744b","title":"Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks","link":"https://thehackernews.com/2026/09/attackers-abuse-msp360-to-deploy.html","source":"The Hacker News","summary":"Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content. \"Once executed, the legitimate MSP360 installer, distributed under…","publishedAt":"2026-09-30T16:32:59.000Z","timestamp":1790785979000,"tags":["intel"],"category":"intel","categoryLabel":"THREAT INTEL","severity":"info","keywordMatches":1,"technologies":[],"enrichment":null},{"id":"37d3b9649beab632","title":"CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS","link":"https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-pre-auth-rce-flaw-in-mikrotik-routeros/","source":"BleepingComputer","summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition. [...]","publishedAt":"2026-09-30T15:49:29.000Z","timestamp":1790783369000,"tags":["vulns"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":3,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-pre-auth-rce-flaw-in-mikrotik-routeros/","basis":"publisher-feed-excerpt"}},{"id":"9475c717ac1e7275","title":"Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager","link":"https://thehackernews.com/2026/09/cisco-warns-of-attackers-exploiting.html","source":"The Hacker News","summary":"Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an advisory on September 30. The flaw, CVE-2026-76504, could allow a remote attacker with no login access to use the Manager's API as the admin user. Fix…","publishedAt":"2026-09-30T15:24:54.000Z","timestamp":1790781894000,"tags":["vulns"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":4,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://thehackernews.com/2026/09/cisco-warns-of-attackers-exploiting.html","basis":"publisher-feed-excerpt"}},{"id":"78f1dc506aa66542","title":"ArgoCon North America 2026: What to expect as the Argo community looks toward CD 4.0","link":"https://www.cncf.io/blog/2026/09/30/argocon-north-america-2026-what-to-expect-as-the-argo-community-looks-toward-cd-4-0/","source":"CNCF","summary":"Work across the Argo Project is accelerating, with growing adoption, new use cases, and more maintainers contributing across the community. The community is also beginning the visioning process for Argo CD 4.0, making ArgoCon an opportunity...","publishedAt":"2026-09-30T15:24:47.000Z","timestamp":1790781887000,"tags":[],"category":"uncategorized","categoryLabel":"UNSORTED","severity":"info","keywordMatches":0,"technologies":["kubernetes"],"enrichment":{"matches":[{"technology":"kubernetes","reason":"Argo projects are described as building blocks similar to Kubernetes and the event coincides with KubeCon + CloudNativeCon, indicating a close relation.","evidence":"Much like Kubernetes, the Argo projects provide building blocks that teams can use to create systems suited to their own requirements."}],"sourceUrl":"https://www.cncf.io/blog/2026/09/30/argocon-north-america-2026-what-to-expect-as-the-argo-community-looks-toward-cd-4-0/","basis":"publisher-feed-excerpt"}},{"id":"ec979f717a949a7f","title":"Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net","link":"https://www.darkreading.com/threat-intelligence/russia-star-blizzard-apt-ditches-clickfix-widen-phishing-net","source":"Dark Reading","summary":"The APT actor is using a new tactic, dubbed \"RedFlick,\" against Ukrainian-linked targets such as NGOs, think tanks, and journalists to deploy its CosmicPulse backdoor.","publishedAt":"2026-09-30T15:02:25.000Z","timestamp":1790780545000,"tags":["malware","apt","intel"],"category":"malware","categoryLabel":"MALWARE","severity":"info","keywordMatches":3,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.darkreading.com/threat-intelligence/russia-star-blizzard-apt-ditches-clickfix-widen-phishing-net","basis":"publisher-feed-excerpt"}},{"id":"72dbeeb1790cb6f9","title":"Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures","link":"https://thehackernews.com/2026/09/attackers-abuse-chatgpt-custom-gpts-to.html","source":"The Hacker News","summary":"Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artifi…","publishedAt":"2026-09-30T15:00:15.000Z","timestamp":1790780415000,"tags":["malware","apt"],"category":"malware","categoryLabel":"MALWARE","severity":"info","keywordMatches":2,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://thehackernews.com/2026/09/attackers-abuse-chatgpt-custom-gpts-to.html","basis":"publisher-feed-excerpt"}},{"id":"8f1d5c9abb635858","title":"Cisco warns of new SD-WAN zero-day exploited in attacks","link":"https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-sd-wan-authentication-bypass-zero-day-exploited-in-attacks/","source":"BleepingComputer","summary":"Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges. [...]","publishedAt":"2026-09-30T14:46:40.000Z","timestamp":1790779600000,"tags":["vulns"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":3,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-sd-wan-authentication-bypass-zero-day-exploited-in-attacks/","basis":"publisher-feed-excerpt"}},{"id":"ad0d1f3062bdc5bc","title":"AI's Third Wave: Coworkers Break