SignalSec: Trending Cyber News

Latest threats, advisories, and industry developments

Trending
SecurityWeek•Just now

Pentagon Personnel Agency Data Breach Impacts 3 Million People

The data breach affects the Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense. The post Pentagon Personnel Agency Data Breach Impacts 3 Million People appeared first on SecurityWeek.

AI/MLData Breach
Trending
SecurityWeek•Just now

Rig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity Risks

Rig provides an identity dependencies graph to distinguish between legitimate users and rogue AI agents The post Rig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity Risks appeared first on SecurityWeek.

AI/ML
Trending
BleepingComputer•1h ago

Vietnamese man charged in $16 million 'pig butchering' crypto scam

A Vietnamese national was charged with money laundering for his role in a massive "pig butchering" scam, which defrauded a victim out of $16 million worth of cryptocurrency. [...]

Crypto
Trending
The Register Security•1h ago

Former X-Force hackers chase the offensive cyber gold rush

RemoteThreat launches with $7M, 1,000 attack tools, and ambitions to equip enterprises and Uncle Sam for AI-speed operations

AI/ML
Trending
SecurityWeek•1h ago

Four Cyber Threats Harboring Big Plans for the Future

- AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. The post Four Cyber Threats Harboring Big Plans for the Future appeared first on SecurityWeek.

AI/ML
Trending
SecurityWeek•1h ago

OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training

The GPT-6.1 Astra model was slated to debut in ChatGPT and Codex in October, but it fell short of expectations.  The post OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training appeared first on SecurityWeek.

AI/ML
Trending
SecurityWeek•1h ago

Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation

Pepijn van der Stap was convicted in 2023 for hacking multiple organizations, stealing their data, and extorting them. The post Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation appeared first on SecurityWeek.

General
Trending
SecurityWeek•2h ago

Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft

The malware framework uses a modular architecture and a custom executable file format for long-term persistence. The post Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft appeared first on SecurityWeek.

MalwareMicrosoft
Trending
BleepingComputer•3h ago

Kiteworks patches critical flaw, brings customer systems online

American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability. [...]

General
Trending
The Hacker News•4h ago

Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation

Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. "It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters," the Politie Landelijke Opsporing en Inte...

AI/ML
Trending
BleepingComputer•5h ago

Apple patches CoreGraphics zero-day flaw exploited in attacks

Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices. [...]

Zero-DayHardware/IoTApple
Trending
SecurityWeek•6h ago

Apple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’ 

Apple released iOS and macOS updates to patch a zero-day vulnerability (CVE-2026-86950) reported by Meta’s product security team. The post Apple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’  appeared first on SecurityWeek.

Zero-DayApple
Trending
SecurityWeek•6h ago

Apple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’ 

Apple has released iOS and macOS updates to patch the zero-day vulnerability tracked as CVE-2026-86950. The post Apple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’  appeared first on SecurityWeek.

Zero-DayApple
Trending
The Hacker News•6h ago

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory. Affected versions sent the client secret, the authorization code, and the PKCE proof...

AI/ML
Trending
The Hacker News•7h ago

OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions

OpenAI on Monday shelved plans to release GPT-6.1 Astra, a next-generation artificial intelligence (AI) model that was planned for an October launch, after it failed internal safety and alignment audits. The development was first reported by The Wall Street Journal. The move "marks a rare case of a...

AI/ML
Trending
The Hacker News•7h ago

OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot

OpenAI said it has made the decision to pause training of its most powerful models after one of its agents during reinforcement learning (RL) training contacted an external chatbot by exploiting a loophole in its internet-access restrictions. "An agent attempting to complete a search-based training...

AI/ML
Trending
The Register Security•10h ago

OpenAI’s dirty deeds Down Under included security bypass attempts, using exposed keys, source code siphon

Admits its agents side-swiped four Australian government sites

AI/ML
Trending
CyberScoop•11h ago

Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings

The vendor’s products are a common, recurring target for attackers, yet the official warning for some Citrix NetScaler customers was too late. The post Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings appeared first on CyberScoop.

Zero-Day
Trending
BleepingComputer•15h ago

Japan's Keio confirms ransomware attack disrupted business systems

Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting  some of its business systems. [...]

AI/MLRansomware
Trending
BleepingComputer•16h ago

Times Car confirms data breach affecting 6.6 million user accounts

Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. [...]

Data Breach
Trending
The Register Security•16h ago

JadePuffer crims hijacked Azure identities and used them to blow up cloud resources

Smells like more agentic ransomware, Redmond warns

RansomwareCloud Security
Trending
BleepingComputer•16h ago

Dutch police confirm arrest in ShinyHunters hacking investigation

Dutch police have confirmed that a 24-year-old Amsterdam man arrested earlier this month was detained as part of an investigation into the ShinyHunters hacking group. [...]

AI/ML
Trending
The Hacker News•17h ago

Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to...

AI/MLHardware/IoTApple
Trending
BleepingComputer•17h ago

Over 16,000 Supabase databases expose PII, passwords, auth tokens

Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens. [...]

General
Trending
BleepingComputer•17h ago

Misconfigured Supabase apps expose data in over 16,000 databases

Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens. [...]

General
Trending
The Hacker News•18h ago

Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits,...

