{"generated":"2026-10-10T14:00:22.944Z","refreshMinutes":30,"sources":[{"id":"acsc-alerts","name":"ACSC (Australian Cyber Security Centre)"},{"id":"acsc-advice","name":"ACSC Advisories"},{"id":"cisa-kev","name":"CISA Known Exploited Vulnerabilities"},{"id":"cisa-adv","name":"CISA Cybersecurity Advisories"},{"id":"msrc","name":"Microsoft Security Response Center"},{"id":"bleeping","name":"BleepingComputer"},{"id":"hackernews","name":"The Hacker News"},{"id":"krebs","name":"Krebs on Security"},{"id":"sans-isc","name":"SANS Internet Storm Center"},{"id":"m365-message","name":"Microsoft 365 Blog"}],"sourceStatus":[{"id":"bleeping","ok":false,"error":"Error: HTTP 403 (https://www.bleepingcomputer.com/feed/)"},{"id":"cisa-adv","ok":true},{"id":"krebs","ok":true},{"id":"acsc-alerts","ok":true},{"id":"cisa-kev","ok":true},{"id":"hackernews","ok":true},{"id":"acsc-advice","ok":false,"error":"Error: HTTP 404 (https://www.cyber.gov.au/acsc/view-all-content/advisories/rss)"},{"id":"sans-isc","ok":true},{"id":"msrc","ok":true},{"id":"m365-message","ok":true}],"kevCount30d":34,"counts":{"total":40,"critical":10,"scam":5},"items":[{"title":"The Third-Party Agent Problem: Why Security Built for AI You Chose Misses the Agents You Didn't","link":"https://thehackernews.com/2026/10/the-third-party-agent-problem-why.html","published":"2026-10-10T11:00:00.000Z","summary":"In environments studied for the 2026 State of Agent Security Report, roughly 1,280 third-party products now embed AI. About 282 of them sit behind single sign-on. The other thousand are invisible to identity infrastructure by default, not because anyone hid th","source":"The Hacker News","sourceId":"hackernews","au":false,"severity":"fyi","category":"ai"},{"title":"Anthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection Flaws","link":"https://thehackernews.com/2026/10/anthropic-cuts-live-internet-access-for.html","published":"2026-10-10T09:18:45.000Z","summary":"Anthropic on Friday said it's cutting off live internet access for all its internal evaluations following the discovery of new incidents in which its artificial intelligence (AI) models exhibited misaligned behavior and targeted real websites. The AI company s","source":"The Hacker News","sourceId":"hackernews","au":false,"severity":"high","category":"ai"},{"title":"Why TLP should not replace your internal information classification, (Sat, Oct 10th)","link":"https://isc.sans.edu/diary/rss/33414","published":"2026-10-10T09:11:34.000Z","summary":"The Traffic Light Protocol (TLP)[1], which is now in its second incarnation, is a wonderful standard that enables one to easily communicate whether information may be shared further (and if so, how far).","source":"SANS Internet Storm Center","sourceId":"sans-isc","au":false,"severity":"fyi","category":"security"},{"title":"FBI Arrests Founder of Ransomware Negotiation Firm","link":"https://krebsonsecurity.com/2026/10/fbi-arrests-founder-of-ransomware-negotiation-firm/","published":"2026-10-10T00:17:42.000Z","summary":"Agents with the Federal Bureau of Investigation (FBI) on Thursday arrested the co-founder of a Canadian cybersecurity firm in connection with an investigation into the ShinyHunters hacking group that recently relieved the FBI of sensitive data on thousands of ","source":"Krebs on Security","sourceId":"krebs","au":false,"severity":"high","category":"security"},{"title":"Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories","link":"https://thehackernews.com/2026/10/credential-stealing-github-actions.html","published":"2026-10-09T19:14:28.000Z","summary":"Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories. \"Using the account of Takashi Kitao, author ","source":"The Hacker News","sourceId":"hackernews","au":false,"severity":"high","category":"security"},{"title":"FBI Arrests Another ShinyHunters Suspect Reportedly Involved in Its Jobs Portal Hack","link":"https://thehackernews.com/2026/10/fbi-arrests-another-shinyhunters.html","published":"2026-10-09T17:45:26.000Z","summary":"The FBI has arrested another suspected co-conspirator of ShinyHunters, FBI Director Kash Patel said on October 9 in a&nbsp;post on