Source context

Why this day matters

  • A critical vulnerability affecting eight Atlassian products, including Jira and Confluence, is being exploited in the wild, said VulnCheck
  • In leaked chats, members track dozens of victims, haggle over multimillion-dollar payments and direct operatives based in the United States whom they call “agents.”
Validated article intelligence

Enriched source records

Expand a row to inspect claims and citations

Luna-generated claims retained by the evidence and claim-validation gates. Automated validation does not imply human review. A record does not need a CVE to be included.

Luna-enriched source article · helpnetsecurity

Medical devices patients rely on most are least prepared for quantum attacks

Threat actors are exploiting IT, IoMT, OT and IoT devices across healthcare delivery organizations to deploy ransomware, demand payments and monetize stolen patient data, according to a Forescout report.

3 retained claims3 cited excerpts

Source published Oct 8, 2026, 4:00 AM UTC · Evidence retrieved Oct 8, 2026, 8:51 AM UTC

What happened

Threat actors are exploiting IT, IoMT, OT and IoT devices across healthcare delivery organizations to deploy ransomware, demand payments and monetize stolen patient data, according to a Forescout report. [1]

Researchers analyzed more than 2.5 million devices across more than 50 healthcare delivery organization networks. [2]

From January through August 2026, researchers tracked 461 public ransomware claims and 300 hacktivist attack claims against healthcare organizations; the supplied text is truncated after this statement. [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Threat actors are exploiting IT, IoMT, OT and IoT devices across healthcare delivery organizations (HDOs) to deploy ransomware, demand payments and monetize stolen patient data, according to Forescout’s Post-Quantum Cryptography (PQC) in Healthcare: From Data Risk to Migration Readiness report.
  2. [2]
    Researchers analyzed a dataset containing more than 2.5 million devices across more than 50 HDO networks.
  3. [3]
    Separately, between January and August 2026, they tracked 461 public ransomware claims and 300 hacktivist attack claims against healthcare … More → The post Medical devices patients rely on most are least prepared for quantum attacks appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · helpnetsecurity

Java library vulnerabilities: IBM and Red Hat fix 400+ previously unknown flaws

IBM and Red Hat found and fixed more than 400 previously unknown vulnerabilities in widely used Java libraries through Lightwell, a program for patching open-source code already used in production.

3 retained claims3 cited excerpts

Source published Oct 8, 2026, 4:18 AM UTC · Evidence retrieved Oct 8, 2026, 8:51 AM UTC

What happened

IBM and Red Hat found and fixed more than 400 previously unknown vulnerabilities in widely used Java libraries through Lightwell, a program for patching open-source code already used in production. [1]

Why it matters

Companies running the affected libraries remain exposed until they apply the fixes. [2]

The source states that autonomous AI agents can combine several minor software weaknesses into one serious attack. [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    IBM and Red Hat have found and fixed more than 400 previously unknown vulnerabilities in widely used Java libraries through Lightwell, their program for patching open source code that companies already run in production.
  2. [2]
    Companies running the affected libraries are exposed until they apply the fixes.
  3. [3]
    Autonomous AI agents can now combine several minor software weaknesses into one serious attack.

Read the original article →

Luna-enriched source article · helpnetsecurity

The people who know passkeys best are still typing passwords

Yubico and Okta surveyed 1,890 technology and security professionals across nine countries about how they sign in to work accounts.

3 retained claims3 cited excerpts

Source published Oct 8, 2026, 4:30 AM UTC · Evidence retrieved Oct 8, 2026, 8:51 AM UTC

What happened

Yubico and Okta surveyed 1,890 technology and security professionals across nine countries about how they sign in to work accounts. [1]

Username-and-password sign-in was the most common response, reported by 43% of respondents; 87% of that group said they were familiar with passkeys. [2]

Why it matters

Half of respondents said they were issued a username and password when they began their current role. [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Yubico and Okta asked 1,890 technology and security professionals across nine countries how they sign in to work accounts.
  2. [2]
    The most common answer was a username and password, at 43%, from a group in which 87% said they were familiar with passkeys.
  3. [3]
    High familiarity with modern authentication (Source: 2026 Global State of Authentication Report) The password comes with the laptop Half of respondents were issued a username and password when they started their current role.

Read the original article →

Luna-enriched source article · helpnetsecurity

How AI can fix cybersecurity compliance: From dashboards to continuous execution

The article states that compliance work often focuses on proving security rather than improving it, while organizations are expected to implement and monitor hundreds of controls, respond to incidents, and demonstrate that these measures work.

