CYBER THREAT INTEL
DAILY BRIEFING · 2026-10-08 12:15 UTC · REPORT BRIEF-20261008-121527
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Ars Technica Security, BBC Technology, BleepingComputer, BleepingComputer (Google News), Cyber Risk & Security, Cyber Threat Intelligence
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
20
Stories Featured
53
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases
Cybersecurity researchers have discovered a cluster of 16 malicious Mozilla Firefox extensions that are capable of stealing cryptocurrency wallet recovery phrases and private keys.
"The extensions masquerade as wallet portals, desktop utilities, and browser tools, but their code intercepts recovery
SRC: The Hacker News
Thu, 08 Oct 2026 15:16:32 +0530
https://thehackernews.com/2026/10/16-malicious-firefox-extensions-pose-as.html
02
Atlassian Vulnerability Comes Under Attack Hours After Details Go Public
Threat actors are exploiting CVE-2026-21589, a critical Atlassian flaw that can expose sensitive files across multiple Data Center products. Threat actors have started exploiting CVE-2026-21589 (CVSS score of 9.3), a critical arbitrary file access flaw in Atlassian Data Center products. The vulnerab
SRC: Security Affairs
Thu, 08 Oct 2026 07:26:49 +0000
https://securityaffairs.com/200591/security/atlassian-vulnerability-comes-under-attack-hours-after-details-go-public.html
03
Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland
On the second day of Pwn2Own Ireland 2026, security researchers collected $232,500 in cash awards after exploiting 45 unique zero-day vulnerabilities. […]
SRC: BleepingComputer
Thu, 08 Oct 2026 02:32:16 -0400
https://www.bleepingcomputer.com/news/security/samsung-galaxy-s26-hacked-three-more-times-at-pwn2own-ireland/
04
Anthropic Gives Vetted Defenders Fewer Claude Guardrails
Anthropic has merged Project Glasswing into a tiered access program for its advanced cyber LLMs, including Opus, Sonnet, and Mythos.
SRC: DarkReading
Wed, 07 Oct 2026 20:51:25 GMT
https://www.darkreading.com/vulnerabilities-threats/anthropic-vetted-defenders-claude-guardrails
05
Quantum computers could break today’s encryption. Washington needs to prepare now.
As advances lower the barrier to breaking current encryption, Washington must move with equal urgency on post-quantum defenses.
The post Quantum computers could break today’s encryption. Washington needs to prepare now. appeared first on CyberScoop.
SRC: CyberScoop
Thu, 08 Oct 2026 10:00:00 +0000
https://cyberscoop.com/quantum-computers-could-break-todays-encryption-washington-needs-to-prepare-now/
06
Fake Decryption Tools Masked $11M Markup in Ransomware Recovery Scheme
Zohar Pinhasi was paying ransoms to obtain decryption keys and then charging victims substantially more for remediation.
The post Fake Decryption Tools Masked $11M Markup in Ransomware Recovery Scheme appeared first on SecurityWeek.
SRC: SecurityWeek
Thu, 08 Oct 2026 09:27:55 +0000
https://www.securityweek.com/fake-decryption-tools-masked-11m-markup-in-ransomware-recovery-scheme/
07
MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data
The U.S. Department of Justice (DoJ) on Wednesday announced charges against a 50-year-old U.S. and Israeli national for allegedly defrauding ransomware victims by secretly paying the attackers to obtain decryptors while claiming to use proprietary tools to recover their data.
Zohar Pinhasi (aka Zac
SRC: The Hacker News
Thu, 08 Oct 2026 13:11:44 +0530
https://thehackernews.com/2026/10/monstercloud-owner-accused-of-billing.html
08
Ransomware recovery CEO charged over secret ransom payments
The owner of ransomware remediation company MonsterCloud has been charged with allegedly defrauding ransomware victims by secretly paying their attackers for decryptors while claiming to use proprietary technology to recover encrypted data. […]
SRC: BleepingComputer
Wed, 07 Oct 2026 19:04:37 -0400
https://www.bleepingcomputer.com/news/security/ransomware-recovery-ceo-charged-over-secret-ransom-payments/
09
Writing the Next Chapter
Dark Reading is about to begin a new decade in its storied history, and we have some breaking news of our own to share.
SRC: DarkReading
Thu, 08 Oct 2026 12:00:00 GMT
https://www.darkreading.com/cybersecurity-operations/writing-next-chapter
10
U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks
The U.S. State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 2021 Microsoft Exchange Server attacks known as HAFNIUM.
The reward is for information leading to his
SRC: The Hacker News
Thu, 08 Oct 2026 13:12:04 +0530
https://thehackernews.com/2026/10/us-offers-up-to-10-million-for-tips-on.html
11
FBI, French authorities seize deepfake CSAM-for-sale websites
Some of the material appeared to be recorded or stolen video of girls through interactions on social media sites like Snapchat, TikTok, Instagram and Facebook.
