Source context

Why this day matters

  • A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck.
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog. The U.S.
Validated article intelligence

Enriched source records

Expand a row to inspect claims and citations

Luna-generated claims retained by the evidence and claim-validation gates. Automated validation does not imply human review. A record does not need a CVE to be included.

Luna-enriched source article · helpnetsecurity

How RMM abuse gives attackers a way in that looks like business as usual

Huntress reported that attackers used legitimate remote monitoring and management (RMM) software in 45% of the endpoint-related incidents it recorded in the first quarter of 2026.

3 retained claims3 cited excerpts

Source published Oct 5, 2026, 4:30 AM UTC · Evidence retrieved Oct 5, 2026, 8:51 AM UTC

What happened

Huntress reported that attackers used legitimate remote monitoring and management (RMM) software in 45% of the endpoint-related incidents it recorded in the first quarter of 2026. [1]

RMM tools are used by IT teams to manage computers remotely, which provides the business-as-usual context described for RMM abuse. [3]

Why it matters

Huntress ranked attack tactics by observed frequency and potential damage, placing RMM abuse farthest right on its chart, the position for tactics it sees most often. [2]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Huntress found attackers using legitimate remote monitoring and management (RMM) software in 45% of the endpoint-related incidents it recorded in the first quarter of 2026.
  2. [2]
    The security company also ranked 11 attack tactics by how often it sees them and how much damage each can do, and RMM abuse sits farthest right on the chart, the position for tactics it sees most often.
  3. [3]
    IT teams use RMM tools to manage computers from anywhere, so an … More → The post How RMM abuse gives attackers a way in that looks like business as usual appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · helpnetsecurity

Keyorix: Open-source secrets management for teams that can’t use SaaS

Keyorix is an open-source secrets manager that runs entirely on a company’s own servers.

4 retained claims4 cited excerpts

Source published Oct 5, 2026, 5:00 AM UTC · Evidence retrieved Oct 5, 2026, 8:51 AM UTC

What happened

Keyorix is an open-source secrets manager that runs entirely on a company’s own servers. [1]

The source describes a secrets manager as a store for application database passwords, API keys, and tokens, keeping them out of configuration files and source code. [2]

Keyorix ships as a single binary and, in its core form, requires no internet connection. [3]

Why it matters

The company presents Keyorix as an option for teams that cannot send credentials to a cloud service or use SaaS. [4]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Keyorix is an open-source secrets manager that runs entirely on a company’s own servers.
  2. [2]
    A secrets manager is the locked store where an application fetches the database passwords, API keys, and tokens it needs, so they stay out of config files and source code.
  3. [3]
    It ships as one binary and, in its core form, needs no internet connection.
  4. [4]
    Keyorix SL, the company behind it, pitches that to teams that cannot send credentials to a cloud … More → The post Keyorix: Open-source secrets management for teams that can’t use SaaS appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · helpnetsecurity

Three questions a hospital CISO should ask a healthcare fintech vendor

Drew McCombs, Cylerity’s CTO and CISO, describes how he balances those roles and prioritizes security work involving patient data or funds disbursement.

3 retained claims3 cited excerpts

Source published Oct 5, 2026, 5:30 AM UTC · Evidence retrieved Oct 5, 2026, 8:51 AM UTC

What happened

Drew McCombs, Cylerity’s CTO and CISO, describes how he balances those roles and prioritizes security work involving patient data or funds disbursement. [1] [2]

The interview discusses keeping PHI away from a bank partner and using AI models that recommend but do not act. [3]

The source identifies enabling email MFA as a low-cost fix for small practices. [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    In this Help Net Security interview, Drew McCombs, CTO and CISO at Cylerity, explains how he balances both roles.
  2. [2]
    Security work is scheduled into every sprint, and issues touching patient data or funds disbursement come first.
  3. [3]
    He covers how Cylerity keeps PHI away from its bank partner, why AI models recommend but never act, and why turning on MFA for email is the cheapest fix for small practices.

Read the original article →

Luna-enriched source article · securityaffairs

Another OpenAI Safety Expert Quits and Raises New AI Safety Concerns

David Robinson resigned from OpenAI after three and a half years, having helped write safety reports for each major product launch; he said the company’s culture was broken and its development path unacceptable.

