October 9, 2026
Enriched source records
Luna-generated claims retained by the evidence and claim-validation gates. Automated validation does not imply human review. A record does not need a CVE to be included.
Luna-enriched source article · helpnetsecurityCompanies want autonomous IT operations but hesitate to let AI act alone
Ninety percent of companies surveyed want to move toward autonomous IT operations within two years, using agentic AI to plan and execute multistep tasks.
Companies want autonomous IT operations but hesitate to let AI act alone
Ninety percent of companies surveyed want to move toward autonomous IT operations within two years, using agentic AI to plan and execute multistep tasks.
Source published Oct 9, 2026, 4:30 AM UTC · Evidence retrieved Oct 9, 2026, 8:51 AM UTC
What happened
Ninety percent of companies surveyed want to move toward autonomous IT operations within two years, using agentic AI to plan and execute multistep tasks. [1]
Seventy-seven percent of respondents say their organizations hesitate to allow AI to make an operational decision without human approval. [2]
Why it matters
The article says most companies envision autonomy that retains a person at the approval step, while few have the groundwork for even that model. [3]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Ninety percent of companies want to move toward autonomous IT operations over the next two years, with agentic AI, software that plans and carries out multi-step tasks on its own, doing the work.
- [2]
Yet 77 percent say their own organization hesitates to let AI make an operational decision without a human approving it.
- [3]
Most of those companies mean autonomy with a person at the approval step, and few have the groundwork for even that.
Luna-enriched source article · helpnetsecurityPCI SSC calls for human approval of AI agent actions involving cardholder data
The PCI Security Standards Council published Security Considerations for AI Systems, covering protection of data supplied to AI systems in payment environments and defenses against AI-assisted attacks.
PCI SSC calls for human approval of AI agent actions involving cardholder data
The PCI Security Standards Council published Security Considerations for AI Systems, covering protection of data supplied to AI systems in payment environments and defenses against AI-assisted attacks.
Source published Oct 9, 2026, 5:00 AM UTC · Evidence retrieved Oct 9, 2026, 8:51 AM UTC
What happened
The PCI Security Standards Council published Security Considerations for AI Systems, covering protection of data supplied to AI systems in payment environments and defenses against AI-assisted attacks. [1]
Developed with industry stakeholders, the document addresses governance, deployment, access controls, testing, and application of PCI standards. [2]
Known limitations
The document’s recommendations are advisory, and existing PCI requirements take precedence. [3]
Some generated claims did not pass validation and were omitted. Only retained claims are shown.
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
The PCI Security Standards Council (PCI SSC) has published Security Considerations for AI Systems, guidance covering the protection of data supplied to AI systems in payment environments and defenses against AI-assisted attacks.
- [2]
Developed with industry stakeholders, the document addresses governance, deployment, access controls, testing and the application of PCI standards.
- [3]
Its recommendations are advisory, and existing PCI requirements take precedence.
Luna-enriched source article · helpnetsecurityThousands of wind and solar park systems sit exposed on the internet across Europe
Modat and NCSC-NL found 8,547 internet-facing systems at wind farms and solar parks in 35 countries in and around the EU that should not be reachable from the internet.
Thousands of wind and solar park systems sit exposed on the internet across Europe
Modat and NCSC-NL found 8,547 internet-facing systems at wind farms and solar parks in 35 countries in and around the EU that should not be reachable from the internet.
Source published Oct 9, 2026, 5:30 AM UTC · Evidence retrieved Oct 9, 2026, 8:51 AM UTC
What happened
Modat and NCSC-NL found 8,547 internet-facing systems at wind farms and solar parks in 35 countries in and around the EU that should not be reachable from the internet. [1]
The exposed systems range from login screens to a turbine control page with a browser-accessible Stop button. [2]
Why it matters
Confirmed systems were concentrated among operators in Spain, Greece, Italy and Germany. [3]
Known limitations
The article states that the actual number of exposed systems is higher than the confirmed 8,547, without providing a fuller estimate in the supplied evidence. [4]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Modat and NCSC-NL, the Dutch government’s cybersecurity center, found 8,547 internet-facing systems at wind farms and solar parks in 35 countries in and around the EU that should not be reachable from the internet.
- [2]
The systems range from login screens to a turbine control page that offers a Stop button to anyone with a browser.
- [3]
Operators in Spain, Greece, Italy and Germany account for most of the confirmed systems.
- [4]
The real number is higher.
Luna-enriched source article · helpnetsecurityWhat the BPFDoor backdoor tells us about attacks on the network edge
BPFDoor is described as Linux malware that waits for a special “magic packet” before acting.
What the BPFDoor backdoor tells us about attacks on the network edge
BPFDoor is described as Linux malware that waits for a special “magic packet” before acting.
Source published Oct 9, 2026, 6:00 AM UTC · Evidence retrieved Oct 9, 2026, 8:51 AM UTC
What happened
BPFDoor is described as Linux malware that waits for a special “magic packet” before acting. [1] [2]
Christiaan Beek of Rapid7 Intelligence discusses why BPFDoor operators target mail gateways and other edge devices that cannot run endpoint agents. [3]
Why it matters
The source characterizes BPFDoor as difficult to detect and says a compromised telecom network can pose risks to an entire nation. [1] [3]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
A backdoor that makes no noise is hard to catch, and that’s the point of BPFDoor.
- [2]
The Linux malware waits for a special “magic packet” before it acts.
- [3]
In this interview with Help Net Security, Christiaan Beek, VP of Rapid7 Intelligence, explains why its operators go after mail gateways and other edge devices that can’t run endpoint agents, and why a hacked telecom network can put a whole nation at risk.
Luna-enriched source article · securityaffairsAI-Driven tool ARTEX used in attacks against South Korean Banks
CrowdStrike analyzed a campaign against South Korean financial organizations in late September–early October 2026 that ended with stolen data, using open directories left by the attacker.
AI-Driven tool ARTEX used in attacks against South Korean Banks
CrowdStrike analyzed a campaign against South Korean financial organizations in late September–early October 2026 that ended with stolen data, using open directories left by the attacker.
Source published Oct 9, 2026, 7:53 AM UTC · Evidence retrieved Oct 9, 2026, 8:51 AM UTC
What happened
CrowdStrike analyzed a campaign against South Korean financial organizations in late September–early October 2026 that ended with stolen data, using open directories left by the attacker. [1] [2] [3]
The exposed directories contained Claude Code session histories, ARTEX configuration files, and Claude memory files, giving researchers direct visibility into the operator’s methods and tooling. [4] [5] [6]
The operator combined the open-source ARTEX autonomous penetration-testing tool with large language models; DeepSeek v4.1-flash was the main model, with GLM-5.3 and Grok 4.6 used in additional sessions. [7] [8] [9]
CrowdStrike did not attribute the activity to a specific group, but assessed with moderate confidence that the operator was Chinese-speaking and financially motivated, based on the tool and Chinese-language prompts. [10]
The activity targeted Korean financial organizations, including a loan-progress inquiry service used by brokers and an employee mobile work-support system; the number of affected organizations remains unconfirmed. [11] [12] [13] [14]
Why it matters
CrowdStrike said the activity demonstrates that AI tooling can enable a financially motivated actor to conduct multiple intrusions within a short time span. [15] [16]
The stolen data was reportedly being prepared for sale, and the operator used Claude to ask where Korean breach data and Korean Telegram data-sale groups could be found. [17] [18] [19]
Known limitations
CrowdStrike could not confirm that personal details found in the sessions belonged to the operator or that the same Telegram username linked the other observed activities. [20] [21] [22] [23]
ARTEX’s developer reportedly closed the source and stopped updates, but copies already in circulation remain available; the developer said the tool was for learning and research and unrelated to the attacks. [24] [25]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
CrowdStrike analyzes open directories left by an attacker who used the ARTEX AI pentest tool and LLMs to breach South Korean financial firms.
