Source context

Why this day matters

  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active
  • Explore this source record from Anthropic. Follow the canonical source link to read the original publication.
Validated article intelligence

Enriched source records

Expand a row to inspect claims and citations

Luna-generated claims retained by the evidence and claim-validation gates. Automated validation does not imply human review. A record does not need a CVE to be included.

Luna-enriched source article · helpnetsecurity

Cybersecurity jobs available right now: September 22, 2026

An Optimum on-site U.S. Analyst Threat Intelligence role involves collecting and analyzing intelligence on threats, threat actors, malware campaigns, and relevant tactics, techniques, and procedures.

3 retained claims3 cited excerpts

Source published Sep 22, 2026, 4:00 AM UTC · Evidence retrieved Sep 22, 2026, 8:51 AM UTC

What happened

An Optimum on-site U.S. Analyst Threat Intelligence role involves collecting and analyzing intelligence on threats, threat actors, malware campaigns, and relevant tactics, techniques, and procedures. [1]

The role includes mapping adversary behavior to MITRE ATT&CK, producing actionable reports and alerts, supporting incident response and threat hunting, and maintaining threat intelligence platforms. [2]

The article also lists an Application Security Specialist position at SMBC Group in Ireland with a hybrid work arrangement. [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Analyst Threat Intelligence Optimum | USA | On-site – View job details As an Analyst Threat Intelligence, you will collect and analyze intelligence to identify threats, threat actors, malware campaigns, and relevant TTPs.
  2. [2]
    You will map adversary behavior to MITRE ATT&CK, produce actionable reports and alerts, support incident response and threat hunting, and maintain threat intelligence platforms.
  3. [3]
    Application Security Specialist SMBC Group | Ireland | Hybrid – View job details As an Application Security Specialist, … More → The post Cybersecurity jobs available right now: September 22, 2026 appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · helpnetsecurity

European AI spending is on track to reach nearly $470 billion by 2030

IDC forecasts that European organizations will spend nearly $470 billion on AI in 2030, with spending growing at a 35% compound annual rate from 2025.

5 retained claims5 cited excerpts

Source published Sep 22, 2026, 4:30 AM UTC · Evidence retrieved Sep 22, 2026, 8:51 AM UTC

What happened

IDC forecasts that European organizations will spend nearly $470 billion on AI in 2030, with spending growing at a 35% compound annual rate from 2025. [1]

At that projected growth rate, the European AI market would more than quadruple over five years. [2]

Generative AI is projected to account for 55.4% of total European AI spending by 2030. [3]

The article identifies agentic AI as the main driver of the projected spending growth. [4]

Why it matters

Companies are moving from single-purpose copilots toward multiple agents working together while operating under the EU AI Act. [5]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    European organizations will spend nearly $470 billion on AI in 2030, IDC forecasts, with spending growing at a compound annual rate of 35% from 2025.
  2. [2]
    At that rate, the market more than quadruples in five years.
  3. [3]
    Generative AI will account for 55.4% of the total by 2030.
  4. [4]
    agentic AI is the main driver.
  5. [5]
    Companies are moving from single-purpose copilots to several agents working together, and they are doing it under the EU AI Act, whose … More → The post European AI spending is on track to reach nearly $470 billion by 2030 appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · helpnetsecurity

Passwork NIS2 efficiency guide: Save your team hours before the 2026 audit

By the second half of 2026, national competent authorities across the EU are actively reviewing NIS2 compliance documentation.

4 retained claims3 cited excerpts

Source published Sep 22, 2026, 5:00 AM UTC · Evidence retrieved Sep 22, 2026, 8:51 AM UTC

What happened

By the second half of 2026, national competent authorities across the EU are actively reviewing NIS2 compliance documentation. [1]

Under Article 20(1), senior management at essential and important entities can be held personally liable for infringements. [2]

Why it matters

The source characterizes potential personal liability as a factor that tends to concentrate executive attention. [2]

ENISA’s 2025 NIS Investments report found that 34% of EU organizations report severe skills shortages in IAM implementation. [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    By the second half of 2026, national competent authorities across the EU are actively reviewing NIS2 compliance documentation.
  2. [2]
    Under Article 20(1) of the directive, senior management at essential and important entities can be held personally liable for infringements — a detail that tends to concentrate executive attention.
  3. [3]
    ENISA’s 2025 NIS Investments report found that 34% of EU organizations report severe skills shortages specifically in identity and access management (IAM) implementation.

