CYBER THREAT INTEL
DAILY BRIEFING · 2026-10-07 12:15 UTC · REPORT BRIEF-20261007-121522
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Ars Technica Security, BBC Technology, BleepingComputer, BleepingComputer (Google News), Cyber Risk & Security, Cyber Threat Intelligence
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
16
Stories Featured
53
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
Chrome 155 Update Patches 247 Vulnerabilities
Four critical-severity use-after-free defects were fixed in Chromecast, Browser, Navigation, and Track.
The post Chrome 155 Update Patches 247 Vulnerabilities appeared first on SecurityWeek.
SRC: SecurityWeek
Wed, 07 Oct 2026 10:51:57 +0000
https://www.securityweek.com/chrome-155-update-patches-247-vulnerabilities/
02
Android’s October 2026 Updates Patch 25 Vulnerabilities
The patches resolve a critical vulnerability in Android’s System component that could lead to privilege escalation.
The post Android’s October 2026 Updates Patch 25 Vulnerabilities appeared first on SecurityWeek.
SRC: SecurityWeek
Wed, 07 Oct 2026 06:55:52 +0000
https://www.securityweek.com/androids-october-2026-updates-patch-25-vulnerabilities/
03
Atlassian Patches Critical Vulnerability Affecting 8 Products
Unauthenticated attackers could exploit the flaw to access specific files in the web application root directory.
The post Atlassian Patches Critical Vulnerability Affecting 8 Products appeared first on SecurityWeek.
SRC: SecurityWeek
Wed, 07 Oct 2026 06:37:16 +0000
https://www.securityweek.com/atlassian-patches-critical-vulnerability-affecting-8-products/
04
ClickFix Attacks Evolve to Better Hide Malicious Payloads
Threat actors are now hiding payloads by using DNS TXT records and browser cache pre-fetching, making it tougher to spot early attack stages.
SRC: DarkReading
Tue, 06 Oct 2026 20:32:58 GMT
https://www.darkreading.com/cyberattacks-data-breaches/clickfix-attacks-evolve-better-hide-malicious-payloads
05
Advantest confirms personal information stolen in ransomware attack
Advantest Corporation is notifying affected individuals that a ransomware attack earlier this year exposed their personally identifiable data. […]
SRC: BleepingComputer
Wed, 07 Oct 2026 06:27:52 -0400
https://www.bleepingcomputer.com/news/security/advantest-confirms-personal-information-stolen-in-ransomware-attack/
06
Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks
The FBI and Secret Service warned Fortinet users that FortiBleed, uncovered this summer, is a continuing threat.
The post Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks appeared first on CyberScoop.
SRC: CyberScoop
Tue, 06 Oct 2026 21:03:58 +0000
https://cyberscoop.com/fortibleed-fortinet-vpn-ransomware-fbi-warning/
07
100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer
The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer (aka Psychedelic Stealer).
The activity, which was observed by the agency in Sep
SRC: The Hacker News
Wed, 07 Oct 2026 12:27:54 +0530
https://thehackernews.com/2026/10/100-compromised-websites-use-fake.html
08
Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan
Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection.
Threat actors are known to name their malicious software after a legitimate operating system co
SRC: The Hacker News
Tue, 06 Oct 2026 23:54:25 +0530
https://thehackernews.com/2026/10/linux-backdoors-impersonate-email.html
09
ASOS Confirms Cyberattack, Data Breach
Hackers compromised a third-party communication platform and sent rogue notifications to ASOS users.
The post ASOS Confirms Cyberattack, Data Breach appeared first on SecurityWeek.
SRC: SecurityWeek
Wed, 07 Oct 2026 09:46:20 +0000
https://www.securityweek.com/asos-confirms-cyberattack-data-breach/
10
Personal Information for Over 1 Million People Stolen in a Cyberattack on Arizona’s Court System
The Arizona Supreme Court said the information was copied for people dating back as far as 30 years.
The post Personal Information for Over 1 Million People Stolen in a Cyberattack on Arizona’s Court System appeared first on SecurityWeek.
SRC: SecurityWeek
Wed, 07 Oct 2026 01:32:58 +0000
https://www.securityweek.com/personal-information-for-over-1-million-people-stolen-in-a-cyberattack-on-arizonas-court-system/
11
Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes
Cybersecurity researchers have disclosed details of a "human-operated phishing platform" that impersonates advertising products for artificial intelligence (AI) chatbots like Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus.
The products, which claim to offer campai
SRC: The Hacker News
Wed, 07 Oct 2026 00:08:55 +0530
https://thehackernews.com/2026/10/fake-chatgpt-gemini-and-claude-ad.html
12
ASOS confirms data breach after “HACKED” in-app notifications
UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment. […]
SRC: BleepingComputer
Tue, 06 Oct 2026 12:33:54 -0400
https://www.bleepingcomputer.com/news/security/asos-confirms-data-breach-after-hacked-in-app-notifications/
13
SonicWall warns of max severity SSRF flaw in SMA1000 gateways
SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances. […]
SRC: BleepingComputer
Wed, 07 Oct 2026 07:37:07 -0400
https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-max-severity-ssrf-flaw-in-sma1000-gateways/
14
Musician sent to prison for $10 million streaming fraud using AI bots
A North Carolina musician was sentenced to 18 months in prison for collecting more than $10 million in royalties from Spotify, Apple Music, Amazon Music, and YouTube Music in a massive streaming royalty fraud scheme. […]
SRC: BleepingComputer
Wed, 07 Oct 2026 06:35:15 -0400
https://www.bleepingcomputer.com/news/security/musician-gets-18-months-in-prison-for-10-million-streaming-fraud-using-ai-bots/
15
Anthropic Introduces 3-Tier Cyber Verification Program for AI Access
Anthropic is integrating the CVP and Project Glasswing into a single offering, with three levels of access to its most capable AI models.
The post Anthropic Introduces 3-Tier Cyber Verification Program for AI Access appeared first on SecurityWeek.
SRC: SecurityWeek
Wed, 07 Oct 2026 10:07:09 +0000
https://www.securityweek.com/anthropic-introduces-3-tier-cyber-verification-program-for-ai-access/
16
Anthropic Creates Three Tiers for Claude Cyber Access
Anthropic created three access tiers for Claude’s offensive security use, matching cyber capabilities and safeguards to the user’s level of trust. Anthropic is trying to solve the difficult balance between using AI for cybersecurity and preventing misuse. The same model that helps security teams fix
SRC: Security Affairs
Wed, 07 Oct 2026 10:06:28 +0000
https://securityaffairs.com/200521/ai/anthropic-creates-three-tiers-for-claude-cyber-access.html
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-88779 | NetScaler (Citrix) | 2026-10-04 |
| CVE-2026-102490 | Zammad (Zammad GmbH) | 2026-10-02 |
| CVE-2026-102489 | Zammad (Zammad GmbH) | 2026-10-02 |
| CVE-2026-104286 | FortiMail (Fortinet) | 2026-10-01 |
| CVE-2026-76504 | Catalyst SD-WAN Manager (Cisco) | 2026-09-30 |
| CVE-2026-86950 | Multiple Products (Apple) | 2026-09-29 |
| CVE-2026-88772 | NetScaler (Citrix) | 2026-09-27 |
| CVE-2026-88771 | NetScaler (Citrix) | 2026-09-27 |
| CVE-2026-67279 | RouterOS (MikroTik) | 2026-09-25 |
| CVE-2026-65660 | SharePoint (Microsoft) | 2026-09-25 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