- [2]
CrowdStrike published a research on a campaign against South Korean financial organizations that ran from late September to early October 2026 and ended with stolen data.
- [3]
The attacker left their working notes where anyone could read them.
- [4]
Open directories on servers controlled by the attacker exposed Claude Code session histories, ARTEX configuration files, and Claude memory files.
- [5]
Researchers could see how the operator worked, prompt by prompt.
- [6]
“Analysis of threat actor-controlled open directories uncovered Claude Code session histories, ARTEX configuration files, and Claude memory files, providing direct insight into the threat actor’s operational methodology and tooling.” reads the report published by CrowdStrike.
- [7]
“The use of agentic AI tooling alongside traditional offensive capabilities highlights the continued evolution CrowdStrike has observed in adversarial tradecraft.” ARTEX is a recently released open-source tool from China that allows AI agents to run penetration tests on their own.
- [8]
The attacker combined it with large language models.
- [9]
DeepSeek v4.1-flash served as the main model, with GLM-5.3 from Zhipu AI and Grok 4.6 added for extra sessions.
- [10]
CrowdStrike has not linked the activity to a specific group, but it has moderate confidence that the operator is Chinese-speaking and financially motivated, based on the tool used and the Chinese-language prompts.
- [11]
Industry reports describe several South Korean financial organizations breached since late September.
- [12]
At one bank, the attacker reportedly got into a loan progress inquiry service used by financial brokers.
- [13]
At another, they compromised an employee mobile work-support system.
- [14]
Nobody has confirmed how many organizations were hit.
- [15]
CrowdStrike says this activity shows how AI tooling can let a financially motivated actor run several intrusions in a short time.
- [16]
This activity demonstrates how AI tooling can enable a financially motivated threat actor to conduct multiple intrusions within a short time span.” concludes the report.
- [17]
Exfiltration was only the first step.
- [18]
The stolen data was already being prepared for sale.
- [19]
“Analysis of Claude Code sessions showed the threat actor also used the following proxy IP addresses during the ARTEX-related activity: 101.53.80[.]20 205.214.59[.]31 124.155.252[.]63 154.201.79[.]246 23.248.249[.]90 23.158.220[.]98 103.248.148[.]84 203.160.133[.]172 209.209.85[.]38 In addition to conducting ARTEX-related operations, the threat actor asked Claude where threat actors typically sell Korean data breach information and asked Claude for assistance in finding Korean Telegram data sales groups.” reads the report.
- [20]
In one session, the user asked Claude to write a security researcher résumé with bullet points describing the ARTEX results.
- [21]
The prompt also included personal details.
- [22]
The same Telegram username appeared in sessions involving a Telegram-based NFT gift marketplace and the targeting of what may have been a Chinese payment platform.
- [23]
CrowdStrike says the details likely belong to the operator, but it cannot confirm the link.
- [24]
According to The Hacker News , ARTEX’s developer, Autumn-27, has since closed the source and stopped updates, saying the tool was built for learning and research and that the attacks have nothing to do with the project.
- [25]
Copies already in circulation don’t disappear with a license change.
Luna-enriched source article · the hacker newsCitrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments
Citrix released patches for a critical memory-overflow vulnerability, CVE-2026-107406, affecting NetScaler ADC and NetScaler Gateway; under specific configuration conditions, it may enable remote code execution or denial of service.
Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments
Citrix released patches for a critical memory-overflow vulnerability, CVE-2026-107406, affecting NetScaler ADC and NetScaler Gateway; under specific configuration conditions, it may enable remote code execution or denial of service.
Source published Oct 9, 2026, 8:11 AM UTC · Evidence retrieved Oct 9, 2026, 1:23 PM UTC
What happened
Citrix released patches for a critical memory-overflow vulnerability, CVE-2026-107406, affecting NetScaler ADC and NetScaler Gateway; under specific configuration conditions, it may enable remote code execution or denial of service. [1] [2]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Citrix has released patches for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions.
- [2]
"CVE-2026-107406 is a memory overflow vulnerability that may lead to remote code execution or denial-of-service under specific configuration conditions," Citrix said.
Luna-enriched source article · the hacker newsThree Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own
Three research teams demonstrated exploits against Google’s Pixel 10 at Pwn2Own Ireland on October 8; the contest rules required each target to be fully patched.
Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own
Three research teams demonstrated exploits against Google’s Pixel 10 at Pwn2Own Ireland on October 8; the contest rules required each target to be fully patched.
Source published Oct 9, 2026, 8:26 AM UTC · Evidence retrieved Oct 9, 2026, 1:23 PM UTC
What happened
Three research teams demonstrated exploits against Google’s Pixel 10 at Pwn2Own Ireland on October 8; the contest rules required each target to be fully patched. [1]
One Pixel exploit earned Ikotas Labs $300,000, the contest’s top prize, and the team became the overall winner. [3]
Why it matters
Pwn2Own pays researchers to demonstrate working exploits and passes the identified flaws to the vendors. [2]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched.
- [2]
The contest pays researchers to show working exploits and passes the flaws to the vendors.
- [3]
One of the three Pixel exploits earned Ikotas Labs $300,000, the contest's top prize, and made the team the overall winner.
Luna-enriched source article · helpnetsecurityProduct showcase: SimpleLogin keeps your email address private with aliases
SimpleLogin is Proton’s email-alias service that forwards messages to an existing mailbox.
Product showcase: SimpleLogin keeps your email address private with aliases
SimpleLogin is Proton’s email-alias service that forwards messages to an existing mailbox.
Source published Oct 9, 2026, 8:51 AM UTC · Evidence retrieved Oct 9, 2026, 2:51 PM UTC
What happened
SimpleLogin is Proton’s email-alias service that forwards messages to an existing mailbox. [1]
Users can create aliases for registrations, purchases, and correspondence to control where their primary email address is shared. [2]
The service is open source and supports self-hosting. [3]
In a Gmail trial, verification was followed by a dashboard displaying an initial alias for SimpleLogin communications. [4] [5]
The alias card included an enable/disable toggle, a description field, and access to contacts. [6]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
SimpleLogin is an email alias service from Proton that forwards messages to an existing mailbox.
- [2]
Users create addresses for registrations, purchases, and correspondence, giving them control over where their primary email address is shared.
- [3]
The service is open source and supports self-hosting.
- [4]
Getting started I tried SimpleLogin using a Gmail address.
- [5]
After verification, the dashboard displayed an initial alias for SimpleLogin communications.
- [6]
Its card included an enable/disable toggle, a description field, and access to contacts.
Luna-enriched source article · the hacker newsGoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys
GoBalance has a bug that lets anyone derive the secret key controlling a site’s .onion address from public information and take over that address.
GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys
GoBalance has a bug that lets anyone derive the secret key controlling a site’s .onion address from public information and take over that address.
Source published Oct 9, 2026, 9:03 AM UTC · Evidence retrieved Oct 9, 2026, 1:23 PM UTC
What happened
GoBalance has a bug that lets anyone derive the secret key controlling a site’s .onion address from public information and take over that address. [1]
Why it matters
Searchlight Cyber says an attacker who recovers the key can redirect visitors to a copy of the site controlled by the attacker. [2]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
A bug in GoBalance, a tool many dark-web sites use to stay reachable during attacks, lets anyone work out the secret key that controls a site's .onion address using only public information, and then take that address over.
- [2]
Searchlight Cyber, which disclosed the flaw on October 8, says an attacker who recovers the key can redirect the site's visitors to a copy of the site they control.
Luna-enriched source article · helpnetsecurityFBI disrupts Flax Typhoon hacking tools used in global cyberattacks
The FBI seized seven domains used to operate Microscan and FishHub, hacking tools linked to Chinese state-sponsored hackers known as Flax Typhoon.
FBI disrupts Flax Typhoon hacking tools used in global cyberattacks
The FBI seized seven domains used to operate Microscan and FishHub, hacking tools linked to Chinese state-sponsored hackers known as Flax Typhoon.
