A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group ShinyHunters has been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang. KrebsOnSecurity has learned that the suspect, who uses the hacker handle "Rey," was detained as ShinyHunters was in the process of extorting a business unit recently divested by the global aerospace company Boeing. READ MORE...
FortiBleed, a credential compromise campaign targeting Fortinet firewalls and VPN gateways, is an ongoing threat that can lock users out of their Fortinet accounts and also lead to ransomware attacks, the FBI and Secret Service said in an alert published Tuesday. "Affected organizations may find themselves locked out of their systems if threat actors disable accounts or change passwords," the alert states. READ MORE...
A cyberattack on Arizona's court system stole personal information for more than a million people and is believed to have started when a court employee clicked a malicious link in an email. The Arizona Supreme Court said the information was copied for 1.3 million people with unpaid court fees, fines and restitution payments for traffic and criminal violations dating back as far as 30 years. Those leading the attack also took records of nearly 30,000 active and inactive orders of protection. READ MORE...
UK fashion retailer ASOS has confirmed a data breach after a notification claiming hackers had broken into its data was sent to shoppers through its app. ASOS was founded in 2000 and has 16.5 million active customers in more than 100 markets. According to the company's update to investors, the unauthorised notification went out to its customers at around 10am on 6 October 2026. ASOS warned that basic personal information, including names and contact details, may have been accessed. READ MORE...
Google has published security fixes for Android. The October updates are available for Android operating system versions 14, 15, 16, 16-qpr2, and 17 where "qpr" stands for Quarterly Platform Release. QPRs are interim updates Google pushes out between major yearly cycles. These Android security bulletins contain valuable information for Android users. The updates are important as they fix several vulnerabilities rated as Critical, which can be exploited without users even doing anything. READ MORE...
Atlassian has rolled out patches for a critical-severity vulnerability that impacts all versions of eight of its products. The security defect, tracked as CVE-2026-21589 (CVSS score of 9.3), is described as an arbitrary file access issue. It can be exploited without authentication to access specific files in the web application root directory. Organizations are advised to patch their self-hosted deployments as soon as possible. READ MORE...
In August, the Malwarebytes research team reported on a new malicious turnkey kit that makes it possible for almost anyone to launch a sophisticated online scam. The kit was not simply a fake website. It bundled the command center, victim tracking, and administrative tools into a ready-to-use package, reducing the technical knowledge needed to operate a scam. The discovery highlights an important feature of the cybercrime economy. READ MORE...
A cryptomining campaign targeting exposed AI services is using PoeLLM malware to turn compromised servers into scanners and exploit launchpads. The malware features an uncommon method to retrieve command-and-control (C2) addresses by extracting keywords in a poem hosted on GitHub. Researchers at Lumen's Black Lotus Labs (BLL) tracking the botnet malware say it has compromised more than 2,100 servers, with peak activity reaching as many as 800 infected systems active on a single day. READ MORE...
Attackers are altering ClickFix tactics to hide payloads until after the victim has already performed the trusted action, as two recent examples showcase. ClickFix has become a prominent social engineering technique in the past few years, due largely to how it exploits human problem solving tendencies as well as trust in software. A typical ClickFix attack presents victims with a fake technical problem or verification prompt, then instructs them to paste and execute a command. READ MORE...
A novel proof-of-concept (PoC) cyberattack technique is capable of preventing Windows Defender from receiving updates without exploiting a vulnerability in the process. Dubbed "BigDiskBuster" by researchers from LevelBlue, the PoC was originally published on Sept. 19 by security researcher and former Microsoft employee Abdelhamid Naceri, who goes by MSNightmare (aka Nightmare-Eclipse). The GitHub page for the PoC has since been taken down, but LevelBlue researchers were able to reproduce it. READ MORE...
IBM's vulnerability discovery clearinghouse has found and fixed more than 400 vulnerabilities in popular Java libraries, the company announced on Tuesday. The Lightwell clearinghouse is also now generally available, IBM said, meaning that customers can request priority security reviews of specific open-source software vulnerabilities. As AI has made it easier to discover and exploit vulnerabilities, the cybersecurity community has begun paying more attention. READ MORE...