Daily feed
Today in security.
The last seven days from every source RedPatch watches — vendors, government CERTs and the security press. Refreshed every morning and evening; if a source is down you see its last good copy, never a blank.
Industry news · 120 items
- Internal files add to evidence of an ExxonMobil climate deception campaignHacker News · Oct 11
- Nippon Columbia malware incident exposes 8.6 million karaoke fan recordsBleepingComputer · Oct 11
- Open-Source Microsoft Office Excel, PowerPoint, and Word ReplicationsHacker News · Oct 11
- Terence Tao: Math 2.0 [pdf]Hacker News · Oct 11
- The tilde in your PATH may not be your HOMEHacker News · Oct 11
- Valen's Memory Safety: A New Kind of Borrow CheckingHacker News · Oct 11
- Show HN: BetterWispr – Free, open-source dictation for MacHacker News · Oct 11
- Weave (YC W25) is hiring ML, AI, product, & design engineersHacker News · Oct 11
- I paid people to try and follow my READMEHacker News · Oct 11
- Nitter: Update Oct 10th seeking funding and legal helpHacker News · Oct 11
- IRCv3Hacker News · Oct 11
- 3rd Yandex Cloud Data Center Was HitHacker News · Oct 11
- LineageOS 24.0Hacker News · Oct 11
- P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote CommandsThe Hacker News · Oct 11
- PSPi 6 – Raspberry Pi in a PSPHacker News · Oct 10
- Build your own decision modelHacker News · Oct 10
- A city-building game in which the city would prefer you didn'tHacker News · Oct 10
- Knuth reward checkHacker News · Oct 10
- Cyber exec arrested in case allegedly tied to ShinyHunters hackersBleepingComputer · Oct 10
- ARTEX AI, Claude agents used in cyberattacks on South Korean banksBleepingComputer · Oct 10
- Criminal IP Introduces AITEM as the Next Evolution of Attack Surface ManagementBleepingComputer · Oct 10
- AI Is Getting Really Good at Messing With CybercriminalsWIRED Security · Oct 10
- The Third-Party Agent Problem: Why Security Built for AI You Chose Misses the Agents You Didn'tThe Hacker News · Oct 10
- Insider Cyber Extortion Plot Against Industrial Firm Lands Engineer in PrisonSecurityWeek · Oct 10
- Talorys – A self-hosted personal AI agent on Cloudflare's free tierHacker News · Oct 10
- When Ldaxr Doesn't Work: Exclusive Accesses and Cacheability on AArch64Hacker News · Oct 10
- Anthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection FlawsThe Hacker News · Oct 10
- Why TLP should not replace your internal information classification, (Sat, Oct 10th)SANS Internet Storm Center · Oct 10
- GhostAction Hackers Compromise 500+ GitHub Accounts to Steal Cloud and AI API CredentialsGBHackers · Oct 10
- Iranian VPN-over-DNS Activity Generates 40 Billion DNS Observations During Military ConflictGBHackers · Oct 10
- DarkBlinders Hackers Use Fake Meeting App to Deploy Backdoor and Steal Government DataGBHackers · Oct 10
- Two AhsayCBS Zero-Day Vulnerabilities Actively Exploited to Take Over Backup ServersGBHackers · Oct 10
- Hackers Use AI Agents and GodPotato Exploit to Gain Windows SYSTEM PrivilegesGBHackers · Oct 10
- Rat's Register AllocatorHacker News · Oct 10
- AWS Bedrock AgentCore Flaw Allowed Attackers to Hijack AI Agents Using a Single PromptGBHackers · Oct 10
- The Lightbulb ComputerHacker News · Oct 10
- The RAM shortage is bringing back DDR4Hacker News · Oct 9
- FBI Arrests Executive at Ransomware Negotiation FirmKrebs on Security · Oct 9
- OpenAI Fires 3 Safety Researchers in Dispute Over AI RisksSecurityWeek · Oct 9
- ASOS Breach Reveals the Risks in Customer-Facing SaaSDark Reading · Oct 9
- Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksBleepingComputer · Oct 9