the Security Model That Worked for Agents","link":"https://www.bleepingcomputer.com/news/security/ais-third-wave-coworkers-break-the-security-model-that-worked-for-agents/","source":"BleepingComputer","summary":"Persistent AI coworkers may operate continuously with standing access, creating identity risks that existing security models were not designed to handle. Token Security explains why these agents need their own identities, owners, scoped permissions, and lifecycle controls. [...]","publishedAt":"2026-09-30T14:01:11.000Z","timestamp":1790776871000,"tags":[],"category":"uncategorized","categoryLabel":"UNSORTED","severity":"info","keywordMatches":0,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.bleepingcomputer.com/news/security/ais-third-wave-coworkers-break-the-security-model-that-worked-for-agents/","basis":"publisher-feed-excerpt"}},{"id":"29c0329f5a87d971","title":"Microsoft to block Entra ID script injection attacks starting October","link":"https://www.bleepingcomputer.com/news/security/microsoft-to-block-entra-id-script-injection-attacks-starting-october/","source":"BleepingComputer","summary":"Microsoft has reminded customers that the Entra ID authentication system will get better protection against external script injection attacks starting next month. [...]","publishedAt":"2026-09-30T13:37:15.000Z","timestamp":1790775435000,"tags":[],"category":"uncategorized","categoryLabel":"UNSORTED","severity":"info","keywordMatches":0,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.bleepingcomputer.com/news/security/microsoft-to-block-entra-id-script-injection-attacks-starting-october/","basis":"publisher-feed-excerpt"}},{"id":"8889e814016cf0b0","title":"TeamViewer urges users to patch severe flaws “as soon as possible”","link":"https://www.bleepingcomputer.com/news/security/teamviewer-urges-users-to-patch-severe-flaws-as-soon-as-possible/","source":"BleepingComputer","summary":"Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. [...]","publishedAt":"2026-09-30T12:25:10.000Z","timestamp":1790771110000,"tags":["vulns","cloud"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":2,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.bleepingcomputer.com/news/security/teamviewer-urges-users-to-patch-severe-flaws-as-soon-as-possible/","basis":"publisher-feed-excerpt"}},{"id":"13e00ab44d20734e","title":"CISA Adds One Known Exploited Vulnerability to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/30/cisa-adds-one-known-exploited-vulnerability-catalog","source":"CISA Advisories","summary":"CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-76504 Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to…","publishedAt":"2026-09-30T12:00:00.000Z","timestamp":1790769600000,"tags":["vulns"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":3,"technologies":[],"enrichment":null},{"id":"239ba2260483c4a6","title":"Know Your Enemy: Browser-Based Attack Techniques in 2026","link":"https://thehackernews.com/2026/09/know-your-enemy-browser-based-attack.html","source":"The Hacker News","summary":"Given that the browser is where business apps are accessed and used, it makes sense that attacks are happening there too. Most breaches today begin in a browser session. Often, they never leave it, with the entire attack chain from initial access to exfiltration playing out in the browser. Here are the six most danger…","publishedAt":"2026-09-30T11:58:00.000Z","timestamp":1790769480000,"tags":["intel"],"category":"intel","categoryLabel":"THREAT INTEL","severity":"info","keywordMatches":1,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://thehackernews.com/2026/09/know-your-enemy-browser-based-attack.html","basis":"publisher-feed-excerpt"}},{"id":"d36b3ecb6626d39f","title":"AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub","link":"https://thehackernews.com/2026/09/ai-coding-agents-exposed-13000-internal.html","source":"The Hacker News","summary":"AI coding agents asked to share screenshots of code changes for review have put internal company images in public GitHub repositories, security company Glow said. Its researchers found more than 13,000 internal images from developers at over 300 organizations, including customer billing records and screens of features…","publishedAt":"2026-09-30T11:30:00.000Z","timestamp":1790767800000,"tags":[],"category":"uncategorized","categoryLabel":"UNSORTED","severity":"info","keywordMatches":0,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://thehackernews.com/2026/09/ai-coding-agents-exposed-13000-internal.html","basis":"publisher-feed-excerpt"}},{"id":"52ffe63dd45a7f65","title":"Bitget hacked via zero-day in third-party security products","link":"https://www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/","source":"BleepingComputer","summary":"Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. [...]","publishedAt":"2026-09-30T11:11:46.000Z","timestamp":1790766706000,"tags":["vulns","intel"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":3,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/","basis":"publisher-feed-excerpt"}},{"id":"96835b5dcd5ab75d","title":"I Want Better Reporting on