Latest stories — Page 3

Australia Orders Federal Agencies to Audit Old Tech After AI Agent Exploited Medicare Systems
A government-wide stocktake of ageing technology is now mandatory for all 194 Australian federal entities, after an AI-assisted attack exposed how outdated systems make government networks easier to breach.

Australia Calls Out Steam, Roblox, Fortnite and Minecraft Over Child Safety Failures
A new government report finds the four biggest gaming platforms leave children exposed to predators and harmful content, with Steam singled out for the weakest protections of all.

Fortinet FortiMail Has a Critical Zero-Day Being Exploited and No Patch Yet
A vulnerability scored 9.8 out of 10 in Fortinet FortiMail lets attackers write files to affected servers without logging in. Fixes are not out yet. US federal agencies had until 4 October 2026 to apply workarounds.

Jordan Detains Alleged ShinyHunters Member 'Rey' in FBI-Linked Operation
A suspect tied to the prolific extortion crew is reportedly cooperating with U.S. investigators after a September arrest.

China-linked hackers posed as Anthropic staff to phish U.S. AI policy experts
A group tracked as TA419 ran fake-login pages that could capture passwords and the one-time codes meant to stop them.

Ransomware Group Wallstreet Claims Attack on St. Francis Healthcare Systems of Hawaii
A criminal ransomware group has listed a century-old Catholic nonprofit hospital network on its dark-web claims site. The organisation has not confirmed any incident, and the claim remains unverified.

Ransomware Group The Gentlemen Claims Attack on Gerrity Stone
A Massachusetts stone fabrication company has been listed on a dark-web extortion site. The claim is unverified, but the group behind it has been active since at least June.

Qilin Ransomware Group Claims Attack on US Lender Genesis Credit Management
The criminal group has listed the Texas-based financial services firm on its dark-web pressure site. No breach has been confirmed, and the claim has not been independently verified.

Kiteworks patches critical flaw in email gateway that let attackers seize root control
A chain of three bugs in the company's Email Protection Gateway handed unauthenticated outsiders a path to full appliance takeover. The fix is in version 9.4.1.

Pentagon tells 3 million military personnel their records were stolen in nine-month breach
The Defense Manpower Data Center says attackers sat in its file-sharing systems from October 2025 to July 2026 before anyone noticed.

Warlock keeps hitting SharePoint servers across Latin America and Iberia, Symantec says
The ransomware group is still breaking into Microsoft SharePoint servers in Portuguese and Spanish-speaking countries, hitting hospitals, government offices and schools.

An AI Found a Critical Security Hole in BeyondTrust. Hackers Were Inside It Four Days Later.
A new Google report shows how artificial intelligence is speeding up both the discovery of software flaws and their exploitation. One flaw found by an AI tool had attackers knocking within days of going public.

WatchGuard Patches Three Critical Flaws That Could Hand Attackers Full Control of Firewalls and Access Points
A clutch of serious vulnerabilities in WatchGuard's networking gear could hand attackers root-level control of firewalls and wireless access points. Patches are out, but the window between disclosure and update is where organisations get hurt.

CISA Gives Federal Agencies Three Days to Patch Two Zammad Flaws Being Exploited Now
Two critical bugs in the Zammad helpdesk platform can be chained for root-level takeover. CISA added both to the Known Exploited Vulnerabilities catalogue on 2 October 2026, with a patch deadline of 5 October.

China-Linked Spies Hide Inside Outlook and OneDrive to Steal Asian Government Secrets
A newly documented backdoor called Antino is sitting on at least 16 government networks across eight Asian countries, and it talks to its handlers through legitimate Microsoft 365 traffic.

GitLab patches a near-perfect-score AI Gateway bug that lets logged-in users run commands on the server
CVE-2026-90970 scores 9.9 out of 10 and lets any authenticated user with Duo Agent Platform access escape a prompt template and execute code. Only self-hosted gateways need the fix.

Hackers Built Malware That Perfectly Mimics Korean and Taiwanese Email Security Boxes
Rapid7 has documented a set of Linux implants so well-tailored to their target appliances that they impersonate specific product files, ports, and processes used in real telecom environments across South Korea and Taiwan.

The EU's New Cyber Security Law Gives Manufacturers 24 Hours to Report Flaws. Almost No One Is Ready.
The Cyber Resilience Act, which took effect in September, requires companies to report actively exploited vulnerabilities within one day. Security experts say the clock will break every manual process most vendors currently rely on.

Kairos Ransomware Group Claims Attack on Vermont School District, Alleges Student Medical Records Stolen
The Kairos ransomware group has listed Slate Valley Unified Union School District on its dark-web claims page, alleging it seized hundreds of gigabytes of data including personal and medical records. The district has not confirmed any incident.

Ransomware Group Krybit Claims Attack on Disk Precision Group
The group listed the US-based manufacturer on its dark-web site on 1 October 2026. Disk Precision has not publicly confirmed any incident, and the claim has not been independently verified.

A 16-Year-Old Is Suspected of Running KillSec, One of Ransomware's Busiest Criminal Groups
European police arrested three people and seized servers after a year-long investigation into roughly 1,000 cyberattacks. The alleged ringleader is a Romanian teenager.