LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication

threat actors news

6 stories
aihigh

Microsoft: AI Cuts Post-Compromise Attack Time to Minutes

Microsoft's Digital Defense Report 2026, released October 1, 2026, warns that artificial intelligence (AI) has dramatically accelerated portions of the cyber-attack lifecycle, compressing post-compromise activities from days to mere minutes. This rapid evolution, driven by threat actors' early adoption of AI, presents a significant challenge for cybersecurity defenders.

malwarehigh

Malware Crypting Services Aid Threat Actors in Evading Detection

Cybersecurity researchers have identified a growing market for "crypting" services, which enable threat actors to modify malicious payloads to evade detection by antivirus (AV) and endpoint detection and response (EDR) tools. These services are becoming increasingly sophisticated, offering a range of features beyond basic encryption to complicate analysis and preserve malware usability.

cybercrime

Attackers Exploit Law Enforcement Coordination Gaps

A recent report indicates that cybercriminals are successfully exploiting existing coordination gaps among law enforcement agencies, allowing them to adapt their tactics and evade detection more effectively. This suggests a growing challenge for authorities in responding to the rapidly evolving landscape of cyber threats, as attackers leverage the lack of unified global or even regional responses.

aihigh

Bypassing AI guardrails is so easy a script kiddie can do it

Researchers from Cisco Talos have found that bypassing the guardrails designed to prevent large language models (LLMs) from assisting with cyberattacks is often straightforward, requiring little more than specific phrasing in prompts. Their analysis of prompt logs and artifacts from threat actor endpoints using tools like Claude Code, Codex, Cursor, and Gemini indicates that current guardrails…

aihigh

Threat Actors Uses Agentic AI to Rapidly Compromise Cloud Target

A threat actor utilized agentic artificial intelligence to compromise an Amazon Web Services (AWS) cloud environment within 72 hours, a task that would typically take weeks, according to a report by the security vendor Sygnia. The attack, aimed at extortion, leveraged familiar cloud infrastructure exploitation techniques but at an accelerated pace due to AI assistance.

fortinetcritical

FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems

A campaign dubbed "FortiBleed" has exposed administrative and VPN credentials for an estimated 73,932 FortiGate firewall systems globally. The compromised data, reportedly originating from a Russian-speaking threat group, has impacted organizations across critical sectors including government, telecommunications, financial services, healthcare, manufacturing, and multinational corporations.