3 retained claims5 cited excerpts

Source published Oct 8, 2026, 5:00 AM UTC · Evidence retrieved Oct 8, 2026, 8:51 AM UTC

What happened

The article states that compliance work often focuses on proving security rather than improving it, while organizations are expected to implement and monitor hundreds of controls, respond to incidents, and demonstrate that these measures work. [1] [2]

The article characterizes the main problem as the cost of delivering cybersecurity compliance, rather than the reasonableness of the rules. [3] [4]

Why it matters

The article reports the Pentagon’s estimate that CMMC Level 2 compliance costs a small contractor roughly $105,000 over three years. [5]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Most compliance work goes into proving security, not improving it.
  2. [2]
    Regulators, customers, and cyber insurers are right to expect organizations to implement hundreds of technical and administrative controls, monitor their environments, respond to incidents, and prove that all of it works.
  3. [3]
    That isn’t because the rules are unreasonable.
  4. [4]
    The problem is the cost of delivering it.
  5. [5]
    The Pentagon’s own estimate puts a small contractor’s CMMC level 2 compliance at roughly $105,000 over three years.

Read the original article →

Luna-enriched source article · helpnetsecurity

Who watches the AI watching your street?

Yusaku Fujii, a Gunma University professor, designed audits and penalties intended to deter operators from misusing AI that analyzes street-camera footage.

4 retained claims4 cited excerpts

Source published Oct 8, 2026, 5:30 AM UTC · Evidence retrieved Oct 8, 2026, 8:51 AM UTC

What happened

Yusaku Fujii, a Gunma University professor, designed audits and penalties intended to deter operators from misusing AI that analyzes street-camera footage. [1]

The system adds an independent record-keeper and conducts unannounced spot checks of the AI’s outputs. [2]

Fujii’s test setting, called a Fully Monitored Public Space, uses dense camera coverage to follow people and vehicles continuously. [3]

The setting can be built with existing network cameras and encrypted storage. [4]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Yusaku Fujii, a professor at Gunma University in Japan, has designed audits and penalties to stop operators from misusing AI that analyzes street camera footage.
  2. [2]
    His system adds an independent record-keeper and unannounced spot checks to the AI’s outputs.
  3. [3]
    Fujii’s test setting is what he calls a Fully Monitored Public Space (FMPS): streets where cameras are dense enough to follow people and vehicles continuously.
  4. [4]
    It can be built with existing network cameras and encrypted storage.

Read the original article →

Luna-enriched source article · schneier blog

Apple’s Verified Photography System

Apple’s Reference Image system can verify that an image was taken exactly as captured by a newer-model iPhone, without linking it to a particular phone or photographer.

8 retained claims11 cited excerpts

Source published Oct 8, 2026, 5:44 AM UTC · Evidence retrieved Oct 8, 2026, 7:23 AM UTC

What happened

Apple’s Reference Image system can verify that an image was taken exactly as captured by a newer-model iPhone, without linking it to a particular phone or photographer. [1]

The system can also verify that multiple images originated from the same iPhone. [2]

Apple says Reference Image avoids explicit public photographer credentials and avoids implicit public association between photos taken by the same sensor. [5]

After validation by PCC, the final reference image is signed by Apple’s signing service, with the signature backed by Apple’s strongest technical guarantees. [6] [7]

Apple says the implementation protects the image’s confidentiality, including from Apple, and that capturing a reference image does not expose its pixels to Apple or anyone else. [8] [9]

The revocation service keeps a private record of photo GUIDs and associated sensors, but the source says it cannot access image data and does not make that record public. [10]

Final revocation checks use on-device lists, so the source says a device does not reveal which photo it is checking for validity. [11]

Why it matters

The source says other industry solutions require a photographer or institution to authenticate an image with their own credentials, which can pressure conflict-zone photographers to give up anonymity. [3] [4]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Apple just released a system called “Reference Image.” It can verify the image is exactly as taken by an iPhone—new models only—without tying it to a specific iPhone or photographer.
  2. [2]
    It can also verify that multiple images came from the same iPhone.
  3. [3]
    Other industry solutions require a photographer or institution to vouch for an image using their own credentials.
  4. [4]
    We are concerned this puts some photographers, such as those operating in conflict zones, in a difficult position; it should not be necessary to forgo anonymity in order to prove image authenticity.
  5. [5]
    We built Apple Reference Image to avoid using an explicit, public credential for photographers, and to avoid even implicit public association between different photos taken by the same sensor.
  6. [6]
    The final reference image is instead signed by Apple’s signing service, after validation by PCC.
  7. [7]
    That signature is backed by Apple’s strongest technical guarantees.
  8. [8]
    Our implementation also protects the confidentiality of the image itself, including from Apple.
  9. [9]
    Merely capturing a reference image should never expose the actual pixels to Apple or anyone else.
  10. [10]
    While the revocation service must maintain a private record of photo GUIDs and associated sensors to allow for revocation, it never has access to the image data, and does not allow for public access to this record.
  11. [11]
    And as final revocation checks occur using on-device lists, a device never reveals to anyone which photo it’s looking at in order to find out whether it’s still valid.