8 retained claims16 cited excerpts

Source published Oct 5, 2026, 7:30 AM UTC · Evidence retrieved Oct 5, 2026, 2:51 PM UTC

What happened

David Robinson resigned from OpenAI after three and a half years, having helped write safety reports for each major product launch; he said the company’s culture was broken and its development path unacceptable. [1] [2] [3] [4]

Robinson described OpenAI’s iterative-deployment approach as releasing systems, finding problems, and then adding or improving safeguards. [5] [6]

Robinson said OpenAI lacked colleagues with direct experience managing safety in aviation, nuclear power, or financial-system collapse prevention. [10]

Robinson argued that current methods for evaluating whether AI systems follow human values are too basic, and that the industry lacks a clear way to measure alignment. [11] [12] [13]

OpenAI said it was improving security in research environments, training models to act responsibly, increasing outside testing, and strengthening real-time monitoring to detect harmful behavior earlier. [14] [15]

Why it matters

Robinson said this trial-and-error approach could produce failures that become more serious as AI systems grow more powerful, citing the Hugging Face breach involving OpenAI agents and other rogue-agent incidents as signs the problem is already occurring. [7] [8]

He argued frontier AI laboratories should use redundancy and deliberate planning comparable to safety-critical facilities, rather than relying on a single human mistake not causing disaster. [9]

Known limitations

Robinson characterized OpenAI’s stated security improvements as continuing the cycle of finding problems and fixing them after they appear; the supplied evidence does not establish whether the measures prevent future failures. [14] [15] [16]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    But Robinson was not a junior employee; he helped write the safety reports released with OpenAI’s major product launches and, after three and a half years at the company, says he was one of its longest-serving employees.
  2. [2]
    He is leaving because he believes the company’s culture is broken.
  3. [3]
    I led the writing of the safety reports we published with each major launch.
  4. [4]
    Now I’m joining a parade of former colleagues—at OpenAI and the industry’s other leaders—who have decided that the current path is unacceptable.” Robinson told The Atlantic .
  5. [5]
    Robinson says OpenAI relies on a trial-and-error approach.
  6. [6]
    The company calls it iterative deployment: release systems, find problems, and then add or improve safeguards.
  7. [7]
    His concern is that this approach will inevitably lead to failures, and those failures could become more serious as AI systems become more powerful.
  8. [8]
    He points to the recent breach of Hugging Face systems involving OpenAI agents, along with other rogue-agent incidents, as signs that this problem is already happening.
  9. [9]
    His comparison is blunt: frontier AI labs should be run like nuclear plants or major airports, with redundancy built in and planning that takes real time, so one human mistake doesn’t open the door to disaster.
  10. [10]
    In his time at OpenAI he says he never worked alongside anyone with real experience keeping airplanes safe, keeping reactors from melting down, or keeping the financial system from collapsing.
  11. [11]
    Robinson says the problem goes beyond safety engineering and company culture.
  12. [12]
    He argues that current methods for checking whether AI systems follow human values are still too basic for such a complex problem.
  13. [13]
    The industry, he says, has no clear way to measure alignment, and that becomes more worrying as AI systems become more capable.
  14. [14]
    OpenAI says it is already working on these issues, according to spokesperson Drew Pusateri, reported TechCrunch .
  15. [15]
    The company says it is improving security in research environments, training models to act responsibly, increasing outside testing, and using stronger real-time monitoring to detect harmful behavior earlier.
  16. [16]
    Robinson’s criticism is that this is still the same cycle of finding problems and fixing them after they appear.

Read the original article →

Luna-enriched source article · the hacker news

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

VulnCheck reports active exploitation attempts against a critical Rejetto HTTP File Server (HFS) flaw, CVE-2026-61500, rated CVSS 9.3.

3 retained claims2 cited excerpts

Source published Oct 5, 2026, 8:09 AM UTC · Evidence retrieved Oct 5, 2026, 1:23 PM UTC

What happened

VulnCheck reports active exploitation attempts against a critical Rejetto HTTP File Server (HFS) flaw, CVE-2026-61500, rated CVSS 9.3. [1] [2]

The flaw involves session forgery caused by a weak pseudo-random number generator that can produce a predictable key for unauthorized access. [2]

Known limitations

The supplied evidence truncates the description of what an attacker can do after gaining unauthorized access. [2]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck.
  2. [2]
    The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and

Read the original article →

Luna-enriched source article · securityaffairs

Iranian hacker accused of draining 31TB from university inboxes extradited to the US

Montenegro approved extraditing dual Turkish-Iranian citizen Amir Barati to the United States after his arrest in Kotor on an FBI warrant; he faces charges including conspiracy, computer fraud, hacking and identity theft.

