News
Cybersecurity headlines, summarized. Updated hourly.Last update: Oct 3, 2026, 11:00 PM UTC
ShinyHunters hacker reportedly detained in Jordan, aiding FBI
A suspected member of the ShinyHunters hacking group, known online as Rey, has reportedly been detained in Jordan. The individual is allegedly cooperating with the FBI to help locate and identify other members of the extortion group.
199 stories
- The Register · 1 minNewsVulnerability
Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows
Anthropic's AI model Mythos has demonstrated advanced math and bug-hunting capabilities. Meanwhile, a newly discovered vulnerability is currently under active exploitation by attackers originating from China-hosted IP addresses.
Why this matters
Active exploitation of zero-day vulnerabilities by threat actors poses an immediate risk to organizations running affected systems.
Affected: Not specified
Action: Monitor threat intelligence feeds and apply vendor patches immediately when available.
- SANS ISC · 2 minNewsNews
YARA-X 1.21.0 Release, (Sat, Oct 3rd)
YARA-X has released version 1.21.0, which includes five improvements and four bugfixes. This update continues the ongoing development and maintenance of the pattern-matching tool.
Why this matters
Staying updated with the latest software releases ensures users benefit from bug fixes and functional improvements.
Affected: YARA-X < 1.21.0
Action: Update YARA-X to version 1.21.0.
- The Hacker News · 1 minNewsResearch
MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics
The U.K.'s MI5 agency has warned that over 100 academics have assisted China's Ministry of State Security with intelligence gathering efforts. This involvement highlights ongoing concerns regarding foreign state influence and research security within U.K. academic institutions.
Why this matters
It exposes potential national security vulnerabilities and espionage risks arising from foreign state-funded academic research partnerships.
Affected: Not specified
Action: Review and strengthen vetting processes for academic partnerships and foreign research funding.
- The Hacker News · 1 minHighRansomwareVulnerability
Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
The suspected China-linked threat actor Warlock is exploiting Microsoft SharePoint vulnerabilities to target organizations in Portuguese- and Spanish-speaking regions. These attacks utilize the flaws to disable security tools and deploy ransomware.
Why this matters
It demonstrates active exploitation of critical enterprise software by a persistent threat actor to disable defenses and execute high-impact ransomware attacks.
Affected: Microsoft SharePoint
Action: Patch Microsoft SharePoint immediately and audit security tool statuses.
- BleepingComputer · 1 minNewsIncident Response
Danish university DTU breach exposes data of up to 200,000 people
The Technical University of Denmark (DTU) suffered a data breach after hackers accessed its identity and access management system. The security incident may have exposed the personal information of up to 200,000 users.
Why this matters
This breach compromises sensitive personal data for a large number of individuals, highlighting the critical risks associated with compromised identity and access management systems.
Affected: DTU identity and access management system
Action: Investigate the extent of the breach and secure all identity and access management systems.
- SecurityWeek · 1 minNewsAI Security
doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures
The startup doxx.net has raised $38 million in funding to develop its new ADN platform. This platform is designed to prevent autonomous AI agents from making mistakes or causing security issues while operating on the internet.
Why this matters
As autonomous AI agents become more prevalent, securing their operations and preventing unintended actions is critical to enterprise safety.
Affected: Not specified
Action: Monitor the development and capabilities of the ADN platform.
- SecurityWeek · 1 minMediumVulnerabilityVendor Advisory
Fortra Patches Critical Vulnerabilities in BoKS
Fortra has released patches to address critical vulnerabilities in its BoKS software. These security flaws could potentially allow attackers to achieve authentication bypass, execute shell commands, and cause memory corruption.
Why this matters
These critical vulnerabilities expose systems to severe compromise, including unauthorized access and remote code execution.
Affected: Fortra BoKS
Action: Apply the latest patches provided by Fortra for BoKS immediately.
- The Hacker News · 1 minNewsAI Security
The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations
This article discusses the evolving state of cybersecurity in 2026, driven by the expansion of cloud infrastructure, artificial intelligence, and distributed systems. It highlights the growing complexity organizations face when managing increasingly large volumes of identities, devices, and data.
Why this matters
It highlights foundational industry trends that shape modern enterprise risk management and defensive strategies.
Affected: Not specified
Action: Monitor industry trends to adapt security strategies for emerging cloud and AI complexities.
- Microsoft MSRC · 2 minMediumVulnerabilityVendor Advisory
Chromium: CVE-2025-10502 Heap buffer overflow in ANGLE
A heap buffer overflow vulnerability has been identified in the ANGLE component of Google Chromium, tracked as CVE-2025-10502. Public information regarding this security flaw has been officially published.
Why this matters
This memory corruption vulnerability could potentially be exploited by attackers to execute arbitrary code or cause a browser crash.
Affected: Google Chromium
Action: Update Chromium to the latest patched version as soon as it becomes available.