X. ShinyHunters is the extortion group that said in September it had&nbsp;breached the FBI's jobs portal&nbsp;and stolen sensitiv","source":"The Hacker News","sourceId":"hackernews","au":false,"severity":"high","category":"security"},{"title":"P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands","link":"https://thehackernews.com/2026/10/p7-darksword-ios-exploit-kit-adds.html","published":"2026-10-09T16:29:55.000Z","summary":"Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword. \"Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet ","source":"The Hacker News","sourceId":"hackernews","au":false,"severity":"high","category":"security"},{"title":"TP-Link Sued by Four More U.S. States Over Router Security and China Ties","link":"https://thehackernews.com/2026/10/tp-link-sued-by-four-more-us-states.html","published":"2026-10-09T13:22:53.000Z","summary":"Four more U.S. states sued router maker TP-Link Systems on October 6, bringing the total to five, with &nbsp;Texas filing a suit in February. Florida, Iowa, Montana and Nebraska allege the California company misled buyers about how secure its routers are and h","source":"The Hacker News","sourceId":"hackernews","au":false,"severity":"fyi","category":"security"},{"title":"Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access","link":"https://thehackernews.com/2026/10/researchers-publish-working-exploit-for.html","published":"2026-10-09T12:59:22.000Z","summary":"Security researchers have&nbsp;published a full working exploit&nbsp;for a pre-authentication remote code execution flaw in AnyDesk Linux that gives attackers root access before anyone approves the connection. AnyDesk patched the flaw in version 8.0.3 in June,","source":"The Hacker News","sourceId":"hackernews","au":false,"severity":"high","category":"security"},{"title":"Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects","link":"https://thehackernews.com/2026/10/anthropic-launches-free-ai.html","published":"2026-10-09T12:47:28.000Z","summary":"Anthropic on Thursday unveiled OSS Scanner as an opt-in vulnerability scanner to help secure the open-source ecosystem using artificial intelligence (AI). \"It's an opt-in service informed by our experience using Claude to find vulnerabilities during Project Gl","source":"The Hacker News","sourceId":"hackernews","au":false,"severity":"high","category":"ai"},{"title":"Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge","link":"https://thehackernews.com/2026/10/attackers-exploit-ahsaycbs-flaws-to.html","published":"2026-10-09T12:47:26.000Z","summary":"Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners. Details of the flaws are below - CVE-2026-105133 (CVSS v4 score:","source":"The Hacker News","sourceId":"hackernews","au":false,"severity":"high","category":"security"},{"title":"Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies","link":"https://thehackernews.com/2026/10/flax-typhoon-exploits-five-flaws-as.html","published":"2026-10-09T12:21:51.000Z","summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their abuse by a China-linked threat actor known as Flax Typhoon. The vulnerabilities in ques","source":"The Hacker News","sourceId":"hackernews","au":false,"severity":"high","category":"security"},{"title":"ISC Stormcast For Friday, October 9th, 2026 https://isc.sans.edu/podcastdetail/10130, (Fri, Oct 9th)","link":"https://isc.sans.edu/diary/rss/33412","published":"2026-10-09T07:52:03.000Z","summary":"","source":"SANS Internet Storm Center","sourceId":"sans-isc","au":false,"severity":"fyi","category":"security"},{"title":"Reconstructing AI Agent Activity: Two New Scripts for Forensic Review, (Thu, Oct 8th)","link":"https://isc.sans.edu/diary/rss/33410","published":"2026-10-08T16:52:53.000Z","summary":"We just did a major update to FOR577 and added a lot of new material on day 5 about investigating AI usage in incident response. In the new material we dicsuss 8&&#x23;x26;&#x23;xc2;&&#x23;x26;&#x23;xa0;of the most popular AI coding assistants and&&#x23;x26;&#","source":"SANS Internet Storm Center","sourceId":"sans-isc","au":false,"severity":"fyi","category":"ai"},{"title":"Satel Netco