# Today's Top Stories

October 08, 2026

  1. 1
    0
    The Hacker News general Oct 07
    FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

    The FBI and Secret Service issued a joint warning that the FortiBleed credential harvesting campaign remains active, having already amassed 86,644 sets of credentials from internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling attackers to lock out legitimate administrators. Security teams running exposed FortiGate devices should immediately audit credentials and review authentication configurations.

  2. 2
    0
    The Hacker News general Oct 07
    Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details

    CVE-2026-21589 (CVSS 9.3), a critical arbitrary file access vulnerability affecting Atlassian Data Center products including Confluence, Jira Software, Jira Service Management, and Bitbucket, drew active exploitation attempts within two hours of public disclosure. The flaw allows unauthenticated attackers to read sensitive files in the web application root directory. Organizations running self-hosted Atlassian Data Center deployments should apply patches immediately given the speed of exploitation.

  3. 3
    0
    The Hacker News general Oct 07
    SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

    SonicWall patched four vulnerabilities in its SMA1000 remote access appliances, including a CVSS 10.0 pre-authentication server-side request forgery (SSRF) flaw that allows unauthenticated attackers to route requests through the gateway to reach internal network functions. SonicWall stated no evidence of exploitation exists for any of the four flaws at time of disclosure. Administrators of SMA1000 series appliances should apply the released hotfixes immediately given the maximum severity rating.

  4. 4
    0
    BleepingComputer general Oct 07
    Hackers hijack Google domains after breaching ccTLD registries

    Attackers compromised third-party operators of the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) ccTLD registries to modify authoritative DNS records and obtain unauthorized HTTPS certificates for several Google domains. Google confirmed its own systems were not breached, but the attack demonstrates that certificate issuance security is only as strong as the weakest ccTLD registry operator. This supply-chain-style DNS attack puts any domain under those three TLDs at risk of impersonation via valid TLS certificates.

  5. 5
    0
    Krebs on Security threat-intel Oct 07
    ShinyHunters Extorted Boeing Spin-off Prior to Arrests

    A teenager from Amman, Jordan, using the handle 'Rey' and suspected of leading the ShinyHunters data theft and extortion group, has been detained and is reportedly cooperating with the FBI to identify other members. KrebsOnSecurity revealed the arrest came while ShinyHunters was actively extorting a business unit recently divested by Boeing. Separately, the FBI attributed a breach of an Accenture contractor to ShinyHunters, exposing personal data of thousands of FBI employees due to a missed patch.

  6. 6
    0
    The Record threat-intel Oct 07
    Senate passes healthcare cybersecurity bill after 190 million impacted by Change Healthcare breach

    The U.S. Senate passed the Health Care Cybersecurity and Resiliency Act of 2026 by unanimous consent, a direct legislative response to the Change Healthcare ransomware breach that impacted 190 million individuals. The bill would potentially expand federal cybersecurity requirements for healthcare organizations, a sector that has faced escalating ransomware attacks on critical systems. Security practitioners in healthcare should monitor rulemaking that follows, as compliance obligations are likely to broaden significantly.

  7. 7
    0
    The Record threat-intel Oct 07
    US posts $10 million reward for accused Chinese ‘Hafnium’ hacker

    The U.S. government posted a $10 million reward for Zhang Yu, a Chinese national identified as a prominent figure in the Hafnium hacking campaign that breached thousands of computers running on-premises Microsoft Exchange servers and exfiltrated large volumes of documents. Hafnium was attributed to Chinese state-sponsored actors and exploited a series of ProxyLogon-era Exchange vulnerabilities. The bounty signals continued U.S. government efforts to hold China-linked threat actors publicly accountable.

  8. 8
    0
    The Hacker News general Oct 07
    100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer

    CERT-UA identified over 100 compromised Ukrainian websites injected with malicious JavaScript serving LunexStealer (also known as Psychedelic Stealer), in a ClickFix-style campaign that uses fake Cloudflare verification pages. The activity, observed in September 2026, has been attributed to threat cluster UAC-0277. The technique of abusing trusted infrastructure prompts to deliver infostealers continues to evolve, making it difficult for end users to distinguish legitimate browser security checks from malicious ones.

  9. 9
    0
    The Hacker News general Oct 07
    Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

    Researchers from CloudSEK and Checkmarx detailed the MALFEX npm supply chain campaign, in which a single threat actor published 12 malicious packages since August 2023, eight of which accumulated 40,767 downloads before detection and delivered the Overlord RAT and an information stealer. The campaign's longevity — spanning over three years — underscores the persistent risk of malicious packages in open-source ecosystems. Developers using npm should audit dependencies for packages published by unknown or single-maintainer accounts.

  10. 10
    0
    SecurityWeek general Oct 07
    Chrome 155 Update Patches 247 Vulnerabilities

    Google released Chrome 155, patching 247 vulnerabilities including four rated critical-severity use-after-free flaws affecting Chromecast, Browser, Navigation, and Track components. Use-after-free bugs in browser components are frequently targeted for remote code execution and sandbox escape chains. Organizations and individuals should prioritize updating to Chrome 155 immediately given the volume and severity of the patched vulnerabilities.