Latest news
-
Vulnerabilities via oss-security
CVE-2026-91863: Apache Neethi: Uncontrolled recursion while parsing crafted WS-Policy documents allows denial of service
Posted by Colm O hEigeartaigh on Sep 18 Severity: moderate Affected versions: - Apache Neethi (org.apache.neethi:neethi) before 3.2.4 Description: A specially crafted…
-
Ransomware via RansomLook
United Federation of Teachers By n0n
Education / Labor Union · US — New York What will be published if no settlement is reached The union’s complete legal case archive — approx.
-
Vulnerabilities via BleepingComputer
Gyazo server flaw exploited to steal 23.6 million user records
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user…
-
Threat Intel via Wired
An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang
TeamPCP pulled off the worst-ever software supply-chain hacking spree and breached thousands of companies. Now Google’s threat intelligence group says it had a mole…
-
Ransomware via ransomware.live
🏴☠️ Auditteam has just published a new victim : Paid Victim 192EB2B6AD7B98D9
[AI generated] N/A I don't have any reliable information about a company named "Paid Victim 192EB2B6AD7B98D9." This appears to be an anonymized or coded identifier…
-
AI Security via CyberScoop
International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data
North Korean hackers are infiltrating tens of thousands of job seekers’ computer networks by posing as prospective employers, such as artificial intelligence firms, to…
-
Breaches via TechCrunch
FBI, Coast Guard boarded hacked oil tankers heading toward US coast
The feds are said to be investigating the compromise of the tankers' networks, which in one case interfered with one of the tanker's navigation and propulsion systems.
-
Vulnerabilities via Canadian Centre for Cyber Security
Google security advisory (AV26-939)
Serial number: AV26-939 Date: September 18, 2026 As of September 17, 2026, Google is affected by vulnerabilities in the following product: Chrome Prior to 153.0.8010.53…
-
Vulnerabilities via Halcyon
The Patch Gap Is Structural. Here Is What That Means for Your SOC.
AI-driven vulnerability discovery will outpace patching. Project Glasswing shows the patch gap is structural, not operational. Here is what that means for SOC teams.
-
Threat Intel via Malwarebytes Labs
New Android malware uses AI to steal bank logins and PINs
Researchers at Zimperium’s zLabs have analyzed an Android Trojan that uses an automated, multi-stage infection process. What’s new is that RatHat gives a live AI…
-
Breaches via ransomware.live
🏴☠️ N0n has just published a new victim : PayPal support operations (Transcom WorldWide)
Outsourced customer support / financial services · Netherlands / Tunisia | 86.7M connection records: daily support-agent sessions into PayPal corporate Citrix/AAA…
-
Breaches via ransomware.live
🏴☠️ N0n has just published a new victim : Ministry of Education — Argentina
Government / education · Argentina | Complete network-security configuration of the ministry network; 1.08M connection records: national library (BNM), school-book…
-
Breaches via ransomware.live
🏴☠️ N0n has just published a new victim : Argentem Creek Partners (investment firm)
Investment management / private credit · United States | Full corporate network evidence: 2.5M+ connection records, complete internal systems map (Active Directory…
-
Breaches via ransomware.live
🏴☠️ N0n has just published a new victim : AstraZeneca Türkiye
Pharmaceutical manufacturing (GxP) · Türkiye | Complete internal network-security configuration of all 3 sites (940 MB): every rule, device definition, remote-access…
-
Ransomware via ransomware.live
🏴☠️ N0n has just published a new victim : STOKR (digital securities platform)
Digital securities / investment platform · Luxembourg - EU | KYC investor register: full names, emails, countries, nationalities, wallet addresses and tax IDs where…
-
Vulnerabilities via Canadian Centre for Cyber Security
[Control Systems] Moxa security advisory (AV26-938)
Serial number: AV26-938 Date: September 18, 2026 As of September 18, 2026, Moxa is affected by a vulnerability in the following product: TN-4500B Series Prior to or…
-
Threat Intel via The Hacker News
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government…
-
Threat Intel via BleepingComputer
Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called…
-
AI Security via Simon Willison
The Creative Spirit of Who Framed Roger Rabbit
The Creative Spirit of Who Framed Roger Rabbit I love Who Framed Roger Rabbit, the 1988 movie by Robert Zemeckis. I haven't watched it in quite a few years, and Cypress…
-
Breaches via HIPAA Journal
Democratic Senators Reintroduce the Health Infrastructure Security and Accountability Act
On September 17, 2026, two Democratic Senators reintroduced the Health Infrastructure Security and Accountability Act, which seeks to improve cybersecurity standards for…