7 retained claims18 cited excerpts

Source published Oct 5, 2026, 8:33 AM UTC · Evidence retrieved Oct 5, 2026, 2:51 PM UTC

What happened

Montenegro approved extraditing dual Turkish-Iranian citizen Amir Barati to the United States after his arrest in Kotor on an FBI warrant; he faces charges including conspiracy, computer fraud, hacking and identity theft. [1] [2] [3] [4] [5]

US prosecutors allege Barati was directly involved in an Iranian Mabna Institute operation targeting universities and research institutions between 2013 and 2017. [6] [7] [8] [9]

Prosecutors say the campaign compromised roughly 8,000 professor email accounts and stole at least 31 terabytes of research and other data. [8] [10] [11]

The alleged activity included tracking spearphishing campaigns, sharing stolen credentials, building target lists, conducting network reconnaissance and writing phishing emails. [12] [13]

Why it matters

US officials estimate the alleged damage at $3.4 billion, while affected universities reportedly spent about $20 million investigating and repairing the attacks. [14] [15]

According to the DOJ, stolen data was sent to the Iranian government and sold through websites to universities in Iran; one site enabled access to US university library systems with professors’ stolen credentials. [16] [17]

Known limitations

The allegations are attributed to US prosecutors and officials; the supplied reporting does not establish a conviction or independently confirm the claim that Barati was recruited as an Iranian intelligence asset. [3] [7] [14] [18]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Amir Barati spent June 25 getting arrested in Montenegro, and this week a Montenegrin court signed off on sending him to the United States.
  2. [2]
    He’s a dual Turkish and Iranian citizen, 40 years old, picked up by Montenegro’s Police Directorate after the FBI issued a warrant.
  3. [3]
    “He is accused of committing the following crimes: conspiracy to commit computer fraud and computer hacking, as well as identity theft, by conducting massive hacking attacks on the infrastructure of the United States of America since 2013, as an associate of a legal entity from the territory of Iran – at over 150 universities in the United States of America, causing damage estimated at more than 3.4 billion US dollars.” reads the press release published by Montenegro’s Police.
  4. [4]
    Iran International also confirmed that Montenegro plans to extradite Barati to the United States.
  5. [5]
    Barati now faces multiple counts of conspiracy to commit computer intrusions, wire fraud, computer fraud, and identity theft.
  6. [6]
    A US indictment subsequently linked him to the Mabna network and its alleged IRGC-backed campaign targeting universities.
  7. [7]
    Prosecutors allege they were part of an operation run through the Iranian Mabna Institute on behalf of the Islamic Revolutionary Guard Corps.
  8. [8]
    Between 2013 and 2017, the campaign allegedly compromised roughly 8,000 professor email accounts, using stolen credentials to get in and stay in.
  9. [9]
    Prosecutors describe Barati as directly involved in the operation, not just someone working in the background.
  10. [10]
    Prosecutors say the group hacked email accounts at universities and research institutions around the world and stole at least 31 terabytes of data.
  11. [11]
    Academic journals, theses, dissertations, electronic books, pulled from 144 American universities and 42 US companies, plus 178 foreign universities and at least 11 foreign companies.
  12. [12]
    The Record Media quoted the government saying he helped track the progress of the spearphishing campaigns.
  13. [13]
    He also allegedly shared stolen credentials with other members, built lists of targets, carried out network reconnaissance, and wrote phishing emails himself.
  14. [14]
    US officials estimate the damage at $3.4 billion.
  15. [15]
    The affected universities also spent about $20 million investigating the attacks and repairing the damage.
  16. [16]
    According to the DOJ, the stolen data was sent to the Iranian government and also sold through two websites to universities in Iran.
  17. [17]
    One of those sites allowed users to log in to US university library systems using stolen credentials belonging to professors.
  18. [18]
    After his 2010 arrest by Iran’s Intelligence Ministry, sources said he was recruited as an intelligence asset, although this could not be independently confirmed.

Read the original article →

Luna-enriched source article · securityaffairs

MI5 Raises Alarm Over Chinese Funding of UK Academic Research

MI5 warned UK universities that more than 100 UK-linked academics contributed to research funded through CGTRI, an institute MI5 assessed as having very strong ties to China’s Ministry of State Security; some academics may not have known CGTRI was involved.

5 retained claims16 cited excerpts

Source published Oct 5, 2026, 9:12 AM UTC · Evidence retrieved Oct 5, 2026, 2:51 PM UTC

What happened

MI5 warned UK universities that more than 100 UK-linked academics contributed to research funded through CGTRI, an institute MI5 assessed as having very strong ties to China’s Ministry of State Security; some academics may not have known CGTRI was involved. [1] [2] [3] [4] [5]

The alert identified research areas including artificial intelligence, cybersecurity, covert communications systems and steganography. [6] [7]

Why it matters

MI5 said continuing work on CGTRI-funded projects could create legal risk under National Security Act 2023 provisions concerning assistance to a foreign intelligence service and obtaining material benefit from one. [8] [9] [10]

The UK China Transparency think tank reported that CGTRI shares staff with the University of International Relations and that its work overlaps with cyber capabilities previously used by the MSS against UK entities. [15] [16]

Known limitations

China rejected MI5’s allegations as fabricated and baseless, maintaining that UK-China university cooperation is voluntary, lawful and mutually beneficial. [11] [12] [13] [14]

Some generated claims did not pass validation and were omitted. Only retained claims are shown.

