RedPatch
Headlines refreshed Sun Oct 11, 11:45 AM ET (2 h ago) · content checked against vendor docs

Daily feed

Today in security.

The last seven days from every source RedPatch watches — vendors, government CERTs and the security press. Refreshed every morning and evening; if a source is down you see its last good copy, never a blank.

Industry news · 120 items

  1. Internal files add to evidence of an ExxonMobil climate deception campaignHacker News · Oct 11
  2. Nippon Columbia malware incident exposes 8.6 million karaoke fan recordsBleepingComputer · Oct 11
  3. Open-Source Microsoft Office Excel, PowerPoint, and Word ReplicationsHacker News · Oct 11
  4. Terence Tao: Math 2.0 [pdf]Hacker News · Oct 11
  5. The tilde in your PATH may not be your HOMEHacker News · Oct 11
  6. Valen's Memory Safety: A New Kind of Borrow CheckingHacker News · Oct 11
  7. Show HN: BetterWispr – Free, open-source dictation for MacHacker News · Oct 11
  8. Weave (YC W25) is hiring ML, AI, product, & design engineersHacker News · Oct 11
  9. I paid people to try and follow my READMEHacker News · Oct 11
  10. Nitter: Update Oct 10th seeking funding and legal helpHacker News · Oct 11
  11. IRCv3Hacker News · Oct 11
  12. 3rd Yandex Cloud Data Center Was HitHacker News · Oct 11
  13. LineageOS 24.0Hacker News · Oct 11
  14. P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote CommandsThe Hacker News · Oct 11
  15. PSPi 6 – Raspberry Pi in a PSPHacker News · Oct 10
  16. Build your own decision modelHacker News · Oct 10
  17. A city-building game in which the city would prefer you didn'tHacker News · Oct 10
  18. Knuth reward checkHacker News · Oct 10
  19. Cyber exec arrested in case allegedly tied to ShinyHunters hackersBleepingComputer · Oct 10
  20. ARTEX AI, Claude agents used in cyberattacks on South Korean banksBleepingComputer · Oct 10
  21. Criminal IP Introduces AITEM as the Next Evolution of Attack Surface ManagementBleepingComputer · Oct 10
  22. AI Is Getting Really Good at Messing With CybercriminalsWIRED Security · Oct 10
  23. The Third-Party Agent Problem: Why Security Built for AI You Chose Misses the Agents You Didn'tThe Hacker News · Oct 10
  24. Insider Cyber Extortion Plot Against Industrial Firm Lands Engineer in PrisonSecurityWeek · Oct 10
  25. Talorys – A self-hosted personal AI agent on Cloudflare's free tierHacker News · Oct 10
  26. When Ldaxr Doesn't Work: Exclusive Accesses and Cacheability on AArch64Hacker News · Oct 10
  27. Anthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection FlawsThe Hacker News · Oct 10
  28. Why TLP should not replace your internal information classification, (Sat, Oct 10th)SANS Internet Storm Center · Oct 10
  29. GhostAction Hackers Compromise 500+ GitHub Accounts to Steal Cloud and AI API CredentialsGBHackers · Oct 10
  30. Iranian VPN-over-DNS Activity Generates 40 Billion DNS Observations During Military ConflictGBHackers · Oct 10
  31. DarkBlinders Hackers Use Fake Meeting App to Deploy Backdoor and Steal Government DataGBHackers · Oct 10
  32. Two AhsayCBS Zero-Day Vulnerabilities Actively Exploited to Take Over Backup ServersGBHackers · Oct 10
  33. Hackers Use AI Agents and GodPotato Exploit to Gain Windows SYSTEM PrivilegesGBHackers · Oct 10
  34. Rat's Register AllocatorHacker News · Oct 10
  35. AWS Bedrock AgentCore Flaw Allowed Attackers to Hijack AI Agents Using a Single PromptGBHackers · Oct 10
  36. The Lightbulb ComputerHacker News · Oct 10
  37. The RAM shortage is bringing back DDR4Hacker News · Oct 9
  38. FBI Arrests Executive at Ransomware Negotiation FirmKrebs on Security · Oct 9
  39. OpenAI Fires 3 Safety Researchers in Dispute Over AI RisksSecurityWeek · Oct 9
  40. ASOS Breach Reveals the Risks in Customer-Facing SaaSDark Reading · Oct 9
  41. Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksBleepingComputer · Oct 9
  42. Friday Squid Blogging: I Caught a SquidSchneier on Security · Oct 9
  43. AI Scramble Drives Cybersecurity M&A BoomDark Reading · Oct 9
  44. Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of RepositoriesThe Hacker News · Oct 9
  45. Japan confirms arrest of Russian Qilin operative, extradition to GermanyThe Record · Oct 9
  46. Rolling the Root KeyHacker News · Oct 9
  47. FBI Arrests Another ShinyHunters Suspect Reportedly Involved in Its Jobs Portal HackThe Hacker News · Oct 9
  48. What We Missed: FBI Strikes Back at ShinyHuntersDark Reading · Oct 9
  49. Unpatched AhsayCBS flaws exploited to deploy webshells, mine cryptoBleepingComputer · Oct 9
  50. FBI arrests another suspected ShinyHunters hacker after agency breachBleepingComputer · Oct 9
  51. Security Threats Don't Stop at the Office: Why Executives' Families Need Training, TooDark Reading · Oct 9
  52. Hundreds of thousands impacted by data breach at biosensor firm iRhythmThe Record · Oct 9
  53. Leader of vast money mule operation that laundered cybercriminal proceeds pleads guiltyThe Record · Oct 9
  54. FBI touts another ShinyHunters arrest in response to data breachThe Record · Oct 9
  55. Germany arrests alleged core Qilin ransomware member after extraditionBleepingComputer · Oct 9
  56. Five months treating bugs like patients and coding agents like a medical teamHacker News · Oct 9
  57. Wikimedia Says Rogue AI Agents Abused its PlatformsInfosecurity Magazine · Oct 9
  58. Belarusian hacktivists admit to 2023 breach of Russian state healthcare networkThe Record · Oct 9
  59. How to keep AI agents within their permissionsBleepingComputer · Oct 9
  60. TP-Link Sued by Four More U.S. States Over Router Security and China TiesThe Hacker News · Oct 9
  61. Social Engineering AI Agents: The New BEC for 2026Dark Reading · Oct 9
  62. Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root AccessThe Hacker News · Oct 9