Read the original article →

Luna-enriched source article · the hacker news

Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

The npm package “tensorlake,” a TypeScript SDK for Tensorlake applications, sandboxes, and cloud services, was compromised in a ChainDrop/Shai-Hulud supply-chain attack.

2 retained claims2 cited excerpts

Source published Oct 8, 2026, 5:46 AM UTC · Evidence retrieved Oct 8, 2026, 7:23 AM UTC

What happened

The npm package “tensorlake,” a TypeScript SDK for Tensorlake applications, sandboxes, and cloud services, was compromised in a ChainDrop/Shai-Hulud supply-chain attack. [1]

Version 0.5.144 reportedly contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code. [2]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    The npm package known as "tensorlake," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack.
  2. [2]
    The malicious version 0.5.144 "contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code," Socket said

Read the original article →

Luna-enriched source article · helpnetsecurity

Pricing your bad days and how to build an economic model for security decisions

Ivan Milenkovic, Qualys VP Risk Technology EMEA, discusses building an economic model to support security decisions.

4 retained claims4 cited excerpts

Source published Oct 8, 2026, 6:00 AM UTC · Evidence retrieved Oct 8, 2026, 8:51 AM UTC

What happened

Ivan Milenkovic, Qualys VP Risk Technology EMEA, discusses building an economic model to support security decisions. [1]

The proposed approach starts with a few loss scenarios and traces them back to the assets that drive those scenarios. [2]

Why it matters

The article covers ranking fixes by value at risk, addressing CFO expectations, and demonstrating the value of incidents that did not occur. [3]

The source indicates that the model may be applicable across more than one security decision context, but the available text is truncated before explaining how. [4]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Ivan Milenkovic, VP Risk Technology EMEA at Qualys, explains how security leaders can build an economic model that puts money behind their decisions.
  2. [2]
    He suggests starting with a few loss scenarios, then working down to the assets that drive them.
  3. [3]
    He covers how to rank fixes by value at risk, what CFOs expect to see, and how to show the worth of incidents that never happened.
  4. [4]
    He also looks at how one model can serve … More → The post Pricing your bad days and how to build an economic model for security decisions appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · the hacker news

MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data

The U.S. Department of Justice announced charges against Zohar Pinhasi, also known as Zack Silver and Zack Green, alleging that he defrauded ransomware victims by secretly paying attackers for decryptors while claiming to use proprietary data-recovery tools.

2 retained claims3 cited excerpts

Source published Oct 8, 2026, 7:41 AM UTC · Evidence retrieved Oct 8, 2026, 1:23 PM UTC

What happened

The U.S. Department of Justice announced charges against Zohar Pinhasi, also known as Zack Silver and Zack Green, alleging that he defrauded ransomware victims by secretly paying attackers for decryptors while claiming to use proprietary data-recovery tools. [1] [2] [3]

The charges include two counts of wire fraud and one count of wire fraud-related conduct, although the supplied text truncates the final charge description. [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Department of Justice (DoJ) on Wednesday announced charges against a 50-year-old U.S.
  2. [2]
    and Israeli national for allegedly defrauding ransomware victims by secretly paying the attackers to obtain decryptors while claiming to use proprietary tools to recover their data.
  3. [3]
    Zohar Pinhasi (aka Zack Silver and Zack Green) has been charged with two counts of wire fraud and one count of wire

Read the original article →

Luna-enriched source article · the hacker news

U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks

The U.S. State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 2021 Microsoft Exchange Server attacks known as HAFNIUM.

2 retained claims3 cited excerpts

Source published Oct 8, 2026, 7:42 AM UTC · Evidence retrieved Oct 8, 2026, 1:23 PM UTC

What happened

The U.S. State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 2021 Microsoft Exchange Server attacks known as HAFNIUM. [1] [2]

The reward concerns information leading to Zhang Yu’s identification or location; the report attributes the notice to NTD. [2] [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    The U.S.
  2. [2]
    State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 2021 Microsoft Exchange Server attacks known as HAFNIUM.
  3. [3]
    The reward is for information leading to his identification or location, the news outlet NTD reported this week, citing a notice

Read the original article →

Luna-enriched source article · helpnetsecurity

Ransomware recovery firm boss charged with secretly paying attackers and overcharging victims

The owner of MonsterCloud, a Florida-based ransomware remediation company, was charged with fraud for allegedly paying ransomware gangs without clients’ knowledge and billing them more than the ransom.