Design","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-03","published":"2026-10-08T12:00:00.000Z","summary":"View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary scripts in a user's browser, consume excessive system resources, enumerate files, create or modify files, and potentially execute arbitrary code. Th","source":"CISA Cybersecurity Advisories","sourceId":"cisa-adv","au":false,"severity":"high","category":"scam"},{"title":"Grid Protection Alliance openPDC and openHistorian","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-02","published":"2026-10-08T12:00:00.000Z","summary":"View CSAF Summary The following versions of Grid Protection Alliance openPDC and openHistorian are affected: openPDC &lt;2.9.477, &lt;2.9.482 (CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, CVE-2026-101022) openPDC (Docker image) &lt;2.9.47","source":"CISA Cybersecurity Advisories","sourceId":"cisa-adv","au":false,"severity":"high","category":"scam"},{"title":"Red Lion Controls N-Tron 700 Series","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-01","published":"2026-10-08T12:00:00.000Z","summary":"View CSAF Summary Successful exploitation of these vulnerabilities could allow a malicious user to access the device and gain administrative access. This access would allow the user to view, edit, and upload configuration files. Further, a malicious user can c","source":"CISA Cybersecurity Advisories","sourceId":"cisa-adv","au":false,"severity":"high","category":"scam"},{"title":"Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data","link":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a","published":"2026-10-08T12:00:00.000Z","summary":"Advisory at a Glance&nbsp; Title&nbsp; Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data&nbsp; Original Publication&nbsp; October 8, 2026 &nbsp; Executive Summary&nbsp; Chinese government-linked ","source":"CISA Cybersecurity Advisories","sourceId":"cisa-adv","au":false,"severity":"high","category":"scam"},{"title":"ISC Stormcast For Thursday, October 8th, 2026 https://isc.sans.edu/podcastdetail/10128, (Thu, Oct 8th)","link":"https://isc.sans.edu/diary/rss/33408","published":"2026-10-08T02:00:02.000Z","summary":"","source":"SANS Internet Storm Center","sourceId":"sans-isc","au":false,"severity":"fyi","category":"security"},{"title":"CVE-2015-5477:  ISC BIND Data Processing Errors Vulnerability (actively exploited)","link":"https://nvd.nist.gov/vuln/detail/CVE-2015-5477","published":"2026-10-08T00:00:00.000Z","summary":"ISC BIND — ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries. CISA has confirmed active exploitation; required remediation date applies (2026-10-11).","source":"CISA Known Exploited Vulnerabilities","sourceId":"cisa-kev","au":false,"severity":"critical","category":"security"},{"title":"CVE-2016-3081: Apache Struts Command Injection Vulnerability (actively exploited)","link":"https://nvd.nist.gov/vuln/detail/CVE-2016-3081","published":"2026-10-08T00:00:00.000Z","summary":"Apache Struts — Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled. CISA has confirmed active exploitation; required remediation date applies (2026-10-11).","source":"CISA Known Exploited Vulnerabilities","sourceId":"cisa-kev","au":false,"severity":"critical","category":"security"},{"title":"CVE-2023-22894: Strapi Cleartext Storage of Sensitive Information Vulnerability (actively exploited)","link":"https://nvd.nist.gov/vuln/detail/CVE-2023-22894","published":"2026-10-08T00:00:00.000Z","summary":"Strapi Strapi — Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) CISA has confirmed active exploitation; required remediation date applies (2026-10-11).","source":"CISA Known Exploited Vulnerabilities","sourceId":"cisa-kev","au":false,"severity":"critical","category":"security"},{"title":"CVE-2021-3199: ONLYOFFICE Docs Server Path Traversal Vulnerability (actively exploited)","link":"https://nvd.nist.gov/vuln/detail/CVE-2021-3199","published":"2026-10-08T00:00:00.000Z","summary":"ONLYOFFICE Docs — ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution. CISA has confirmed active exploitation; required remediation date applies (2026-10-11).","source":"CISA