AI Genie Behavior","link":"https://www.schneier.com/blog/archives/2026/09/i-want-better-reporting-on-ai-genie-behavior.html","source":"Schneier on Security","summary":"AI systems are regularly completing tasks in ways that their prompters don’t want or intend. Some of them are disturbing, and some of them are dangerous. This is something I’ve been calling “ genie behavior ,” because I think that really gets at the core of what’s happening. I wish the popular press would report on th…","publishedAt":"2026-09-30T11:05:35.000Z","timestamp":1790766335000,"tags":[],"category":"uncategorized","categoryLabel":"UNSORTED","severity":"info","keywordMatches":0,"technologies":[],"enrichment":null},{"id":"f07322002d5eaf6c","title":"From 40 seconds to under 10: rebuilding incident detection on OpenTelemetry, Apache Kafka, and Apache Flink on Kubernetes","link":"https://www.cncf.io/blog/2026/09/30/from-40-seconds-to-under-10-rebuilding-incident-detection-on-opentelemetry-apache-kafka-and-apache-flink-on-kubernetes/","source":"CNCF","summary":"Every SaaS company has the same uncomfortable question after a major incident: who noticed first, the monitoring or the customers? For a long time our honest answer was “it depends”. This post describes how a small...","publishedAt":"2026-09-30T11:00:00.000Z","timestamp":1790766000000,"tags":["kubernetes"],"category":"kubernetes","categoryLabel":"KUBERNETES","severity":"info","keywordMatches":1,"technologies":["kubernetes"],"enrichment":null},{"id":"4e63cd870861b1c9","title":"US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access","link":"https://thehackernews.com/2026/09/us-focused-csuite-phishing-steals.html","source":"The Hacker News","summary":"ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployme…","publishedAt":"2026-09-30T10:45:00.000Z","timestamp":1790765100000,"tags":["intel"],"category":"intel","categoryLabel":"THREAT INTEL","severity":"info","keywordMatches":1,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://thehackernews.com/2026/09/us-focused-csuite-phishing-steals.html","basis":"publisher-feed-excerpt"}},{"id":"7595f834fb9c59d6","title":"Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT","link":"https://thehackernews.com/2026/09/attackers-exploit-netscaler-flaw-for.html","source":"The Hacker News","summary":"Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has targeted gover…","publishedAt":"2026-09-30T08:24:35.000Z","timestamp":1790756675000,"tags":["vulns","apt"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":2,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://thehackernews.com/2026/09/attackers-exploit-netscaler-flaw-for.html","basis":"publisher-feed-excerpt"}},{"id":"1b25f217f4254941","title":"OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted","link":"https://thehackernews.com/2026/09/openssl-fixes-high-severity-dtls-flaw.html","source":"The Hacker News","summary":"A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such…","publishedAt":"2026-09-30T08:09:28.000Z","timestamp":1790755768000,"tags":[],"category":"uncategorized","categoryLabel":"UNSORTED","severity":"info","keywordMatches":0,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://thehackernews.com/2026/09/openssl-fixes-high-severity-dtls-flaw.html","basis":"publisher-feed-excerpt"}},{"id":"22d143dd8ff5b09e","title":"South Africa Seeks Help After Cyberattack Targets Air Traffic Control","link":"https://www.darkreading.com/cyberattacks-data-breaches/south-africa-help-cyberattack-air-traffic-control","source":"Dark Reading","summary":"As aviation infrastructure suffers more cyberattacks, air traffic systems are the latest target, with a ransomware toolkit installed on at least one operational network.","publishedAt":"2026-09-30T07:00:00.000Z","timestamp":1790751600000,"tags":["malware","kubernetes"],"category":"malware","categoryLabel":"MALWARE","severity":"info","keywordMatches":2,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.darkreading.com/cyberattacks-data-breaches/south-africa-help-cyberattack-air-traffic-control","basis":"publisher-feed-excerpt"}},{"id":"a2c9b41769a0c066","title":"Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution","link":"https://thehackernews.com/2026/09/citrix-netscaler-cve-2026-88772-exploit.html","source":"The Hacker News","summary":"Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Tr…","publishedAt":"2026-09-30T05:30:30.000Z","timestamp":1790746230000,"tags":["vulns"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":3,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://thehackernews.com/2026/09/citrix-netscaler-cve-2026-88772-exploit.html","basis":"publisher-feed-excerpt"}},{"id":"3b6b222f8b8e8706","title":"Microsoft is rolling out Linux container support to WSL","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-is-rolling-out-linux-container-support-to-wsl/","source":"BleepingComputer","summary":"Microsoft is taking Windows Subsystem for Linux beyond just running Linux distributions, as WSL Containers is now generally available. [...]","publishedAt":"2026-09-30T00:40:57.000Z","timestamp":1790728857000,"tags":["cloud"],"category":"cloud","categoryLabel":"CLOUD","severity":"info","keywordMatches":1,"technologies":["docker"],"enrichment":{"matches":[{"technology":"docker","reason":"WSL