- Friday Squid Blogging: I Caught a SquidSchneier on Security · Oct 9
- AI Scramble Drives Cybersecurity M&A BoomDark Reading · Oct 9
- Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of RepositoriesThe Hacker News · Oct 9
- Japan confirms arrest of Russian Qilin operative, extradition to GermanyThe Record · Oct 9
- Rolling the Root KeyHacker News · Oct 9
- FBI Arrests Another ShinyHunters Suspect Reportedly Involved in Its Jobs Portal HackThe Hacker News · Oct 9
- What We Missed: FBI Strikes Back at ShinyHuntersDark Reading · Oct 9
- Unpatched AhsayCBS flaws exploited to deploy webshells, mine cryptoBleepingComputer · Oct 9
- FBI arrests another suspected ShinyHunters hacker after agency breachBleepingComputer · Oct 9
- Security Threats Don't Stop at the Office: Why Executives' Families Need Training, TooDark Reading · Oct 9
- Hundreds of thousands impacted by data breach at biosensor firm iRhythmThe Record · Oct 9
- Leader of vast money mule operation that laundered cybercriminal proceeds pleads guiltyThe Record · Oct 9
- FBI touts another ShinyHunters arrest in response to data breachThe Record · Oct 9
- Germany arrests alleged core Qilin ransomware member after extraditionBleepingComputer · Oct 9
- Five months treating bugs like patients and coding agents like a medical teamHacker News · Oct 9
- Wikimedia Says Rogue AI Agents Abused its PlatformsInfosecurity Magazine · Oct 9
- Belarusian hacktivists admit to 2023 breach of Russian state healthcare networkThe Record · Oct 9
- How to keep AI agents within their permissionsBleepingComputer · Oct 9
- TP-Link Sued by Four More U.S. States Over Router Security and China TiesThe Hacker News · Oct 9
- Social Engineering AI Agents: The New BEC for 2026Dark Reading · Oct 9
- Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root AccessThe Hacker News · Oct 9
- Anthropic Launches Free AI Vulnerability Scanner for Open-Source ProjectsThe Hacker News · Oct 9
- Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft EdgeThe Hacker News · Oct 9
- Max severity SonicWall SMA1000 flaw now exploited in attacksBleepingComputer · Oct 9
- React Server Components Vulnerability Lets Attackers Freeze Next.js Servers With a Single RequestGBHackers · Oct 9
- Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal AgenciesThe Hacker News · Oct 9
- In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 YearsSecurityWeek · Oct 9
- Q3 2026 Sets New Record for Ransomware AttacksInfosecurity Magazine · Oct 9
- Google Domains Impacted by Recent ccTLD HijacksSecurityWeek · Oct 9
- CastleStealer Malware Bypasses Chromium ABE and Adds Remote Command Execution CapabilitiesGBHackers · Oct 9
- The AI Velocity Paradox: Why Security Is Decades Behind AI AmbitionThe Hacker News · Oct 9
- Plumbers, chains, and famous painters: The history of the pipe operator in RHacker News · Oct 9
- Man admits to running network of 15,000 money mules for cybercriminalsBleepingComputer · Oct 9
- Cisco Talos Warns AI Agent Swarms Can Compress Cyberattacks From Months to HoursGBHackers · Oct 9
- Unpatched AhsayCBS Vulnerabilities Exploited in the WildSecurityWeek · Oct 9
- Microsoft: Outdated Windows devices will stop receiving security updatesBleepingComputer · Oct 9
- UK and Allies Warn of Cyber Threat from China’s Integrity Technology GroupInfosecurity Magazine · Oct 9
- Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ CountriesSecurityWeek · Oct 9
- GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format KeysThe Hacker News · Oct 9
- AI Training Critical as Governance Challenges GrowInfosecurity Magazine · Oct 9
- Suspected TraderTraitor Hackers Trojanize Terraform Provider to Deploy Cross-Platform MalwareGBHackers · Oct 9