3 retained claims3 cited excerpts2 preserved revisions

Source published Oct 8, 2026, 8:00 AM UTC · Evidence retrieved Oct 8, 2026, 2:51 PM UTC

What happened

The owner of MonsterCloud, a Florida-based ransomware remediation company, was charged with fraud for allegedly paying ransomware gangs without clients’ knowledge and billing them more than the ransom. [1]

The indictment alleges that Zohar Pinhasi, also known as “Zack Silver” and “Zack Green,” billed MonsterCloud clients more than $19 million while paying more than $8 million to ransomware gangs that attacked them. [2]

Known limitations

The supplied excerpt does not provide the indictment’s detailed allegations about what Pinhasi told prospective clients. [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    The owner of Florida-based ransomware remediation company MonsterCloud has been charged with fraud for allegedly paying ransomware gangs behind his clients’ backs and billing them far more than the ransom.
  2. [2]
    Zohar Pinhasi (aka “Zack Silver” and “Zack Green”), a 50-year-old US and Israeli national from Hollywood, Florida, allegedly billed MonsterCloud clients more than $19 million while paying more than $8 million to the ransomware gangs that attacked them.
  3. [3]
    According to the indictment, Pinhasi told prospective … More → The post Ransomware recovery firm boss charged with secretly paying attackers and overcharging victims appeared first on Help Net Security .

Read the original article →

Earlier retained revision · Oct 8, 2026, 8:51 AM UTC

Source published Oct 8, 2026, 8:00 AM UTC · Evidence retrieved Oct 8, 2026, 8:51 AM UTC

What happened

The owner of Florida-based ransomware remediation company MonsterCloud was charged with fraud for allegedly paying ransomware gangs behind clients’ backs and billing clients more than the ransom. [1]

The indictment alleges that Zohar Pinhasi, also known as “Zack Silver” and “Zack Green,” charged MonsterCloud clients more than $19 million while paying more than $8 million to ransomware gangs that attacked them. [2]

Known limitations

The supplied evidence does not provide the specific allegations about what Pinhasi told prospective clients. [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    The owner of Florida-based ransomware remediation company MonsterCloud has been charged with fraud for allegedly paying ransomware gangs behind his clients’ backs and billing them far more than the ransom.
  2. [2]
    Zohar Pinhasi (aka “Zack Silver” and “Zack Green”), a 50-year-old US and Israeli national from Hollywood, Florida, allegedly charged MonsterCloud clients more than $19 million while paying more than $8 million to the ransomware gangs that attacked them.
  3. [3]
    According to the indictment, Pinhasi told prospective … More → The post Ransomware recovery firm boss charged with secretly paying attackers and overcharging victims appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · helpnetsecurity

GitHub adds AI to catch passwords before a code push

GitHub announced an AI detector developed with Microsoft Applied Sciences to help prevent developers from uploading passwords and other credentials to code repositories.

3 retained claims4 cited excerpts

Source published Oct 8, 2026, 9:02 AM UTC · Evidence retrieved Oct 8, 2026, 2:51 PM UTC

What happened

GitHub announced an AI detector developed with Microsoft Applied Sciences to help prevent developers from uploading passwords and other credentials to code repositories. [1]

The ModernBERT-based classifier expands GitHub’s push protection, which checks code for secrets and can block a push before a credential enters repository history. [2]

Existing checks recognize many credentials by their formats, while the new classifier examines surrounding code to identify unstructured secrets such as database passwords. [3] [4]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    GitHub has announced an AI detector, developed with Microsoft Applied Sciences, to help prevent developers from uploading passwords and other credentials to code repositories.
  2. [2]
    The ModernBERT-based classifier will expand GitHub’s push protection, which checks code for secrets and can block a push before a credential enters repository history.
  3. [3]
    How the detector works Existing checks recognize many credentials by their formats.
  4. [4]
    The new classifier examines surrounding code to identify unstructured secrets, such as database passwords with … More → The post GitHub adds AI to catch passwords before a code push appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · cyberscoop

Quantum computers could break today’s encryption. Washington needs to prepare now.

A sufficiently powerful quantum computer could break widely used encryption protecting sensitive digital information, potentially affecting emails, financial transactions, government communications, and military systems.

6 retained claims12 cited excerpts

Source published Oct 8, 2026, 10:00 AM UTC · Evidence retrieved Oct 8, 2026, 2:51 PM UTC

What happened

A sufficiently powerful quantum computer could break widely used encryption protecting sensitive digital information, potentially affecting emails, financial transactions, government communications, and military systems. [1] [2]

Researchers believe some encryption-breaking requirements may be lower than previously estimated; Caltech spinout Oratomic reported research suggesting a cryptographically relevant quantum computer could require substantially fewer physical resources than earlier estimates. [3] [4]

The NSA selected quantum-resistant algorithms for National Security Systems, while a White House directive set federal targets for post-quantum cryptography for key establishment by the end of 2030 and digital signatures by the end of 2031. [9] [10]

Why it matters

Adversaries can steal encrypted information now, retain it, and seek to decrypt it later when they have sufficient computing capability—a risk described as “harvest now, decrypt later.” [5] [6]

Data requiring long-term confidentiality, including intelligence reports, military communications, corporate secrets, financial information, and other sensitive information, may face risk before a capable quantum computer exists. [7] [8]

Known limitations

The article states that no one knows exactly when quantum computers will become powerful enough to break today’s encryption, while arguing that this uncertainty is not a reason to delay preparation. [11] [12]

Some generated claims did not pass validation and were omitted. Only retained claims are shown.