Source published Oct 9, 2026, 9:44 AM UTC · Evidence retrieved Oct 9, 2026, 2:51 PM UTC
What happened
The FBI seized seven domains used to operate Microscan and FishHub, hacking tools linked to Chinese state-sponsored hackers known as Flax Typhoon. [1]
The U.S. Department of Justice said the hackers worked for Integrity Technology Group, a China-based company holding contracts with the Chinese government. [2]
Why it matters
The tools were used to target critical infrastructure and other organizations in the United States and abroad. [1]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
The FBI seized seven domains used to operate Microscan and FishHub, two hacking tools linked to Chinese state-sponsored hackers known as Flax Typhoon that were used to target critical infrastructure and other organizations in the US and abroad.
- [2]
Seizure notice (Source: US Department of Justice) According to the US Department of Justice, the hackers worked for Integrity Technology Group (Integrity Tech), a China-based company that holds contracts with the Chinese government.
Luna-enriched source article · helpnetsecurityAnthropic offers free AI security scans to open-source maintainers
Anthropic’s OSS Scanner is a free service that uses its AI models to find security vulnerabilities in open-source software.
Anthropic offers free AI security scans to open-source maintainers
Anthropic’s OSS Scanner is a free service that uses its AI models to find security vulnerabilities in open-source software.
Source published Oct 9, 2026, 9:55 AM UTC · Evidence retrieved Oct 9, 2026, 2:51 PM UTC
What happened
Anthropic’s OSS Scanner is a free service that uses its AI models to find security vulnerabilities in open-source software. [1]
Open-source maintainers who opt in receive periodic scans and reports describing suspected flaws, reproduction steps, and available fixes. [2]
Why it matters
Anthropic says the service builds on Project Glasswing, which used Claude to find software vulnerabilities. [3]
Anthropic identifies human validation as a bottleneck in its vulnerability research. [4]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Anthropic’s OSS Scanner is a new, free service that uses the company’s strongest AI models to find security vulnerabilities in open-source software.
- [2]
Maintainers who opt in receive periodic scans and reports explaining suspected flaws, how to reproduce them and, when available, how to fix them.
- [3]
The service builds on Anthropic’s experience with Project Glasswing, which used Claude to find software vulnerabilities.
- [4]
Anthropic says human validation has become a bottleneck in its vulnerability research.
Luna-enriched source article · securityaffairsUS Disrupts China-Linked Integrity Tech ‘s Cyber Espionage Tools
The DOJ and FBI seized the China-linked Microscan and FishHub tools, which court documents allege were operated by Integrity Technology Group, a PRC-based company with PRC government contracts.
US Disrupts China-Linked Integrity Tech ‘s Cyber Espionage Tools
The DOJ and FBI seized the China-linked Microscan and FishHub tools, which court documents allege were operated by Integrity Technology Group, a PRC-based company with PRC government contracts.
Source published Oct 9, 2026, 10:49 AM UTC · Evidence retrieved Oct 9, 2026, 2:51 PM UTC
What happened
The DOJ and FBI seized the China-linked Microscan and FishHub tools, which court documents allege were operated by Integrity Technology Group, a PRC-based company with PRC government contracts. [1] [2] [3]
The tools were used to scan and, in some cases, intrude into U.S. and foreign critical-infrastructure systems and other networks. [4] [5] [6]
Microscan used the seized c0cc.cc domain and more than 1,300 penetration-testing scripts targeting known weaknesses in OpenSSL, WordPress, Jenkins, and Apache Struts. [7]
Microscan scanning targeted a South Carolina power company, a multinational NGO, airports in Japan and Poland, natural-gas and power companies in Taiwan, and Taiwanese universities. [8] [9]
FishHub used spear-phishing emails; confirmed victims included about 20 universities in Taiwan, and the tool could deliver malware, provide clients remote network access, or exfiltrate selected files to Integrity Tech servers. [10] [11] [12]
Why it matters
The associated Mirai-based IoT botnet database contained records for more than 1.2 million infected devices in June 2024, including more than 385,000 in the United States; about 260,000 devices were actively infected then. [13] [14] [15] [16]
The FBI said Integrity Tech provided China-linked actors capabilities for widespread vulnerability scanning and some intrusions against U.S. and foreign critical infrastructure. [17] [18]
Known limitations
The article states that disrupting the group’s infrastructure does not necessarily stop its activities permanently and notes that the timing of two China-linked disruption efforts was unclear. [19] [20] [21] [22]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
The Justice Department and FBI took down two hacking tools this week, Microscan and FishHub, both built and run by a Beijing-based company with direct government contracts.
- [2]
“As alleged in court documents unsealed in the Western District of Pennsylvania, malicious cyber actors working for Integrity Technology Group (Integrity Tech), a company based in the People’s Republic of China (PRC), operated and used the tools.
- [3]
Integrity Tech has contracts with the PRC government.” The company behind the tools is Integrity Technology Group.
- [4]
The tools were used to scan, and in plenty of cases actually break into, critical infrastructure across multiple countries.
- [5]
“Today the Justice Department and FBI announced court-authorized seizures to deny malicious cyber actors access to two hacking tools, “Microscan” and “FishHub,” used to scan and, in some cases, hack, U.S.
- [6]
and foreign critical infrastructure systems and other networks.” DoJ states .
- [7]
Microscan, accessed through the now-seized domain c0cc.cc, ran more than 1,300 penetration testing scripts aimed at known weaknesses in software like OpenSSL, WordPress, Jenkins, and Apache Struts.
- [8]
The target list included several sensitive organizations and critical infrastructure sites.
- [9]
Microscan was used to scan a power company in South Carolina, a multinational NGO, airports in Japan and Poland, natural gas and power companies in Taiwan, and two Taiwanese universities.
- [10]
FishHub used spear-phishing emails instead.
- [11]
Confirmed victims of this tool include around 20 universities in Taiwan.
- [12]
FishHub’s job after the initial phishing hook landed was straightforward and nasty: deliver more malware, then either hand Integrity Tech’s clients remote access to the victim network or hunt down specific files and ship them off to Integrity Tech’s own servers.
- [13]
Integrity Tech built and ran a botnet made up of infected Internet of Things (IoT) devices running a version of the Mirai malware.
- [14]
According to The Hacker News, which reviewed unsealed court documents, the botnet database contained records for more than 1.2 million infected devices in June 2024.
- [15]
More than 385,000 were located in the United States.
- [16]
At the time, around 260,000 devices were actively infected, including about 126,000 in the U.S.
- [17]
“Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting U.S.
- [18]
and foreign critical infrastructure,” said Assistant Director Brett Leatherman of the FBI’s Cyber Division.
- [19]
Attorney Troy Rivetti described the operation as the Department’s “second disruption of Integrity Tech’s massive operations in as many years.” The case shows that taking down a group’s infrastructure does not necessarily stop its activities for good.
- [20]
Two separate China-linked hacking operations faced disruption efforts within days of each other.
- [21]
It is unclear whether the timing was planned or simply reflected the progress of ongoing investigations, but both cases show continued U.S.
- [22]
efforts to target Chinese cyber operations.
Luna-enriched source article · malwarebytes labsASOS breach update: Hackers stole customer details and shopping searches
ASOS confirmed attackers accessed customer information after tricking an employee into disclosing login credentials; the stolen credentials were used on third-party platforms used by ASOS.
ASOS breach update: Hackers stole customer details and shopping searches
ASOS confirmed attackers accessed customer information after tricking an employee into disclosing login credentials; the stolen credentials were used on third-party platforms used by ASOS.