The post FBI, French authorities seize deepfake CSAM-for-sale websites appeared first on CyberScoop.
SRC: CyberScoop
Wed, 07 Oct 2026 17:05:56 +0000
https://cyberscoop.com/fbi-french-authorities-seize-deepfake-csam-websites/
12
ASOS links data breach to social engineering attack, credential theft
ASOS is sending updates to affected customers about the cybersecurity incident it suffered earlier this week, confirming that hackers accessed some personal data. […]
SRC: BleepingComputer
Thu, 08 Oct 2026 07:42:46 -0400
https://www.bleepingcomputer.com/news/security/asos-links-data-breach-to-social-engineering-attack-credential-theft/
13
Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia
Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials. Attackers are increasingly building filtering, session management, and traffic controls into the infrastructure that delivers the phishing page itself.
ANY.RUN has identified Wazza, a
SRC: The Hacker News
Thu, 08 Oct 2026 16:00:00 +0530
https://thehackernews.com/2026/10/wazza-phishkit-targets-banking.html
14
Oracle Health Data Breach Tally Climbs to Nearly 20 Million
The figure is far higher than the counts that surfaced in earlier filings and patient notifications.
The post Oracle Health Data Breach Tally Climbs to Nearly 20 Million appeared first on SecurityWeek.
SRC: SecurityWeek
Thu, 08 Oct 2026 08:23:31 +0000
https://www.securityweek.com/oracle-health-data-breach-tally-climbs-to-nearly-20-million/
15
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
The npm package known as "tensorlake," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack.
The malicious version 0.5.144 "contains obfuscated malware that harvests credential
SRC: The Hacker News
Thu, 08 Oct 2026 11:16:20 +0530
https://thehackernews.com/2026/10/tensorlake-npm-package-compromised-to.html
16
Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer
Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts.
The campaign has been codenamed MALFEX by CloudSEK and Checkmarx. The activity is assessed to be the work of a
SRC: The Hacker News
Wed, 07 Oct 2026 23:13:20 +0530
https://thehackernews.com/2026/10/eight-malicious-npm-packages-downloaded.html
17
Rein Security Raises $25 Million to Guard AI Agents at Runtime
The cybersecurity startup will invest in product innovation, agentic research, and employee base expansion.
The post Rein Security Raises $25 Million to Guard AI Agents at Runtime appeared first on SecurityWeek.
SRC: SecurityWeek
Thu, 08 Oct 2026 11:11:28 +0000
https://www.securityweek.com/rein-security-raises-25-million-to-guard-ai-agents-at-runtime/
18
Owner of Empire cybercrime market gets 40 years in prison
The co-creator of Empire Market, one of the largest dark web marketplaces before its shutdown, has been sentenced to 40 years in prison for facilitating $430 million in illegal transactions from 2018 to 2020. […]
SRC: BleepingComputer
Thu, 08 Oct 2026 06:29:19 -0400
https://www.bleepingcomputer.com/news/security/owner-of-empire-cybercrime-market-gets-40-years-in-prison/
19
TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws
SEC Consult has published technical details on vulnerabilities mentioned in a complaint filed by several US states.
The post TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws appeared first on SecurityWeek.
SRC: SecurityWeek
Thu, 08 Oct 2026 10:24:04 +0000
https://www.securityweek.com/tp-link-faces-state-lawsuits-and-new-scrutiny-over-isp-router-flaws/
20
U.S. Offers $10 Million Reward for Alleged HAFNIUM Hacker Zhang Yu
The U.S. offers $10M for Zhang Yu, accused of helping run HAFNIUM attacks that compromised thousands of organizations worldwide. The U.S. State Department is offering a $10 million reward for information leading to the arrest of Zhang Yu. He is accused of being a key figure in the HAFNIUM campaign,
SRC: Security Affairs
Thu, 08 Oct 2026 10:11:44 +0000
https://securityaffairs.com/200608/intelligence/u-s-offers-10-million-reward-for-alleged-hafnium-hacker-zhang-yu.html
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-88779 | NetScaler (Citrix) | 2026-10-04 |
| CVE-2026-102490 | Zammad (Zammad GmbH) | 2026-10-02 |
| CVE-2026-102489 | Zammad (Zammad GmbH) | 2026-10-02 |
| CVE-2026-104286 | FortiMail (Fortinet) | 2026-10-01 |
| CVE-2026-76504 | Catalyst SD-WAN Manager (Cisco) | 2026-09-30 |
| CVE-2026-86950 | Multiple Products (Apple) | 2026-09-29 |
| CVE-2026-88772 | NetScaler (Citrix) | 2026-09-27 |
| CVE-2026-88771 | NetScaler (Citrix) | 2026-09-27 |
| CVE-2026-67279 | RouterOS (MikroTik) | 2026-09-25 |
| CVE-2026-65660 | SharePoint (Microsoft) | 2026-09-25 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