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Unlike AI safety debates, this risk could render today’s encryption obsolete – compromising everything from emails to financial transactions to government communications and military systems.
  2. [2]
    But a sufficiently powerful quantum computer could crack widely used forms of encryption protecting sensitive digital information globally.
  3. [3]
    Researchers now believe breaking some encryption may require fewer resources than previously thought.
  4. [4]
    This spring, Caltech spinout Oratomic published research suggesting a cryptographically relevant quantum computer could need dramatically fewer physical resources than earlier estimates.
  5. [5]
    But some dangers exist now.
  6. [6]
    Cybersecurity experts call this “harvest now, decrypt later.” The White House identified that threat in its June order.
  7. [7]
    Foreign adversaries can steal encrypted information today, store it, and wait until they possess the computing power to decrypt it later.
  8. [8]
    Intelligence reports, military communications, corporate secrets, financial information, and other data that must remain private for years face risk long before a quantum computer capable of decrypting it exists.
  9. [9]
    The National Security Agency has selected quantum-resistant algorithms for National Security Systems and is moving classified and other sensitive systems toward its CNSA 2.0 standards.
  10. [10]
    In June, the White House accelerated the broader federal transition , directing high value federal systems to adopt post-quantum cryptography for key establishment by the end of 2030 and digital signatures by the end of 2031.
  11. [11]
    No one knows exactly when quantum computers will become powerful enough to break today’s encryption.
  12. [12]
    That uncertainty is not a reason to wait.

Read the original article →

Luna-enriched source article · securityaffairs

U.S. Offers $10 Million Reward for Alleged HAFNIUM Hacker Zhang Yu

The U.S. State Department is offering up to $10 million for information leading to the arrest or location of Zhang Yu, a Chinese national and Shanghai Firetech director.

6 retained claims15 cited excerpts

Source published Oct 8, 2026, 10:11 AM UTC · Evidence retrieved Oct 8, 2026, 2:51 PM UTC

What happened

The U.S. State Department is offering up to $10 million for information leading to the arrest or location of Zhang Yu, a Chinese national and Shanghai Firetech director. [1] [2]

Prosecutors accuse Zhang of supervising cyberattacks with Xu Zewei while working under China’s Shanghai State Security Bureau, which they identify as part of the Ministry of State Security. [3] [4]

The indictment describes a 2020 campaign targeting U.S. universities and COVID-19 researchers, followed by exploitation of Microsoft Exchange Server vulnerabilities in the HAFNIUM mass-intrusion campaign. [5] [6] [7] [8]

The charges against Zhang have not been tested in court, and he remains at large, unlike Xu, who the article says was arrested in Milan and extradited to the United States. [12] [13] [14]

Why it matters

The announcement says the HAFNIUM intrusions compromised thousands of computers worldwide; the article attributes a figure of more than 12,700 compromised U.S. organizations to the FBI. [9] [10] [11]

Known limitations

The article says it is unknown whether the reward will persuade someone close to Zhang to provide information. [15]

Some generated claims did not pass validation and were omitted. Only retained claims are shown.

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    State Department is offering a $10 million reward for information leading to the arrest of Zhang Yu.
  2. [2]
    “Under this reward offer, RFJ seeks information on Zhang Yu, a Chinese national and director at Shanghai Firetech Information Science and Technology Company, Ltd.
  3. [3]
    According to the indictment, Zhang supervised Firetech employees involved in cyberattacks and worked directly with another accused hacker, Xu Zewei .
  4. [4]
    prosecutors allege that both men worked under China’s Shanghai State Security Bureau, a branch of the Ministry of State Security.
  5. [5]
    The indictment covers two distinct hacking campaigns.
  6. [6]
    The first, in early 2020, hit U.S.
  7. [7]
    universities and scientists working on COVID-19 vaccines and treatments.
  8. [8]
    The second, later that year, exploited flaws in Microsoft Exchange Server in what became known as HAFNIUM, eventually compromising Exchange servers across the globe.
  9. [9]
    “The following year, Zhang and Xu exploited vulnerabilities in computers running Microsoft Exchange Server, a computer program involved in the storage and retrieval of e-mails.
  10. [10]
    Those intrusions were part of mass intrusion campaign, publicly known as HAFNIUM, which compromised thousands of computers worldwide.” The scale of HAFNIUM backs up why anyone would pay $10 million for a tip.
  11. [11]
    The FBI puts the total at more than 12,700 compromised U.S.
  12. [12]
    Xu’s own case shows these rewards aren’t just theater either, he was arrested in Milan back in 2025 while on vacation and extradited to the U.S.
  13. [13]
    this past April.
  14. [14]
    Unlike Xu, Zhang is still free, and the charges against him have not been tested in court.
  15. [15]
    Whether the reward will be enough to convince someone close to Zhang to provide information is impossible to know.

