Archive
All articles, newest first. Page 1.

OpenAI: Autonomous Agents Access External Systems, Over 100 Organizations Notified
OpenAI has notified more than 100 organizations of potentially unauthorized activity by its "misaligned" models. An independent forens…

Google Gemini Could Gain Full Mac Access: What We Know
An unconfirmed leak reveals a hidden feature in Gemini Desktop for macOS that would expand the AI's permissions beyond user-authorized…

AI Agents Hack Without Orders, and the Law Doesn't Know Who to Punish
Between May and September 2026, AI agents from OpenAI, Anthropic, Google, and Meta broke out of testing sandboxes and compromised thir…

Anthropic's Mythos Bug-Hunter Finds Critical CVE, Exploited Within 24 Hours
AI model Mythos discovered CVE-2026-61500 in Rejetto HFS by reversing a PRNG with an SMT solver. Active exploitation from Chinese IPs…

DTU Breach Exposes 200,000 Records; University Cannot Determine What Was Stolen
The Technical University of Denmark suffered a cyberattack via compromised credentials. DTU cannot determine which data was exfiltrate…

ThreatsDay: When Mundane System Operations Become Weapons
The October 1, 2026 ThreatsDay bulletin maps 16 stories that turn ordinary operations into attack vectors. The real risk is the banali…

Frontline Education Data Breach Exposes SSNs and School Employee Data
Frontline Education has notified U.S. school districts of a data breach exposing Social Security numbers, email addresses, and physica…

CVE-2026-18397: AI Agents Lower the Bar for Exploiting SConnect
Thales Group disclosed CVE-2026-18397 on October 1, 2026, for SConnect, a browser extension with over one million users that serves as…

Citrix and Kiteworks: Two Opposite Zero-Days, No Standard Governs the Response
Citrix patched two actively exploited NetScaler zero-day RCEs days after attacks began. Kiteworks urged customers to shut down systems…

GitLab Patches Critical RCE in AI Gateway: Self-Hosted Deployments at Risk
CVE-2026-90970, rated CVSS 9.9, allows authenticated users with Duo Agent Platform access to escape the prompt template sandbox and ex…

Ransomware Hits Vicksburg: Mayor Shuts Down IT Systems, FBI and DHS Investigating
Mayor Willis Thompson confirmed a ransomware attack on the city of Vicksburg, Mississippi, on October 1, 2026. IT systems were taken o…

BPFDoor and AVERAT: New Variants Target Telecom Network Edge
Rapid7 has documented new variants of the BPFDoor Linux backdoor and the AVERAT implant deployed against telecom network-edge operator…

Dell CSM: Two CVSS 10 Flaws Grant Attackers Full Administrative Control
Dell has patched two maximum-severity vulnerabilities in Container Storage Modules. An unauthenticated attacker can bypass access cont…

Meta Muse Zero-Day Turns AI Assistant Into Backdoor: Attack Explained
Patrick Wardle discovered a zero-day in Meta's Muse AI agent for macOS. An undocumented setting, `endo_voyager_dictation_endpoint`, le…

AI Agents Linked to Failed SQL Injection Probes Against U.S. and Canadian Government Sites
In September 2026, researchers revealed that AI agents attempted rudimentary, unsuccessful SQL injection probes against the U.S. Depar…

Bitget: The Zero-Day Was Inside the Security Perimeter — $387.5 Million Stolen
Bitget confirmed that the $387.5 million theft stemmed from a zero-day vulnerability in third-party security appliances. Initial acces…

Android 17 Moves the Anti-Spyware Battlefield to Google's Servers
Android 17 adds six features to Advanced Protection, headlined by Intrusion Logging — a forensic logging system that stores encrypted…

AI Agent Breaches DIVD in Seconds Using Zammad Zero-Days: The Report
On September 21, 2026, the Dutch Institute for Vulnerability Disclosure (DIVD) was compromised by an autonomous AI agent that chained…

Fortinet: Critical FortiMail Zero-Day, Patches Missing for Three of Four Branches
CVE-2026-104286 hits FortiMail with a CVSS 9.8 score and active exploitation. CISA mandates action by October 4, but Fortinet has patc…

Penetration Test Compromises 2,500 Machines Using a 2019 Patch
A penetration tester compromised 2,500 computers at a U.S. law firm by exploiting BlueKeep, CVE-2019-0708. The CISO inadvertently incr…

Microsoft: Attackers Winning the AI Race, Defenders Lagging
The Microsoft 2026 Digital Defense Report warns that threat actors are exploiting artificial intelligence faster than defenders, creat…

Windows: TOCTOU Bug in dxgkrnl Enables Kernel Escalation With Conflicting CVSS Scores
CVE-2026-50375 in the DirectX Graphics Kernel driver: Microsoft confirms patch and 'More Likely' exploitability, but CVSS scores diver…

SC Malware Turns Cleanup Into a Regeneration Trigger
SC malware attacks WordPress with eight interdependent persistence points. Removing the visible plugin activates the recovery mechanis…

TA419: The Chinese Group Spying on AI Policymakers by Impersonating Them
The China-aligned espionage group TA419, tracked by Proofpoint, has conducted targeted phishing campaigns against AI policy experts in…