Source published Oct 9, 2026, 10:56 AM UTC · Evidence retrieved Oct 9, 2026, 8:51 PM UTC
What happened
ASOS confirmed attackers accessed customer information after tricking an employee into disclosing login credentials; the stolen credentials were used on third-party platforms used by ASOS. [1] [2]
Reportedly exposed data includes names, home addresses, phone numbers, email addresses, customer numbers, dates of birth, ASOS website searches, and information about when customers began using ASOS. [3] [4]
ASOS says payment-card information and customer passwords were not accessed, while Snowflake said it found no compromise of its platform; available reporting does not establish a vulnerability in Snowflake or Simon AI. [7] [8] [9]
ASOS says it locked down affected platforms, began an investigation with internal and external specialists, and strengthened its security controls. [10] [11]
Why it matters
The exposed shopping searches and customer details can reveal customers’ interests and relationships with ASOS, and could make targeted phishing messages more convincing. [5] [6]
Known limitations
ASOS said its investigation would continue over the coming weeks and that it would contact customers directly where it believed further information, support, or action was required. [12] [13]
Some generated claims did not pass validation and were omitted. Only retained claims are shown.
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
ASOS has confirmed that attackers accessed customer information after tricking an employee into handing over login credentials.
- [2]
The stolen login details were used to access information on third-party platforms used by ASOS.
- [3]
The BBC’s findings now establish that at least some shopping-related information was taken.
- [4]
According to the BBC, which received a sample from the attackers, the exposed data includes: Names and home addresses Phone numbers and email addresses Customer numbers and dates of birth Searches customers made on the ASOS website Details such as when a customer started using ASOS The BBC reported search terms including “reclaimed vintage,” “glamorous wide fit,” and “Asos petite.” That makes this more than a stolen contact list.
- [5]
The information can also reveal customers’ shopping interests and their relationship with the retailer.
- [6]
But the stolen details and shopping searches could help scammers make targeted phishing messages more convincing.
- [7]
While the retailer says payment card information and customer passwords were not accessed, reporting by the BBC shows the stolen information includes more than the “basic personal information” initially mentioned by the company.
- [8]
Snowflake said it had found no compromise of its platform.
- [9]
The available reporting does not establish a vulnerability in Snowflake or Simon AI.
- [10]
The company says it locked down the affected platforms and launched an investigation with internal and external specialists.
- [11]
It also says it has strengthened its security controls.
- [12]
If you’re dealing with Advanced Persistent Teenagers you need much better crisis plans.” While the attackers are threatening to release the data, ASOS says its full investigation will continue over the coming weeks.
- [13]
It will contact customers directly where it believes further information, support, or action is required.
Luna-enriched source article · theregister securityCitrix gives NetScaler admins another critical reason to patch
Citrix urged customers to patch CVE-2026-107406, a critical vulnerability affecting NetScaler ADC and NetScaler Gateway that can enable remote code execution or denial of service.
Citrix gives NetScaler admins another critical reason to patch
Citrix urged customers to patch CVE-2026-107406, a critical vulnerability affecting NetScaler ADC and NetScaler Gateway that can enable remote code execution or denial of service.
Source published Oct 9, 2026, 11:43 AM UTC · Evidence retrieved Oct 9, 2026, 7:23 PM UTC
What happened
Citrix urged customers to patch CVE-2026-107406, a critical vulnerability affecting NetScaler ADC and NetScaler Gateway that can enable remote code execution or denial of service. [1] [2]
The vulnerability has a CVSS v4.0 score of 9.5 and is classified as CWE-119, involving improper restriction of operations within a memory buffer. [3] [4]
Affected configurations vary by software version: older builds are vulnerable when configured as a SAML service provider or identity provider, while some newer builds are affected only as identity providers. [5] [6]
Why it matters
Secure Private Access Hybrid deployments using NetScaler instances also require patching, while Citrix handles necessary updates for its managed cloud services and Adaptive Authentication. [7] [8]
The disclosure followed another Citrix NetScaler memory-overflow flaw affecting SAML configurations; unlike that previously disclosed flaw, CVE-2026-107406 has not been identified by Citrix as exploited and also allows remote code execution. [12] [13] [14]
Source-supported guidance
Customers should update their own affected deployments using the builds and required updates listed in Citrix’s advisory. [9] [10]
Known limitations
Citrix did not state whether CVE-2026-107406 had been exploited as a zero-day before disclosure. [11]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Citrix is urging customers to patch another critical NetScaler vulnerability after weeks of disclosures involving actively exploited flaws.
- [2]
CVE-2026-107406 affects NetScaler ADC and NetScaler Gateway and can lead to remote code execution (RCE) or denial of service (DoS).
- [3]
It carries a CVSS v4.0 score of 9.5.
- [4]
Citrix classifies the flaw as CWE-119: improper restriction of operations within a memory buffer.
- [5]
The affected configurations depend on the software version.
- [6]
Older builds are vulnerable when configured as a SAML (Security Assertion Markup Language) service provider (SP) or identity provider (IdP); some more recent builds are affected only in the identity provider configuration.
- [7]
Secure Private Access Hybrid deployments using NetScaler instances also need patching.
- [8]
Citrix says it handles the necessary updates for its managed cloud services and Adaptive Authentication.
- [9]
Citrix's advisory lists the affected builds and required updates.
- [10]
Customers must update their own deployments.
- [11]
Citrix did not say whether this vulnerability was already exploited as a zero-day before disclosure, but credited Michael Tucker, Chew Keong Tan, and Alex Bernier at JPMorgan Chase's XOR Team, along with Maxim Suhanov, for the discovery.
- [12]
Citrix disclosed another exploited flaw, CVE-2026-88779, last Friday that carries a severity score of 8.7.
- [13]
Both that flaw and the newly disclosed vulnerability involve memory overflows affecting SAML configurations.
- [14]
The latter can also allow remote code execution, carries a higher severity score, and has not been identified by Citrix as exploited.
Luna-enriched source article · openssl releasesOpenSSL 4.1.0-beta2
OpenSSL 4.1.0 is a feature release adding significant new functionality, including DTLS 1.3 support, RFC 8701 GREASE, DTLS support in the SSL listener API, IKEV2 KDF support, and initial Elbrus2000 architecture support.
OpenSSL 4.1.0-beta2
OpenSSL 4.1.0 is a feature release adding significant new functionality, including DTLS 1.3 support, RFC 8701 GREASE, DTLS support in the SSL listener API, IKEV2 KDF support, and initial Elbrus2000 architecture support.
Source published Oct 9, 2026, 12:22 PM UTC · Evidence retrieved Oct 10, 2026, 8:51 AM UTC
What happened
OpenSSL 4.1.0 is a feature release adding significant new functionality, including DTLS 1.3 support, RFC 8701 GREASE, DTLS support in the SSL listener API, IKEV2 KDF support, and initial Elbrus2000 architecture support. [1] [2] [3] [4] [5] [6]
The release adds optimized ML-DSA and ML-KEM operations on ppc64le, optimized ML-DSA operations on x86_64, AVX-512-optimized SHAKE x4 operations for ML-DSA on x86_64, and AVX-512 and VAES optimizations for AES-CBC decryption on x86_64. [7]
Windows-on-Itanium and Windows CE targets were removed, and the no-ecdsa and no-ecdh Configure options were dropped because they did not actually disable their implementations; no-ec should be used to disable elliptic-curve support. [10] [11] [12]
A known DTLS 1.3 issue causes outstanding post-handshake records, such as a NewSessionTicket awaiting acknowledgment, to be dropped from the retransmission buffer when a DTLS 1.3 KeyUpdate is received. [13] [14]
Source-supported guidance
Users who rely on the tsget utility should install Net::Curl::Easy before upgrading, because tsget now uses it instead of the abandoned WWW::Curl::Easy. [8] [9]
Known limitations
The DTLS 1.3 retransmission issue is not fixed in the supplied release information; a fix is in progress and planned for a future release. [15]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
OpenSSL 4.1.0 is a feature release adding significant new functionality to OpenSSL.
- [2]
This release adds the following new features: Support for DTLS 1.3 ( RFC 9147 ).
- [3]
Support for RFC 8701 GREASE (Generate Random Extensions And Sustain Extensibility).
- [4]
DTLS support in the SSL listener API.
- [5]
Support for IKEV2 KDF.
