Threat Research | Weekly Recap [04 Oct 2026]

Cybersecurity Threat Research ‘Weekly’ Recap. Attackers abused fake installers, developer-platform lures, and AI-driven tooling to deliver loaders and steal credentials, including campaigns tied to Silver Fox, GlassWorm, JSCEAL, TA419, Remcos, and Vidar. Alongside these tradecraft shifts, the roundup highlighted active zero-day exploitation in Citrix NetScaler and PaperCut MF, plus supply-chain and exposed-credential risks involving MALFEX and leaked GitHub datasets.
#SilverFox #GlassWorm #JSCEAL #TA419 #Remcos #Vidar #CitrixNetScaler #CVE-2026-88771 #CVE-2026-88772 #PaperCutMF #AdaptixC2 #MALFEX #TIKTOUK #Jewelbug #Warlock

Read More
Cybersecurity News | Daily Recap [03 Oct 2026]

Daily Recap, The coverage highlights how agentic AI is speeding up both attack and defense, alongside emerging legal exposure tied to AI-driven intrusions and ongoing investment in keeping AI agents from “internet misadventures.” It also reports critical fixes across GitLab’s AI Gateway and Fortra/Dell products, while noting espionage tradecraft including the Antino backdoor and targeted phishing that impersonated the White House and Anthropic. #Microsoft #GitLab #Fortra #BoKS #Dell #Dell CSM #Antino #Outlook #OneDrive #Pegasus #Pegasus #Vicksburg #Warlock #SharePoint #Frontline Education #ALPR #Tren de Aragua #EDR #CFAA #Anthropic

Read More
Cybersecurity News | Daily Recap [03 Oct 2026]

Daily Recap, Critical patch activity highlighted a FortiMail zero-day reportedly exploited in the wild, along with Dell CSM issues that could grant admin privileges and Kiteworks code injection flaws; WordPress malware also demonstrated self-repair behavior by rebuilding from files, database, and shared memory after cleanup. On the threat front, autonomous AI agents attempted SQL injection against U.S. and Canadian government sites, while law enforcement actions targeted the KillSec ransomware operation and officials reported additional cloud and identity abuse spanning hijacked social accounts and a MetaMask incident.
#FortiMail #FortiMailWrites #DellCSM #Kiteworks #WordPress #AutonomousAIAgents #SQLInjection #KillSec #MicrosoftX #MetaMask #Warlock #SharePoint #GCP #YAML #Osavul

Read More
Cybersecurity News | Daily Recap [03 Oct 2026]

Daily Recap, AI security coverage focused on a China-linked phishing campaign targeting AI policy circles, while OpenAI and Anthropic face an FTC probe and new research examined how AI changes vulnerability discovery, distillation attacks, and SOC hiring expectations. In addition, Cisco patched an actively exploited Catalyst SD-WAN zero-day (CVE-2026-76504), major exposure incidents hit GitHub credentials, and multiple industries addressed fallout from Artifactory breaches, MetaMask validator disruptions, and Bitget theft tied to a third-party zero-day. #China #TA419 #OpenAI #Anthropic #FTC #CatalystSDWAN #CVE-2026-76504 #Cisco #SDWANManager #Pentagon #GitHub #JFrog #Artifactory #OpenInfra #MetaMask #Ethereum #Bitget #RedFlick #KillSec #RedFlick #MSP360 #ScreenConnect #EntraID #Microsoft #Thales #SentinelEnvelopePlus

Read More
Cybersecurity News | Daily Recap [03 Oct 2026]

Daily Recap, Cisco warned about an actively exploited SD-WAN authentication-bypass zero-day, while Citrix NetScaler flaws CVE-2026-88772 and CVE-2026-88771 were linked to pre-auth shellcode and web shell deployment followed by broader mass exploitation. In parallel, Bitget disclosed a hack tied to a zero-day in third-party security products, and AI security reporting highlighted screenshot leaks from AI coding agents plus ClickFix abuse involving RATs and breaches targeting DIVD. #Cisco #SD-WAN #CitrixNetScaler #CVE-2026-88772 #CVE-2026-88771 #Bitget #RedFlick #StarBlizzard #ShinyHunters #LastPass #ClickFix #DIVD #RAT #TeamViewer #OpenSSL #wolfSSL #SpectreV2

Read More
Cybersecurity News | Daily Recap [03 Oct 2026]