  63. Anthropic Launches Free AI Vulnerability Scanner for Open-Source ProjectsThe Hacker News · Oct 9
  64. Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft EdgeThe Hacker News · Oct 9
  65. Max severity SonicWall SMA1000 flaw now exploited in attacksBleepingComputer · Oct 9
  66. React Server Components Vulnerability Lets Attackers Freeze Next.js Servers With a Single RequestGBHackers · Oct 9
  67. Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal AgenciesThe Hacker News · Oct 9
  68. In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 YearsSecurityWeek · Oct 9
  69. Q3 2026 Sets New Record for Ransomware AttacksInfosecurity Magazine · Oct 9
  70. Google Domains Impacted by Recent ccTLD HijacksSecurityWeek · Oct 9
  71. CastleStealer Malware Bypasses Chromium ABE and Adds Remote Command Execution CapabilitiesGBHackers · Oct 9
  72. The AI Velocity Paradox: Why Security Is Decades Behind AI AmbitionThe Hacker News · Oct 9
  73. Plumbers, chains, and famous painters: The history of the pipe operator in RHacker News · Oct 9
  74. Man admits to running network of 15,000 money mules for cybercriminalsBleepingComputer · Oct 9
  75. Cisco Talos Warns AI Agent Swarms Can Compress Cyberattacks From Months to HoursGBHackers · Oct 9
  76. Unpatched AhsayCBS Vulnerabilities Exploited in the WildSecurityWeek · Oct 9
  77. Microsoft: Outdated Windows devices will stop receiving security updatesBleepingComputer · Oct 9
  78. UK and Allies Warn of Cyber Threat from China’s Integrity Technology GroupInfosecurity Magazine · Oct 9
  79. Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ CountriesSecurityWeek · Oct 9
  80. GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format KeysThe Hacker News · Oct 9
  81. AI Training Critical as Governance Challenges GrowInfosecurity Magazine · Oct 9
  82. Suspected TraderTraitor Hackers Trojanize Terraform Provider to Deploy Cross-Platform MalwareGBHackers · Oct 9
  83. US Disrupts Chinese State-Sponsored Hacking ToolsSecurityWeek · Oct 9
  84. Citrix warns admins to patch new NetScaler RCE flaw immediatelyBleepingComputer · Oct 9
  85. Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2OwnThe Hacker News · Oct 9
  86. Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT SecuritySecurityWeek · Oct 9
  87. How big is a Git commit?Hacker News · Oct 9
  88. Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML DeploymentsThe Hacker News · Oct 9
  89. Major AI Firms Pledge Data Protection Changes Following UK Privacy Watchdog PushInfosecurity Magazine · Oct 9
  90. ISC Stormcast For Friday, October 9th, 2026 https://isc.sans.edu/podcastdetail/10130, (Fri, Oct 9th)SANS Internet Storm Center · Oct 9
  91. Citrix Urges Immediate Patching of Critical NetScaler VulnerabilitySecurityWeek · Oct 9
  92. Google Pixel 10 Exploits Earned Hackers $560,000 at Pwn2OwnSecurityWeek · Oct 9
  93. FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure IntrusionsThe Hacker News · Oct 9
  94. Hackers get $1,262,000 for 98 zero-days at Pwn2Own IrelandBleepingComputer · Oct 9
  95. ICE Agent at NYC Shooting Has History of Alleged Violence and Illegal ArrestsWIRED Security · Oct 9
  96. FBI disrupts Chinese hacking tools used to breach critical infrastructureBleepingComputer · Oct 8
  97. Post-quantum authentication: Why organizations should start testing certificate ecosystems nowMicrosoft Security Blog · Oct 8
  98. 'AgentCorruption' Puts AWS Environments at Risk With Single PromptDark Reading · Oct 8
  99. Venezuelan Cartel's Malware Honcho Nabbed for ATM JackpottingDark Reading · Oct 8
  100. FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen EmailsThe Hacker News · Oct 8
  101. Russian Spies Give 'MatchBoil' Malware a Stealthy FaceliftDark Reading · Oct 8
  102. Making sure the checks get printedCisco Talos · Oct 8
  103. ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More StoriesThe Hacker News · Oct 8
  104. Reconstructing AI Agent Activity: Two New Scripts for Forensic Review, (Thu, Oct 8th)SANS Internet Storm Center · Oct 8
  105. Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase AttacksThe Hacker News · Oct 8
  106. UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTMLThe Hacker News · Oct 8
  107. Attackers Hijack Three ccTLDs to Obtain Google CertificatesInfosecurity Magazine · Oct 8
  108. ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial FirmsThe Hacker News · Oct 8
  109. ASOS Confirms Data Breach Linked to Stolen Employee CredentialsInfosecurity Magazine · Oct 8
  110. Russia-Aligned UAC-0099 Evolves MATCHBOIL MalwareInfosecurity Magazine · Oct 8
  111. Satel Netco DesignCISA Cybersecurity Advisories · Oct 8
  112. Grid Protection Alliance openPDC and openHistorianCISA Cybersecurity Advisories · Oct 8
  113. Red Lion Controls N-Tron 700 SeriesCISA Cybersecurity Advisories · Oct 8
  114. Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive DataCISA Cybersecurity Advisories · Oct 8
  115. KEV: CVE-2015-5477 — ISC BIND: ISC BIND Data Processing Errors VulnerabilityCISA Known Exploited Vulnerabilities (KEV) · Oct 8
  116. KEV: CVE-2016-3081 — Apache Struts: Apache Struts Command Injection VulnerabilityCISA Known Exploited Vulnerabilities (KEV) · Oct 8
  117. KEV: CVE-2023-22894 — Strapi Strapi: Strapi Cleartext Storage of Sensitive Information VulnerabilityCISA Known Exploited Vulnerabilities (KEV) · Oct 8
  118. KEV: CVE-2021-3199 — ONLYOFFICE Docs: ONLYOFFICE Docs Server Path Traversal VulnerabilityCISA Known Exploited Vulnerabilities (KEV) · Oct 8
  119. KEV: CVE-2015-3306 — ProFTPD ProFTPD: ProFTPD Improper Access Control VulnerabilityCISA Known Exploited Vulnerabilities (KEV) · Oct 8
  120. Writing the Next ChapterDark Reading · Oct 8