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    MI5 warns UK universities that over 100 academics may have unknowingly worked on research funded by a Chinese institute linked to the MSS.
  2. [2]
    On September 30, MI5 published a formal warning naming the China General Technology Research Institute, CGTRI, also called CAGT in some translations, as an outfit with very strong ties to China’s Ministry of State Security.
  3. [3]
    MI5 says CGTRI exists mainly to “fund academic research that directly improves MSS technical capability for espionage.” That’s not vague suspicion, that’s the agency’s stated assessment of the institute’s whole reason for existing.
  4. [4]
    “More than 100 UK-linked academics have contributed to research projects funded by MSS via CGTRI.
  5. [5]
    In some cases, academics may not be aware that CGTRI is funding the Chinese research project they are contributing to.” reads the alert .
  6. [6]
    The subject areas read like a wishlist for an intelligence service.
  7. [7]
    Artificial intelligence, cybersecurity, covert communications systems, and steganography, the practice of hiding data inside other data.
  8. [8]
    MI5 is flagging that continuing to work with CGTRI after this alert could expose people to real legal risk under the National Security Act 2023 , specifically sections on assisting a foreign intelligence service and obtaining material benefit from one.
  9. [9]
    Under Section 3 of the Act, a person can commit an offence if their actions are likely to materially help a foreign intelligence service, and they know or should reasonably know this.
  10. [10]
    MI5’s wording is important because it does not require someone to know for certain that they are helping an intelligence service.
  11. [11]
    China rejected MI5’s allegations as fabricated and baseless, saying cooperation between UK universities and Chinese institutions is voluntary, lawful and mutually beneficial.
  12. [12]
    “The accusations made by the UK intelligence agency against the relevant Chinese entity are imaginary and purely fabricated.
  13. [13]
    Exchanges and collaboration between UK universities and China have always been conducted on a voluntary basis and in compliance with laws and regulations.
  14. [14]
    Such exchanges and collaboration are mutually beneficial.” a Chinese embassy spokesperson said states.
  15. [15]
    The UK China Transparency think tank found that CGTRI shares staff with China’s University of International Relations, which is widely linked to the MSS.
  16. [16]
    It also said CGTRI’s work overlaps with cyber capabilities that the MSS has previously used against UK companies, universities and critical infrastructure.

Read the original article →

Luna-enriched source article · helpnetsecurity

MAKERphone 2: A DIY 4G phone with plug-in camera, speaker and prototyping board

CircuitMess is selling MAKERphone 2.0, a build-it-yourself 4G phone on Kickstarter that users can program in MicroPython or Arduino C++ and extend with plug-in hardware.

4 retained claims4 cited excerpts

Source published Oct 5, 2026, 9:50 AM UTC · Evidence retrieved Oct 5, 2026, 2:51 PM UTC

What happened

CircuitMess is selling MAKERphone 2.0, a build-it-yourself 4G phone on Kickstarter that users can program in MicroPython or Arduino C++ and extend with plug-in hardware. [1]

With a SIM inserted, the device can make real calls and send real texts. [2]

CircuitMess also pitches MAKERphone 2.0 to parents as a first phone for children. [4]

Why it matters

The article characterizes the device as a cellular handset whose software users write themselves, making it relevant to people who test or tinker with devices. [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    CircuitMess, a Croatian electronics kit maker, is selling MAKERphone 2.0, a build-it-yourself 4G phone on Kickstarter that buyers program in MicroPython or Arduino C++ and extend with plug-in hardware.
  2. [2]
    Insert a SIM and it makes real calls and sends real texts.
  3. [3]
    For anyone who tests or tinkers with devices, that is a cellular handset whose software you write yourself.
  4. [4]
    CircuitMess also pitches it to parents as a first phone for children, so some of the … More → The post MAKERphone 2: A DIY 4G phone with plug-in camera, speaker and prototyping board appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · helpnetsecurity

Detained ShinyHunters hacker reportedly helping FBI track down fellow members

Reuters reportedly said Jordanian authorities detained Saif al-Din Khader, also known as Rey, last week; two of Reuters’ three sources placed the arrest on Tuesday.