Containers indicates support for Linux containers, which often involves Docker technology on Windows.","evidence":"Microsoft is rolling out Linux container support to WSL"}],"sourceUrl":"https://www.bleepingcomputer.com/news/microsoft/microsoft-is-rolling-out-linux-container-support-to-wsl/","basis":"publisher-feed-excerpt"}},{"id":"d49e0531691d1d5c","title":"Apple Zero-Day Vulnerability Weaponized in Targeted Attacks","link":"https://www.darkreading.com/cyberattacks-data-breaches/apple-zero-day-vulnerability-weaponized-targeted-attacks","source":"Dark Reading","summary":"Attackers are exploiting CVE-2026-86950, an out-of-bounds write flaw, in an extremely sophisticated fashion, according to Apple.","publishedAt":"2026-09-29T21:31:29.000Z","timestamp":1790717489000,"tags":["vulns"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":4,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.darkreading.com/cyberattacks-data-breaches/apple-zero-day-vulnerability-weaponized-targeted-attacks","basis":"publisher-feed-excerpt"}},{"id":"1e9b704f29a586f9","title":"Signal adds encypted local backup support to iOS, desktop apps","link":"https://www.bleepingcomputer.com/news/security/signal-adds-encypted-local-backup-support-to-ios-desktop-apps/","source":"BleepingComputer","summary":"Signal, the secure messaging app, released version 8.30, completing the rollout of its secure backups feature across all supported operating systems (Android, iOS, Linux, macOS, and Windows). [...]","publishedAt":"2026-09-29T21:30:08.000Z","timestamp":1790717408000,"tags":[],"category":"uncategorized","categoryLabel":"UNSORTED","severity":"info","keywordMatches":0,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.bleepingcomputer.com/news/security/signal-adds-encypted-local-backup-support-to-ios-desktop-apps/","basis":"publisher-feed-excerpt"}},{"id":"b9ebd84c7b2785aa","title":"Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution","link":"https://www.darkreading.com/application-security/unsloth-studio-flaw-model-inspection-code-execution","source":"Dark Reading","summary":"A patched Unsloth Studio vulnerability allows malicious AI models to execute arbitrary Python code during inspection, via the trust_remote_code setting.","publishedAt":"2026-09-29T21:08:42.000Z","timestamp":1790716122000,"tags":["vulns","ai-sec"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":2,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.darkreading.com/application-security/unsloth-studio-flaw-model-inspection-code-execution","basis":"publisher-feed-excerpt"}},{"id":"aafd86b072fb4eb4","title":"Custom ChatGPTs push ClickFix attacks to deploy RAT malware","link":"https://www.bleepingcomputer.com/news/security/custom-chatgpts-push-clickfix-attacks-to-deploy-rat-malware/","source":"BleepingComputer","summary":"Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware. [...]","publishedAt":"2026-09-29T20:59:39.000Z","timestamp":1790715579000,"tags":["malware","ai-sec"],"category":"malware","categoryLabel":"MALWARE","severity":"info","keywordMatches":2,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.bleepingcomputer.com/news/security/custom-chatgpts-push-clickfix-attacks-to-deploy-rat-malware/","basis":"publisher-feed-excerpt"}},{"id":"156dd54c407b27fb","title":"FBI tells ShinyHunters members to turn themselves in after recent arrest","link":"https://www.bleepingcomputer.com/news/security/fbi-tells-shinyhunters-members-to-turn-themselves-in-after-recent-arrest/","source":"BleepingComputer","summary":"The FBI is warning members of the ShinyHunters extortion group to turn themselves in after Dutch police arrested a man the bureau described as one of the group's alleged leaders. [...]","publishedAt":"2026-09-29T20:09:55.000Z","timestamp":1790712595000,"tags":["intel"],"category":"intel","categoryLabel":"THREAT INTEL","severity":"info","keywordMatches":2,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.bleepingcomputer.com/news/security/fbi-tells-shinyhunters-members-to-turn-themselves-in-after-recent-arrest/","basis":"publisher-feed-excerpt"}},{"id":"3cb734ba29cf05d4","title":"Hackers exploit Citrix NetScaler zero-day to deploy web shells","link":"https://www.bleepingcomputer.com/news/security/hackers-exploit-citrix-netscaler-zero-day-to-deploy-web-shells/","source":"BleepingComputer","summary":"Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks. [...]","publishedAt":"2026-09-29T18:37:12.000Z","timestamp":1790707032000,"tags":["vulns","malware","intel"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":5,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.bleepingcomputer.com/news/security/hackers-exploit-citrix-netscaler-zero-day-to-deploy-web-shells/","basis":"publisher-feed-excerpt"}},{"id":"c4e96687c6145568","title":"Former US Air Force members sent to prison over BEC