Ransomware · 2 artikelen
RansomwareAanvallers
The Hacker News · internationaal · 03-10-2026
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. "In the
RansomwareDatalek
Graham Cluley · internationaal · 03-10-2026
N0n is a newly-emerged cyber extortion gang. The group was first spotted in the middle of September 2026, and within days it had published on its dark web leak site details of what it claimed to be around a dozen victims. Since then, the tally has continued to grow. Read more in my article on the Fortra blog.
Malware · 3 artikelen
Malware
Security Affairs · internationaal · 03-10-2026
Jamf Threat Labs details CloudSyncD, a fake macOS Zoom installer that hides a phished password using invisible zero-width Unicode characters. Jamf Threat Labs found CloudSyncD while doing routine scanning on VirusTotal, buried inside a disguised Zoom client. They first spotted it on September 15, clearly still under construction, and within two days watched it move […]
Malware
Security Affairs · internationaal · 03-10-2026
Cisco Talos details UAT-11587, a China-linked group using the Antino backdoor and Microsoft 365 as cover to spy on Asian governments. Cisco Talos has been tracking a cluster of espionage activity since September 2025 that it calls UAT-11587, and by July 2026 the group had hit at least 16 government and policy organizations across eight […]
Malware
The Record · internationaal · 02-10-2026
The plaintiffs, who all worked for the independent and Salvadoran news outlet El Faro, failed to convince the court that their case had jurisdiction in California, according to the judge’s order.
Aanvallers · 4 artikelen
Aanvallers
BleepingComputer · internationaal · 03-10-2026
A suspected ShinyHunters hacking group member known online as "Rey" has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members of the extortion group. [...]
Aanvallers
NOS Nieuws · nederland · 03-10-2026
Een prominent lid van de hackersgroep ShinyHunters is deze week in Jordanië opgepakt, melden drie ingewijden aan het internationale persbureau Reuters. Het hackerscollectief claimde eind vorige maand de gegevens van duizenden medewerkers en sollicitanten van de Amerikaanse veiligheidsdienst FBI te hebben bemachtigd. Volgens twee bronnen werkt de verdachte inmiddels samen met de FBI bij het opsporen van andere leden van de hackersgroep. Het gaat volgens de bronnen om Saif al-Din Khader, die door de Jordaanse autoriteiten zou zijn opgepakt. Twee bronnen zeggen dat hij dinsdag is aangehouden. Het is niet bekend onder welke omstandigheden dat gebeurde en waar Khader, die binnen de groep opereert onder de alias Rey, zich momenteel bevindt. De FBI wil tegen Reuters niets zeggen over een specifieke arrestatie of operaties in het buitenland. Wel liet de dienst in een verklaring weten het recente cyberincident waarbij ShinyHunters betrokken zou zijn "onverminderd te onderzoeken". Volgens de FBI zijn in samenwerking met internationale partners al meerdere verdachten aangehouden. "We zullen alle beschikbare middelen inzetten om iedereen die verantwoordelijk is ter verantwoording te roepen", a...
RansomwareAanvallers
The Hacker News · internationaal · 03-10-2026
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. "In the
DatalekAanvallers
BleepingComputer · internationaal · 03-10-2026
The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data. [...]
Patch · 5 artikelen
Patch
SecurityWeek · internationaal · 03-10-2026
The bugs could lead to authentication bypass, shell command execution, and memory corruption.
KritiekPatch
Security Affairs · internationaal · 03-10-2026
GitLab fixes critical AI Gateway flaw that could let authenticated Duo users escape a prompt sandbox and execute commands on self-hosted gateways. GitLab has released patches for a critical vulnerability in its AI Gateway, tracked as CVE-2026-90970 (CVSS score of 9.9), that could allow an authenticated user with access to the Duo Agent Platform to […]
PatchBeleid
Security Affairs · internationaal · 03-10-2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: The first flaw, CVE-2026-102489, is a session hijacking vulnerability in Zammad that can lead to remote code execution as the […]
Actief misbruiktPatch
CISA KEV-catalogus · internationaal · 02-10-2026
Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.
Actief misbruiktPatch
CISA KEV-catalogus · internationaal · 02-10-2026
Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.