CYBER THREAT INTEL
DAILY BRIEFING · 2026-10-11 12:15 UTC · REPORT BRIEF-20261011-121547
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Ars Technica Security, BBC Technology, BleepingComputer, BleepingComputer (Google News), Cyber Risk & Security, Cyber Threat Intelligence
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
8
Stories Featured
54
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
U.S. CISA adds ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited
SRC: Security Affairs
Sun, 11 Oct 2026 09:18:56 +0000
https://securityaffairs.com/200734/security/u-s-cisa-adds-proftpd-onlyoffice-docs-strapi-apache-struts-and-isc-bind-flaws-to-its-known-exploited-vulnerabilities-catalog.html
02
Silent Ransom Group Allegedly Extorted $207 Million Without Encrypting Files
Silent Ransom Group allegedly extorted $207 million from 27 law firms in six months using phone calls and social engineering, not encryption. Silent Ransom Group doesn’t rely on encryption. No malware payload, no locked files, just phone calls and social engineering aimed almost entirely at law firm
SRC: Security Affairs
Sat, 10 Oct 2026 15:05:54 +0000
https://securityaffairs.com/200719/cyber-crime/silent-ransom-group-allegedly-extorted-207-million-without-encrypting-files.html
03
ARTEX AI, Claude agents used in cyberattacks on South Korean banks
The cyberattacks that shook the South Korean financial sector earlier this month were launched by a Chinese hacker using the ARTEX AI penetration testing suite and Claude agents. […]
SRC: BleepingComputer
Sat, 10 Oct 2026 10:16:17 -0400
https://www.bleepingcomputer.com/news/security/hacker-used-artex-ai-and-claude-agents-to-target-south-korean-banks/
04
P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands
Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword.
"Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communicatio
SRC: The Hacker News
Sun, 11 Oct 2026 09:54:34 +0530
https://thehackernews.com/2026/10/p7-darksword-ios-exploit-kit-adds.html
05
Criminal IP Introduces AITEM as the Next Evolution of Attack Surface Management
Traditional attack surface management helps organizations discover exposed assets, but visibility alone is not enough to address threats. Criminal IP introduces AITEM, an AI-powered approach that connects exposure discovery with investigation, risk prioritization, and response. […]
SRC: BleepingComputer
Sat, 10 Oct 2026 08:30:39 -0400
https://www.bleepingcomputer.com/news/security/criminal-ip-introduces-aitem-as-the-next-evolution-of-attack-surface-management/
06
Anthropic Restricts Live Internet Access After Claude Evaluation Failures
Anthropic’s models kept working around the rules on the live internet. The company published the cases. Anthropic released a report on unintended actions its Claude models took during evaluations and internal use. The cases involved real websites and real organizations outside the company. Anthropic
SRC: Security Affairs
Sat, 10 Oct 2026 19:04:58 +0000
https://securityaffairs.com/200726/ai/anthropic-restricts-live-internet-access-after-claude-evaluation-failures.html
07
Cyber exec arrested in case allegedly tied to ShinyHunters hackers
Canadian cybersecurity executive Edward Dubrovsky has been arrested in Pennsylvania in connection with alleged extortion activity that multiple reports have linked to the FBI's ongoing crackdown on the ShinyHunters hacking group. […]
SRC: BleepingComputer
Sat, 10 Oct 2026 11:07:54 -0400
https://www.bleepingcomputer.com/news/security/cyber-exec-arrested-in-case-allegedly-tied-to-shinyhunters-hackers/
08
Canadian cybersecurity executive arrested in federal extortion case
Details of the case align with the investigation into ShinyHunters’ attack on FBI IT systems.
The post Canadian cybersecurity executive arrested in federal extortion case appeared first on CyberScoop.
SRC: CyberScoop
Sat, 10 Oct 2026 13:35:50 +0000
https://cyberscoop.com/edward-dubrovsky-cypfer-arrested-fbi-extortion-charges/
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2015-5477 | BIND (ISC) | 2026-10-08 |
| CVE-2016-3081 | Struts (Apache) | 2026-10-08 |
| CVE-2023-22894 | Strapi (Strapi) | 2026-10-08 |
| CVE-2021-3199 | Docs (ONLYOFFICE) | 2026-10-08 |
| CVE-2015-3306 | ProFTPD (ProFTPD) | 2026-10-08 |
| CVE-2026-88779 | NetScaler (Citrix) | 2026-10-04 |
| CVE-2026-102490 | Zammad (Zammad GmbH) | 2026-10-02 |
| CVE-2026-102489 | Zammad (Zammad GmbH) | 2026-10-02 |
| CVE-2026-104286 | FortiMail (Fortinet) | 2026-10-01 |
| CVE-2026-76504 | Catalyst SD-WAN Manager (Cisco) | 2026-09-30 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