Known Exploited Vulnerabilities","sourceId":"cisa-kev","au":false,"severity":"critical","category":"security"},{"title":"CVE-2015-3306: ProFTPD Improper Access Control Vulnerability (actively exploited)","link":"https://nvd.nist.gov/vuln/detail/CVE-2015-3306","published":"2026-10-08T00:00:00.000Z","summary":"ProFTPD ProFTPD — ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands. CISA has confirmed active exploitation; required remediation date applies (2026-10-11).","source":"CISA Known Exploited Vulnerabilities","sourceId":"cisa-kev","au":false,"severity":"critical","category":"security"},{"title":"Scans for Atlassian vulnerablity (CVE-2026-21589), (Wed, Oct 7th)","link":"https://isc.sans.edu/diary/rss/33406","published":"2026-10-07T14:59:33.000Z","summary":"On October 5th, Atlassian published patches&&#x23;x26;&#x23;xc2;&&#x23;x26;&#x23;xa0;for multiple products to fix an \"Arbitrary File Access\" vulnerability &&#x23;x26;&#x23;x5b;CVE-2026-21589&&#x23;x26;&#x23;x5d;. An attacker can read arbitrary files in the web","source":"SANS Internet Storm Center","sourceId":"sans-isc","au":false,"severity":"high","category":"security"},{"title":"ShinyHunters Extorted Boeing Spin-off Prior to Arrests","link":"https://krebsonsecurity.com/2026/10/shinyhunters-extorted-boeing-spin-off-prior-to-arrests/","published":"2026-10-07T13:48:45.000Z","summary":"A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group ShinyHunters has been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang. KrebsOnSecurity has learned that the suspect","source":"Krebs on Security","sourceId":"krebs","au":false,"severity":"fyi","category":"security"},{"title":"ISC Stormcast For Wednesday, October 7th, 2026 https://isc.sans.edu/podcastdetail/10126, (Wed, Oct 7th)","link":"https://isc.sans.edu/diary/rss/33404","published":"2026-10-07T02:00:02.000Z","summary":"","source":"SANS Internet Storm Center","sourceId":"sans-isc","au":false,"severity":"fyi","category":"security"},{"title":"More RMM Tools In the Wild, (Tue, Oct 6th)","link":"https://isc.sans.edu/diary/rss/33400","published":"2026-10-06T13:16:02.000Z","summary":"It seems that a trend started&#xe2;&#x80;&#xa6; I continue my journey discovering more RMM (\"Remote Management & Monitoring\") tools abused by threat actors! A few days ago, I wrote a diary[1] about ScreenConnect used in the wild. Today, I found another one.","source":"SANS Internet Storm Center","sourceId":"sans-isc","au":false,"severity":"critical","category":"security"},{"title":"Johnson Controls EasyIO FG","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-279-01","published":"2026-10-06T12:00:00.000Z","summary":"View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain full unauthorized access to the device. The following versions of Johnson Controls EasyIO FG are affected: EasyIO FG firmware &lt;=2.0b52 (CVE-2026-27872, CVE-20","source":"CISA Cybersecurity Advisories","sourceId":"cisa-adv","au":false,"severity":"high","category":"scam"},{"title":"Hitachi Energy REB500","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-279-05","published":"2026-10-06T12:00:00.000Z","summary":"View CSAF Summary Hitachi Energy is aware of open-source software vulnerabilities that affect REB500 product versions listed in this document. These vulnerabilities can be exploited to carry out Denial of Service (DoS) attack on the product. Please refer to th","source":"CISA Cybersecurity Advisories","sourceId":"cisa-adv","au":false,"severity":"high","category":"update"},{"title":"Hitachi Energy Asset Suite","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-279-03","published":"2026-10-06T12:00:00.000Z","summary":"View CSAF Summary Hitachi Energy is aware of unauthenticated servlet access vulnerabilities that affect Asset Suite product versions listed in this document. These vulnerabilities can be exploited to potentially cause confidentiality, integrity and availabilit","source":"CISA Cybersecurity Advisories","sourceId":"cisa-adv","au":false,"severity":"high","category":"update"},{"title":"Hitachi Energy SOI","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-279-04","published":"2026-10-06T12:00:00.000Z","summary":"View