attacks","link":"https://www.bleepingcomputer.com/news/security/former-us-air-force-members-sent-to-prison-over-bec-attacks/","source":"BleepingComputer","summary":"Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. [...]","publishedAt":"2026-09-29T18:09:39.000Z","timestamp":1790705379000,"tags":["vulns","intel"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":2,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.bleepingcomputer.com/news/security/former-us-air-force-members-sent-to-prison-over-bec-attacks/","basis":"publisher-feed-excerpt"}},{"id":"d45bad10f53fff65","title":"French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks","link":"https://thehackernews.com/2026/09/french-tax-data-theft-using-stolen.html","source":"The Hacker News","summary":"An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July. Neither the tax administration nor France's national cybersecurity agency saw the data leave. The attack was not sophisticated, the agency, ANSSI, says in a…","publishedAt":"2026-09-29T17:47:01.000Z","timestamp":1790704021000,"tags":["kubernetes"],"category":"kubernetes","categoryLabel":"KUBERNETES","severity":"info","keywordMatches":1,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://thehackernews.com/2026/09/french-tax-data-theft-using-stolen.html","basis":"publisher-feed-excerpt"}},{"id":"f429d2e637ac6162","title":"New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses","link":"https://thehackernews.com/2026/09/new-spectre-v2-btr-attack-leaks-linux.html","source":"The Hacker News","summary":"A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in web browsers, language runtimes, and the operating system kernel, across multiple CPU vendors. The new Spectre v2 variant has been codename…","publishedAt":"2026-09-29T17:20:17.000Z","timestamp":1790702417000,"tags":["vulns","kubernetes"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":2,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://thehackernews.com/2026/09/new-spectre-v2-btr-attack-leaks-linux.html","basis":"publisher-feed-excerpt"}},{"id":"ca7def1fee7c7d15","title":"Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor","link":"https://thehackernews.com/2026/09/russias-star-blizzard-targets-100.html","source":"The Hacker News","summary":"Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft. The campaigns, aimed at people and organizations tied to Ukraine, have affected more than 100 organizations since January, mostly in the U.S…","publishedAt":"2026-09-29T17:20:08.000Z","timestamp":1790702408000,"tags":["malware"],"category":"malware","categoryLabel":"MALWARE","severity":"info","keywordMatches":1,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://thehackernews.com/2026/09/russias-star-blizzard-targets-100.html","basis":"publisher-feed-excerpt"}},{"id":"b153e6d8431323d2","title":"Cloudflare Announces Public Certificate Authority for the Post-Quantum Web","link":"https://www.darkreading.com/cloud-security/cloudflare-announces-public-certificate-authority-post-quantum-web","source":"Dark Reading","summary":"Automated certificates for everyone, built for today, and hardened for the era of quantum computing.","publishedAt":"2026-09-29T17:02:16.000Z","timestamp":1790701336000,"tags":["cloud"],"category":"cloud","categoryLabel":"CLOUD","severity":"info","keywordMatches":1,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.darkreading.com/cloud-security/cloudflare-announces-public-certificate-authority-post-quantum-web","basis":"publisher-feed-excerpt"}},{"id":"b9d84f9363933441","title":"'NeedyMantis' Provides Long-Term Access to Compromised Networks","link":"https://www.darkreading.com/threat-intelligence/needymantis-long-term-access-compromised-networks","source":"Dark Reading","summary":"Microsoft observed a China-based actor using a previously unidentified malware framework in targeted intrusions against telcos, universities, medical, and government-related organizations.","publishedAt":"2026-09-29T15:12:39.000Z","timestamp":1790694759000,"tags":["malware"],"category":"malware","categoryLabel":"MALWARE","severity":"info","keywordMatches":1,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.darkreading.com/threat-intelligence/needymantis-long-term-access-compromised-networks","basis":"publisher-feed-excerpt"}},{"id":"c7a5b95ceb99d73e","title":"Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers","link":"https://www.darkreading.com/vulnerabilities-threats/netscaler-zero-days-chaos-citrix","source":"Dark Reading","summary":"The critical vulnerabilities, which impact default configurations of NetScaler products, essentially give attackers a skeleton key to customers' networks.","publishedAt":"2026-09-29T14:19:43.000Z","timestamp":1790691583000,"tags":["vulns"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":2,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.darkreading.com/vulnerabilities-threats/netscaler-zero-days-chaos-citrix","basis":"publisher-feed-excerpt"}},{"id":"ef8a09af0278d8a4","title":"Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown","link":"https://thehackernews.com/2026/09/kiteworks-fixes-critical-flaw-found.html","source":"The Hacker News","summary":"Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during the scheduled precautionary shutdown. \"During the shutdown, this activity led to the discovery of