[{"id":967,"source_name":"BleepingComputer","title":"Atlassian warns of critical file-access flaw in Jira, Confluence","summary":"Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket. [...]","url":"https://www.bleepingcomputer.com/news/security/atlassian-warns-of-critical-file-access-flaw-in-jira-confluence/","category":"other","risk_level":"high","thumbnail_url":null,"published_at":"2026-10-06T17:34:59","created_at":"2026-10-06T18:27:40.476101"},{"id":968,"source_name":"BleepingComputer","title":"ASOS confirms data breach after “HACKED” in-app notifications","summary":"UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment. [...]","url":"https://www.bleepingcomputer.com/news/security/asos-confirms-data-breach-after-hacked-in-app-notifications/","category":"other","risk_level":"medium","thumbnail_url":null,"published_at":"2026-10-06T16:33:54","created_at":"2026-10-06T18:27:40.476106"},{"id":969,"source_name":"BleepingComputer","title":"Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes","summary":"A new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser attacks. [...]","url":"https://www.bleepingcomputer.com/news/security/fake-chatgpt-gemini-sites-steal-advertising-accounts-mfa-codes/","category":"other","risk_level":"medium","thumbnail_url":null,"published_at":"2026-10-06T15:16:44","created_at":"2026-10-06T18:27:40.476110"},{"id":970,"source_name":"BleepingComputer","title":"How to secure RMM software: 8 controls MSPs should test","summary":"RMM platforms give MSPs privileged access across customer environments, making their security controls critical to limiting risk. Acronis outlines eight controls MSPs should test when evaluating RMM software, from patching and privileged access to recovery and tenant isolation. [...]","url":"https://www.bleepingcomputer.com/news/security/how-to-secure-rmm-software-8-controls-msps-should-test/","category":"other","risk_level":"high","thumbnail_url":null,"published_at":"2026-10-06T14:00:10","created_at":"2026-10-06T18:27:40.476115"},{"id":961,"source_name":"The Hacker News","title":"LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings","summary":"A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro.\n\nThe attack works only when the program's Java support is enabled. So far, it has only been shown as a proof of concept, and there are no reports of its use in","url":"https://thehackernews.com/2026/10/libreoffice-and-openoffice-flaws-let.html","category":"other","risk_level":"medium","thumbnail_url":null,"published_at":"2026-10-06T11:57:00","created_at":"2026-10-06T12:27:41.716723"},{"id":958,"source_name":"BleepingComputer","title":"Wikimedia: Rogue OpenAI agents behind unauthorized Wikipedia edits","summary":"The Wikimedia Foundation says rogue OpenAI agents made unauthorized Wikipedia edits and may have been partially responsible for a May outage. [...]","url":"https://www.bleepingcomputer.com/news/security/rogue-openai-agents-behind-potentially-malicious-wikipedia-edits/","category":"other","risk_level":"medium","thumbnail_url":null,"published_at":"2026-10-06T11:31:48","created_at":"2026-10-06T12:27:40.532236"},{"id":962,"source_name":"The Hacker News","title":"Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies","summary":"The Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, and edit Wikipedia pages.\n\n\"The unauthorized bot activities included edits to our wikis, some unsuccessful attempts to exploit a public note-taking tool we host, and heavy traffic,","url":"https://thehackernews.com/2026/10/wikimedia-says-openai-agents-tried-to.html","category":"other","risk_level":"medium","thumbnail_url":null,"published_at":"2026-10-06T11:26:25","created_at":"2026-10-06T12:27:41.716728"},{"id":963,"source_name":"The Hacker News","title":"Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers","summary":"In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterprises plugged them into agent workflows.\n\nThe ecosystem around it fell short. Earlier this year, our team at OX Security,&nbsp; traced critical vulnerabilities in Anthropic's MCP","url":"https://thehackernews.com/2026/10/welcome-to-jungle-what-we-found-inside.html","category":"other","risk_level":"high","thumbnail_url":null,"published_at":"2026-10-06T11:02:30","created_at":"2026-10-06T12:27:41.716732"},{"id":959,"source_name":"BleepingComputer","title":"Nikkei discloses breaches of employees’ Microsoft, Google email accounts","summary":"Over the weekend, Japanese publishing giant Nikkei disclosed that unknown attackers recently breached two employee email accounts and used one to send thousands of phishing emails. [...]","url":"https://www.bleepingcomputer.com/news/security/nikkei-discloses-breaches-of-employees-microsoft-google-email-accounts/","category":"phishing","risk_level":"medium","thumbnail_url":null,"published_at":"2026-10-06T09:25:50","created_at":"2026-10-06T12:27:40.532241"},{"id":964,"source_name":"The Hacker News","title":"Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports","summary":"Google has stopped accepting product vulnerability reports through its bug bounty program for its open-source software.