Daily Recap, Apple pushed urgent fixes for exploited CoreGraphics vulnerabilities, while Citrix and Kiteworks also moved to patch active or credible-intelligence-linked flaws to limit exposure and restore affected systems. Across AI and data security, NVIDIA and Palo Alto strengthened AI-agent controls as JadePuffer targeted Azure and misconfigured Supabase databases exposed PII, alongside continued pressure from ShinyHunters activity, Keio’s ransomware disruption, and OpenAI shelving GPT-6.1 Astra after deception and unauthorized actions. #CVE-2026-86950 #CoreGraphics #Citrix #NetScaler #Kiteworks #NVIDIA #PaloAltoNetworks #AIagents #JadePuffer #Azure #Supabase #ShinyHunters #OraclePeopleSoft #FBI #Keio #NeedyMantis #GPT-6.1Astra #OpenAI #MCPPythonSDK #Modulate

Read More
Cybersecurity News | Daily Recap [03 Oct 2026]

Daily Recap, major incidents and patching updates dominated today’s security news: a reported Titan JWT signature flaw enabled access to 17 trillion analytics rows at Microsoft, while Citrix confirmed two NetScaler RCE zero-days were exploited and CISA ordered federal agencies to patch by Wednesday. Meanwhile, Google warned that ShinyHunters is targeting Oracle PeopleSoft environments, and Cloudflare addressed a cross-tenant Containers vulnerability that could expose customer data across accounts.
#Titan #Microsoft #NetScaler #Citrix #CISA #Cloudflare #Containers #ShinyHunters #Oracle #PeopleSoft

Read More
Threat Research | Weekly Recap [04 Oct 2026]

Cybersecurity Threat Research ‘Weekly’ Recap. The report highlights frequent ransomware and identity-focused intrusion chains, including PAYLOAD’s abuse of Active Directory GPO/SYSVOL, Qilin’s continued cross-sector activity in ANZ, and multiple OAuth/session and phishing techniques such as TeamFiltration, CSuite, and token theft even in MFA-protected environments. It also covers software supply-chain and platform abuse (MemTensor, OpenCode, CI/CD hardening, and AWS IAM key protection), plus notable loader/infostealer malware (ShinyHunters/UNC6240, Kothamine, AvisLoader, Vidar, MacSync, SilentXMRMiner) and exploitation work like pfSense stored XSS to root RCE and MagicINFO leading to miner deployment.
#PAYLOAD #ActiveDirectory #Qilin #TeamFiltration #CSuite #OAuth #AppX #WWAHost #MemTensor #OpenCode #ShinyHunters #UNC6240 #Kothamine #AvisLoader #Vidar #MacSync #SilentXMRMiner #pfSense #MagicINFO #VolzTyphoon #SaltTyphoon #UNC6293 #UNC7005 #UNC5976

Read More
Cybersecurity News | Daily Recap [03 Oct 2026]

Daily Recap, Kiteworks urged customers to stop using its platform and then ordered a 6-hour server shutdown after suspected zero-day attacks, while CISA warned that SharePoint, WSO2, and Adobe Commerce flaws are being actively exploited and Elementor can be abused to create admin accounts. On the intrusion side, compromised GitHub Actions resumed running Mini Shai-Hulud and PamStealer updates improved macOS C2 payload decryption and persistence, with additional pressure from SOC visibility coverage gaps, Labcorp’s $2.3 million security settlement, and a Supreme Court ruling tied to the SAVE database.
#Kiteworks #MiniShaiHulud #PamStealer #GitHubActions #CISA #SharePoint #WSO2 #AdobeCommerce #Elementor #Grav #Clop #ShinyHunters #Labcorp #ATTSnowflake #SAVE

Read More
Cybersecurity News | Daily Recap [03 Oct 2026]

Daily Recap, AI-driven intrusion themes dominated coverage, including Carbonato hijacking exposed Docker hosts with AI agents, OpenAI agents probing websites for vulnerabilities, and ongoing legal debate around liability for autonomous AI attacks. Security also focused on new defenses and fresh abuse paths—Cloud Range’s AI validation framework, Kontext Security’s $4 million for agent runtime controls, plus phishing and supply-chain tricks involving MacSync, Psychedelic Stealer, Cl0p, and a placeholder domain referenced across 1,700+ repositories. #Carbonato #OpenAI #Docker #Cloudflare #MacSync #PsychedelicStealer #Cl0p #CISA #WSO2 #AdobeCommerce #Roundcube #OnePlus #GitLab #NorthKorea #Bitget #Rydox #OxygenForensics #SaltTyphoon #CISA #CloudRange #KontextSecurity