Read the original article →

Luna-enriched source article · the hacker news

Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

CISA added a now-patched vulnerability affecting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation.

3 retained claims2 cited excerpts

Source published Sep 22, 2026, 5:31 AM UTC · Evidence retrieved Sep 22, 2026, 7:23 AM UTC

What happened

CISA added a now-patched vulnerability affecting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. [1]

The vulnerability is identified as CVE-2026-7273 and has a CVSS score of 8.8. [2]

CVE-2026-7273 is described as a stack-based buffer overflow vulnerability that could result in arbitrary operating… [2]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
  2. [2]
    The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow vulnerability that could result in arbitrary operating

Read the original article →

Luna-enriched source article · helpnetsecurity

A cheap fake base station can still track 5G subscribers

Researchers built 5G-Shark, a low-cost tool that lures phones to a fake base station and questions them, then used it to audit commercial 5G networks.

3 retained claims3 cited excerpts

Source published Sep 22, 2026, 6:30 AM UTC · Evidence retrieved Sep 22, 2026, 8:51 AM UTC

What happened

Researchers built 5G-Shark, a low-cost tool that lures phones to a fake base station and questions them, then used it to audit commercial 5G networks. [1]

On the tested standalone-5G networks, operators correctly concealed phones’ permanent identities in all but one case. [2]

The tested networks nevertheless issued temporary identifiers in a pattern predictable enough for an observer to track 5G subscribers. [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Researchers from the i2CAT Foundation, the University of Murcia, and NEC Laboratories Europe built a low-cost tool called 5G-Shark that lures a target phone onto a fake base station and questions it, then used it to audit commercial 5G networks.
  2. [2]
    On the standalone-5G networks they tested, operators concealed the phone’s permanent identity correctly in every case but one.
  3. [3]
    The same networks still handed out temporary IDs in a pattern predictable enough that an observer can … More → The post A cheap fake base station can still track 5G subscribers appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · the hacker news

One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

Security researcher Patrick Wardle demonstrated in a proof of concept that malware already running on a Mac could take over Meta’s Muse assistant and use the broad access granted to the app.

2 retained claims2 cited excerpts

Source published Sep 22, 2026, 6:33 AM UTC · Evidence retrieved Sep 22, 2026, 7:23 AM UTC

What happened

Security researcher Patrick Wardle demonstrated in a proof of concept that malware already running on a Mac could take over Meta’s Muse assistant and use the broad access granted to the app. [1]

The demonstrated technique changes a hidden setting so dictated microphone prompts are sent to the attacker instead of Meta. [2]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Malware already running on a Mac can quietly take over Meta's Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21.
  2. [2]
    It works by changing a hidden setting so that when the user taps the microphone and dictates a prompt, the words go to the attacker instead of Meta.

Read the original article →

Luna-enriched source article · securityaffairs

Contagious Interview: 30,000 devices infected by a fake job interview

The North Korea-linked WaterPlum group uses fake job interviews to target freelance developers and blockchain or Web3 specialists, infecting at least 30,000 devices across more than 100 countries.

7 retained claims17 cited excerpts

Source published Sep 22, 2026, 6:44 AM UTC · Evidence retrieved Sep 22, 2026, 8:51 AM UTC

What happened

The North Korea-linked WaterPlum group uses fake job interviews to target freelance developers and blockchain or Web3 specialists, infecting at least 30,000 devices across more than 100 countries. [1] [2] [3] [4] [5]

Actors impersonate AI, cryptocurrency, or NFT companies and direct candidates to download files for coding tests or supposed bug fixes; the downloads contain malware families including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. [4] [5] [6]

The article reports that Japan’s authorities shut down the country’s first known laptop farm and that the FBI continues prosecuting facilitators who help North Korean IT workers operate through such arrangements. [15] [16]

Why it matters

The campaign reportedly stole funds or credentials from more than 7,000 cryptocurrency wallets and transferred 1.7 billion JPY in cryptocurrency assets to North Korea. [2] [7] [8]

A successful infection can enable theft of browser authentication data, keystrokes, screenshots, wallet data, files, and shared-folder contents, as well as espionage, intellectual-property theft, and lateral movement into an employer’s environment. [9] [10] [11]

The advisory links WaterPlum operators and North Korean IT workers to the same organization and reports shared IP addresses involving laptop farms, freelance platforms, and a crypto-exchange job application. [12] [13] [14]

Known limitations

The advisory says the described techniques are only examples and that the actors continuously evolve and refine their methods. [17]

Some generated claims did not pass validation and were omitted. Only retained claims are shown.