3 retained claims4 cited excerpts

Source published Oct 5, 2026, 10:36 AM UTC · Evidence retrieved Oct 5, 2026, 2:51 PM UTC

What happened

Reuters reportedly said Jordanian authorities detained Saif al-Din Khader, also known as Rey, last week; two of Reuters’ three sources placed the arrest on Tuesday. [1] [2]

A source told Reuters that Khader is walking investigators through his electronic devices and digital correspondence. [3]

Why it matters

The source described Khader’s cooperation as critical to ongoing efforts to arrest other suspected ShinyHunters members. [1] [4]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    A suspected ShinyHunters member known as Rey has been detained in Jordan and is reportedly helping the FBI track down the rest of the group.
  2. [2]
    Reuters reports that Jordanian authorities detained Saif al-Din Khader, alias Rey, last week, with two of its three sources placing the arrest on Tuesday.
  3. [3]
    One source told the publication that Khader is walking investigators through his electronic devices and digital correspondence.
  4. [4]
    “His cooperation is critical to ongoing efforts to arrest … More → The post Detained ShinyHunters hacker reportedly helping FBI track down fellow members appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · the hacker news

Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access

Apple announced steps to tighten controls around macOS Full Disk Access because of security risks posed by artificial intelligence agents.

2 retained claims2 cited excerpts

Source published Oct 5, 2026, 10:38 AM UTC · Evidence retrieved Oct 5, 2026, 1:23 PM UTC

What happened

Apple announced steps to tighten controls around macOS Full Disk Access because of security risks posed by artificial intelligence agents. [1]

The source reports that some developers use Full Disk Access in ways that may expose files, mail, messages, and browsing history without users’ full knowledge. [2]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents.
  2. [2]
    "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history – without users' full knowledge

Read the original article →

Luna-enriched source article · the hacker news

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

Threat actors have been observed attempting to exploit a now-patched critical security flaw affecting the Realtek Jungle software development kit to deploy the Cling botnet malware.

2 retained claims2 cited excerpts

Source published Oct 5, 2026, 11:46 AM UTC · Evidence retrieved Oct 5, 2026, 1:23 PM UTC

What happened

Threat actors have been observed attempting to exploit a now-patched critical security flaw affecting the Realtek Jungle software development kit to deploy the Cling botnet malware. [1]

Nozomi Networks said Cling repurposes ordinary STUN behavior as a practical command-and-control channel rather than introducing a new propagation technique. [2]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling.
  2. [2]
    "Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said in a report

Read the original article →

Luna-enriched source article · helpnetsecurity

RemoveMacAI turns off Apple Intelligence on macOS 27 and deletes its models

RemoveMacAI is a free command-line tool for Apple-silicon Macs running macOS 27 that turns off Apple Intelligence and deletes about 12 GB of downloaded AI models.

4 retained claims5 cited excerpts

Source published Oct 5, 2026, 12:26 PM UTC · Evidence retrieved Oct 5, 2026, 2:51 PM UTC

What happened

RemoveMacAI is a free command-line tool for Apple-silicon Macs running macOS 27 that turns off Apple Intelligence and deletes about 12 GB of downloaded AI models. [1] [2]

The source states that macOS 27 lacks a switch for Apple Intelligence, and that the models remain on disk after the features are disabled. [3]

The tool also prevents macOS from downloading the models again, although the provided text is truncated before further details. [5]

Why it matters

For a matching Mac, the retained models occupy about 12 GB despite Apple Intelligence being switched off. [4]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    A developer has released RemoveMacAI, a free command-line tool that turns off Apple Intelligence on macOS 27 and deletes about 12 GB of downloaded AI models.
  2. [2]
    It requires a Mac with Apple silicon.
  3. [3]
    macOS 27 doesn’t have a switch for Apple Intelligence, and the models stay on disk after you disable the features.
  4. [4]
    If that matches your machine, you are holding 12 GB for software you switched off.
  5. [5]
    The tool also stops macOS from downloading … More → The post RemoveMacAI turns off Apple Intelligence on macOS 27 and deletes its models appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · helpnetsecurity

Malwarebytes Scam Link Check analyzes URLs and explains potential risks

Malwarebytes launched Scam Link Check, a free web tool that lets users check whether a website link is safe or dangerous before clicking it.

3 retained claims3 cited excerpts

Source published Oct 5, 2026, 1:30 PM UTC · Evidence retrieved Oct 5, 2026, 2:51 PM UTC

What happened

Malwarebytes launched Scam Link Check, a free web tool that lets users check whether a website link is safe or dangerous before clicking it. [1]

Users paste suspicious URLs received by text, email, chat, or social media; the tool returns a safety result, reasons for that result, and recommended next steps. [2]

Why it matters

The source characterizes scams as having overtaken many traditional crimes in scale and states that an estimated $442 billion was lost to scams, although the provided text is truncated afterward. [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Malwarebytes has launched the Malwarebytes Scam Link Check, a free web tool that lets anyone check whether a website link is safe or dangerous before clicking it.
  2. [2]
    Users paste any suspicious URL, the kind that arrives by text, email, chat, or social media, and the tool returns a safety result, along with the reasons behind it and recommended next steps.
  3. [3]
    Scams have overtaken many traditional crimes in scale, with an estimated $442 billion lost to … More → The post Malwarebytes Scam Link Check analyzes URLs and explains potential risks appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · helpnetsecurity

Stellar Cyber 7.0 adds measurable workflows for AI-powered SOCs

Stellar Cyber announced Stellar Cyber 7.0 as a release intended to advance its Human-Augmented Autonomous SOC concept into a practical operating model for security operations.