a previously unknown critical vulnerability confined to a c…","publishedAt":"2026-09-29T14:13:20.000Z","timestamp":1790691200000,"tags":["vulns"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":1,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://thehackernews.com/2026/09/kiteworks-fixes-critical-flaw-found.html","basis":"publisher-feed-excerpt"}},{"id":"a748e8f0fd47be44","title":"101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent","link":"https://thehackernews.com/2026/09/101-malicious-npm-packages-add.html","source":"The Hacker News","summary":"Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub. \"The malicious packages abuse the 'Baileys' WhatsApp open source project to add the victims to groups without their consent,\" OX Security researchers Nir…","publishedAt":"2026-09-29T13:45:10.000Z","timestamp":1790689510000,"tags":["supply-chain","vulns"],"category":"supply-chain","categoryLabel":"SUPPLY CHAIN","severity":"info","keywordMatches":3,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://thehackernews.com/2026/09/101-malicious-npm-packages-add.html","basis":"publisher-feed-excerpt"}},{"id":"ef19b502f5a8b531","title":"Baicells Nova 430H","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-04","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to inject malformed messages which may lead to a denial-of-service condition. The following versions of Baicells Nova 430H are affected: Nova 430H eNodeB (model pBS3101SH) <=BaiBLQ_3.0.12 (CVE-2026-96274) CVSS Vendor Equipment Vuln…","publishedAt":"2026-09-29T12:00:00.000Z","timestamp":1790683200000,"tags":["vulns"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":3,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-04","basis":"publisher-feed-excerpt"}},{"id":"4325786426012c69","title":"MikroTik RouterOS","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution or cause a denial of service. The following versions of MikroTik RouterOS are affected: RouterOS <7.24 (CVE-2026-84411) CVSS Vendor Equipment Vulnerabilities v3 9.8 MikroTik MikroTik RouterOS Intege…","publishedAt":"2026-09-29T12:00:00.000Z","timestamp":1790683200000,"tags":["vulns"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":4,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06","basis":"publisher-feed-excerpt"}},{"id":"6c7ec78480f96d0e","title":"VIVOTEK Camera Firmware","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-03","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of this vulnerability may allow attackers to achieve remote command execution on affected devices, potentially with root privileges, leading to full compromise of the camera system. The following versions of VIVOTEK Camera Firmware are affected: V Series model_FD9187 (CVE-2026…","publishedAt":"2026-09-29T12:00:00.000Z","timestamp":1790683200000,"tags":["vulns"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":3,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-03","basis":"publisher-feed-excerpt"}},{"id":"fbfa52177ee528e6","title":"Anjvision YSSD-RTMP-H5","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access sensitive information, access user accounts, execute OS-level commands, or take full control over the device. The following versions of Anjvision YSSD-RTMP-H5 are affected: YSSD-RTMP-H5 firmware 3.3.2.4_build_2024-12-2…","publishedAt":"2026-09-29T12:00:00.000Z","timestamp":1790683200000,"tags":["vulns"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":2,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05","basis":"publisher-feed-excerpt"}},{"id":"faadc0b2b19a69a4","title":"Viidure Dashcam Android Application","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-07","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to access, modify, or delete sensitive user data and critical system files, potentially compromising the operation of the entire platform. The following versions of Viidure Dashcam Android Application are affected: Dashcam Android…","publishedAt":"2026-09-29T12:00:00.000Z","timestamp":1790683200000,"tags":["vulns"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":2,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-07","basis":"publisher-feed-excerpt"}},{"id":"b99a27d23f5221f3","title":"Lantronix G520 Series Cellular Gateway","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-01","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to replace software and execute arbitrary code with root privileges. The following versions of Lantronix G520 Series Cellular Gateway are affected: G520 Series 2.6.0.4R6_stable (CVE-2026-84409, CVE-2026-91191) CVSS Vendor Equipm…","publishedAt":"2026-09-29T12:00:00.000Z","timestamp":1790683200000,"tags":["vulns"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":3,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-01","basis":"publisher-feed-excerpt"}},{"id":"494ffde2d5ef60f2","title":"CISA Adds One Known Exploited Vulnerability to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/29/cisa-adds-one-known-exploited-vulnerability-catalog","source":"CISA Advisories","summary":"CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-86950 Apple