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    North Korea-linked WaterPlum runs the Contagious Interview campaign, infecting over 30,000 devices using a fake job interview.
  2. [2]
    At least 30,000 devices infected across more than 100 countries, funds or credentials stolen from over 7,000 cryptocurrency wallets, and a total of 1.7 billion yen, roughly $10.71 million, funneled back to North Korea.
  3. [3]
    The victims are almost always the same type: freelance developers and specialists in blockchain and Web3 work.
  4. [4]
    WaterPlum actors pose as recruiters or hiring managers, often impersonating real AI, crypto, or NFT companies, and reach out on social media, job boards, and freelance platforms.
  5. [5]
    Candidates get invited to a technical interview, then told to download a file to complete a coding test or fix a supposed bug on the video call.
  6. [6]
    The advisory names five malware families riding inside these downloads, BeaverTail , InvisibleFerret , OtterCookie , OtterCandy, and StoatWaffle , each doing its own piece of the job: one steals browser credentials, another opens a backdoor, another sets up a remote access trojan to move deeper into the machine.
  7. [7]
    “WaterPlum actors have infected at least 30,000 devices in more than 100 countries and exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets.
  8. [8]
    WaterPlum actors have transferred 1.7 billion Japanese yen (JPY) (equivalent to 10.71 million USD) of cryptocurrency assets to the Democratic People’s Republic of Korea (DPRK).” That file is never what it claims to be.
  9. [9]
    The report notes that a successful infection can give WaterPlum a way into the victim’s employer, opening the door to espionage, stolen source code, and further movement inside a company’s systems.
  10. [10]
    “Beyond immediate credential theft, successful infections provide WaterPlum actors opportunities to infiltrate organizations employing targeted developers, enabling espionage, intellectual property theft, and additional lateral movement in corporate environments.
  11. [11]
    “Other sensitive data targeted for exfiltration includes: Authentication data stored in web browsers (ID, password, etc.); Clipboard information, key-logs (recorded keystrokes), screenshots; Cryptocurrency-wallet data (private key, seed phrase, etc.); and Any files or data of interest to the actors on a PC or in shared folders (ID pictures of driver’s licenses, passports, etc.)” Here’s a simpler and more natural version, while keeping the same details: Japan says this is no longer just a theoretical threat.
  12. [12]
    Japan’s NPA and the FBI assess that both WaterPlum operators and some North Korean IT workers report to the same place, the 313 General Bureau of the Munitions Industry Department, under the Workers’ Party’s Central Committee.
  13. [13]
    The advisory draws one more thread together: WaterPlum’s cyberattack operators and North Korea’s IT worker network aren’t running in parallel.
  14. [14]
    They’ve been caught using the same IP addresses to access laptop farms, register on freelance platforms, and apply for that same crypto exchange job.
  15. [15]
    Authorities have already shut down the country’s first known “laptop farm,” run by a local facilitator who had moved several hundred million yen in cryptocurrency out of Japan.
  16. [16]
    In the US, the FBI says it continues to prosecute people who help North Korean IT workers operate this way, across several states and under different charges.
  17. [17]
    “The techniques described in this advisory are only examples; actors continuously evolve and refine their methods.” concludes the advisory.

Read the original article →

Luna-enriched source article · the hacker news

SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

SideCopy has been observed using spear-phishing lures against academic institutions in India, expanding its strategic focus beyond government entities.

2 retained claims2 cited excerpts

Source published Sep 22, 2026, 7:52 AM UTC · Evidence retrieved Sep 22, 2026, 1:23 PM UTC

What happened

SideCopy has been observed using spear-phishing lures against academic institutions in India, expanding its strategic focus beyond government entities. [1]

Trellix researchers state that SideCopy operations typically begin with spear-phishing campaigns abusing mshta.exe to execute malicious scripts and circumvent standard security protocols. [2]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities.
  2. [2]
    "SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of mshta.exe to execute malicious scripts and circumvent standard security protocols," Trellix researchers

Read the original article →

Luna-enriched source article · helpnetsecurity

Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions

Scammers are using a $249 website toolkit to market unverified AI subscriptions costing up to $2,000 annually, with genuine Google sign-in screens making the sites appear convincing.