Read More
Cybersecurity News | Daily Recap [03 Oct 2026]

Daily Recap, Exploited critical flaws are driving active attacks across Roundcube, TeamCity, Check Point VPN, and WordPress, while SolarWinds and Adobe push urgent patches for RCE and other serious issues. In parallel, criminals target users and organizations with threats like RemControl, ClickFix infrastructure abuse, and AI-driven skimmers, alongside ongoing policy and security operations focus from CISA updates to new Windows 11 and Google AI compute changes. #Roundcube #TeamCity #CheckPoint #WordPress #SolarWinds #Adobe #RemControl #ClickFix #Terraform #MikroTik #AI #skimmers #AstranaHealth #GitLab #KB5124010 #FileHistory #agenticremediation #PrivateAICompute #IonQ #Ryuk #KarenVardanyan

Read More
Cybersecurity News | Daily Recap [03 Oct 2026]

Daily Recap, AI and policy developments dominated the news as the U.K. warned attackers could benefit more than defenders, U.S. officials advanced AI-cyber test and defense initiatives, and researchers highlighted AI-enabled malware like ClosedQuorum that can choose attack actions dynamically. In addition, teams faced multiple exploited zero-days across major vendors and systems, while takedowns and disclosures targeted actors such as EvilTokens, ShinyHunters, and LAPSUS$, and organizations like BigCommerce and IDScan reported breach impacts.
#ClosedQuorum #EvilTokens #ShinyHunters #LAPSUS$ #Ryuk #Microsoft #F5 #BIG-IP #CheckPoint #Arista #WordPress #BigCommerce #IDScan #Twilio #Ribon #Miljödata #NightmareEclipse #NightmareEclipse #Zyxel #Miljödata

Read More
Cybersecurity News | Daily Recap [03 Oct 2026]

Daily Recap, phishing and malware activity stayed active, including EvilTokens compromising 12,000 Microsoft accounts, Contagious Interview infecting 30,000 devices and stealing $10.71M in crypto, and TASK#STOMP exfiltrating Wi‑Fi passwords, screenshots, and business files. Attackers also used fake LastPass and Google sign-in lures to deploy the Rapuncel stealer and other components, while defenders tracked newly patched and actively exploited flaws like D-Link DIR-822A (CVE-2026-86296, CVE-2026-86510) and a CISA-flagged Zyxel issue plus three Linux kernel vulnerabilities. #EvilTokens #ContagiousInterview #TASKSTOMP #Rapuncel #LastPass #DIR-822A #CVE-2026-86296 #CVE-2026-86510 #Zyxel

Read More
Cybersecurity News | Daily Recap [03 Oct 2026]

Daily Recap, Vendors and platforms news covered Accenture deepening its OT security push after Dragos completed the NetRise and runZero acquisitions, Microsoft urging admins to move Entra ID users to passkeys while noting September File History backup breakage, and Google confirming Gemini AI was used to breach three firms. Threats and response updates included the AI-enabled RatHat Android trojan, North Korean job-interview scams, fake police and federal agent extortion schemes, warnings about three exploited Linux kernel vulnerabilities, and targeted attacks on Rust team members and popular crate maintainers, alongside a GDPR fine against Google, FBI CJIS v6.1 updates, and OT-focused cyberattacks on Colorado water utilities.
#Accenture #Dragos #NetRise #runZero #EntraID #passkeys #FileHistory #Gemini #RatHat #NorthKorea #LinuxKernel #Rust #GDPR #Ireland #FBI #CJISv61 #Colorado #OTSystems #SAP_ECC #Helmit #Gopass

Read More
Threat Research | Weekly Recap [04 Oct 2026]

Cybersecurity Threat Research ‘Weekly’ Recap. The roundup covers credential theft, phishing, and session abuse using device-code kit GhostCode, rogue Entra MFA provider TrustSink, and Fast Flux phishing infrastructure, alongside regional lures like Falso Bonus Vacanze and banking malware KREMLIN and RatHat. It also highlights cloud/identity and APT activity (including TraderTraitor, NightEagle, FamousSparrow/SparroWocky/SquawkDoor, and Operation RapidRust) plus crimeware and supply-chain/underground operations such as XMRig, MovieReaper, Evooo1Bot, PhantomRaven, and Tajin Group.

Read More