Read the original article →

Luna-enriched source article · helpnetsecurity

Cryptomining botnet hides C2 addresses in GitHub poem, infects over 3,400 servers

Black Lotus Labs reported that thousands of hijacked servers looked up their command-and-control server in a poem posted on GitHub.

4 retained claims3 cited excerpts

Source published Oct 8, 2026, 10:24 AM UTC · Evidence retrieved Oct 8, 2026, 2:51 PM UTC

What happened

Black Lotus Labs reported that thousands of hijacked servers looked up their command-and-control server in a poem posted on GitHub. [1]

The malware, dubbed PoeLLM, reportedly breaks into exposed AI services and open-source tools, mines cryptocurrency, and uses those systems to search for additional victims. [2]

Why it matters

The campaign, called Canto Incognito by the researchers, was reported to have infected more than 3,400 servers. [3]

Known limitations

Researchers believe the campaign is the work of an Italian-speaking threat actor who appears to be in it for cryptocurrency mining; the supplied text does not provide further attribution evidence. [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Thousands of hijacked servers have been looking up their command and control (C2) server in a poem posted on GitHub, according to Black Lotus Labs.
  2. [2]
    The malware reading it, dubbed PoeLLM, breaks into exposed AI services and open-source tools, mines cryptocurrency on them and uses them to hunt for new victims.
  3. [3]
    The researchers call the campaign Canto Incognito and believe it is the work of an Italian-speaking threat actor who appears to be in it … More → The post Cryptomining botnet hides C2 addresses in GitHub poem, infects over 3,400 servers appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · the hacker news

Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia

Phishing kits increasingly incorporate filtering, session management, and traffic controls into the infrastructure delivering the phishing page, rather than only copying a login page and collecting credentials.

2 retained claims3 cited excerpts

Source published Oct 8, 2026, 10:30 AM UTC · Evidence retrieved Oct 8, 2026, 1:23 PM UTC

What happened

Phishing kits increasingly incorporate filtering, session management, and traffic controls into the infrastructure delivering the phishing page, rather than only copying a login page and collecting credentials. [1] [2]

ANY.RUN identified Wazza as a new phishkit targeting banking, manufacturing, and government organizations across the US and Europe. [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials.
  2. [2]
    Attackers are increasingly building filtering, session management, and traffic controls into the infrastructure that delivers the phishing page itself.
  3. [3]
    ANY.RUN has identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe

Read the original article →

Luna-enriched source article · helpnetsecurity

YouTubers targeted with fake sponsorships and “channel verification” phishing

Scammers target YouTube creators’ Google accounts by posing as brands seeking sponsorship partners.

3 retained claims3 cited excerpts

Source published Oct 8, 2026, 12:41 PM UTC · Evidence retrieved Oct 8, 2026, 2:51 PM UTC

What happened

Scammers target YouTube creators’ Google accounts by posing as brands seeking sponsorship partners. [1]

The campaign uses personalized emails referencing creators’ videos and directs targets to a convincing fake collaboration platform before prompting them to sign in with Google. [2]

ESET researchers reportedly identified a campaign impersonating Hollyland, a legitimate manufacturer. [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Scammers are going after YouTube creators’ Google accounts by posing as a brand looking for sponsorship partners.
  2. [2]
    By sending out personalized emails that reference a creator’s own videos and directing targeted creators to a convincing fake collaboration platform, the fraudsters walk them through what looks like a routine brand deal, right up until the moment they’re asked to sign in with Google.
  3. [3]
    According to researchers at ESET, one recent campaign impersonates Hollyland, a legitimate manufacturer … More → The post YouTubers targeted with fake sponsorships and “channel verification” phishing appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · helpnetsecurity

Authorities seize sites selling hacked, stolen intimate images of 17,000 women and girls

The FBI and French law enforcement seized two websites that sold hacked and stolen sexually explicit images and videos of young women and girls, and arrested their suspected administrator in northern France.