AI/MLMalwareMicrosoft
Trending
CyberScoop•18h ago

As AI world debates security, NVIDIA releases open source tools for agents

One expert told CyberScoop that the announcement reflects industry recognition that after years of training models to behave safely or ethically, more outside controls are needed. The post As AI world debates security, NVIDIA releases open source tools for agents appeared first on CyberScoop.

AI/ML
Trending
The Hacker News•18h ago

IAM for AI agents: A Practical Enterprise Framework

What is IAM for AI agents? AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority. IAM for AI Agents is the identity-control architecture that governs those actors. This guide covers the limits of conventional provisioning, the components that matter, how t...

AI/ML
Trending
The Hacker News•19h ago

Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, us...

AI/MLCryptoMicrosoft
Trending
The Hacker News•19h ago

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs...

AI/MLMalware
Trending
SecurityWeek•19h ago

Modulate Raises $25 Million to Advance Deepfake Detection

The misuse and abuse of AI-generated voice is growing. Modulate’s intention is to allow real time detection and intervention.  The post Modulate Raises $25 Million to Advance Deepfake Detection appeared first on SecurityWeek.

AI/ML
Trending
BleepingComputer•20h ago

JadePuffer agentic AI attacks target Azure, destroy cloud resources

The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components. [...]

AI/MLRansomwareCloud Security
Trending
SecurityWeek•21h ago

Call for Presentations Open for 2026 CISO Forum Virtual Summit

SecurityWeek seeks original, vendor-neutral presentations that help cybersecurity leaders navigate emerging threats, strengthen resilience, and address the strategic challenges facing today’s enterprise security programs. The post Call for Presentations Open for 2026 CISO Forum Virtual Summit appear...

General
Trending
Krebs on Security•21h ago

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest, remaining ShinyHunters members dramatically escalated their attac...

AI/MLRansomware
Trending
CyberScoop•21h ago

ShinyHunters trades financial extortion for a reckless war of ego with the FBI

Cybercrime experts are stunned as ShinyHunters risks agent safety and intense federal heat in a bizarre attempt to force the retraction of an agency advisory. The post ShinyHunters trades financial extortion for a reckless war of ego with the FBI appeared first on CyberScoop.

Ransomware
Trending
The Hacker News•22h ago

⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface. Elsewhere, weak service accounts, old bugs, exposed systems...

AI/MLCryptoPhishing
Trending
BleepingComputer•22h ago

80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking

Infostealer logs exposed AI account credentials and sessions tied to more than 80,000 corporate domains, creating risks ranging from stolen conversations to LLMjacking. SOCRadar examines the growing market for stolen AI logins and how organizations can identify their exposure. [...]

AI/MLMalware
Trending
SecurityWeek•1d ago

Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon

Cameron John Wagenius was sentenced to 70 months in prison for stealing information from the wireless carriers. The post Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon appeared first on SecurityWeek.

General
Trending
The Register Security•1d ago

Ex-soldier's telecom hacking spree earns him 70 months

Active-duty campaign targeted at least ten organizations and sought $1 million in ransom payments

AI/ML
Trending
The Hacker News•1d ago

Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI

AI agents are moving into production faster than security teams can govern them. They are connecting to apps, handling data, calling APIs, and acting across business systems—often without the same controls applied to human users. According to Okta’s Global CISO Insights 2026 report, only 47% of CIS...

AI/ML
Trending
The Hacker News•1d ago

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent. "The implant installs the framework unchanged, then overwrites its SOUL.md per...

AI/MLCloud SecurityMalware
Trending
WIRED Security•1d ago

OpenAI Pauses Training Its Most Powerful Models After Rogue Agents Target Government

Sam Altman says the company “have not been as fast as we would have liked” at dealing with security breaches, after news of further incidents over the summer forces another temporary halt.

AI/ML
Trending
SecurityWeek•1d ago

DC Health Agency Exposes 400,000 Beneficiary Records

The Medicaid IDs and other information of Medicaid and DC Healthcare Alliance beneficiaries were exposed. The post DC Health Agency Exposes 400,000 Beneficiary Records appeared first on SecurityWeek.

AI/ML
Trending
SecurityWeek•1d ago

Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign

The extortion group has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273. The post Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign appeared first on SecurityWeek.

AI/MLRansomware
Trending
SecurityWeek•1d ago

New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections

A New Mexico jury has found Facebook liable for deceiving users about privacy protections on the platform. The post New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections appeared first on SecurityWeek.

General
Trending
SecurityWeek•1d ago

Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog

The platform combines open source software and a reference system design to keep AI agents within set boundaries. The post Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog appeared first on SecurityWeek.

AI/MLHardware/IoT
Trending
SecurityWeek•1d ago

Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability

The company says the measure was precautionary and that it has no evidence of Kiteworks or customer systems being compromised. The post Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability appeared first on SecurityWeek.

Data Breach
Trending
BleepingComputer•1d ago

Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist

Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million. [...]

CryptoMicrosoft
Trending
The Hacker News•1d ago

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor's tradecraft. The a...

Cloud SecurityData BreachMicrosoft
Trending
BleepingComputer•1d ago

US soldier gets 70 months in prison for extorting 10 tech, telecom firms

A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024. [...]

General