- [6]
Initial support for the Elbrus2000 ( e2k ) architecture.
- [7]
Added optimized ML-DSA and ML-KEM NTT operations on ppc64le ; optimized ML-DSA operations on x86_64 ; AVX-512-optimized SHAKE x4 operations for ML-DSA on x86_64 ; AVX-512 and VAES optimizations for AES-CBC decryption on x86_64 .
- [8]
Changed tsget utility to use Net::Curl::Easy (from the Net-Curl CPAN distribution) instead of the abandoned WWW::Curl::Easy .
- [9]
Users who rely on tsget should install Net::Curl::Easy before upgrading.
- [10]
Dropped Windows-on-Itanium ( VC-WIN64I ) and Windows CE ( VC-CE ) targets from Configurations.
- [11]
Dropped no-ecdsa and no-ecdh options from Configure , as these options did not really disable the implementations.
- [12]
Use no-ec to disable the elliptic curve support.
- [13]
Known issues in 4.1.0 #32878 When a DTLS 1.3 KeyUpdate is received, all other outstanding post-handshake records are dropped from the retransmission buffer.
- [14]
This means post-handshake records still awaiting an ACK (such as a NewSessionTicket) will no longer be retransmitted if the original transmission is lost.
- [15]
A fix is in progress and planned for a future release.
Luna-enriched source article · helpnetsecurityHigh-severity NVIDIA vulnerability lets unauthenticated attackers crash GPU monitoring
Lava reported that hundreds of internet-exposed GPU servers were open to CVE-2026-47483 in NVIDIA’s DCGM Exporter, a flaw that lets unauthenticated attackers crash the monitoring service and may disrupt AI workloads.
High-severity NVIDIA vulnerability lets unauthenticated attackers crash GPU monitoring
Lava reported that hundreds of internet-exposed GPU servers were open to CVE-2026-47483 in NVIDIA’s DCGM Exporter, a flaw that lets unauthenticated attackers crash the monitoring service and may disrupt AI workloads.
Source published Oct 9, 2026, 12:26 PM UTC · Evidence retrieved Oct 9, 2026, 2:51 PM UTC
What happened
Lava reported that hundreds of internet-exposed GPU servers were open to CVE-2026-47483 in NVIDIA’s DCGM Exporter, a flaw that lets unauthenticated attackers crash the monitoring service and may disrupt AI workloads. [1]
Why it matters
NVIDIA rated CVE-2026-47483 at 8.2 on the CVSS scale and published a security bulletin on July 28, 2026, after Lava reported the flaw. [2]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Hundreds of internet-exposed graphics processing unit (GPU) servers were open to a high-severity flaw in NVIDIA’s DCGM Exporter (CVE-2026-47483) that lets unauthenticated attackers crash the monitoring service and may disrupt AI workloads, according to Lava.
- [2]
Lava reported the flaw to NVIDIA, which rated it 8.2 on the CVSS scale and published a security bulletin on July 28, 2026.
Luna-enriched source article · the hacker newsAnthropic Launches Free AI Vulnerability Scanner for Open-Source Projects
Anthropic unveiled OSS Scanner, an opt-in AI vulnerability scanner intended to help secure the open-source ecosystem.
Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects
Anthropic unveiled OSS Scanner, an opt-in AI vulnerability scanner intended to help secure the open-source ecosystem.
Source published Oct 9, 2026, 12:47 PM UTC · Evidence retrieved Oct 9, 2026, 7:23 PM UTC
What happened
Anthropic unveiled OSS Scanner, an opt-in AI vulnerability scanner intended to help secure the open-source ecosystem. [1]
Anthropic said OSS Scanner is informed by its experience using Claude to find vulnerabilities during Project Glasswing. [2]
Projects that join will receive periodic security scans by Anthropic’s strongest models at no cost. [3]
Why it matters
The service is opt-in, so projects must choose to participate before receiving the described scans. [2] [3]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Anthropic on Thursday unveiled OSS Scanner as an opt-in vulnerability scanner to help secure the open-source ecosystem using artificial intelligence (AI).
- [2]
"It's an opt-in service informed by our experience using Claude to find vulnerabilities during Project Glasswing," Anthropic said.
- [3]
"Projects that join will receive thorough, periodic security scans by our strongest models at no cost."
Luna-enriched source article · the hacker newsResearchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access
Security researchers published a working exploit for a pre-authentication remote-code-execution flaw in AnyDesk Linux that can give attackers root access before connection approval.
Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access
Security researchers published a working exploit for a pre-authentication remote-code-execution flaw in AnyDesk Linux that can give attackers root access before connection approval.
Source published Oct 9, 2026, 12:59 PM UTC · Evidence retrieved Oct 9, 2026, 7:23 PM UTC
What happened
Security researchers published a working exploit for a pre-authentication remote-code-execution flaw in AnyDesk Linux that can give attackers root access before connection approval. [1]
AnyDesk patched the flaw in version 8.0.3 in June, but its changelog described the change only as fixing a crash-related bug; the supplied text ends before stating whether a CVE was assigned or security details were provided. [2]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Security researchers have published a full working exploit for a pre-authentication remote code execution flaw in AnyDesk Linux that gives attackers root access before anyone approves the connection.
- [2]
AnyDesk patched the flaw in version 8.0.3 in June, but its changelog described the fix only as "fixed a bug that could lead to a crash," with no CVE assigned and no security
Luna-enriched source article · the hacker newsTP-Link Sued by Four More U.S. States Over Router Security and China Ties
Four additional U.S. states sued TP-Link Systems on October 6, bringing the total number of states involved to five after Texas filed in February.
TP-Link Sued by Four More U.S. States Over Router Security and China Ties
Four additional U.S. states sued TP-Link Systems on October 6, bringing the total number of states involved to five after Texas filed in February.
Source published Oct 9, 2026, 1:22 PM UTC · Evidence retrieved Oct 9, 2026, 7:23 PM UTC
What happened
Four additional U.S. states sued TP-Link Systems on October 6, bringing the total number of states involved to five after Texas filed in February. [1] [2]
Florida, Iowa, Montana, and Nebraska allege that TP-Link misled buyers about router security and the company’s separation from China. [3]
TP-Link denies the allegations and says it will contest them in court. [4]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Four more U.S.
- [2]
states sued router maker TP-Link Systems on October 6, bringing the total to five, with Texas filing a suit in February.
- [3]
Florida, Iowa, Montana and Nebraska allege the California company misled buyers about how secure its routers are and how separate it is from China.
- [4]
TP-Link denies the claims and says it will fight them in court.
Luna-enriched source article · securityaffairsClaude Helps Secure Open Source as Anthropic Offers Free Vulnerability Scanning
Anthropic launched OSS Scanner, a free vulnerability scanner for open-source projects that uses its AI models to identify vulnerabilities and help maintainers fix them.
Claude Helps Secure Open Source as Anthropic Offers Free Vulnerability Scanning
Anthropic launched OSS Scanner, a free vulnerability scanner for open-source projects that uses its AI models to identify vulnerabilities and help maintainers fix them.
Source published Oct 9, 2026, 1:56 PM UTC · Evidence retrieved Oct 9, 2026, 2:51 PM UTC
What happened
Anthropic launched OSS Scanner, a free vulnerability scanner for open-source projects that uses its AI models to identify vulnerabilities and help maintainers fix them. [1] [2]
Over six months, Anthropic’s models identified more than 29,000 possible vulnerabilities in widely used open-source software; experts had manually reviewed about 6,000. [3] [4] [5] [6]
OSS Scanner operates fully automatically without human review before reports are sent, trading faster and more frequent scanning for the possibility of incorrect reports. [7] [8]
During testing, the scanner combined vulnerabilities into working exploits that enabled remote code execution without login against real software projects. [9] [10]
Why it matters
Anthropic’s validation tested 97 critical or high-severity findings across 48 projects: 85 met its process threshold, 11 of the remaining findings were real duplicates, and one was invalid. [11] [12] [13] [14] [15]
Maintainer feedback identified inflated severity ratings and cases where the scanner misread a project’s specific threat model. [16]
Known limitations
Anthropic has shared nearly 5,000 unverified reports with requesting maintainers, including suggested fixes, and says those findings still require verification. [17] [18]
Some generated claims did not pass validation and were omitted. Only retained claims are shown.
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Anthropic launches free OSS Scanner, using AI to find open-source vulnerabilities and help maintainers fix bugs before attackers exploit them.
- [2]
Anthropic is launching OSS Scanner, a vulnerability scanner for open-source code that costs nothing for projects to join.
- [3]
Over the past six months, Anthropic tested its latest AI models on some of the most widely used open-source software and found more than 29,000 possible vulnerabilities.
- [4]
Its experts have had time to manually check and confirm only about 6,000 of them.
- [5]
“Over the last six months, we’ve used our latest models to scan for vulnerabilities in some of the world’s most important software projects.
- [6]
We have discovered over 29,000 candidate vulnerabilities , but have only been able to manually review and triage approximately 6,000 of these.” reads the announcement .
- [7]
OSS Scanner swaps fuzzing for Anthropic’s strongest models, including Claude Mythos, and runs fully automated, with no human review before a report goes out.
- [8]
That trade-off is explicit: faster, more frequent scanning, in exchange for accepting that some reports will be wrong.
- [9]
During testing, the scanner combined several vulnerabilities to create working exploits that allowed attackers to run code remotely without logging in.
- [10]
These attacks worked against real software projects, not just in theory.
- [11]
Anthropic ran its own accuracy check before wider rollout, having expert penetration testers examine 97 critical and high severity findings across 48 projects.
- [12]
“To validate an early version of OSS Scanner, we asked the expert penetration testers who review our CVD findings to check 97 critical and high-severity vulnerabilities from the scanner across 48 projects.” continues the announcement.
- [13]
“Of these, 85 (88%) met the bar for our CVD process.
- [14]
Of the remaining 12, 11 were real but duplicated known issues or other findings from the scan, and only one was invalid, i.e.
- [15]
a “false positive.” “ Of the remaining 12, 11 turned out to be real but duplicates of already-known issues, and exactly one was a genuine false positive.
- [16]
Some maintainer feedback flagged inflated severity ratings or cases where the scanner misread a project’s specific threat model.
- [17]
“While 6,000 vulnerabilities is significant, we remain bottlenecked on our human capacity to validate these findings.” Because of this, some maintainers asked Anthropic to send them all the findings, even those that had not been confirmed.
- [18]
Anthropic has already shared nearly 5,000 unverified reports, along with suggested fixes, with maintainers who requested them.
Luna-enriched source article · the hacker newsP7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands
Researchers disclosed a previously unseen DarkSword iOS exploit-kit variant called P7 DarkSword.
P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands
Researchers disclosed a previously unseen DarkSword iOS exploit-kit variant called P7 DarkSword.
Source published Oct 9, 2026, 4:29 PM UTC · Evidence retrieved Oct 9, 2026, 7:23 PM UTC
What happened
Researchers disclosed a previously unseen DarkSword iOS exploit-kit variant called P7 DarkSword. [1]
iVerify reported that P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and supports two-way command-and-control communication with attacker infrastructure. [2]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword.
- [2]
"Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker's infrastructure," iVerify said in a new report published Thursday.
Luna-enriched source article · the hacker newsFBI Arrests Another ShinyHunters Suspect Reportedly Involved in Its Jobs Portal Hack
FBI Director Kash Patel said on October 9 that the FBI arrested another suspected ShinyHunters co-conspirator.
FBI Arrests Another ShinyHunters Suspect Reportedly Involved in Its Jobs Portal Hack
FBI Director Kash Patel said on October 9 that the FBI arrested another suspected ShinyHunters co-conspirator.
Source published Oct 9, 2026, 5:45 PM UTC · Evidence retrieved Oct 9, 2026, 7:23 PM UTC
What happened
FBI Director Kash Patel said on October 9 that the FBI arrested another suspected ShinyHunters co-conspirator. [1]
ShinyHunters said in September that it breached the FBI jobs portal and stole sensitive data on almost all FBI agents and job applicants. [2]
Known limitations
The FBI has not named the suspect, and no charges have been made public. [3]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
The FBI has arrested another suspected co-conspirator of ShinyHunters, FBI Director Kash Patel said on October 9 in a post on X.
- [2]
ShinyHunters is the extortion group that said in September it had breached the FBI's jobs portal and stolen sensitive data on almost all FBI agents and job applicants.
- [3]
The FBI has not named the suspect, and no charges have been made public.
Luna-enriched source article · securityaffairsGermany Arrests Suspected Qilin Ransomware Leader After Japan Detention
Germany arrested a Russian national believed to be a leading Qilin ransomware figure after Japanese authorities detained him in Osaka in May under a provisional detention warrant.
Germany Arrests Suspected Qilin Ransomware Leader After Japan Detention
Germany arrested a Russian national believed to be a leading Qilin ransomware figure after Japanese authorities detained him in Osaka in May under a provisional detention warrant.
Source published Oct 9, 2026, 6:45 PM UTC · Evidence retrieved Oct 10, 2026, 2:51 AM UTC
What happened
Germany arrested a Russian national believed to be a leading Qilin ransomware figure after Japanese authorities detained him in Osaka in May under a provisional detention warrant. [1] [2] [3]
Japan’s Ministry of Justice, Tokyo High Public Prosecutors Office, German authorities, and Japanese police cooperated in the detention and subsequent handover under Japan’s extradition law. [3] [4] [5]
The article says Qilin has operated since 2022 and became one of the most active ransomware-as-a-service groups in 2025, claiming over 40 victims monthly and peaking at 100 in June. [12]
Qilin affiliates deploy customized ransomware payloads and use double extortion by encrypting data while threatening to leak it through Tor-based portals. [13] [14]
Why it matters
Japan’s cyber investigators had investigated Qilin attacks in Japan and worked with German investigators; the NPA described international cooperation as essential to investigating cross-border cybercrime. [6] [7] [8]
Qilin has attacked Japanese organizations including Nissan and Asahi; the Asahi attack reportedly disrupted operations for an extended period and exposed data belonging to 1.5 million people. [9] [10] [11]
Despite the suspect’s May detention, the group reportedly listed hundreds of new victims on its Tor leak site from June onward. [15]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Germany has arrested a Russian national believed to be a leading figure in the Qilin ransomware group, and Japan’s National Police Agency just put its own role in that arrest on the record.
- [2]
The suspect was detained in Japan back in May, at a hotel in Osaka, while traveling as a tourist.
- [3]
When the suspect arrived in Japan, the Japanese authorities worked with the Ministry of Justice, the Tokyo High Public Prosecutors Office, and German authorities to detain him under a provisional detention warrant, in accordance with Japan’s Act of Extradition.” reads a full NPA statement in Japanese.
- [4]
“The Japanese authorities subsequently handed the suspect over to Germany in accordance with the procedures established by that law.
- [5]
Per the NPA’s own account, Japan’s Ministry of Justice, the Tokyo High Public Prosecutors Office, and German authorities worked together to detain him under Japan’s extradition law, using a provisional detention warrant, before handing him over to Germany through the proper legal process.
- [6]
It specifically recognizes the work of the Kanto Regional Police Bureau’s Cyber Special Investigation Unit and other local police forces.
- [7]
They had been investigating Qilin ransomware attacks in Japan and working with German investigators on the wider case.
- [8]
The agency stressed that international cooperation is essential to investigating cybercrime, including ransomware attacks that affect countries around the world.
- [9]
Japan has good reason to focus on Qilin.
- [10]
The group has attacked Japanese organizations, including carmaker Nissan and brewing company Asahi .
- [11]
The attack on Asahi disrupted its operations for an extended period and exposed data belonging to 1.5 million people.
- [12]
Qilin ransomware operation has been active since 2022, it has become one of the most active RaaS groups in 2025, claiming over 40 victims monthly and peaking at 100 in June.
- [13]
The group enables affiliates to deploy customized ransomware payloads against targeted organizations.
- [14]
Qilin uses double-extortion tactics, encrypting data while threatening to leak it via Tor-based portals.
- [15]
Despite the suspect’s detention in May, the cybercrime group has listed hundreds of new victims on its Tor leak site since June alone.
Luna-enriched source article · the hacker newsCredential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories
Researchers disclosed an ongoing credential-theft campaign that compromised two high-profile open-source maintainer accounts and used them to push a malicious workflow into more than 340 repositories.
Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories
Researchers disclosed an ongoing credential-theft campaign that compromised two high-profile open-source maintainer accounts and used them to push a malicious workflow into more than 340 repositories.
Source published Oct 9, 2026, 7:14 PM UTC · Evidence retrieved Oct 10, 2026, 1:23 AM UTC
What happened
Researchers disclosed an ongoing credential-theft campaign that compromised two high-profile open-source maintainer accounts and used them to push a malicious workflow into more than 340 repositories. [1]
StepSecurity reported that an attacker using Takashi Kitao’s account pushed a malicious workflow to 27 repositories beginning at 13:20 UTC; Kitao is identified as the author of the 18,400-star pyxel game engine. [2]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories.
- [2]
"Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC," StepSecurity
Luna-enriched source article · theregister securityAWS AgentCore security undone by prompt requesting credentials
The article reports that, when AgentCore used IMDSv1, an exposed agent could return its instance metadata, including temporary credentials, in response to a prompt requesting a credential endpoint.
AWS AgentCore security undone by prompt requesting credentials
The article reports that, when AgentCore used IMDSv1, an exposed agent could return its instance metadata, including temporary credentials, in response to a prompt requesting a credential endpoint.
Source published Oct 9, 2026, 7:15 PM UTC · Evidence retrieved Oct 10, 2026, 7:23 AM UTC
What happened
The article reports that, when AgentCore used IMDSv1, an exposed agent could return its instance metadata, including temporary credentials, in response to a prompt requesting a credential endpoint. [1] [2] [3] [4] [5]
Using those credentials, the reported attacker enumerated other agents in the AWS region, accessed ECR container images, and ran them as root to inspect source code. [6] [7]
The article reports that the credentials also enabled discovery of agent memory resources and extraction of users’ agent sessions and conversations. [8] [9]
AWS reportedly updated AgentCore to use IMDSv2 exclusively as of February 14, 2026; the researchers nevertheless found excessive permissions still present on June 22, 2026. [13] [14]
The researchers’ September 29, 2026 review observed that AWS had addressed the remaining reported problems. [15]
Why it matters
The reported default IAM role covered all AgentCore resources in the region, enabling credential holders to launch agents, read sessions, write memories, and fetch Secrets Manager secrets. [10]
Researchers reported that writing memories across agents and users could persistently alter agent behavior and hijack goals across future sessions. [11] [12]
Known limitations
Amazon disputed the research after publication, saying it misrepresented documented behavior as a vulnerability and suggesting developer error would be required; the article says clarification was requested. [16] [17]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Bob asked the agent for help understanding the content of a URL, a credential endpoint – in raw JSON, if you don't mind.
- [2]
IMDSv2 addresses some of these risks, but back when Bob was browsing late last year, Bedrock AgentCore still used IMDSv1.
- [3]
The metadata provided to Bob by the helpful agent contained the agent's temporary credentials.
- [4]
"We discovered that agents deployed through AgentCore could access their instance's IMDS endpoints," said Tamir Ishay Sharbat and Lana Salameh in a blog post.
- [5]
So an attacker – I know you're thinking it was Mallory, but it was really Bob – could direct the agent to carry out a server-side request forgery (SSRF) attack by fetching temporary AWS credentials for the IAM role assigned to the workload.
- [6]
So Bob loaded them onto his local machine, and remotely enumerated the company's other agents in that AWS region.
- [7]
He then logged into the Amazon Elastic Container Registry (ECR), pulled the agent container images, and ran each as root to inspect the source code.
- [8]
The stolen credentials also allowed Bob to discover the memory resources available in that AWS region, including the ones used by agents.
- [9]
From these, he's able to extract the users and their agent sessions – their conversations.
- [10]
And because the default AgentCore role was overpermissioned – it was scoped to all AgentCore resources in the region rather than a single agent – anyone in possession of the temporary IAM credentials could launch other agents, read sessions, write agent memories, and fetch secrets from AWS Secrets Manager.
- [11]
"By leveraging the IMDS credentials we could send direct API requests to create new memories across different agents and users," said Sharbat and Salameh.
- [12]
"These in turn would persistently alter agent behaviour and hijack the agents’ goals across future sessions." The Zenity researchers told Bob's tale, or something like it, to AWS last December, then followed up in January 2026 with details about AgentCore being overprivileged.
- [13]
On April 12, 2026, AWS responded to the security biz that its report was "informative" and closed the report, noting that as of February 14, 2026, AgentCore had been updated to use IMDSv2 exclusively.
- [14]
AgentCore's excessive permissions remained in place at least until June 22, 2026, when Zenity checked in and found the issue hadn't been remediated.
- [15]
A final review by Zenity occurred on September 29, 2026, at which point the biz observed that AWS had addressed the extant problems, clearing the way for Bob's hypothetical adventure to finally be told.
- [16]
Following publication, Amazon wrote in to say that Zenity’s research misrepresents documented behavior as a vulnerability, suggesting that developer error would be required to enable the attack.
- [17]
We’ve asked for clarification since that’s not the scenario Zenity has described.
Luna-enriched source article · schneier blogFriday Squid Blogging: I Caught a Squid
The author reports catching a squid while fishing from a small boat out of Gloucester, Massachusetts, and identifies it as probably a longfin squid, also called a Boston squid.
Friday Squid Blogging: I Caught a Squid
The author reports catching a squid while fishing from a small boat out of Gloucester, Massachusetts, and identifies it as probably a longfin squid, also called a Boston squid.
Source published Oct 9, 2026, 8:25 PM UTC · Evidence retrieved Oct 10, 2026, 7:23 AM UTC
What happened
The author reports catching a squid while fishing from a small boat out of Gloucester, Massachusetts, and identifies it as probably a longfin squid, also called a Boston squid. [1] [2] [3]
The author says they cooked the squid over a barbecue grill using high heat for a short time and found it delicious. [4] [5]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
On Wednesday I spent a day fishing, on a small boat out of Gloucester, MA.
- [2]
And…I caught a squid!
- [3]
Near as I can tell, it’s a longfin squid, sometimes called a Boston squid ( Doryteuthis (Amerigo) pealeii ).
- [4]
That night I cooked it over a barbecue grill—hot and fast.
- [5]
Delicious.
Luna-enriched source article · krebs on securityFBI Arrests Founder of Ransomware Negotiation Firm
FBI agents arrested a Canadian cybersecurity-firm co-founder in Pennsylvania in an investigation connected to ShinyHunters, which had obtained sensitive data on thousands of FBI agents.
FBI Arrests Founder of Ransomware Negotiation Firm
FBI agents arrested a Canadian cybersecurity-firm co-founder in Pennsylvania in an investigation connected to ShinyHunters, which had obtained sensitive data on thousands of FBI agents.
