❌

Normal view

Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown

29 September 2026 at 14:13
Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during the scheduled precautionary shutdown. "During the shutdown, this activity led to the discovery of a previously unknown critical vulnerability confined to a capability that is enabled for less than 1% of the customer base," the company

101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent

29 September 2026 at 13:45
Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub. "The malicious packages abuse the 'Baileys' WhatsApp open source project to add the victims to groups without their consent," OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko said in a technical

Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation

29 September 2026 at 08:35
Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. "It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters," the Politie Landelijke Opsporing en Interventies said in an X post Monday. Police said the individual is expected to appear before the

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

29 September 2026 at 06:08
A malicious MCP server could trick an application built on the officialΒ MCP Python SDKΒ into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory. Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and

OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions

29 September 2026 at 05:12
OpenAI on Monday shelved plans to release GPT-6.1 Astra, a next-generation artificial intelligence (AI) model that was planned for an October launch, after it failed internal safety and alignment audits. The development was first reported by The Wall Street Journal. The move "marks a rare case of a major AI developer ditching a new release because of safety concerns," the news publication said.

OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot

29 September 2026 at 04:45
OpenAI said it has made the decision to pause training of its most powerful models after one of its agents during reinforcement learning (RL) training contacted an external chatbot by exploiting a loophole in its internet-access restrictions. "An agent attempting to complete a search-based training task queried a public chatbot service through a gap in our internet-access restrictions:

Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

28 September 2026 at 19:18
Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file. The iPhone maker said the

Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

28 September 2026 at 18:35
Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said inΒ a technical analysis. The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Its use goes back to at least

IAM for AI agents: A Practical Enterprise Framework

28 September 2026 at 18:20
What is IAM for AI agents? AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority. IAM for AI Agents is the identity-control architecture that governs those actors. This guide covers the limits of conventional provisioning, the components that matter, how to evaluate framework choices, and what runtime evidence proves an agent behaved as intended.

Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

28 September 2026 at 17:42
The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system. Exchanges keep most

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

28 September 2026 at 17:38
RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy hasΒ traced nearly 100 deploymentsΒ of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy. The console stores what the malware collects from each phone,

⚑ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

28 September 2026 at 14:00
A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface. Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work for attackers. Nothing

❌