Multiple Products Out-of-Bounds Write Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to…","publishedAt":"2026-09-29T12:00:00.000Z","timestamp":1790683200000,"tags":["vulns"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":3,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.cisa.gov/news-events/alerts/2026/09/29/cisa-adds-one-known-exploited-vulnerability-catalog","basis":"publisher-feed-excerpt"}},{"id":"c8fcbf0e2df6a700","title":"Toptech TMS7 and TopHAT","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access critical data or execute arbitrary code. The following versions of Toptech TMS7 and TopHAT are affected: TMS7 7.6.3 (CVE-2026-71379, CVE-2026-70356, CVE-2026-72510, CVE-2026-63713, CVE-2026-68954, CVE-2026-68068, CVE-2…","publishedAt":"2026-09-29T12:00:00.000Z","timestamp":1790683200000,"tags":["vulns"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":3,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02","basis":"publisher-feed-excerpt"}},{"id":"7464b634780dccee","title":"Using Device Linking to Eavesdrop on WhatsApp and Signal","link":"https://www.schneier.com/blog/archives/2026/09/using-device-linking-to-eavesdrop-on-whatsapp-and-signal.html","source":"Schneier on Security","summary":"Modern messaging apps allow users to link their phone accounts to their computer desktop. Eavesdroppers are taking advantage of this capability: Apps such as WhatsApp Web and Signal Desktop allow people to use their accounts on other devices, such as laptops or desktop computers. Germany’s Customs Office has been usin…","publishedAt":"2026-09-29T11:02:19.000Z","timestamp":1790679739000,"tags":["apt"],"category":"apt","categoryLabel":"APT / THREAT ACTOR","severity":"info","keywordMatches":1,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.schneier.com/blog/archives/2026/09/using-device-linking-to-eavesdrop-on-whatsapp-and-signal.html","basis":"publisher-feed-excerpt"}},{"id":"b8f9491162447465","title":"Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation","link":"https://thehackernews.com/2026/09/dutch-police-arrest-24-year-old.html","source":"The Hacker News","summary":"Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. \"It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters,\" the Politie Landelijke Opsporing en Interventies said in an…","publishedAt":"2026-09-29T08:35:10.000Z","timestamp":1790670910000,"tags":["intel"],"category":"intel","categoryLabel":"THREAT INTEL","severity":"info","keywordMatches":1,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://thehackernews.com/2026/09/dutch-police-arrest-24-year-old.html","basis":"publisher-feed-excerpt"}},{"id":"c401e28ae2c1d695","title":"Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials","link":"https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html","source":"The Hacker News","summary":"A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory. Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endp…","publishedAt":"2026-09-29T06:08:25.000Z","timestamp":1790662105000,"tags":["vulns","ai-sec","intel"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":3,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html","basis":"publisher-feed-excerpt"}},{"id":"710938735c9fcf0b","title":"OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions","link":"https://thehackernews.com/2026/09/openai-shelves-gpt-61-astra-after-tests.html","source":"The Hacker News","summary":"OpenAI on Monday shelved plans to release GPT-6.1 Astra, a next-generation artificial intelligence (AI) model that was planned for an October launch, after it failed internal safety and alignment audits. The development was first reported by The Wall Street Journal. The move \"marks a rare case of a major AI developer…","publishedAt":"2026-09-29T05:12:32.000Z","timestamp":1790658752000,"tags":["ai-sec"],"category":"ai-sec","categoryLabel":"AI SECURITY","severity":"info","keywordMatches":1,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://thehackernews.com/2026/09/openai-shelves-gpt-61-astra-after-tests.html","basis":"publisher-feed-excerpt"}},{"id":"50972d407b47a0bf","title":"OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot","link":"https://thehackernews.com/2026/09/openai-pauses-tool-use-after-agent.html","source":"The Hacker News","summary":"OpenAI said it has made the decision to pause training of its most powerful models after one of its agents during reinforcement learning (RL) training contacted an external chatbot by exploiting a loophole in its internet-access restrictions. \"An agent attempting to complete a search-based training task queried a publ…","publishedAt":"2026-09-29T04:45:20.000Z","timestamp":1790657120000,"tags":["vulns","ai-sec"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":2,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://thehackernews.com/2026/09/openai-pauses-tool-use-after-agent.html","basis":"publisher-feed-excerpt"}},{"id":"fad2b6a0f7678a8c","title":"Nvidia Launches AI Agent Safety Platform to Prevent Rogue Activities","link":"https://www.darkreading.com/cyber-risk/nvidia-launches-ai-agent-safety-platform-prevent-rogue-activities","source":"Dark