Cybersecurity and other IT news aggregator

LATEST FEEDS

  • Standard Chartered sees Ethena’s USDe reaching $40B, ENA hitting $2

    Standard Chartered sees Ethena’s USDe reaching $40B, ENA hitting $2 2026-09-30 at 23:57 By Cointelegraph by Nate Kostar The bank also expects Ethena’s ENA token to rise roughly sevenfold to $2 by the end of 2028 as USDe scales and token buybacks increase. This article is an excerpt from Cointelegraph.com News View Original Source


  • Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts and Hunt Indicators

    Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts and Hunt Indicators 2026-09-30 at 23:34 By Sean Shirley With contributions from James Rodriguez, Gus Staminatos, and Timmy Lister. This article is an excerpt from LevelBlue SpiderLabs Blog View Original Source


  • Brazil’s Petrobras uses Cardano to track sustainable aviation fuel, renewable diesel

    Brazil’s Petrobras uses Cardano to track sustainable aviation fuel, renewable diesel 2026-09-30 at 21:28 By Cointelegraph by Nate Kostar Petrobras developed two Cardano-based applications to track sustainability claims tied to aviation fuel and renewable diesel as part of an ongoing research collaboration. This article is an excerpt from Cointelegraph.com News View Original Source


  • Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

    Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets 2026-09-30 at 21:27 By Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team. The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated…


  • Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

    Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks 2026-09-30 at 21:27 By Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content. “Once executed, the legitimate MSP360 installer, distributed under…


  • Better.com founder Vishal Garg claims shareholder victory to oust CEO, board less than 2 months after firing

    Better.com founder Vishal Garg claims shareholder victory to oust CEO, board less than 2 months after firing 2026-09-30 at 20:00 By Ariel Zilber If Better formally accepts the votes as valid, Garg’s group would have enough shareholder support to reshape the board. This article is an excerpt from Latest Technology News | New York Post…


  • ShinyHunters and the New Reality of Identity Theft

    ShinyHunters and the New Reality of Identity Theft 2026-09-30 at 20:00 By The new generation of cybercriminals, exemplified by groups like ShinyHunters, practice a more persistent version of identity theft. This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original Source


  • Bitget ‘gradually back to usual’ as protection fund reaches $309M

    Bitget ‘gradually back to usual’ as protection fund reaches $309M 2026-09-30 at 19:28 By Cointelegraph by Turner Wright Bitget CEO Gracy Chen said that a protection fund created by the company in 2022 “absorbed the financial impact of the incident“ that resulted in $388 million in user losses. This article is an excerpt from Cointelegraph.com…


  • Improving Security Training to Adapt to Modern Phishing Schemes

    Improving Security Training to Adapt to Modern Phishing Schemes 2026-09-30 at 19:00 By Security magazine speaks with with Ron Zayas, Chief Executive Officer at Ironwall by Incogni, about the risks associated with online, publicly accessible information. This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original Source


  • 40M McDonald’s Records Exposed Through Customer Data Platform

    40M McDonald’s Records Exposed Through Customer Data Platform 2026-09-30 at 18:40 By McDonald’s Indonesia exposed more than 40 million records.  This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original Source


  • Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

    Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager 2026-09-30 at 18:24 By Attackers are exploiting a critical flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an advisory on September 30. The flaw, CVE-2026-76504, could allow a remote attacker with no login access to…


  • Anthropic co-founder Daniela Amodei and husband used stuffed-animal ‘advisory council’ for workplace conflicts: report

    Anthropic co-founder Daniela Amodei and husband used stuffed-animal ‘advisory council’ for workplace conflicts: report 2026-09-30 at 18:05 By Ariel Zilber Anthropic co-founder Daniela Amodei used stuffed animals to work through office problems, giving them names and personalities for “managerial role-playing,” according to a report. This article is an excerpt from Latest Technology News | New…


  • Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures

    Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures 2026-09-30 at 18:00 By Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026, said it marks…


