Tel Aviv, Israel, 30th September 2026, CyberNewswire
Opsec Fail Leaks a Rare Look Inside a Media-Buy-Powered Scam Operation
Inside the leaked Keitaro-powered backend of a cloaked investment scam targeting South Africa.
MetaMask Takes Precautionary Action After Infrastructure Security Incident
Crypto wallet provider MetaMask is taking precautions following a security incident impacting one of its infrastructures as it deals with the consequences…
Microsoft: AI Cuts Post-Compromise Attack Time to Minutes
Microsoft has warned that threat actors have gained the advantage over defenders by using AI to enhance the speed and scale of attacks
Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570
Microsoft Threat Intelligence examines CVE-2026-73570 exploitation in Zimbra, including observed attack paths, detection opportunities, and mitigation…
Cyber Briefing: 2026.10.02
Shadow AI exposure, healthcare tracking disputes, a hijacked Microsoft X account, accelerated vulnerability-reporting requirements, an Iranian hacking…
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks,…
Six arrests for smuggling migrants via Schengen airports
Europol supported a migrant smuggling investigation involving law enforcement authorities from 17 countries. The criminal network was also engaged in…
IBM’s Bob wants to move in: Agent available for on-prem deployment
Bob, IBM’s agentic software development platform is now available to run on premises and in private clouds, sovereign clouds, and air-gapped environments…
Hackers Turned a Microsoft SQL Server Into a Command and Data Exfiltration Channel
Hackers turned a Microsoft SQL Server into a channel for running commands and moving collected files in an intrusion linked to a Viva Aerobus environment.…
MCP Python SDK Flaw Exposes OAuth Credentials
A high-severity security vulnerability in the official Model Context Protocol (MCP) Python SDK could allow malicious MCP servers to steal OAuth…
Critical Red Hat Satellite Flaw Could Enable Root Password Theft and Code Execution Attacks
Red Hat has fixed a high-impact vulnerability in Red Hat Satellite that could allow a low-privileged authenticated user to access sensitive host…
Chrome, Firefox Updates Patch Over 100 Vulnerabilities
Google and Mozilla have released major security updates for Chrome and Firefox, collectively patching more than 100 vulnerabilities across both browsers.
Hackers Poison Trusted Software Updates to Steal Developer and Cloud Credentials
Hackers are turning trusted software updates into a route for stealing developer and cloud credentials. Recent supply chain incidents show how a single…
Federal Agencies Disrupt Ransomware Gang Involving A 16-Year Old Member
An international law enforcement operation known as “Operation KillSwitch” seized the KillSec ransomware gang’s data leak site and servers, resulting in…
Multiple Cpanel/WHM Vulnerabilities Allow Arbitrary Command Execution On Server
Multiple security flaws in cPanel & WHM could let attackers run malicious scripts in an administrator’s browser session or execute arbitrary commands as…
Cyber Briefing: 2026.09.30
Executive phishing, browser flaws, and AI-assisted development workflows are creating paths to account compromise, system exploitation, and unintended…
OpenClaw Launches Free Open-source Enterprise Agent Platform for AI Agents
OpenClaw has launched OpenClaw Enterprise (OCE), a free, open-source platform that helps organizations run persistent AI agents with stronger security and…
Oracle launches Fusion Claw AI agentic runtime
Oracle has introduced Fusion Claw, a governed agentic execution runtime designed to automate complex business processes for Oracle Fusion Applications…
Jailbreaking AI: What It Is and Why It Matters for Security
By HOC Team | Updated: October 2026 Read time: ~20 min In March 2023, a researcher posted…
AI Coding Agents Leak 13K Internal Images on GitHub
Security firm Glow has uncovered a widespread data exposure incident involving AI coding assistants that inadvertently published thousands of sensitive…
Sony PS5 Relapse Jailbreak Exploit Uses JSC Memory Corruption and Kernel UAF
A newly released PlayStation 5 jailbreak chain, called Relapse, targets PS5 and PS5 Pro consoles running firmware versions 7.00 through 13.60. This…
Signal adds encrypted backups, cross-platform restore
Signal has finished rolling out cross-platform encrypted backup capabilities with iOS version 8.30, enabling users to transfer their complete message…
Cybercriminals Misuse ChatGPT Custom GPTs in ClickFix RAT Attacks
ChatGPT Custom GPTs are being abused by threat actors as an entry point for malware campaigns, redirecting users to malicious websites using fake…
