The US government is alerting millions of people that their personal information was stolen during a breach of the Pentagon's personnel records at the Defense Manpower Data Center (DMDC). The DMDC is a central US Department of Defense (DoD) organization that manages personnel records, ID credentials, and benefit entitlements for military and civilian staff, veterans, and their families. It maintains over 60 million records for US military and civilian staff and their family members. READ MORE...
Government authorities and security teams are racing to assess the fallout from a campaign aimed at critical flaws in Citrix NetScaler. Government agencies and critical infrastructure providers were targeted in a wave of attacks dating back more than a month in what may be targeted espionage. Security teams were first alerted over the weekend in a series of direct warnings from government security agencies, IT security vendors and others urging them to immediately disable their systems. READ MORE...
The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. Previously, the nonprofit organization of volunteer security researchers said the attack was "loud and very, very messy," driven by an AI agent that moved autonomously and decided its next steps without external intervention or direction. READ MORE...
An alleged key figure in the ShinyHunters cybercrime group has been arrested in the Netherlands, and - in a grotesque turn - the 24-year-old suspect is also being investigated for attempting to arrange two murders. The 24-year-old from Amsterdam, whom Dutch police have not named, was arrested on September 15 on suspicion of playing a role within the ShinyHunters criminal organisation. Celebrated cybersecurity blogger Brian Krebs has identified him as Pepijn van der Stap, a convicted hacker. READ MORE...
A 16-year-old security researcher named Faav found an authentication flaw in Microsoft's Titan analytics service that allowed him to gain administrator access, submit unauthorized SQL queries with no valid credentials, and potentially reach analytics databases containing an estimated 17.3 trillion stored rows. Titan is an internal analytics platform, and Redmond restricts access via its web interface to Microsoft employees. READ MORE...
Attackers exploited a flaw found by an AI research agent within four days of its public disclosure, and they are exploiting more vulnerabilities overall, according to new research by Google Threat Intelligence Group (GTIG). The researchers examined vulnerability disclosure and exploitation data from January 2025 to August 2026. Monthly CVE disclosures doubled in 2026, from 5,045 in January to 10,740 in August. READ MORE...
An international law enforcement operation dubbed "Operation KillSwitch" seized the KillSec ransomware gang's data leak site and servers, led to three arrests, and identified a 16-year-old as the group's alleged administrator. The coordinated law enforcement action was carried out on September 30, involving authorities from Belgium, the United States, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, and the United Kingdom. READ MORE...
A Chinese ransomware outfit is exploiting Microsoft technologies to extort large and critical organizations in the Spanish- and Portuguese-speaking world. The Warlock ransomware group - tracked by Symantec as "Longlegs" and by Microsoft as "Storm-2603" - has never fit neatly into any box. It surfaced in the summer of 2025, in a campaign that mirrored state-level espionage activity in its tactics, techniques, and procedures (TTPs). READ MORE...
Truffle Security has discovered over half a million active unique credentials exposed in public GitHub repositories. A total of 1,103,438 exposed credentials were discovered through the scanning of 224 million public GitHub repositories in August 2025. At the end of July 2026, the security firm tested the credentials against their services and found that 543,699 of them were still active. READ MORE...
OpenAI's hack of Hugging Face in July 2026 has spurred a lawsuit demanding that the company stop accessing third-party computer systems and halt AI development practices that can harm the public. The lawsuit was filed by Legal Advocates for Safe Science & Technology (LASST), which said yesterday that the hack in which OpenAI "agents stole credentials, uploaded malicious files, and gained control over key parts of Hugging Face's internal systems… is unquestionably illegal under California law." READ MORE...
Hackers started exploiting a high-severity OS command injection vulnerability in Zimbra Collaboration Suite (ZCS) shortly after patches were rolled out, before public disclosure, Microsoft reports. Tracked as CVE-2026-73570 (CVSS score of 8.9), the flaw exists because, in ZCS before 10.1.20, untrusted input during SNMP notification processing is improperly sanitized. An attacker could trigger the security defect via specially crafted SMTP requests. READ MORE...
OpenAI said it disrupted a "coordinated campaign" to distill and extract reasoning capabilities from its AI models, pointing the finger at a Chinese rival. On Wednesday, OpenAI said it first spotted low-level activity on July 1 that gradually increased until July 24 and 25, when it observed 16,000 prompts from 4,000 users that fit a similar "relevant extraction pattern." The number of suspicious users had climbed to 15,000 by July 28, when OpenAI said it "fully disrupted" the operation. READ MORE...