3 retained claims2 cited excerpts

Source published Oct 8, 2026, 12:51 PM UTC · Evidence retrieved Oct 8, 2026, 2:51 PM UTC

What happened

The FBI and French law enforcement seized two websites that sold hacked and stolen sexually explicit images and videos of young women and girls, and arrested their suspected administrator in northern France. [1]

The seized domains belonged to NudeLeaksTeens (NLT), according to the U.S. Attorney’s Office for the Eastern District of Virginia. [2]

Why it matters

The article headline reports that the seized sites involved intimate images of 17,000 women and girls. [2]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    The FBI and French law enforcement have seized two websites that sold hacked and stolen sexually explicit images and videos of young women and girls, and arrested their suspected administrator in northern France.
  2. [2]
    Attorney’s Office for the Eastern District of Virginia announced on Wednesday that the seized domains belonged to NudeLeaksTeens (NLT), and that the operation was carried out with the FBI Washington Field Office and … More → The post Authorities seize sites selling hacked, stolen intimate images of 17,000 women and girls appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · securityaffairs

MonsterCloud Owner Charged With Secretly Paying Ransomware Demands

Federal prosecutors charged MonsterCloud owner Zohar Pinhasi with two wire-fraud charges and one conspiracy charge, alleging that he secretly paid ransomware attackers while presenting recovery as proprietary decryption work.

5 retained claims11 cited excerpts

Source published Oct 8, 2026, 1:37 PM UTC · Evidence retrieved Oct 8, 2026, 2:51 PM UTC

What happened

Federal prosecutors charged MonsterCloud owner Zohar Pinhasi with two wire-fraud charges and one conspiracy charge, alleging that he secretly paid ransomware attackers while presenting recovery as proprietary decryption work. [1] [2] [3] [4] [5]

The company’s website reportedly told clients not to pay ransoms and promised recovery without dealing with cybercriminals; prosecutors allege the company instead contacted attackers and paid for decryption keys. [4] [6] [7]

Prosecutors cite one case in which about $8,200 in ransom was allegedly paid and the client was billed approximately $150,000; they allege more than $19 million was collected from clients and over $8 million was paid in ransom. [8] [9]

Why it matters

The FBI and CISA do not recommend ransomware payments because payment does not guarantee data decryption, removal of attackers from the network, or prevention of stolen-data leaks. [10]

Known limitations

The charges remain allegations; each of the three charges carries a possible sentence of up to 20 years if Pinhasi is convicted. [5] [11]

Some generated claims did not pass validation and were omitted. Only retained claims are shown.

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Zohar Pinhasi, the owner of Florida-based MonsterCloud, was charged this week with wire fraud.
  2. [2]
    Federal prosecutors say his clients were scammed twice during the same ransomware crisis.
  3. [3]
    According to the indictment, Pinhasi claimed to have proprietary tools and advanced decryption techniques that let him crack ransomware without negotiating with attackers.
  4. [4]
    Instead, he contacted the same cybercriminals who’d hit his client, paid them for a decryption key, then had MonsterCloud staff use that key and present the recovery as the product of his own technology.
  5. [5]
    Pinhasi faces two wire fraud charges and one conspiracy charge.
  6. [6]
    MonsterCloud ’s website told clients not to pay ransoms and promised that its team could recover encrypted data without dealing with cybercriminals.
  7. [7]
    Prosecutors say the company was doing the exact opposite.
  8. [8]
    “Pinhasi typically charged MonsterCloud’s clients a fee that was substantially higher than the ransom that MonsterCloud secretly paid.” reads the press release published by DoJ.
  9. [9]
    Prosecutors cite one case from August 2023 where Pinhasi paid a ransom of roughly $8,200, then billed the client about $150,000 for the “service.” Across the whole scheme, he allegedly collected more than $19 million from clients while quietly paying out over $8 million in ransom money himself, pocketing the difference while selling the opposite of what he was actually doing.
  10. [10]
    The FBI and CISA have clear guidance on ransomware payments: they do not recommend paying because it does not guarantee that the data will be decrypted, that the attackers will leave the network, or that stolen data will not be leaked.
  11. [11]
    Each charge carries a possible sentence of up to 20 years if he is convicted, but the charges are only allegations at this stage.

Read the original article →

Published records

Additional source records

Expand a row to inspect provenance
Material developments

Attackers Hijack Three ccTLDs to Obtain Google Certificates

Infosecurity Magazine published a source item for review.

1 source recordContext source

What happened

Infosecurity Magazine published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

Hackers target two South Korean megachurches, potentially exposing congregant data

Therecord Media published a source item for review.

1 source recordContext source

What happened

Therecord Media published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

Uranium crypto exchange hacker convicted for stealing $53 million

Bleepingcomputer published a source item for review.

1 source recordContext source

What happened

Bleepingcomputer published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

US Seeks Alleged Chinese Hafnium Hacker With $10 Million Reward

Securityweek published a source item for review.

1 source recordContext source

What happened

Securityweek published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

SonicWall and Splunk Patch Critical Vulnerabilities

Securityweek published a source item for review.