4 retained claims3 cited excerpts

Source published Sep 22, 2026, 8:54 AM UTC · Evidence retrieved Sep 22, 2026, 2:51 PM UTC

What happened

Scammers are using a $249 website toolkit to market unverified AI subscriptions costing up to $2,000 annually, with genuine Google sign-in screens making the sites appear convincing. [1]

Malwarebytes found more than 100 websites built with the same toolkit and linked by closely related developer details. [2]

The network includes sites copying names of existing products, including GPT-6 Astra, DaVinci Resolve, PixAI, and OpenCut. [3]

Why it matters

Interpretation: The combination of copied product identities and genuine Google sign-in screens may make fraudulent subscription sites harder for users to distinguish from legitimate services. [1] [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Scammers are using a $249 website toolkit to sell unverified AI subscriptions worth up to $2,000 a year, and a genuine Google sign-in screen is what makes the sites convincing.
  2. [2]
    Malwarebytes found more than 100 websites built this way, all tied to the same toolkit and closely related developer details.
  3. [3]
    The network includes sites that copy the names of existing products, among them GPT-6 Astra, DaVinci Resolve, PixAI, and OpenCut.

Read the original article →

Luna-enriched source article · the hacker news

Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal

A malicious npm package named "indexed-btree" was observed hiding malicious behavior in application code rather than using lifecycle scripts.

3 retained claims2 cited excerpts

Source published Sep 22, 2026, 9:38 AM UTC · Evidence retrieved Sep 22, 2026, 1:23 PM UTC

What happened

A malicious npm package named "indexed-btree" was observed hiding malicious behavior in application code rather than using lifecycle scripts. [1]

Checkmarx said indexed-btree mimicked the legitimate sorted-btree package, described as an ordinary B-tree/indexing utility. [2]

Why it matters

The observed tactic was characterized as indicating that threat actors are likely shifting tactics in response to recent security controls. [1]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    A malicious npm package named "indexed-btree" has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent security controls.
  2. [2]
    "Indexed-btree is a malicious npm package mimicking the legit sorted-btree package, an ordinary B-tree/indexing utility," Checkmarx said.

Read the original article →

Luna-enriched source article · cyberscoop

Another worry for water systems: infostealer exposure

SpyCloud analyzed 10,000 EPA-registered water and wastewater organizations and found 1,787 with active infostealer exposure, meaning identity data from stolen credentials was exposed.

6 retained claims14 cited excerpts

Source published Sep 22, 2026, 10:00 AM UTC · Evidence retrieved Sep 22, 2026, 2:51 PM UTC

What happened

SpyCloud analyzed 10,000 EPA-registered water and wastewater organizations and found 1,787 with active infostealer exposure, meaning identity data from stolen credentials was exposed. [1] [2]

Among the 1,787 organizations with active infostealer exposure, 258 carried credentials for operational-technology or remote-access systems. [9]

Why it matters

In one reported case, a single infected device at an unnamed smart-meter technology provider contained saved logins linked to about 167 U.S. utility-metering tenants, creating a reported cascading supply-chain exposure. [3] [4] [5]

SpyCloud’s investigations officer said infostealer logs commonly include session cookies, credentials and autofill data, which can enable hijacked authenticated sessions and access to corporate email or VPNs without an alert. [6] [7] [8]

Known limitations

The research did not focus on OT devices running critical utility processes, and the report said its exposure findings should not be interpreted as exposure of specific OT devices. [10] [11]

The report said larger operators and the vendor supply chain were overrepresented, small utilities were underrepresented, and the findings measure identity exposure rather than confirmed intrusion. [12] [13] [14]

Some generated claims did not pass validation and were omitted. Only retained claims are shown.