- US Disrupts Chinese State-Sponsored Hacking ToolsSecurityWeek · Oct 9
- Citrix warns admins to patch new NetScaler RCE flaw immediatelyBleepingComputer · Oct 9
- Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2OwnThe Hacker News · Oct 9
- Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT SecuritySecurityWeek · Oct 9
- How big is a Git commit?Hacker News · Oct 9
- Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML DeploymentsThe Hacker News · Oct 9
- Major AI Firms Pledge Data Protection Changes Following UK Privacy Watchdog PushInfosecurity Magazine · Oct 9
- ISC Stormcast For Friday, October 9th, 2026 https://isc.sans.edu/podcastdetail/10130, (Fri, Oct 9th)SANS Internet Storm Center · Oct 9
- Citrix Urges Immediate Patching of Critical NetScaler VulnerabilitySecurityWeek · Oct 9
- Google Pixel 10 Exploits Earned Hackers $560,000 at Pwn2OwnSecurityWeek · Oct 9
- FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure IntrusionsThe Hacker News · Oct 9
- Hackers get $1,262,000 for 98 zero-days at Pwn2Own IrelandBleepingComputer · Oct 9
- ICE Agent at NYC Shooting Has History of Alleged Violence and Illegal ArrestsWIRED Security · Oct 9
- FBI disrupts Chinese hacking tools used to breach critical infrastructureBleepingComputer · Oct 8
- Post-quantum authentication: Why organizations should start testing certificate ecosystems nowMicrosoft Security Blog · Oct 8
- 'AgentCorruption' Puts AWS Environments at Risk With Single PromptDark Reading · Oct 8
- Venezuelan Cartel's Malware Honcho Nabbed for ATM JackpottingDark Reading · Oct 8
- FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen EmailsThe Hacker News · Oct 8
- Russian Spies Give 'MatchBoil' Malware a Stealthy FaceliftDark Reading · Oct 8
- Making sure the checks get printedCisco Talos · Oct 8
- ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More StoriesThe Hacker News · Oct 8
- Reconstructing AI Agent Activity: Two New Scripts for Forensic Review, (Thu, Oct 8th)SANS Internet Storm Center · Oct 8
- Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase AttacksThe Hacker News · Oct 8
- UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTMLThe Hacker News · Oct 8
- Attackers Hijack Three ccTLDs to Obtain Google CertificatesInfosecurity Magazine · Oct 8
- ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial FirmsThe Hacker News · Oct 8
- ASOS Confirms Data Breach Linked to Stolen Employee CredentialsInfosecurity Magazine · Oct 8
- Russia-Aligned UAC-0099 Evolves MATCHBOIL MalwareInfosecurity Magazine · Oct 8
- Satel Netco DesignCISA Cybersecurity Advisories · Oct 8
- Grid Protection Alliance openPDC and openHistorianCISA Cybersecurity Advisories · Oct 8
- Red Lion Controls N-Tron 700 SeriesCISA Cybersecurity Advisories · Oct 8
- Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive DataCISA Cybersecurity Advisories · Oct 8
- KEV: CVE-2015-5477 — ISC BIND: ISC BIND Data Processing Errors VulnerabilityCISA Known Exploited Vulnerabilities (KEV) · Oct 8
- KEV: CVE-2016-3081 — Apache Struts: Apache Struts Command Injection VulnerabilityCISA Known Exploited Vulnerabilities (KEV) · Oct 8
- KEV: CVE-2023-22894 — Strapi Strapi: Strapi Cleartext Storage of Sensitive Information VulnerabilityCISA Known Exploited Vulnerabilities (KEV) · Oct 8
- KEV: CVE-2021-3199 — ONLYOFFICE Docs: ONLYOFFICE Docs Server Path Traversal VulnerabilityCISA Known Exploited Vulnerabilities (KEV) · Oct 8
- KEV: CVE-2015-3306 — ProFTPD ProFTPD: ProFTPD Improper Access Control VulnerabilityCISA Known Exploited Vulnerabilities (KEV) · Oct 8
- Writing the Next ChapterDark Reading · Oct 8