3 retained claims3 cited excerpts

Source published Oct 5, 2026, 1:31 PM UTC · Evidence retrieved Oct 5, 2026, 2:51 PM UTC

What happened

Stellar Cyber announced Stellar Cyber 7.0 as a release intended to advance its Human-Augmented Autonomous SOC concept into a practical operating model for security operations. [1]

The release unifies AI-powered case triage, measurable SOC workflows, deeper investigative evidence, expanded automated response, and new APIs for operating security at scale. [2]

Why it matters

The article characterizes Stellar Cyber 7.0 as progress beyond using AI only to help analysts work faster. [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Stellar Cyber has announced Stellar Cyber 7.0, a release that advances the Human-Augmented Autonomous SOC from a vision for applying AI to security operations into a practical operating model for running them.
  2. [2]
    Stellar Cyber 7.0 unifies AI-powered case triage, measurable SOC workflows, deeper investigative evidence, expanded automated response and new APIs for operating security at scale.
  3. [3]
    The result marks significant progress from simply using AI to help analysts work faster.

Read the original article →

Luna-enriched source article · helpnetsecurity

LTM launches BlueVerse AgenTraceIQ to monitor AI agents and reverse unintended actions

LTM announced BlueVerse AgenTraceIQ, an offering intended to help organizations adopt and scale agentic AI securely.

4 retained claims3 cited excerpts

Source published Oct 5, 2026, 1:37 PM UTC · Evidence retrieved Oct 5, 2026, 2:51 PM UTC

What happened

LTM announced BlueVerse AgenTraceIQ, an offering intended to help organizations adopt and scale agentic AI securely. [1]

The offering combines Rubrik Agent Cloud with LTM’s AI-governance and managed-services expertise. [2]

AgenTraceIQ is described as enabling organizations to monitor AI agents, establish guardrails, and rewind unintended agent actions in business-critical environments. [2]

Why it matters

LTM and other Global Systems Integrators are partnering with Rubrik through Project Hourglass to deliver the offering. [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    LTM has announced the launch of BlueVerse AgenTraceIQ, an offering designed to help organizations securely adopt and scale agentic AI.
  2. [2]
    Combining Rubrik Agent Cloud with LTM’s AI governance and managed services expertise, the offering enables organizations to monitor AI agents, establish guardrails, and rewind unintended agent actions across business-critical environments.
  3. [3]
    As part of Rubrik’s Project Hourglass, LTM and other elite Global Systems Integrators partner with Rubrik, the Security and AI Operations Company, to deliver Rubrik … More → The post LTM launches BlueVerse AgenTraceIQ to monitor AI agents and reverse unintended actions appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · securityaffairs

Denmark ’s Population Registry Breached, 8.8 Million Affected

Hackers accessed names, addresses and CPR numbers in Denmark’s national population register through a third-party company with legal registry access.

7 retained claims16 cited excerpts

Source published Oct 5, 2026, 1:49 PM UTC · Evidence retrieved Oct 5, 2026, 2:51 PM UTC

What happened

Hackers accessed names, addresses and CPR numbers in Denmark’s national population register through a third-party company with legal registry access. [1] [2] [3] [4]

The registry covers 8.8 million people and contains around 11 million records, including people who have died or moved abroad. [5] [6]

The digital affairs minister called the incident extremely serious; authorities are mapping its full extent and investigating, but did not yet know who carried out the attack. [7] [8] [9]

The government said the company’s registry access had not been revoked after the breach. [12]

Why it matters

Because CPR numbers support banking, healthcare and tax services, combining them with names and addresses could create a serious identity-fraud risk. [10] [11]

The source characterizes the exposed population data as potentially valuable for identity fraud, intelligence, influence operations, social engineering, disinformation and future cyber operations. [13] [14] [15]