Reading","summary":"The Open Agent Safety Platform relies on hardware and software components to monitor agent activities and quarantine unruly agents before they can cause harm.","publishedAt":"2026-09-28T22:02:46.000Z","timestamp":1790632966000,"tags":["ai-sec"],"category":"ai-sec","categoryLabel":"AI SECURITY","severity":"info","keywordMatches":1,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.darkreading.com/cyber-risk/nvidia-launches-ai-agent-safety-platform-prevent-rogue-activities","basis":"publisher-feed-excerpt"}},{"id":"ae5b26793ac123d0","title":"One Packet Can Crash OT Servers in Industrial Sectors","link":"https://www.darkreading.com/ics-ot-security/one-packet-crash-servers-tdengine","source":"Dark Reading","summary":"A high-severity vulnerability affects the TDengine time-series database used across industrial, IoT, energy, and automotive environments, and orgs should patch right away.","publishedAt":"2026-09-28T21:13:04.000Z","timestamp":1790629984000,"tags":["vulns"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":1,"technologies":[],"enrichment":{"matches":[],"sourceUrl":"https://www.darkreading.com/ics-ot-security/one-packet-crash-servers-tdengine","basis":"publisher-feed-excerpt"}},{"id":"6c46ed3fad49c449","title":"Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts","link":"https://www.darkreading.com/identity-access-management-security/carbonato-botnet-ai-agent-hacked-docker-hosts","source":"Dark Reading","summary":"The botnet uses the open source Hermes Agent AI framework to execute commands via Telegram and steal AI API keys from exposed Docker hosts.","publishedAt":"2026-09-28T20:23:58.000Z","timestamp":1790627038000,"tags":["vulns","malware","ai-sec","cloud"],"category":"vulns","categoryLabel":"VULNERABILITIES","severity":"info","keywordMatches":4,"technologies":["docker"],"enrichment":{"matches":[{"technology":"docker","reason":"The text describes the botnet targeting Docker hosts to execute commands and steal AI API keys.","evidence":"The botnet uses the open source Hermes Agent AI framework to execute commands via Telegram and steal AI API keys from exposed Docker hosts."}],"sourceUrl":"https://www.darkreading.com/identity-access-management-security/carbonato-botnet-ai-agent-hacked-docker-hosts","basis":"publisher-feed-excerpt"}}],"sources":[{"source":"The Hacker News","ok":true,"count":50,"attempts":1},{"source":"BleepingComputer","ok":true,"count":15,"attempts":1},{"source":"Krebs on Security","ok":true,"count":10,"attempts":1},{"source":"Schneier on Security","ok":true,"count":10,"attempts":1},{"source":"CISA Advisories","ok":true,"count":30,"attempts":1},{"source":"Kubernetes Blog","ok":true,"count":50,"attempts":1},{"source":"CNCF","ok":true,"count":10,"attempts":1},{"source":"Docker Blog","ok":true,"count":10,"attempts":1},{"source":"AWS Security","ok":true,"count":20,"attempts":1},{"source":"Google Project Zero","ok":true,"count":10,"attempts":1},{"source":"Dark Reading","ok":true,"count":50,"attempts":1}],"stats":{"scanned":265,"caught":51,"signal":85,"sourcesOnline":11,"sourcesTotal":11,"durationMs":1224},"updatedAt":"2026-09-30T23:45:29.315Z","capacity":60,"categories":[{"id":"vulns","label":"VULNERABILITIES","severity":"critical","keywords":["cve-","vulnerab","zero-day","zero day","0day","exploit","rce ","remote code execution","privilege escalation","buffer overflow","sql injection","xss","patch tuesday","advisory","kev catalog"]},{"id":"malware","label":"MALWARE","severity":"critical","keywords":["malware","ransomware","trojan","botnet","backdoor","infostealer","stealer","spyware","rootkit","worm","loader","cryptominer","wiper"]},{"id":"supply-chain","label":"SUPPLY CHAIN","severity":"high","keywords":["supply chain","npm package","pypi","malicious package","typosquat","dependency confusion","sbom","sigstore","build pipeline","compromised package","crates.io","rubygems"]},{"id":"apt","label":"APT / THREAT ACTOR","severity":"high","keywords":["apt","nation-state","state-sponsored","threat actor","espionage","lazarus","sandworm","campaign targeting","hacking group","cyberattack on"]},{"id":"kubernetes","label":"KUBERNETES","severity":"info","keywords":["kubernetes","k8s","kubectl","kubelet","etcd","container runtime","helm","operator","cri-o","containerd","istio","service mesh","eks","gke","aks","pod security","admission controller"]},{"id":"cloud","label":"CLOUD","severity":"medium","keywords":["cloud","aws ","azure","gcp","s3 bucket","iam ","serverless","terraform","misconfigur","cspm","multi-cloud","docker","container"]},{"id":"ai-sec","label":"AI SECURITY","severity":"high","keywords":["prompt injection","llm","ai model","jailbreak","deepfake","model poisoning","ai agent","mcp server","hallucinat","openai","anthropic","machine learning attack","adversarial"]},{"id":"intel","label":"THREAT INTEL","severity":"medium","keywords":["breach","data leak","leaked","phishing","credential","extortion","dark web","incident response","report finds","arrested","sanction","indicted"]}],"enrichment":{"enabled":true,"running":false,"status":"daily-limit","callsToday":0,"dailyLimit":100},"refreshing":false,"filtered":60}