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    water and wastewater organizations have identity data actively exposed from infostealers harvesting their credentials, according to research published Tuesday.
  2. [2]
    The company built a database of 66,845 Environmental Protection Agency-registered systems, examined internet domains and ultimately analyzed 10,000 organizations, finding that 1,787 showed active infostealer exposure.
  3. [3]
    In one case, a single infected device at a smart meter technology provider that SpyCloud didn’t name contained saved logins linked to roughly 167 different U.S.
  4. [4]
    utility metering tenants — meaning that one exposure opened the door to many more.
  5. [5]
    That “cascading supply chain exposure” was one of the biggest findings of the report that SpyCloud shared exclusively with CyberScoop, said Jason Lancaster, chief investigations officer at the cyber firm, along with the quantitative approach” to measure exposure overall.
  6. [6]
    “There’s examples here and there, but that was a standout example of, here’s a tangible thing that is an exposure right now.” Generally, “Infostealer exposure means the attacker isn’t guessing anymore, they’ve got legitimate points of entry,” Lancaster said.
  7. [7]
    “In the investigations I’ve worked, that log data usually contains stolen session cookies, credentials, and autofill info pulled straight off the infected device.
  8. [8]
    That’s enough to walk right past [multifactor authentication] by hijacking an already-authenticated session, log into corporate email or VPNs without raising a single alert, and sit there quietly for weeks while they map out the network.” Still, the study had limitations.
  9. [9]
    It did, however, find that 258 of the 1,787 organizations with active infostealer exposure carried credentials to operational technology or remote-access systems.
  10. [10]
    It doesn’t address what apparently led to the cyberattacks that unfolded in Minnesota and elsewhere this summer: internet-exposed programmable logic controllers .
  11. [11]
    It’s “important to note that our research did not focus on OT devices which run the most critical processes within these utilities, and any exposure we cite herein should not be interpreted as exposure of specific OT devices,” the report said.
  12. [12]
    Some of the report’s conclusions were about the limitations of the data itself.
  13. [13]
    “Exposure concentrated in larger operators and in the vendor supply chain; small utilities were largely underrepresented,” SpyCloud said.
  14. [14]
    “That’s a pattern in the data, not a claim that every water system nationwide carries this risk — and it measures identity exposure, not confirmed intrusion.” It’s the first study of its kind that SpyCloud has done for a specific industry, so the company doesn’t have comparisons to other industries, Lancaster said.

Read the original article →

Luna-enriched source article · helpnetsecurity

Somewhere in your traffic logs, a bot is doing more than looking

Akamai reports that verified AI crawlers, including ChatGPT, have shifted from reading web pages to sending high-frequency POST requests.

3 retained claims4 cited excerpts

Source published Sep 22, 2026, 10:30 AM UTC · Evidence retrieved Sep 22, 2026, 2:51 PM UTC

What happened

Akamai reports that verified AI crawlers, including ChatGPT, have shifted from reading web pages to sending high-frequency POST requests. [1]

In Akamai’s 30-day analysis of global customers, ecommerce represented 44.8% of AI-bot POST transactions, while travel reached 30% in one month. [2]

Why it matters

The article distinguishes GET requests, which ask for a page, from POST requests, which tell a site to perform an action such as logging in or adding an item to a cart. [3] [4]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Akamai has watched verified AI crawlers, ChatGPT among them, move from reading web pages to sending high-frequency POST requests.
  2. [2]
    In a 30-day analysis of its global customers, ecommerce accounted for 44.8% of those AI bot POST transactions, and travel climbed to 30% in a single month.
  3. [3]
    A GET request asks a website for a page.
  4. [4]
    A POST request tells the site to do something, like log a user in, add an item to a cart, … More → The post Somewhere in your traffic logs, a bot is doing more than looking appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · helpnetsecurity

Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)

GreyNoise reported that a Chinese-speaking threat actor exploited CVE-2026-7273 in unpatched ZyXEL GS1900 Smart Managed Switches and exfiltrated sensitive data from 996 devices across 48 countries.

3 retained claims3 cited excerpts

Source published Sep 22, 2026, 10:42 AM UTC · Evidence retrieved Sep 22, 2026, 2:51 PM UTC

What happened

GreyNoise reported that a Chinese-speaking threat actor exploited CVE-2026-7273 in unpatched ZyXEL GS1900 Smart Managed Switches and exfiltrated sensitive data from 996 devices across 48 countries. [1]

Why it matters

The affected switches were predominantly located in Italy, the United States, Taiwan, South Korea, and several European Union countries. [2]

Known limitations

The supplied evidence does not state the exploitation prerequisites, affected firmware versions, mitigation steps, or whether a permanent fix is available. [1] [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    A Chinese-speaking threat actor has exploited a vulnerability (CVE-2026-7273) in unpatched ZyXEL GS1900 Smart Managed Switches and has exfiltrated sensitive data from 996 devices across 48 countries, GreyNoise reported on Monday.
  2. [2]
    The affected switches are predominantly located in Italy, the US, Taiwan, South Korea, and a number of EU countries.
  3. [3]
    CVE-2026-7273 exploitation is part of an unfolding operation The Zyxel GS1900 Series is a line of Gigabit Ethernet switches aimed at small and mid-sized business … More → The post Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273) appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · the hacker news

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

Viettel Cyber Security researcher Dinh Ho Anh Khoa reported that CVE-2026-65660, initially classified by Microsoft as a spoofing flaw with a 6.5 CVSS score, enables authenticated remote code execution.

