elitegeekZ Cybersecurity nieuws zaterdag 3 oktober 2026

Nederland

Reuters: belangrijke hacker ShinyHunters aangehouden, werkt samen met FBI

Aanvallers

NOS Nieuws · nederland · 03-10-2026

Een prominent lid van de hackersgroep ShinyHunters is deze week in Jordanië opgepakt, melden drie ingewijden aan het internationale persbureau Reuters. Het hackerscollectief claimde eind vorige maand de gegevens van duizenden medewerkers en sollicitanten van de Amerikaanse veiligheidsdienst FBI te hebben bemachtigd. Volgens twee bronnen werkt de verdachte inmiddels samen met de FBI bij het opsporen van andere leden van de hackersgroep. Het gaat volgens de bronnen om Saif al-Din Khader, die door de Jordaanse autoriteiten zou zijn opgepakt. Twee bronnen zeggen dat hij dinsdag is aangehouden. Het is niet bekend onder welke omstandigheden dat gebeurde en waar Khader, die binnen de groep opereert onder de alias Rey, zich momenteel bevindt. De FBI wil tegen Reuters niets zeggen over een specifieke arrestatie of operaties in het buitenland. Wel liet de dienst in een verklaring weten het recente cyberincident waarbij ShinyHunters betrokken zou zijn "onverminderd te onderzoeken". Volgens de FBI zijn in samenwerking met internationale partners al meerdere verdachten aangehouden. "We zullen alle beschikbare middelen inzetten om iedereen die verantwoordelijk is ter verantwoording te roepen", a...

Internationaal

ShinyHunters hacker reportedly detained in Jordan, aiding FBI

Aanvallers

BleepingComputer · internationaal · 03-10-2026

A suspected ShinyHunters hacking group member known online as "Rey" has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members of the extortion group. [...]

Fake Zoom installer hides macOS backdoor CloudSyncD

Malware

Security Affairs · internationaal · 03-10-2026

Jamf Threat Labs details CloudSyncD, a fake macOS Zoom installer that hides a phished password using invisible zero-width Unicode characters. Jamf Threat Labs found CloudSyncD while doing routine scanning on VirusTotal, buried inside a disguised Zoom client. They first spotted it on September 15, clearly still under construction, and within two days watched it move […]

YARA-X 1.21.0 Release, (Sat, Oct 3rd)

SANS Internet Storm Center · internationaal · 03-10-2026

YARA-X&#;x26;#;39;s 1.21.0 release brings 5 improvements and 4 bugfixes.

MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics

The Hacker News · internationaal · 03-10-2026

The U.K.'s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering efforts on behalf of Beijing's state security service. In a "Security Service Espionage Alert" issued on September 30, 2026, MI5 said the "primary purpose of the China General Technology Research Institute (CGTRI) 中国通用技术研究院 is to fund research that

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

RansomwareAanvallers

The Hacker News · internationaal · 03-10-2026

The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. "In the

Danish university DTU breach exposes data of up to 200,000 people

DatalekAanvallers

BleepingComputer · internationaal · 03-10-2026

The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data. [...]

doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures

SecurityWeek · internationaal · 03-10-2026

doxx.net’s new ADN platform prevents agentic misadventure while the agent is operating under the user’s authority.

Fortra Patches Critical Vulnerabilities in BoKS

Patch

SecurityWeek · internationaal · 03-10-2026

The bugs could lead to authentication bypass, shell command execution, and memory corruption.

The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations

The Hacker News · internationaal · 03-10-2026

Featuring: Cybersecurity is being reshaped by the expansion of cloud infrastructure, AI, distributed systems, and increasingly complex digital environments. As organizations manage more identities, devices, data, and internet-facing infrastructure, security is shifting toward continuous visibility, control, and the ability to respond to risk at scale. This report examines how core areas of

CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed

KritiekPatch

Security Affairs · internationaal · 03-10-2026

GitLab fixes critical AI Gateway flaw that could let authenticated Duo users escape a prompt sandbox and execute commands on self-hosted gateways. GitLab has released patches for a critical vulnerability in its AI Gateway, tracked as CVE-2026-90970 (CVSS score of 9.9), that could allow an authenticated user with access to the Duo Agent Platform to […]

Antino Backdoor Lets China-Linked UAT-11587 Turn Microsoft 365 Into a C2 Channel

Malware

Security Affairs · internationaal · 03-10-2026

Cisco Talos details UAT-11587, a China-linked group using the Antino backdoor and Microsoft 365 as cover to spy on Asian governments. Cisco Talos has been tracking a cluster of espionage activity since September 2025 that it calls UAT-11587, and by July 2026 the group had hit at least 16 government and policy organizations across eight […]

N0n ransomware: what you need to know

RansomwareDatalek

Graham Cluley · internationaal · 03-10-2026

N0n is a newly-emerged cyber extortion gang. The group was first spotted in the middle of September 2026, and within days it had published on its dark web leak site details of what it claimed to be around a dozen victims. Since then, the tally has continued to grow. Read more in my article on the Fortra blog.

U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog

PatchBeleid

Security Affairs · internationaal · 03-10-2026

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: The first flaw, CVE-2026-102489, is a session hijacking vulnerability in Zammad that can lead to remote code execution as the […]

Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing

Beleid

Schneier on Security · internationaal · 02-10-2026

The EU is recommending import controls to combat unregulated squid fishing in the Southwest Atlantic. I’m not optimistic. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

Judge dismisses spyware case brought by Salvadoran journalists targeted with Pegasus

Malware

The Record · internationaal · 02-10-2026

The plaintiffs, who all worked for the independent and Salvadoran news outlet El Faro, failed to convince the court that their case had jurisdiction in California, according to the judge’s order.

RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail

Dark Reading · internationaal · 02-10-2026

The offensive cyber operations startup looks to evolve red teaming beyond traditional methods to simulate attackers' increasingly advanced capabilities.

Bipartisan backlash to ALPRs grows as two high-profile bills are introduced

The Record · internationaal · 02-10-2026

Republican Sen. Josh Hawley has new legislation on limiting automated license plate readers (ALPRs), while Democratic Sens. Bernie Sanders and Jeff Merkley, with Rep. Alexandria Ocasio-Cortez, have teed up a broader bill.

CVE-2026-102490: Zammad GmbH Zammad Improper Privilege Management Vulnerability (Zammad)

Actief misbruiktPatch

CISA KEV-catalogus · internationaal · 02-10-2026

Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.

CVE-2026-102489: Zammad GmbH Zammad Session Fixation Vulnerability (Zammad)

Actief misbruiktPatch

CISA KEV-catalogus · internationaal · 02-10-2026

Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.

Kwetsbaarheden & patches

CVE of productToelichtingScoreStatus
CVE-2026-102490 (Zammad)Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerabili...n.n.b.Actief misbruikt (CISA KEV)
CVE-2026-102489 (Zammad)Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with C...n.n.b.Actief misbruikt (CISA KEV)
CVE-2026-90970CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed9.9Genoemd in nieuws (Security Affairs)
CVE-2026-102489U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalogn.n.b.Genoemd in nieuws (Security Affairs)

Actiepunten voor vandaag

Bronnen

Nederlandse media

Internationale media