# Archive
Browse past daily curated stories
Friday, October 09, 2026
-
1BleepingComputer generalCisco warns of critical flaws allowing Nexus switch takeover
Cisco disclosed five critical vulnerabilities in its NX-OS data center operating system affecting Nexus switches, allowing arbitrary code execution with root privileges. Security teams managing Cisco data center infrastructure should treat these as urgent patching priorities given the breadth of NX-OS deployments in enterprise and service provider environments.
-
2SecurityWeek generalAttackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication
Threat actors began exploiting CVE-2026-21589, a critical vulnerability in Atlassian's self-hosted Data Center products, within hours of a public proof-of-concept being published. The rapid weaponization underscores the shrinking window between PoC disclosure and active exploitation for Atlassian products, which have been a persistent target for ransomware and espionage actors.
-
3BleepingComputer generalFBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins
The FBI issued an active warning that FortiBleed attacks against Fortinet FortiGate firewalls and SSL VPN gateways are ongoing, with attackers creating new administrative accounts and deleting existing ones to lock out legitimate administrators. Organizations running exposed Fortinet devices should immediately audit admin accounts and apply available patches, as the FBI's involvement signals widespread exploitation.
-
4BleepingComputer generalFBI disrupts Chinese hacking tools used to breach critical infrastructure
The FBI seized seven domains used by Chinese state-sponsored group Flax Typhoon — linked to Beijing-based firm Integrity Tech — to operate hacking tools MicroScan and FishHub against critical infrastructure and government organizations globally. The DOJ, FBI, CISA, and NSA issued a joint advisory, and Integrity Tech has been sanctioned by both the US and UK.
-
5SecurityWeek generalOracle Health Data Breach Tally Climbs to Nearly 20 Million
The Oracle Health data breach tally has climbed to nearly 20 million affected individuals, far exceeding figures cited in earlier patient notifications and state filings. The scale makes this one of the largest healthcare data breaches on record, with significant implications for HIPAA liability and patient notification obligations across affected hospital systems.
-
6SecurityWeek generalFortiBleed Attackers Locking Victims Out of Fortinet Devices
Attackers exploiting the FortiBleed vulnerability are actively locking victims out of Fortinet devices by creating rogue accounts and deleting legitimate credentials, preventing recovery. This persistence tactic significantly raises the severity of the campaign beyond initial compromise, requiring forensic account audits before restoration.
-
7The Hacker News generalARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms
CrowdStrike Intelligence tracked a targeted campaign against South Korean financial organizations from late September to early October 2026 that leveraged ARTEX, an AI-powered penetration testing tool, to conduct and automate data exfiltration. The abuse of legitimate offensive AI tooling for real attacks marks a notable escalation in adversary tradecraft against the financial sector.
-
8The Hacker News generalMonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data
The DOJ charged MonsterCloud owner Zohar Pinhasi (also known as Zack Silver and Zack Green) with wire fraud for secretly paying ransomware operators to obtain decryptors while billing victims over $19 million for purportedly proprietary recovery technology — a markup of approximately $11 million. The case exposes a predatory niche in the ransomware recovery industry and raises due-diligence questions for organizations vetting incident response vendors.
-
9The Hacker News generalAttackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains
Attackers compromised the DNS registries for three country-code top-level domains — .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) — to obtain unauthorized HTTPS certificates for several Google domains, as disclosed by Google on October 6, 2026. While Google's own infrastructure was not breached, the attack demonstrates that ccTLD registry compromise can undermine certificate trust for any domain under those TLDs.
-
10BleepingComputer generalFakeGit malware campaign returns with 17,610 malicious GitHub repos
The FakeGit campaign reactivated in October 2026, creating over 17,610 malicious GitHub repositories distributing SmartLoader malware as a dropper for the StealC infostealer. The campaign's industrial-scale abuse of GitHub's trusted platform makes it particularly dangerous for developers who may inadvertently clone or reference the repositories as dependencies.