3 retained claims3 cited excerpts

Source published Sep 22, 2026, 11:17 AM UTC · Evidence retrieved Sep 22, 2026, 1:23 PM UTC

What happened

Viettel Cyber Security researcher Dinh Ho Anh Khoa reported that CVE-2026-65660, initially classified by Microsoft as a spoofing flaw with a 6.5 CVSS score, enables authenticated remote code execution. [1]

CVE-2026-65660 affects SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. [2]

Known limitations

The supplied evidence truncates the statement about patches, so patch availability or status cannot be determined. [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa.
  2. [2]
    The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition.
  3. [3]
    Patches have been

Read the original article →

Luna-enriched source article · the hacker news

New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory

A Linux kernel KVM virtualization flaw affecting ARM64 hosts with nested virtualization enabled can expose freed host memory to a guest virtual machine.

3 retained claims2 cited excerpts

Source published Sep 22, 2026, 11:38 AM UTC · Evidence retrieved Sep 22, 2026, 1:23 PM UTC

What happened

A Linux kernel KVM virtualization flaw affecting ARM64 hosts with nested virtualization enabled can expose freed host memory to a guest virtual machine. [1]

Tracked as CVE-2026-89775, the flaw allows a guest to read and write host kernel memory. [2]

Why it matters

The discovering researcher says the flaw can enable a guest to escape and run code on the host machine. [2]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    A new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled.
  2. [2]
    The bug, tracked as CVE-2026-89775, allows a guest to read and write host kernel memory, and the researcher who found it says it can be used to escape the guest and run code on the host machine.

Read the original article →

Luna-enriched source article · helpnetsecurity

The latest deepfake numbers give CISOs plenty to worry about

Gartner reported that 41% of surveyed CISOs experienced at least one deepfake-related social-engineering incident during an employee audio call in the prior 12 months.

4 retained claims4 cited excerpts

Source published Sep 22, 2026, 12:05 PM UTC · Evidence retrieved Sep 22, 2026, 2:51 PM UTC

What happened

Gartner reported that 41% of surveyed CISOs experienced at least one deepfake-related social-engineering incident during an employee audio call in the prior 12 months. [1]

Gartner reported that 36% of surveyed CISOs experienced at least one deepfake-related social-engineering incident during a video call in the prior 12 months. [2]

Why it matters

Among surveyed CISOs, 79% reported at least one phishing, spear-phishing, or business-email-compromise incident in the prior 12 months. [3]

Among surveyed CISOs, 58% reported at least one vishing or smishing incident in the prior 12 months. [4]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    41% of CISOs reported at least one social engineering incident involving a deepfake during an employee audio call in the past 12 months, according to Gartner.
  2. [2]
    36% reported the same for a video call.
  3. [3]
    79% of CISOs surveyed reported at least one phishing, spear-phishing, or business email compromise incident in the past 12 months.
  4. [4]
    58% reported a vishing or smishing incident.

Read the original article →

Luna-enriched source article · helpnetsecurity

Brief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” page

Three Elsevier domains or web portals redirected users to a page branded “LAPSUS$ GROUP, Chapter II,” which included a signed statement taunting the FBI and a countdown to a future victim.

3 retained claims3 cited excerpts

Source published Sep 22, 2026, 1:46 PM UTC · Evidence retrieved Sep 22, 2026, 2:51 PM UTC

What happened

Three Elsevier domains or web portals redirected users to a page branded “LAPSUS$ GROUP, Chapter II,” which included a signed statement taunting the FBI and a countdown to a future victim. [1]

Cloudskope researchers reported that the redirect lasted at least 78 minutes, from approximately 7:49 p.m. CT until it was cleared before 10:09 p.m. CT on September 21, 2026. [2]

Known limitations

The supplied evidence states that Elsevier had not yet offered an explanation for how the redirect occurred. [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Three domains / web portals belonging to Dutch academic publishing company Elsevier have been redirecting users to a page branded “LAPSUS$ GROUP, Chapter II,” carrying a signed statement that taunted the FBI and counted down to a future victim.
  2. [2]
    According to Cloudskope researchers, the redirect ran for at least 78 minutes, from roughly 7:49pm CT until it was cleared before 10:09pm CT on September 21, 2026.
  3. [3]
    Elsevier is yet to offer an explanation on how … More → The post Brief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” page appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · helpnetsecurity

Researchers uncover malware that uses AI to choose its next move

Cisco Talos researchers shared an open-source framework called CAIRN to help security practitioners classify and analyze malware that uses AI.