  • Know Your Enemy: Browser-Based Attack Techniques in 2026

    Know Your Enemy: Browser-Based Attack Techniques in 2026 2026-09-30 at 17:11 By Given that the browser is where business apps are accessed and used, it makes sense that attacks are happening there too. Most breaches today begin in a browser session. Often, they never leave it, with the entire attack chain from initial access to…


  • Google: AI Is Changing the Pace and Profile of Vulnerability Discovery

    Google: AI Is Changing the Pace and Profile of Vulnerability Discovery 2026-09-30 at 17:05 By Eduard Kovacs Google’s analysis found that AI-discovered vulnerabilities are more likely to enable remote code execution. The post Google: AI Is Changing the Pace and Profile of Vulnerability Discovery appeared first on SecurityWeek. This article is an excerpt from SecurityWeek…


  • Could THORChain face prosecution over stolen Bitget funds?

    Could THORChain face prosecution over stolen Bitget funds? 2026-09-30 at 16:30 By Cointelegraph by Andrew Fenton THORChain will not — or can not — block addresses linked to the $387.5 million Bitget hack. Can the devs be prosecuted for money laundering? It’s complicated, says crypto lawyer Yuriy Brisov. This article is an excerpt from Cointelegraph.com…


  • WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

    WatchGuard Patches Critical Fireware OS Code Injection Vulnerability 2026-09-30 at 16:16 By Ionut Arghire WatchGuard has rolled out patches for 15 code execution, DoS, authorization, and path traversal bugs in Fireware OS. The post WatchGuard Patches Critical Fireware OS Code Injection Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original…


  • Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks

    Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks 2026-09-30 at 15:48 By Eduard Kovacs Several security firms have confirmed seeing exploitation of the NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772. The post Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)

    Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772) 2026-09-30 at 15:33 By Zeljka Zorz “Advanced and suspected state-sponsored threat actors” are likely to be behind the initial targeted intrusions that leveraged CVE-2026-88772, one of the two recently disclosed NetScaler vulnerabilities that have been exploited as zero-days, says Mandiant CTO Charles Carmakal. Mandiant and…


  • Chrome, Firefox Updates Patch Over 100 Vulnerabilities

    Chrome, Firefox Updates Patch Over 100 Vulnerabilities 2026-09-30 at 15:16 By Ionut Arghire Some of the flaws could allow remote attackers to execute arbitrary code or escape the browser sandbox. The post Chrome, Firefox Updates Patch Over 100 Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • FCA opens crypto authorization window ahead of 2027 UK regime

    FCA opens crypto authorization window ahead of 2027 UK regime 2026-09-30 at 15:06 By Cointelegraph by Yohan Yun Crypto businesses should apply by Feb. 28, 2027, while existing money laundering registrations will not convert into FCA authorization. This article is an excerpt from Cointelegraph.com News View Original Source


  • AI coding agents leaked 13,000 internal company screenshots to public GitHub repos

    AI coding agents leaked 13,000 internal company screenshots to public GitHub repos 2026-09-30 at 14:52 By Sinisa Markovic When developers ask AI coding agents to prove that a user interface fix works, some agents have been posting the evidence where anyone can find it, according to Glow Labs. Diagram showing how AI agents leak screenshots…


  • AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub

    AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub 2026-09-30 at 14:30 By AI coding agents asked to share screenshots of code changes for review have put internal company images in public GitHub repositories, security company Glow said. Its researchers found more than 13,000 internal images from developers at over 300 organizations,…


  • Altcoin exchange deposit count jumps 160% in 2 weeks

    Altcoin exchange deposit count jumps 160% in 2 weeks 2026-09-30 at 14:23 By Cointelegraph by William Suberg CryptoQuant flagged potential selling pressure as deposit transactions and depositing addresses hit their highest counts since October 2025. This article is an excerpt from Cointelegraph.com News View Original Source


  • Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit

    Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit 2026-09-30 at 14:19 By Eduard Kovacs Attacks by autonomous AI agents are moving out of the lab and into the courtroom, raising unsettled questions about who is liable for what agents do. The post Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking…


