Section
Cybersecurity
Breaches, vulnerabilities, threat intel, APTs, and zero-days.
Microscan and FishHub: the tools FBI says China used to scan US networks
The Justice Department seized domains for Microscan and FishHub, alleging a China-based contractor supplied tooling to state-linked hacking.
Seven nations say Integrity Tech hacking is ongoing, but advisory gives no breach count
The FBI seized seven domains linked to Integrity Technology Group. A seven-nation advisory describes the same activity in the present tense, with no breach count or theft dates.
Banks face two clocks on AI: NCSC oversight guidance and ECB's October demand
The NCSC's resilience director says agentic AI must stay observable, constrained and overseen — as the ECB demands frontier-AI risk plans by the end of October.
FBI Removes Contractor After Patch Failure Exposes Employee Data
The FBI terminated an Accenture contractor on October 5, 2026, following a security breach that compromised the personal information of thousands of bureau employees.
How international cooperation led to the arrest of an alleged IRGC operative
Amir Barati was extradited to the U.S. on October 1, marking a rare legal victory against state-sponsored hacking operations.
110 Terabytes Seized, but the Ransomware Threat Isn't Over.
Operation KillSwitch dismantled the KillSec ransomware group on September 30, 2026. The real story is the hidden coordination machine that spanned ten nations to stop a 16-year-old suspected operator.
Hackers Targeted the Plumbing Behind South Korea's Banking Apps, Not the Apps Themselves
A coordinated campaign hit five major South Korean banks through their Operations Development Systems — backend infrastructure separate from customer-facing transaction platforms — exposing a regulatory blind spot.
Pentagon breach: The nine-month gap that exposed three million records
A vulnerability in a Defense Manpower Data Center file-sharing system allowed unauthorized access to unencrypted PII including Social Security numbers and military occupational specialties from October 2025 through July 2026.
Nine Months Unchecked: How a Pentagon File Server Exposed 3 Million Service Members' Identities
A Defense Manpower Data Center file-sharing server leaked Social Security numbers and military records for 2.76 million living and 294,000 deceased personnel over nine months before discovery.
UNC6692 Uses Fake IT Helpdesk Teams Messages to Deploy SNOW Malware
UNC6692 buried inboxes in spam, then posed as IT support on Microsoft Teams to plant a malicious browser extension and steal Active Directory data. Defenders should watch outside Teams chats, headless Edge and unusual S3 traffic.