CSAF Summary Hitachi Energy is aware of RCE (Remote Code Execution) vulnerability in Apache ActiveMQ component of SOI product versions listed in this document. These vulnerabilities can be exploited to carry out various attacks affecting confidentiality, ","source":"CISA Cybersecurity Advisories","sourceId":"cisa-adv","au":false,"severity":"critical","category":"update"},{"title":"Hitachi Energy RTU500","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-279-06","published":"2026-10-06T12:00:00.000Z","summary":"View CSAF Summary Hitachi Energy is publishing this cybersecurity advisory in response to the security findings reported by Dragos affecting end-of-life RTU500 CMU firmware version 9.x. The reported findings are associated with legacy RTU500 firmware versions ","source":"CISA Cybersecurity Advisories","sourceId":"cisa-adv","au":false,"severity":"high","category":"update"},{"title":"Savannah lwIP SMTP client","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-279-02","published":"2026-10-06T12:00:00.000Z","summary":"View CSAF Summary Successful exploitation of this vulnerability could crash the device being accessed; a buffer overflow condition may allow remote code execution. The following versions of Savannah lwIP SMTP client are affected: lwIP SMTP client 2.2.1 (CVE-20","source":"CISA Cybersecurity Advisories","sourceId":"cisa-adv","au":false,"severity":"high","category":"update"},{"title":"ISC Stormcast For Tuesday, October 6th, 2026 https://isc.sans.edu/podcastdetail/10124, (Tue, Oct 6th)","link":"https://isc.sans.edu/diary/rss/33402","published":"2026-10-06T11:45:11.000Z","summary":"","source":"SANS Internet Storm Center","sourceId":"sans-isc","au":false,"severity":"fyi","category":"security"},{"title":"ISC Stormcast For Monday, October 5th, 2026 https://isc.sans.edu/podcastdetail/10122, (Mon, Oct 5th)","link":"https://isc.sans.edu/diary/rss/33398","published":"2026-10-05T02:00:02.000Z","summary":"","source":"SANS Internet Storm Center","sourceId":"sans-isc","au":false,"severity":"fyi","category":"security"},{"title":"TTY Logs and the Data it Captures, (Sun, Oct 4th)","link":"https://isc.sans.edu/diary/rss/33396","published":"2026-10-05T00:15:00.000Z","summary":"For an experiment, I created a script [1] that parses and send the TTY logs collected from actors or bots activity that run various commands after they successfully login the DShield sensor. Those TTY logs are sent daily at the end of each day to the DShield S","source":"SANS Internet Storm Center","sourceId":"sans-isc","au":false,"severity":"fyi","category":"security"},{"title":"CVE-2026-88779: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (actively exploited)","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-88779","published":"2026-10-04T00:00:00.000Z","summary":"Citrix NetScaler — Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service. CISA has confirmed active exploitation; required remediation date applies (2026-10-07).","source":"CISA Known Exploited Vulnerabilities","sourceId":"cisa-kev","au":false,"severity":"critical","category":"security"},{"title":"CVE-2026-102490: Zammad GmbH Zammad Improper Privilege Management Vulnerability (actively exploited)","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-102490","published":"2026-10-02T00:00:00.000Z","summary":"Zammad GmbH Zammad — Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489. CISA has confirmed active exploitation; required remediation date applies (2026-10-05).","source":"CISA Known Exploited Vulnerabilities","sourceId":"cisa-kev","au":false,"severity":"critical","category":"security"},{"title":"CVE-2026-102489: Zammad GmbH Zammad Session Fixation Vulnerability (actively exploited)","link":"https://nvd.nist.gov/vuln/detail/CVE-2026-102489","published":"2026-10-02T00:00:00.000Z","summary":"Zammad GmbH Zammad — Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490. CISA has confirmed active exploitation; required remediation date applies (2026-10-05).","source":"CISA Known Exploited Vulnerabilities","sourceId":"cisa-kev","au":false,"severity":"critical","category":"security"}]}