ICYMI: 2026-10-06
Latest Headlines
Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes
Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan
LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings
Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies
Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers
Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach
Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account
ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits
FBI Blames Contractor’s Missed Patch for ShinyHunters Breach
Apple to Tighten Full Disk Access Controls in macOS Amid AI Risks
Cybersecurity M&A Roundup: 39 Deals Announced in September 2026
Long-Running NPM Malware Campaign Accumulates 40,000 Downloads
8.8 Million Impacted by Data Breach at Denmark’s Central Person Register
Social Engineering Detection Moves Into the Live Conversation
Critical Apache Struts Vulnerabilities Enables Remote Code Execution Attacks
Former Infrastructure Engineer Sentenced for Sabotaging Employer’s Windows Network
From Telemetry to Defense: How SOC and MSSP Leaders Can Build Intelligence-Led Threat Monitoring
ASOS Hacked – App Users Receive Notifications Sent by Hackers
Iranian Hackers Use Fake Dubai Airports Coding Test to Target Iraqi Critical Infrastructure
Criminal IP Introduces AITEM as the Next Evolution of Attack Surface Management
AppViewX Adds Shadow AI Visibility and a Runtime Kill Switch to Agent Identity Security
Ransomware Hacker Uses AI Coding Assistant as Attack Channel Against Enterprise Networks
Hackers exploit 32 zero-days on first day of Pwn2Own Ireland
Atlassian warns of critical file-access flaw in Jira, Confluence
ASOS confirms data breach after “HACKED” in-app notifications
Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes
Wikimedia: Rogue OpenAI agents behind unauthorized Wikipedia edits
Nikkei discloses breaches of employees’ Microsoft, Google email accounts
Engineer sentenced for locking over 3,000 devices on employer network
– MTZ