  • A single market worth protecting: Getting the MiCA review right

    A single market worth protecting: Getting the MiCA review right 2026-09-30 at 14:00 By Cointelegraph by Simon Schneider As the European Commission’s MiCA review consultation closes, Europe must decide whether its crypto rulebook is protecting the market without making it too costly to build in. This article is an excerpt from Cointelegraph.com News View Original…


  • Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks

    Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks 2026-09-30 at 13:59 By Ionut Arghire The state-sponsored group has launched larger-scale phishing campaigns to deploy the CosmicPulse backdoor. The post Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View…


  • US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

    US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access 2026-09-30 at 13:45 By ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft…


  • OpenInfra Europe’s JFrog Artifactory instance breached, packages potentially compromised

    OpenInfra Europe’s JFrog Artifactory instance breached, packages potentially compromised 2026-09-30 at 13:39 By Zeljka Zorz Attackers have compromised a self-hosted JFrog Artifactory instance operated by OpenInfra Europe, the regional hub of the OpenInfra Foundation warned in a security notice prominently displayed on its homepage. OpenInfra Europe’s security incident notice “Anyone who downloaded or installed artifacts…


  • ShinyHunters Defiant After FBI Calls on Members to Come Forward

    ShinyHunters Defiant After FBI Calls on Members to Come Forward 2026-09-30 at 13:20 By Ionut Arghire In the wake of a suspected leader’s arrest, ShinyHunters says it never intended to publish data stolen from the FBI. The post ShinyHunters Defiant After FBI Calls on Members to Come Forward appeared first on SecurityWeek. This article is…


  • Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

    Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT 2026-09-30 at 13:16 By Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG)…


  • OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted

    OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted 2026-09-30 at 13:16 By A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if…


  • SlowMist traces Bitget hack activity to Aug. 31 zero-day exploit

    SlowMist traces Bitget hack activity to Aug. 31 zero-day exploit 2026-09-30 at 13:05 By Cointelegraph by Ezra Reguerra SlowMist identified malicious activity weeks before the Bitget theft, involving a zero-day vulnerability, two security products and a custom withdrawal tool. This article is an excerpt from Cointelegraph.com News View Original Source


  • Signal brings encrypted local backups to iOS and desktop, adds cross-platform restore

    Signal brings encrypted local backups to iOS and desktop, adds cross-platform restore 2026-09-30 at 12:31 By Sinisa Markovic Signal users who switch from an Android phone to an iPhone, or the other way around, can take their message history with them, and backups can be restored on Android, iOS, Linux, macOS and Windows. The option…


  • Former US Air Force members behind million-dollar BEC scheme head to prison

    Former US Air Force members behind million-dollar BEC scheme head to prison 2026-09-30 at 10:42 By Sinisa Markovic Two men who ran BEC and phishing campaigns against US businesses while serving in the Air Force have been sentenced to a combined 189 months in federal prison. According to public documents and evidence presented at sentencing,…


  • European stablecoin issuer AllUnity launches USD stablecoin USDAU

    European stablecoin issuer AllUnity launches USD stablecoin USDAU 2026-09-30 at 10:00 By Cointelegraph by Helen Partz AllUnity is launching USDAU, its fourth fiat-backed stablecoin, expanding a MiCA-regulated lineup that already covers the euro, Swiss franc and Swedish krona. This article is an excerpt from Cointelegraph.com News View Original Source


  • High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL

    High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL 2026-09-30 at 09:55 By Eduard Kovacs Roughly a dozen vulnerabilities have been patched in each of the open source cryptographic libraries.  The post High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • Genea brings AI agents to access control with role-based permissions

    Genea brings AI agents to access control with role-based permissions 2026-09-30 at 09:49 By Industry News Genea has announced the release of Genea MCP, a Model Context Protocol (MCP) server that connects AI agents directly to the Genea Access Control platform. Onboarding a new hire, setting up a contractor for two weeks, or unlocking the…


  • Security tools can now scan Claude Enterprise chats and uploads for sensitive data