Known limitations

The full scope of the incident and the identity of the attacker remained unresolved in the supplied evidence. [7] [9] [16]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Hackers accessed names, addresses and CPR numbers of 8.8 million people in Denmark through a third-party company with legal registry access.
  2. [2]
    The affected database is Denmark’s national population register.
  3. [3]
    It contains names, addresses and CPR numbers, which are similar to Social Security numbers in the US.
  4. [4]
    What they do know is the entry point: the hackers didn’t breach the government’s systems directly, they went through a Danish company that had legal access to the registry for its own business purposes.
  5. [5]
    The registry covers 8.8 million people, even though Denmark has about six million residents, because it also includes people who have died or moved abroad.
  6. [6]
    In total, the database contains around 11 million records.
  7. [7]
    She called it “an extremely serious incident,” and said the government is working with every relevant authority to map out how far it actually goes.
  8. [8]
    “Together with all the relevant authorities, we are in the process of mapping out the full extent of the incident,” she added.
  9. [9]
    Authorities have launched an investigation, and as of Monday they had no information on who carried out the attack.
  10. [10]
    In Denmark, CPR numbers are used for many important services, including banking, healthcare and taxes.
  11. [11]
    When combined with a person’s name and address, this data could create a serious risk of identity fraud.
  12. [12]
    One detail is especially concerning: the government said the company’s access to the registry has not been revoked.
  13. [13]
    Denmark relies heavily on its CPR system for services such as healthcare, banking and taxes, making this type of data highly valuable not only for identity fraud but also for intelligence and influence operations.
  14. [14]
    Personal data held by governments can help hostile actors build detailed profiles of citizens, officials, businesses and institutions.
  15. [15]
    In a period of growing tensions between states, such databases can become strategic targets because the information can support espionage, social engineering, disinformation or future cyber operations.
  16. [16]
    Translation: they’ve confirmed the break-in, but they genuinely don’t know the full scope yet.

Read the original article →

Luna-enriched source article · helpnetsecurity

Fake brand discounts on social media prey on shoppers’ fear of missing out

Cybercriminals are using fake discounts on Facebook and TikTok to direct shoppers to phishing sites that steal payment-card details and one-time passwords, according to Group-IB.

3 retained claims2 cited excerpts

Source published Oct 5, 2026, 1:55 PM UTC · Evidence retrieved Oct 5, 2026, 2:51 PM UTC

What happened

Cybercriminals are using fake discounts on Facebook and TikTok to direct shoppers to phishing sites that steal payment-card details and one-time passwords, according to Group-IB. [1]

The Milk Dragon phishing kit, also known as NaiLong, has reportedly been active since October 2025 and linked to 258 phishing pages and victims in 66 countries. [2]

Why it matters

The campaign uses fake brand discounts on social media to target shoppers’ fear of missing out and obtain payment information and one-time passwords. [1]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Cybercriminals are using fake discounts posted on Facebook and TikTok to lure shoppers to phishing sites that steal their payment card details and one-time passwords, Group-IB has warned.
  2. [2]
    The phishing kit called Milk Dragon (also known as NaiLong) has been active since October 2025, and is linked to 258 phishing pages and victims in 66 countries.

Read the original article →

Published records

Additional source records

Expand a row to inspect provenance
Material developments

Need for Speed: AI-Driven Attacks Are Changing Security Strategies

Darkreading published a source item for review.

1 source recordContext source

What happened

Darkreading published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

Securityweek published a source item for review.

1 source recordContext source

What happened

Securityweek published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms

Securityweek published a source item for review.

1 source recordContext source

What happened

Securityweek published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

Senate Passes Bipartisan Bill to Strengthen Healthcare Cybersecurity

Securityweek published a source item for review.

1 source recordContext source

What happened

Securityweek published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

The US needs a real plan to defend its water systems

Cyberscoop published a source item for review.

1 source recordContext source

What happened

Cyberscoop published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

Microsoft: Windows KB5124010 update crashes some games and apps

Bleepingcomputer published a source item for review.

1 source recordContext source

What happened

Bleepingcomputer published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

More UK Schools Are Recovering Faster from Cyber Incidents

Infosecurity Magazine published a source item for review.

1 source recordContext source

What happened

Infosecurity Magazine published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

doxx.net opens Agentic Defined Networking public beta, raises $38 million

Helpnetsecurity published a source item for review.

1 source recordContext source

What happened

Helpnetsecurity published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

U.S. CISA adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog

Securityaffairs published details for CVE-2026-88779.

1 source recordContext source

What happened

Securityaffairs published details for CVE-2026-88779.

Why it matters

A reviewed impact interpretation has not been published for this record.

Structured associations

CVE-2026-88779 mentioned

Reviewed next steps

  • Check asset inventory and patch status for CVE-2026-88779.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

The Hacker News published details for CVE-2026-88779.

1 source recordContext source

What happened

The Hacker News published details for CVE-2026-88779.

