International law enforcement dismantled the KillSec ransomware group on September 30, seizing its dark web leak site and servers. The operation, led by German authorities, resulted in three arrests, including a 16-year-old suspected main operator, and the seizure of 110 terabytes of stolen data.
Two newly patched PaperCut NG/MF flaws (CVE-2026-81578 and CVE-2026-82078) are being exploited to bypass authentication and remotely execute code, with attackers now dumping Derby DB tables to steal data. PaperCut released multiple emergency patches (including Release 3) and urges internet-facing servers to apply them; over 800 PaperCut servers are exposed online per Shadowserver. While attribution is unclear, this follows a history of targeted PaperCut exploits by ransomware and state-backed groups and underscores ongoing risk from misconfigured or exposed deployments.
Health-ISAC warns that ShinyHunters are increasingly targeting healthcare by chaining supply-chain and identity attacks to gain access to cloud services through compromised SSO (Okta, Microsoft Entra, Google). Attackers use live voice phishing (vishing) to persuade employees or helpdesk staff to reset credentials or MFA, enabling rapid exfiltration from connected SaaS apps like Salesforce, Microsoft 365 and SharePoint. The advisory urges breaking the attack chain with out-of-band verification for resets, phishing-resistant MFA (FIDO2/WebAuthn), disabling SMS/voice OTP, treating SSO as Tier 0, centralizing SaaS logs, restricting API tokens, and rapid session revocation. Incidents have involved organizations such as Medtronic, DentaQuest, iRhythm, and OneMedical, and healthcare entities should focus on containment and strengthening controls over the next 30–60 days.
Security researchers found 108 malicious Chrome extensions—designed as games, utilities, or add-ons—that quietly siphon user data and inject ads across every site. Despite different publishers, all stolen data is sent to a single command-and-control server; 54 extensions harvest Gmail addresses, full names, and Google 'sub' IDs to build a persistent profile. If you have any of these extensions installed, delete them via Chrome or Edge extensions manager. To stay safe, download only trusted extensions, inspect permissions, enable Enhanced Safe Browsing, and consider antivirus and identity protection to guard against similar threats.
Salesforce warns customers that misconfigured Experience Cloud guest access can let unauthenticated visitors query CRM data, while ShinyHunters claims to be exploiting a bug with a modified AuraInspector to steal data. Salesforce stresses there is no platform flaw and urges admins to audit guest permissions, set org defaults to private, disable API access for guest profiles, turn off self-registration, and monitor Aura Event Monitoring. