Nyheter inom IT-säkerhet
De senaste rubrikerna från ledande källor inom cybersäkerhet. Uppdateras varje timme – klicka för att läsa hela artikeln hos källan.
-
BleepingComputer ·
Nippon Columbia malware incident exposes 8.6 million karaoke fan records
Daiichi Kosho, a major Japanese entertainment system maker, disclosed that a malware infection at its contractor, Nippon Columbia, exposed more than 8.7 million customer and employee records. [...]
-
BleepingComputer ·
Cyber exec arrested in case allegedly tied to ShinyHunters hackers
Canadian cybersecurity executive Edward Dubrovsky has been arrested in Pennsylvania in connection with alleged extortion activity that multiple reports have linked to the FBI's ongoing crackdown on …
-
BleepingComputer ·
ARTEX AI, Claude agents used in cyberattacks on South Korean banks
The cyberattacks that shook the South Korean financial sector earlier this month were launched by a Chinese hacker using the ARTEX AI penetration testing suite and Claude agents. [...]
-
BleepingComputer ·
Criminal IP Introduces AITEM as the Next Evolution of Attack Surface Management
Traditional attack surface management helps organizations discover exposed assets, but visibility alone is not enough to address threats. Criminal IP introduces AITEM, an AI-powered approach that …
-
SecurityWeek ·
Insider Cyber Extortion Plot Against Industrial Firm Lands Engineer in Prison
The former core infrastructure engineer deleted admin accounts, reset hundreds of passwords, and demanded 20 bitcoin to spare the company’s servers. The post Insider Cyber Extortion Plot Against …
-
The Hacker News ·
The Third-Party Agent Problem: Why Security Built for AI You Chose Misses the Agents You Didn't
In environments studied for the 2026 State of Agent Security Report, roughly 1,280 third-party products now embed AI. About 282 of them sit behind single sign-on. The other thousand are invisible to …
-
The Hacker News ·
Anthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection Flaws
Anthropic on Friday said it's cutting off live internet access for all its internal evaluations following the discovery of new incidents in which its artificial intelligence (AI) models exhibited …
-
Krebs on Security ·
FBI Arrests Executive at Ransomware Negotiation Firm
Agents with the Federal Bureau of Investigation (FBI) on Thursday arrested the co-founder of a Canadian cybersecurity firm in connection with an investigation into the ShinyHunters hacking group that …
-
SecurityWeek ·
OpenAI Fires 3 Safety Researchers in Dispute Over AI Risks
The ChatGPT maker said the researchers "violated clear policies on handling sensitive information.” The post OpenAI Fires 3 Safety Researchers in Dispute Over AI Risks appeared first on SecurityWeek .
-
Dark Reading ·
ASOS Breach Reveals the Risks in Customer-Facing SaaS
The attack on the British retailer shows that compromising a single identity can lead to much deeper penetration of the corporate network.
-
BleepingComputer ·
Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks
Hackers are abusing legitimate Bing search-result redirects as click URLs in Google search ads to direct users to fake Claude installers that deliver ClickFix attacks. [...]
-
Dark Reading ·
AI Scramble Drives Cybersecurity M&A Boom
Welcome to another gangbuster year for strategic M&A activity in cyber, with 117 deals announced in the latest quarter. What's different: Many of the buyers are not your typical cybersecurity firms.
-
The Hacker News ·
Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories
Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over …
-
The Hacker News ·
FBI Arrests Another ShinyHunters Suspect Reportedly Involved in Its Jobs Portal Hack
The FBI has arrested another suspected co-conspirator of ShinyHunters, FBI Director Kash Patel said on October 9 in a post on X. ShinyHunters is the extortion group that said in September it had …
-
Dark Reading ·
What We Missed: FBI Strikes Back at ShinyHunters
In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the arrest of a suspected ShinyHunters operative to the compromise of a Pentagon-run …
-
BleepingComputer ·
Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto
Threat actors are exploiting one critical and one medium-severity vulnerability still unpatched in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners. [...]
-
BleepingComputer ·
FBI arrests another suspected ShinyHunters hacker after agency breach
The FBI has arrested another suspected member of the ShinyHunters extortion group believed to be involved in the recent breach of FBI systems, Director Kash Patel announced Friday. [...]
-
The Hacker News ·
P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands
Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword. "Compared with the variants we usually observe, P7 reduces its …
-
Dark Reading ·
Security Threats Don't Stop at the Office: Why Executives' Families Need Training, Too
Those closest to executives must match their security postures because the weakest link in a family can become the entry point for attacks.
-
BleepingComputer ·
Germany arrests alleged core Qilin ransomware member after extradition
Germany has arrested a Russian national suspected of being a leading member of the Qilin ransomware group following extradition from Japan earlier this month. [...]
-
BleepingComputer ·
How to keep AI agents within their permissions
AI agents can use valid credentials to perform actions beyond their assigned permissions, creating risks that traditional access controls may not prevent. Token Security explains how organizations …
-
The Hacker News ·
TP-Link Sued by Four More U.S. States Over Router Security and China Ties
Four more U.S. states sued router maker TP-Link Systems on October 6, bringing the total to five, with Texas filing a suit in February. Florida, Iowa, Montana and Nebraska allege the California …
-
Dark Reading ·
Social Engineering AI Agents: The New BEC for 2026
As AI agents gain authority over business systems, attackers can manipulate them like business email compromise (BEC) victims.
-
The Hacker News ·
Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access
Security researchers have published a full working exploit for a pre-authentication remote code execution flaw in AnyDesk Linux that gives attackers root access before anyone approves the connection …
-
The Hacker News ·
Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects
Anthropic on Thursday unveiled OSS Scanner as an opt-in vulnerability scanner to help secure the open-source ecosystem using artificial intelligence (AI). "It's an opt-in service informed by our …
-
The Hacker News ·
Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge
Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners …
-
BleepingComputer ·
Max severity SonicWall SMA1000 flaw now exploited in attacks
Attackers are exploiting a maximum-severity vulnerability in SonicWall SMA1000 appliances (CVE-2026-102255) that was patched on Tuesday, three days ago. [...]
-
The Hacker News ·
Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their abuse by a China-linked …
-
SecurityWeek ·
In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 Years
Noteworthy stories that might have slipped under the radar: Tensorlake npm SDK compromised, Empire Market co-founder gets 40 years, exposed NVIDIA GPU monitors leak telemetry. The post In Other News …
-
SecurityWeek ·
Google Domains Impacted by Recent ccTLD Hijacks
Hackers hijacked the .gh, .sl, and .as ccTLDs and obtained HTTPS certificates for several Google domains. The post Google Domains Impacted by Recent ccTLD Hijacks appeared first on SecurityWeek .
Källor: BleepingComputer, The Hacker News, Krebs on Security, CERT-SE, SecurityWeek och Dark Reading. Rubriker och korta utdrag visas med länk till originalet; innehållet tillhör respektive källa. Läs även våra egna artiklar.