Why it matters

A reviewed impact interpretation has not been published for this record.

Structured associations

CVE-2026-88779 mentioned

Reviewed next steps

  • Check asset inventory and patch status for CVE-2026-88779.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

ClingSTUN Malware Turns Unpatched IoT Devices Into Proxy Nodes

Infosecurity Magazine published a source item for review.

1 source recordContext source

What happened

Infosecurity Magazine published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

New Stealthy Linux Backdoors Target Telecoms, Masquerade as Email Traffic

Infosecurity Magazine published a source item for review.

1 source recordContext source

What happened

Infosecurity Magazine published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

Citrix NetScaler Targeted Via New Zero Day

Infosecurity Magazine published a source item for review.

1 source recordContext source

What happened

Infosecurity Magazine published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

Alleged dev of Ploutus ATM malware appears in US court after arrest

Bleepingcomputer published a source item for review.

1 source recordContext source

What happened

Bleepingcomputer published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

Exploitation Hits Rejetto HFS Vulnerability Discovered by AI

Securityweek published details for CVE-2026-61500.

1 source recordContext source

What happened

Securityweek published details for CVE-2026-61500.

Why it matters

A reviewed impact interpretation has not been published for this record.

Structured associations

CVE-2026-61500 mentioned

Reviewed next steps

  • Check asset inventory and patch status for CVE-2026-61500.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

Out-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940)

Helpnetsecurity published details for CVE-2026-96940.

1 source recordContext source

What happened

Helpnetsecurity published details for CVE-2026-96940.

Why it matters

A reviewed impact interpretation has not been published for this record.

Structured associations

CVE-2026-96940 mentioned

Reviewed next steps

  • Check asset inventory and patch status for CVE-2026-96940.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

Google Suspends Open-Source Bug Bounty Due to AI Vulnerability Reports

Infosecurity Magazine published a source item for review.

1 source recordContext source

What happened

Infosecurity Magazine published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

Google halts open-source bug bounty program amid AI spam surge

Bleepingcomputer published a source item for review.

1 source recordContext source

What happened

Bleepingcomputer published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

AI slop submissions force Google to freeze its open-source bug bounty

Helpnetsecurity published a source item for review.

1 source recordContext source

What happened

Helpnetsecurity published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

A week in security (September 28 – October 4)

Malwarebytes Labs published a source item for review.

1 source recordAuthoritative source

What happened

Malwarebytes Labs published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Securityweek published details for CVE-2026-88779.

1 source recordContext source

What happened

Securityweek published details for CVE-2026-88779.

Why it matters

A reviewed impact interpretation has not been published for this record.

Structured associations

CVE-2026-88779 mentioned

Reviewed next steps

  • Check asset inventory and patch status for CVE-2026-88779.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Cloud and infrastructure

Belarusian hacktivists spent two years inside Russian healthcare network, researchers say

Therecord Media published a source item for review.

1 source recordContext source

What happened

Therecord Media published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Cloud and infrastructure

0.45.1-rc1

Falcosecurity Falco Releases published a source item for review.

1 source recordAuthoritative source

What happened

Falcosecurity Falco Releases published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

  • 0.45.1-rc1 Falcosecurity Falco Releases · Published 2026-10-05T07:54:26Z · Retrieved Oct 5, 2026, 8:51 AM UTC

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Incidents and exposure

Japanese media group Nikkei discloses cyberattack targeting journalistic sources

Therecord Media published a source item for review.

1 source recordContext source

What happened

Therecord Media published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Incidents and exposure

Data breach at Denmark’s national population register exposes 8.8 million people

Therecord Media published a source item for review.

1 source recordContext source

What happened

Therecord Media published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Incidents and exposure

Frontline Education Breach Impacts K-12 School District Staff

Infosecurity Magazine published a source item for review.

1 source recordContext source

What happened

Infosecurity Magazine published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Incidents and exposure

Alleged ShinyHunters Leader Arrested in Jordan

Securityweek published a source item for review.

1 source recordContext source

What happened

Securityweek published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

AI and model reality

Our approach to EU text provenance rules

OpenAI published a source item for review.

1 source recordAuthoritative source

What happened

OpenAI published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

AI and model reality

The Credential Layer Is Expanding Faster Than Security Teams Can See It

The Hacker News published a source item for review.

1 source recordContext source

What happened

The Hacker News published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

AI and model reality

OpenAI will show visual ads in ChatGPT while you generate images

Bleepingcomputer published a source item for review.

1 source recordContext source

What happened

Bleepingcomputer published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

AI and model reality

Apple tightens macOS disk access as AI agents become more powerful

Helpnetsecurity published a source item for review.

1 source recordContext source

What happened

Helpnetsecurity published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.