3 retained claims4 cited excerpts

Source published Sep 22, 2026, 1:56 PM UTC · Evidence retrieved Sep 22, 2026, 2:51 PM UTC

What happened

Cisco Talos researchers shared an open-source framework called CAIRN to help security practitioners classify and analyze malware that uses AI. [1]

CAIRN operates entirely on metadata extracted from files, without downloading or executing the malware. [2] [3]

Why it matters

CAIRN connects malware binaries through metadata attributes including submitter, import hash, domain, and AI provider. [4]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    To help security practitioners catch malware that leans on AI, researchers from Cisco Talos shared an open-source framework that they hope will be used to classify and analyze the threat.
  2. [2]
    The tool, called CAIRN, works entirely from metadata pulled off files.
  3. [3]
    No downloading the malware, no running it.
  4. [4]
    CAIRN explorer connects malware binaries by metadata attributes like submitter, import hash, domain or AI provider (Source: Cisco Talos) How CAIRN hunts Researchers look for what Talos … More → The post Researchers uncover malware that uses AI to choose its next move appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · securityaffairs

Chaotic Eclipse Released BigDiskBuster, A PoC For Windows Defender Update DoS Zero-Day

Researcher Chaotic Eclipse released BigDiskBuster, a proof-of-concept exploit for a reported Windows Defender Update denial-of-service zero-day.

4 retained claims6 cited excerpts

Source published Sep 22, 2026, 2:04 PM UTC · Evidence retrieved Sep 22, 2026, 2:51 PM UTC

What happened

Researcher Chaotic Eclipse released BigDiskBuster, a proof-of-concept exploit for a reported Windows Defender Update denial-of-service zero-day. [1] [2] [3]

The researcher claims BigDiskBuster can block Microsoft Defender from receiving platform and signature updates. [4] [5]

Why it matters

If the reported behavior works as claimed, blocking Defender platform and signature updates could interfere with its updating process; the source presents this as a proof-of-concept capability, not a confirmed universal effect. [4] [5] [6]

Known limitations

Chaotic Eclipse says the technique works on supported Windows versions, but describes the proof of concept as buggy and needing further development. [6]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    The researcher Chaotic Eclipse released BigDiskBuster, a PoC exploit for a Windows Defender Update DoS Zero-Day vulnerability.
  2. [2]
    Security researcher Chaotic Eclipse , also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Microsoft Defender.
  3. [3]
    The researcher named the exploit BigDiskBuster, it triggers a Denial of Service Vulnerability in Windows Defender Update.
  4. [4]
    The security researcher claims to have developed BigDiskBuster, a proof-of-concept that can block Microsoft Defender from receiving platform and signature updates.
  5. [5]
    “This proof of concept is similar to UnDefend , it prevents windows defender from performing platform/signature updates.” wrote the expert.
  6. [6]
    “Seems to work on all supported windows versions but PoC is a bit buggy and needs some rewritting but you get the idea.” Chaotic Eclipse says the technique works across supported Windows versions, although the current PoC is still buggy and needs further development.

Read the original article →

Published records

Additional source records

Expand a row to inspect provenance
Material developments

roadmap — Anthropic

Anthropic published a source item for review.

1 source recordAuthoritative source

What happened

Anthropic published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

How Reactiv automates mobile commerce 80% faster with Amazon Bedrock AgentCore

Amazon Web Services published a source item for review.

1 source recordAuthoritative source

What happened

Amazon Web Services published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

How Trane gets building insights 60x faster with Amazon Bedrock AgentCore

Amazon Web Services published a source item for review.

1 source recordAuthoritative source

What happened

Amazon Web Services published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

North Korean Attackers Hit 30,000 Devices and Steal $10.7m

Infosecurity Magazine published a source item for review.