Sources

SourceStatusNewest item
CISA Cybersecurity Advisories ● live Oct 8
CISA ICS Advisories ● live Oct 8
CISA Known Exploited Vulnerabilities (KEV) ● live Oct 8
The Hacker News ● live Oct 11
Krebs on Security ● live Oct 9
GBHackers ● live Oct 10
MITRE ATT&CK ● live —
WIRED Security ● live Oct 10
SecurityWeek ● live Oct 10
Schneier on Security ● live Oct 9
NSA Cybersecurity Advisories & Guidance ● live —
Microsoft Security Blog ● live Oct 8
CERT/CC Vulnerability Notes ● live Oct 1
Infosecurity Magazine ● live Oct 9
Dark Reading ● live Oct 9
BleepingComputer ● live Oct 11
Unit 42 (Palo Alto Networks) ● live Oct 7
The Record ● live Oct 9
Cisco Talos ● live Oct 8
Google Security Blog ● live —
Apple Security Research ● link only —
Apple Developer Releases (OS updates) ● live Oct 6
Apple Security Releases ● link only —
MSRC Blog ● link only —
Microsoft Security Update Guide ● live Oct 9
Windows Release Health ● live Oct 9
Cloudflare Blog - Security ● live Oct 7
AWS Security Blog ● live Oct 7
Hacker News ● live Oct 11
Anthropic Research ● live Oct 8
HiddenLayer Research ● link only —
LLM Security ● link only —
Ubuntu Security Notices (USN) ● live Oct 9
Debian Security Advisories (DSA) ● live Oct 9
Red Hat Security Advisories (RHSA) ● live Oct 9
Linux Kernel CVE Announce ● live Oct 9
NVD (NIST) CVE API 2.0 ● live —
SANS Internet Storm Center ● live Oct 10
Apple Developer news ● live Oct 6
macOS Security Compliance Project releases ● live —
Microsoft Security Baselines blog (Tech Community) ● live Oct 8
Fedora security updates (Bodhi) ● live Oct 11

Go deeper

networks.jelia.nycHow the internet actually moves your data — packets, DNS, routing, TLS. waves.jelia.nycElectromagnetism explained — Wi-Fi, 2.4 GHz, Bluetooth and why RF leaks. lib.jelia.nycThe library — security, Linux, assembly and networking books on the shelf. blog.redpatch.usRedPatch field notes.