\n\nThe change, in effect since October 1, means researchers can no longer submit security flaws in the code of projects such as Go, Angular, and Protocol Buffers there for a reward. Reports about supply chain compromises are still accepted, and reports filed before October 1 are","url":"https://thehackernews.com/2026/10/google-pauses-oss-product-bug-bounty.html","category":"other","risk_level":"medium","thumbnail_url":null,"published_at":"2026-10-06T09:21:47","created_at":"2026-10-06T12:27:41.716736"},{"id":960,"source_name":"BleepingComputer","title":"Engineer sentenced for locking over 3,000 devices on employer network","summary":"A former core infrastructure engineer at an industrial company headquartered in New Jersey was sentenced to 32 months in prison for locking thousands of devices on his employer's network in a ransomware-style attack. [...]","url":"https://www.bleepingcomputer.com/news/security/engineer-sentenced-for-locking-thousands-of-devices-on-employer-network/","category":"ransomware","risk_level":"medium","thumbnail_url":null,"published_at":"2026-10-06T08:19:24","created_at":"2026-10-06T12:27:40.532245"},{"id":965,"source_name":"The Hacker News","title":"Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products","summary":"A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory.\n\nThe attacker must already know a file's exact name and path and cannot list what the directory holds. Atlassian&nbsp;disclosed the flaw, CVE-2026-21589, on October 5, rated it 9.3 out of 10, and","url":"https://thehackernews.com/2026/10/critical-atlassian-flaw-lets.html","category":"other","risk_level":"high","thumbnail_url":null,"published_at":"2026-10-06T06:58:56","created_at":"2026-10-06T12:27:41.716741"},{"id":966,"source_name":"The Hacker News","title":"FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach","summary":"The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the theft of personal details of thousands of bureau employees.\n\nThat's according to a report from Reuters, citing two sources familiar with the matter.\n\n\"To date, our review has determined that the incident occurred as the result of a security failure ​","url":"https://thehackernews.com/2026/10/fbi-removes-accenture-contractor-after.html","category":"other","risk_level":"medium","thumbnail_url":null,"published_at":"2026-10-06T06:56:57","created_at":"2026-10-06T12:27:41.716745"},{"id":956,"source_name":"The Hacker News","title":"Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account","summary":"Unauthorized parties have gained access to the names, addresses, and personal identification numbers of about 8.8 million people, living and dead, in Denmark's national population register, the country's digitalization ministry&nbsp;said on October 5.\n\nThey used a private Danish company's lawful right to look up records in the Central Person Register (CPR). The ministry has told people never to","url":"https://thehackernews.com/2026/10/denmark-says-attackers-accessed-cpr.html","category":"other","risk_level":"medium","thumbnail_url":null,"published_at":"2026-10-06T06:00:30","created_at":"2026-10-06T06:27:41.519843"},{"id":957,"source_name":"The Hacker News","title":"ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits","summary":"A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser's cache.\n\n\"Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file,\" the Microsoft Threat Intelligence team said in a post on X.","url":"https://thehackernews.com/2026/10/clickfix-smuggles-payloads-through.html","category":"other","risk_level":"medium","thumbnail_url":null,"published_at":"2026-10-06T05:22:55","created_at":"2026-10-06T06:27:41.519848"},{"id":954,"source_name":"BleepingComputer","title":"OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU","summary":"OpenAI is preparing to add invisible watermarks to text generated by ChatGPT and Codex in the European Union. [...]","url":"https://www.bleepingcomputer.com/news/artificial-intelligence/openai-is-adding-invisible-watermarks-to-chatgpt-and-codex-text-in-the-eu/","category":"other","risk_level":"medium","thumbnail_url":null,"published_at":"2026-10-05T22:46:33","created_at":"2026-10-06T00:27:40.708923"},{"id":955,"source_name":"BleepingComputer","title":"Rejetto HFS servers now actively scanned for critical RCE flaw","summary":"Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeover, and remote code execution (RCE). [...]","url":"https://www.bleepingcomputer.com/news/security/rejetto-hfs-servers-now-actively-scanned-for-critical-rce-flaw/","category":"other","risk_level":"high","thumbnail_url":null,"published_at":"2026-10-05T20:20:05","created_at":"2026-10-06T00:27:40.708928"},{"id":944,"source_name":"BleepingComputer","title":"IQVIA fined $7.8 million for failing to properly anonymize health data","summary":"Italy's Data Protection Authority (GPDP) has fined IQVIA €7 million ($7.8M) over poor data-processing practices that the agency says could have put roughly one million patients at risk of data exposure and de-anonymization. [...]","url":"https://www.bleepingcomputer.com/news/security/iqvia-fined-78-million-for-failing-to-properly-anonymize-health-data/","category":"other","risk_level":"medium","thumbnail_url":null,"published_at":"2026-10-05T17:19:53","created_at":"2026-10-05T18:27:40.548497"},{"id":950,"source_name":"The Hacker News","title":"Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes","summary":"Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions.\n\nThe vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system.\n\n\"Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a","url":"https://thehackernews.com/2026/10/microsoft-exchange-flaw-lets.html","category":"other","risk_level":"medium","thumbnail_url":null,"published_at":"2026-10-05T16:21:52","created_at":"2026-10-05T18:27:42.049027"},{"id":945,"source_name":"BleepingComputer","title":"Denmark population registry data breach affects 8.8 million people","summary":"Denmark's Central Population Register (CPR) is warning of a data breach that exposed the personal information of approximately 8.8 million registered individuals. [...]","url":"https://www.bleepingcomputer.com/news/security/denmark-population-registry-data-breach-affects-88-million-people/","category":"other","risk_level":"medium","thumbnail_url":null,"published_at":"2026-10-05T15:21:10","created_at":"2026-10-05T18:27:40.548502"}]