Source published Oct 10, 2026, 12:17 AM UTC · Evidence retrieved Oct 10, 2026, 7:23 AM UTC
What happened
FBI agents arrested a Canadian cybersecurity-firm co-founder in Pennsylvania in an investigation connected to ShinyHunters, which had obtained sensitive data on thousands of FBI agents. [1] [2]
Sources identified the arrested person as Edward Dubrovsky, whose company specialized in ransomware negotiations; court records describe an Edward Dobrovsky arrested on October 8 on cyber-extortion and conspiracy charges. [3] [4] [5]
Several court documents, including the core complaint, are sealed; indexed records summarize charges involving conspiracy to threaten information confidentiality to extort money and interference with commerce by threats. [6] [7]
ShinyHunters typically uses phishing and stolen credentials to take data from software-as-a-service corporate accounts, then threatens publication unless victims pay ransom; the FBI reportedly attributes more than $70 million in extortion this year to the group. [10] [11]
Sources said the FBI is examining devices seized during a Dutch arrest linked to ShinyHunters and that charges against principals at other ransomware-negotiation companies may follow. [12]
Why it matters
Sources said control of the ShinyHunters investigation was centralized at an FBI field office in Texas, and court records show the case was moved to the Eastern District of Texas. [8] [9]
Known limitations
The FBI declined comment, Dubrovsky could not immediately be reached, and available court records indicate he had no attorney or appointed public defender at that time. [13] [14] [15]
The article describes the story as fast-moving and says updates would be added with timestamps. [16] [17]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Agents with the Federal Bureau of Investigation (FBI) on Thursday arrested the co-founder of a Canadian cybersecurity firm in connection with an investigation into the ShinyHunters hacking group that recently relieved the FBI of sensitive data on thousands of agents, multiple sources tell KrebsOnSecurity.
- [2]
The New York Times reported today that the FBI has arrested a Canadian man in Pennsylvania on suspicion of assisting ShinyHunters.
- [3]
One source close to the investigation told KrebsOnSecurity the Canadian person arrested this week was visiting Pennsylvania for a cyber insurance conference, and that the suspect’s company specialized in handling ransomware negotiations with cybercrime groups.
- [4]
According to LinkedIn, Cypher was co-founded by a Canadian man named Edward Dubrovsky , who is now associated with another Canadian security firm and sponsor called CyberSteward .
- [5]
Federal court records show that on October 8, an Edward Dobrovsky (note the slight misspelling of the last name) was arrested in Pennsylvania on cyber extortion and conspiracy charges.
- [6]
Several of those documents — including the core complaint — are now sealed.
- [7]
But a handful of them were indexed at Courtlistener.com , including a summary of the complaint, which charges the defendant with “conspiracy to threaten to impair the confidentiality of information with the intent to extort money,” and “interference with commerce by threats.” Image: Courtlistener.com The inmate locator at the U.S.
- [8]
Another shared that control over the ShinyHunters investigation has been centralized at an FBI field office in Texas.
- [9]
But the court records indexed by CourtListener include a notice filed on October 9 that moved the case to the Eastern District of Texas, which sources say is now the epicenter of the FBI’s ShinyHunters investigation.
- [10]
ShinyHunters typically uses phishing and stolen credentials to siphon data from corporate accounts at software-as-a-service companies, and then threatens to publish the stolen data online unless a ransom demand is paid.
- [11]
According to the FBI, the group has extorted more than $70 million from victims so far this year.
- [12]
Sources tell KrebsOnSecurity the FBI has been poring over devices that were seized last month when the Dutch police arrested the convicted cybercriminal Pepijn van der Stap in connection with the ShinyHunters investigation, and that charges against principals at other companies that specialize in ransomware negotiation may be forthcoming.
- [13]
The FBI declined to comment for this story.
- [14]
Dubrovsky could not be immediately reached for comment.
- [15]
The available court records in Dubrovsky’s case show that he does not currently have an attorney and has yet to be appointed a public defender by the courts.
- [16]
This is likely to be a fast-moving story.
- [17]
Updates will be noted along with timestamps.
Earlier retained revision · Oct 10, 2026, 1:23 AM UTC
Source published Oct 10, 2026, 12:17 AM UTC · Evidence retrieved Oct 10, 2026, 1:23 AM UTC
What happened
The FBI arrested a Canadian man in Pennsylvania in connection with an investigation into ShinyHunters; the New York Times also reported the arrest, but did not identify the suspect. [1] [2] [3]
A source told KrebsOnSecurity that the arrested person was visiting Pennsylvania for a cyber-insurance conference and that his company handled ransomware negotiations with cybercrime groups. [4]
The article links the arrest to Edward Dubrovsky through reporting on his conference plans, professional affiliations, and court records showing that an Edward Dobrovsky was arrested in Pennsylvania on October 8 on cyber-extortion and conspiracy charges. [5] [6] [7] [8]
Several court documents, including the core complaint, were sealed; indexed records summarize charges involving conspiracy to threaten information confidentiality to extort money and interference with commerce by threats. [9] [10]
ShinyHunters typically uses phishing and stolen credentials to take data from software-as-a-service company accounts, then threatens publication unless victims pay ransom; the FBI says the group has extorted more than $70 million this year. [13] [14]
Sources said the FBI is examining devices seized during a Dutch arrest connected to the investigation and that additional charges against ransomware-negotiation companies may be forthcoming. [15]
Why it matters
Sources said control of the ShinyHunters investigation was centralized at an FBI field office in Texas, and court records show the case was moved to the Eastern District of Texas. [11] [12]
Known limitations
The FBI declined to comment, Dubrovsky could not immediately be reached, and available court records said he had no attorney and had not yet been appointed a public defender. [16] [17] [18]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Agents with the Federal Bureau of Investigation (FBI) on Thursday arrested the co-founder of a Canadian cybersecurity firm in connection with an investigation into the ShinyHunters hacking group that recently relieved the FBI of sensitive data on thousands of agents, multiple sources tell KrebsOnSecurity.
- [2]
The New York Times reported today that the FBI has arrested a Canadian man in Pennsylvania on suspicion of assisting ShinyHunters.
- [3]
The Times story did not identify the man, nor did a statement on Twitter/X about the arrest from FBI Director Kash Patel .
- [4]
One source close to the investigation told KrebsOnSecurity the Canadian person arrested this week was visiting Pennsylvania for a cyber insurance conference, and that the suspect’s company specialized in handling ransomware negotiations with cybercrime groups.
- [5]
The conference had several sponsors, but according to the summit’s website its biggest sponsor was a Canadian security company called Cypfer .
- [6]
According to LinkedIn, Cypher was co-founded by a Canadian man named Edward Dubrovsky , who is now associated with another Canadian security firm called CyberSteward .
- [7]
In a post to LinkedIn approximately one month ago, Dubrovsky said he had plans to attend the Cyber Risk Summit with the rest of the CyberSteward team.
- [8]
Federal court records show that on October 8, an Edward Dobrovsky (note the slight misspelling of the last name) was arrested in Pennsylvania on cyber extortion and conspiracy charges.
- [9]
Several of those documents — including the core complaint — are now sealed.
- [10]
But a handful of them were indexed at Courtlistener.com , including a summary of the complaint, which charges the defendant with “conspiracy to threaten to impair the confidentiality of information with the intent to extort money,” and “interference with commerce by threats.” Image: Courtlistener.com The inmate locator at the U.S.
- [11]
Another shared that control over the ShinyHunters investigation has been centralized at an FBI field office in Texas.
- [12]
But the court records indexed by CourtListener include a notice filed on October 9 that moved the case to the Eastern District of Texas, which sources say is now the epicenter of the FBI’s ShinyHunters investigation.
- [13]
ShinyHunters typically uses phishing and stolen credentials to siphon data from corporate accounts at software-as-a-service companies, and then threatens to publish the stolen data online unless a ransom demand is paid.
- [14]
According to the FBI, the group has extorted more than $70 million from victims so far this year.
- [15]
Sources tell KrebsOnSecurity the FBI has been poring over devices that were seized last month when the Dutch police arrested the convicted cybercriminal Pepijn van der Stap in connection with the ShinyHunters investigation, and that charges against principals at other companies that specialize in ransomware negotiation may be forthcoming.
- [16]
The FBI declined to comment for this story.
- [17]
Dubrovsky could not be immediately reached for comment.
- [18]
The available court records in Dubrovsky’s case show that he does not currently have an attorney and has yet to be appointed a public defender by the courts.