    Security tools can now scan Claude Enterprise chats and uploads for sensitive data 2026-09-30 at 09:31 By Anamarija Pogorelec More than 100 security and compliance vendors have integrations with the Claude Compliance API, which lets a company send Claude activity into the monitoring tools it already uses. CrowdStrike, Microsoft Purview, Splunk, Palo Alto Networks, Cloudflare…


  • OWASP Noir: Open-source static analysis tool

    OWASP Noir: Open-source static analysis tool 2026-09-30 at 08:30 By Anamarija Pogorelec OWASP Noir is an open-source static analysis tool that reads an application’s source code and lists the endpoints it exposes: paths, HTTP methods, parameters, headers, and cookies, each tied to the file and line it came from. Here’s where it gets useful. Shadow…


  • Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

    Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution 2026-09-30 at 08:30 By Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as…


  • EU Cyber Resilience Act requirements for containers and Kubernetes

    EU Cyber Resilience Act requirements for containers and Kubernetes 2026-09-30 at 08:00 By Help Net Security Starting in full force on Dec. 10, 2024, the EU Cyber Resilience Act (CRA) is a regulation (EU 2024/2847) that defines mandatory cybersecurity requirements for all products with digital elements sold in EU markets. Reporting obligations will begin on Sept. 11, 2026,…


  • Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development

    Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development 2026-09-30 at 04:48 By Associated Press The accord opened the door to future regulation but focused on four voluntary steps for the companies to take. The post Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development appeared first on SecurityWeek.…


  • Trump accord calls for tech firms to ‘self police’ their own frontier AI

    Trump accord calls for tech firms to ‘self police’ their own frontier AI 2026-09-30 at 03:28 By Cointelegraph by Felix Ng The voluntary accord puts much of the responsibility for managing frontier AI risks on developers. This article is an excerpt from Cointelegraph.com News View Original Source


  • 11 more women allegedly abused by tech honchos come forward after Post’s Silicon Valley ‘sex assault list’ expose

    11 more women allegedly abused by tech honchos come forward after Post’s Silicon Valley ‘sex assault list’ expose 2026-09-30 at 00:41 By Vivi Lin “We need another MeToo movement for the tech community,” one tech worker told The Post. This article is an excerpt from Latest Technology News | New York Post View Original Source


  • Meta releases new ‘secret weapon’ Muse assistant aimed at small businesses

    Meta releases new ‘secret weapon’ Muse assistant aimed at small businesses 2026-09-30 at 00:23 By Will Zimmerman Muse for Small Business, available both online and in the app store in the U.S. and Canada, is an extension of the artificial intelligence product Meta launched earlier in September for personal use. This article is an excerpt…


  • OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference

    OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference 2026-09-29 at 23:14 By Associated Press Altman made a slew of product announcements and updates, including the company’s new agents, called Dots. The post OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference appeared…


  • Crypto regulation at SEC, CFTC to come down to 3 commissioners following key resignation

    Crypto regulation at SEC, CFTC to come down to 3 commissioners following key resignation 2026-09-29 at 22:59 By Cointelegraph by Turner Wright Seven commissioner seats at the SEC and CFTC will be empty after Friday, leaving only a few leaders at financial regulators to oversee aspects of the $3 trillion crypto industry. This article is…


  • OpenAI valuation could hit $1.4T in new funding round: Report

    OpenAI valuation could hit $1.4T in new funding round: Report 2026-09-29 at 22:55 By Cointelegraph by Sam Bourgi OpenAI is reportedly seeking another $30 billion from investors as the ChatGPT developer pushes its long-awaited public market debut into 2027. This article is an excerpt from Cointelegraph.com News View Original Source


  • Kakaopay partners with Dinari, Ondo to explore tokenized Korean stocks

    Kakaopay partners with Dinari, Ondo to explore tokenized Korean stocks 2026-09-29 at 22:49 By Cointelegraph by Nate Kostar Kakaopay Securities is working with Dinari and Ondo Finance to explore tokenizing Korean-listed equities and expanding their availability to investors in international markets. This article is an excerpt from Cointelegraph.com News View Original Source


Browse older archives

Scroll to Top