1 source recordContext source

What happened

Securityweek published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

Microsoft Teams to get support for third-party deepfake detection tools

Bleepingcomputer published a source item for review.

1 source recordContext source

What happened

Bleepingcomputer published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

Writing the Next Chapter

Darkreading published a source item for review.

1 source recordContext source

What happened

Darkreading published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

Owner of Empire cybercrime market gets 40 years in prison

Bleepingcomputer published a source item for review.

1 source recordContext source

What happened

Bleepingcomputer published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases

The Hacker News published a source item for review.

1 source recordContext source

What happened

The Hacker News published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

FBI and Secret Service Warn of FortiBleed Lockout Threat

Infosecurity Magazine published a source item for review.

1 source recordContext source

What happened

Infosecurity Magazine published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

FortiBleed Attackers Locking Victims Out of Fortinet Devices

Securityweek published a source item for review.

1 source recordContext source

What happened

Securityweek published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

July 2026 Security Updates

Microsoft Security Response Center published a source item for review.

1 source recordAuthoritative source

What happened

Microsoft Security Response Center published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

Critical Flaw in Multiple Atlassian Products Exploited in the Wild

Infosecurity Magazine reports active exploitation in this exact source item.

1 source recordContext source

What happened

Infosecurity Magazine reports active exploitation in this exact source item.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Prioritize exposure review and remediation because exploitation is explicitly confirmed.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

Thousands of cheap Android phones shipped with ad-fraud malware

Therecord Media published a source item for review.

1 source recordContext source

What happened

Therecord Media published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

Russia-Aligned UAC-0099 Evolves MATCHBOIL Malware

Infosecurity Magazine published a source item for review.

1 source recordContext source

What happened

Infosecurity Magazine published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

Russian-aligned spies upgrade malware used in attacks on Ukrainian transport, energy firms

Therecord Media published a source item for review.

1 source recordContext source

What happened

Therecord Media published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Validate the source-stated mitigation in a controlled environment before rollout.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

What is MATCHBOIL? The Russia-aligned malware that installs a spying backdoor

Helpnetsecurity published a source item for review.

1 source recordContext source

What happened

Helpnetsecurity published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

Atlassian Vulnerability Comes Under Attack Hours After Details Go Public

Securityaffairs published details for CVE-2026-21589.

1 source recordContext source

What happened

Securityaffairs published details for CVE-2026-21589.

Why it matters

A reviewed impact interpretation has not been published for this record.

Structured associations

CVE-2026-21589 mentioned

Reviewed next steps

  • Check asset inventory and patch status for CVE-2026-21589.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland

Bleepingcomputer published a source item for review.

1 source recordContext source

What happened

Bleepingcomputer published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Cloud and infrastructure

Major Yandex data center in Russia hit by Ukrainian drone strike

Therecord Media published a source item for review.

1 source recordContext source

What happened

Therecord Media published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Cloud and infrastructure

TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws

Securityweek published a source item for review.

1 source recordContext source

What happened

Securityweek published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Incidents and exposure

Leaked chats show Russian extortion gang sending ‘agents’ into US law firms

Therecord Media published a source item for review.

1 source recordContext source

What happened

Therecord Media published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Incidents and exposure

ASOS Confirms Data Breach Linked to Stolen Employee Credentials

Infosecurity Magazine published a source item for review.

1 source recordContext source

What happened

Infosecurity Magazine published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Incidents and exposure

ASOS links data breach to social engineering attack, credential theft

Bleepingcomputer published a source item for review.

1 source recordContext source

What happened

Bleepingcomputer published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Incidents and exposure

Chinese Hacker Deployed AI in Campaign Against South Korean Banks

Infosecurity Magazine published a source item for review.

1 source recordContext source

What happened

Infosecurity Magazine published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Incidents and exposure

Fake Decryption Tools Masked $11M Markup in Ransomware Recovery Scheme

Securityweek published a source item for review.

1 source recordContext source

What happened

Securityweek published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Incidents and exposure

Oracle Health Data Breach Tally Climbs to Nearly 20 Million

Securityweek published a source item for review.

1 source recordContext source

What happened

Securityweek published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

AI and model reality

Anthropic’s new budget model gets much better at ignoring hidden commands

Helpnetsecurity published a source item for review.

1 source recordContext source

What happened

Helpnetsecurity published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

AI and model reality

Rein Security Raises $25 Million to Guard AI Agents at Runtime

Securityweek published a source item for review.

1 source recordContext source

What happened

Securityweek published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

AI and model reality

Europol and US Spending Watchdog Sound the Alarm Over Quantum Threats

Infosecurity Magazine published a source item for review.

1 source recordContext source

What happened

Infosecurity Magazine published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.