1 source recordContext source

What happened

Infosecurity Magazine published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

Public PoC Exposes Critical Veeam Agent Privilege Escalation

Securityaffairs published a source item for review.

1 source recordContext source

What happened

Securityaffairs published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme

Securityweek published a source item for review.

1 source recordContext source

What happened

Securityweek published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)

Sans Isc Diary published a source item for review.

1 source recordContext source

What happened

Sans Isc Diary published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

D-Link warns of max severity zero-day bug in DIR-822A routers

Bleepingcomputer published details for CVE-2026-86296.

1 source recordContext source

What happened

Bleepingcomputer published details for CVE-2026-86296.

Why it matters

A reviewed impact interpretation has not been published for this record.

Structured associations

CVE-2026-86296 mentioned

Reviewed next steps

  • Check asset inventory and patch status for CVE-2026-86296.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

The next intellectual property thief may sound like your CEO

Helpnetsecurity published a source item for review.

1 source recordContext source

What happened

Helpnetsecurity published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers

Securityweek published a source item for review.

1 source recordContext source

What happened

Securityweek published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

Malicious B-tree NPM Package Accumulates Millions of Downloads

Securityweek published a source item for review.

1 source recordContext source

What happened

Securityweek published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

WordPress Patches ‘Click2Shell’ Vulnerability

Securityweek published a source item for review.

1 source recordContext source

What happened

Securityweek published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

New Windows Defender zero-day blocks Microsoft antivirus updates

Bleepingcomputer published a source item for review.

1 source recordContext source

What happened

Bleepingcomputer published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog

Securityaffairs published details for CVE-2026-7273.

1 source recordContext source

What happened

Securityaffairs published details for CVE-2026-7273.

Why it matters

A reviewed impact interpretation has not been published for this record.

Structured associations

CVE-2026-7273 mentioned

Reviewed next steps

  • Check asset inventory and patch status for CVE-2026-7273.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

CISA orders feds to patch Zyxel flaw exploited for data theft

Bleepingcomputer published a source item for review.

1 source recordContext source

What happened

Bleepingcomputer published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

The Hacker News published details for CVE-2026-93485.

1 source recordContext source

What happened

The Hacker News published details for CVE-2026-93485.

Why it matters

A reviewed impact interpretation has not been published for this record.

Structured associations

CVE-2026-93485 mentioned

Reviewed next steps

  • Check asset inventory and patch status for CVE-2026-93485.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Cloud and infrastructure

Extending public sector intelligence with Agentforce and AWS

Amazon Web Services published a source item for review.

1 source recordAuthoritative source

What happened

Amazon Web Services published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Cloud and infrastructure

Only 13% of OT Network Segments Are Fully Isolated: Analysis

Securityweek published a source item for review.

1 source recordContext source

What happened

Securityweek published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Cloud and infrastructure

Network Segmentation Failures Are Expanding the Corporate Attack Surface

Infosecurity Magazine published a source item for review.

1 source recordContext source

What happened

Infosecurity Magazine published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Incidents and exposure

AI Incident Response Readiness Lags Behind AI Adoption, ISACA Finds

Infosecurity Magazine published a source item for review.

1 source recordContext source

What happened

Infosecurity Magazine published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Incidents and exposure

Webinar tomorrow: Inside real-world Google Workspace breaches

Bleepingcomputer published a source item for review.

1 source recordContext source

What happened

Bleepingcomputer published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Incidents and exposure

DORA Year Two: Can Your SOC Actually See the Attack?

The Hacker News published a source item for review.

1 source recordContext source

What happened

The Hacker News published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Incidents and exposure

CISOs Must Update Incident Response Playbooks for Multimodal Deepfakes, Gartner Warns

Infosecurity Magazine published a source item for review.

1 source recordContext source

What happened

Infosecurity Magazine published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

AI and model reality

AI is set to help cyber attackers much more than defenders, says UK official

Therecord Media published a source item for review.

1 source recordContext source

What happened

Therecord Media published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

AI and model reality

More Than a Third of Industrial Orgs See Cybersecurity Risk as a Top Obstacle to Growth, Study Finds

Darkreading published a source item for review.

1 source recordContext source

What happened

Darkreading published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

AI and model reality

AI Drives Surge in Bot and API Threats

Infosecurity Magazine published a source item for review.

1 source recordContext source

What happened

Infosecurity Magazine published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.