CYBER THREAT INTEL
DAILY BRIEFING · 2026-10-04 12:15 UTC · REPORT BRIEF-20261004-121511
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Ars Technica Security, BBC Technology, BleepingComputer, BleepingComputer (Google News), Cyber Risk & Security, Cyber Threat Intelligence
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
10
Stories Featured
54
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
Security Affairs newsletter Round 598 by Pierluigi Paganini – INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Fake Zoom installer hides macOS backdoor CloudSyncD C
SRC: Security Affairs
Sun, 04 Oct 2026 07:58:06 +0000
https://securityaffairs.com/200326/breaking-news/security-affairs-newsletter-round-598-by-pierluigi-paganini-international-edition.html
02
Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
Warlock ransomware continues to exploit unpatched SharePoint flaws to breach water utilities, telecoms, governments, and universities worldwide. Warlock ransomware made headlines back in mid-2025 for exploiting a chain of SharePoint zero-days collectively dubbed ToolShell. More than a year later, th
SRC: Security Affairs
Sun, 04 Oct 2026 07:49:27 +0000
https://securityaffairs.com/200304/malware/warlock-ransomware-still-exploits-year-old-sharepoint-flaws-to-hit-critical-infrastructure.html
03
Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries.
The activity, observed by the Symantec and Carbon Black Threat H
SRC: The Hacker News
Sat, 03 Oct 2026 20:06:33 +0530
https://thehackernews.com/2026/10/warlock-exploits-sharepoint-flaws-to.html
04
China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations.
The campaigns have impersonated prominent economists and AI
SRC: The Hacker News
Sun, 04 Oct 2026 12:50:32 +0530
https://thehackernews.com/2026/10/china-aligned-ta419-targets-us-ai.html
05
MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics
The U.K.'s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering efforts on behalf of Beijing's state security service.
In a "Security Service Espionage Alert" issued on September 30, 2026, MI5 said the "primary purpose
SRC: The Hacker News
Sat, 03 Oct 2026 20:08:46 +0530
https://thehackernews.com/2026/10/mi5-says-chinas-mss-funded-research.html
06
Danish university DTU breach exposes data of up to 200,000 people
The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data. […]
SRC: BleepingComputer
Sat, 03 Oct 2026 10:35:20 -0400
https://www.bleepingcomputer.com/news/security/danish-university-dtu-breach-exposes-data-of-up-to-200-000-people/
07
Anthropic asks Claude users to share voice data for AI model training
Anthropic has started asking Claude users to voluntarily share their voice conversations to help train and improve its AI models. […]
SRC: BleepingComputer
Sun, 04 Oct 2026 06:53:21 -0400
https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-asks-claude-users-to-share-voice-data-for-ai-model-training/
08
ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members
A suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter.
Rey, whose real name is Saif al-Din Khader, is said to have been brought into cu
SRC: The Hacker News
Sun, 04 Oct 2026 12:52:05 +0530
https://thehackernews.com/2026/10/shinyhunters-suspect-rey-reportedly.html
09
Google Gemini could soon get full access to your Mac’s files, apps and the web
Google's Gemini could soon access any file on your macOS device, open apps, browse the web, and perform actions without asking for permission every time. […]
SRC: BleepingComputer
Sat, 03 Oct 2026 19:12:34 -0400
https://www.bleepingcomputer.com/news/google/google-gemini-could-soon-get-full-access-to-your-macs-files-apps-and-the-web/
10
Federal judge calls Flock ‘indiscriminate mass surveillance’
A federal judge ruled that a sheriff’s deputy violated a woman’s Fourth Amendment rights when using Flock to search for her license plate without a warrant.
SRC: TechCrunch Security
Sat, 03 Oct 2026 19:33:15 +0000
https://techcrunch.com/2026/10/03/federal-judge-calls-flock-indiscriminate-mass-surveillance/
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-102490 | Zammad (Zammad GmbH) | 2026-10-02 |
| CVE-2026-102489 | Zammad (Zammad GmbH) | 2026-10-02 |
| CVE-2026-104286 | FortiMail (Fortinet) | 2026-10-01 |
| CVE-2026-76504 | Catalyst SD-WAN Manager (Cisco) | 2026-09-30 |
| CVE-2026-86950 | Multiple Products (Apple) | 2026-09-29 |
| CVE-2026-88772 | NetScaler (Citrix) | 2026-09-27 |
| CVE-2026-88771 | NetScaler (Citrix) | 2026-09-27 |
| CVE-2026-67279 | RouterOS (MikroTik) | 2026-09-25 |
| CVE-2026-65660 | SharePoint (Microsoft) | 2026-09-25 |
| CVE-2026-87902 | Core (WordPress) | 2026-09-25 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
