11 posts published in the last hour 19:31Gemini 4 enters the ring, MI5 flags research ties, Custom GPTs deliver malware 19:31Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path 19:31‘North Korean’ Attackers Steal $387.5m From Bitget…
Gemini 4 enters the ring, MI5 flags research ties, Custom GPTs deliver malware
Gemini 4 starts with cybersecurity MI5 flags Chinese research funding Custom GPTs steer users into ClickFix attacks Get the show notes here:…
Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in…
‘North Korean’ Attackers Steal $387.5m From Bitget
Exchange Bitget resumes transactions after suspected North Korean attackers carry out biggest single crypto heist so far this year
Halfway is No Way: Why DSPM Fails if it Can Detect, But Not Respond
Halfway is No Way: Why DSPM Fails if it Can Detect, But Not Respond andrew.gertz@t… Wed, 09/30/2026 – 20:13 Data Security Todd Moore | Global VP of Data…
Sydney Data Centre Plan Withdrawn After Protests
Developer Goodman Group pulls plan for 90 MW data centre that it intended to build in Sydney suburb near homes, schools
Warlock ransomware breach SharePoint in water, telecom operator attacks
The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting…
What enterprises need to know about the Cyber Resilience Act and software supply chain risk
In part 1 of this series, we examined why enterprises need more than an inventory of the open source components in their software. Understanding where…
Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security…
ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)
Threat Actors do not always use top-notch techniques or very complex malware to perform their attacks. Sometimes, they just abuse of existing…
What enterprises need to know about the software they depend on
Knowing an application contains open source components is not the same as understanding the software and communities behind them.For many organizations,…
IT Security News Hourly Summary 2026-10-02 21h : 10 posts
10 posts published in the last hour 18:31Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents 18:31Fire That Killed Four Linked To Lithium-Ion Battery 18:31MetaMask Security Incident Prompts Exit of Affected Ethereum Validators…
Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents
Apple says it will add new controls around macOS’s Full Disk Access permission, warning that increasingly capable AI agents make broad access to users’…
Fire That Killed Four Linked To Lithium-Ion Battery
Electrical event caused lithium-ion battery to go into thermal runaway, sparking intense fire that killed mother, three children
MetaMask Security Incident Prompts Exit of Affected Ethereum Validators
MetaMask on Thursday said it’s responding to what it described as an “ongoing security incident” impacting part of its infrastructure. “We are actively…
Most Enterprises Are Unprepared for AI and Quantum Threats, PwC Survey Finds
Most organizations around the world are spending more on cybersecurity than at any point in their history. Very few are spending it on the threats that…
Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad…
OpenAI alerts 100+ orgs that its ‘misaligned models’ attempted to break in – or worse
Mostly ‘routine research tasks,’ and ‘some involved government websites, which our models often use,’ AI giant tells The Reg
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
A critical flaw in GitLab’s AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions,…
The legal questions raised by agentic AI hacks
Experts and policymakers want AI companies to face consequences for agentic hacks. There may not be a clear-cut answer under existing laws and regulations.
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which…
IT Security News Hourly Summary 2026-10-02 20h : 7 posts
7 posts published in the last hour 17:31Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response 17:31Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs 17:01ISC Stormcast For Thursday, October 1st, 2026 https://isc.sans.edu/podcastdetail/10118, (Thu, Oct 1st) 17:01Exabeam…
Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response
One company told customers to power down its data-protection platform during a nine-hour window, while the other remained mum on reported attacks prior to…
Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs
Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to…
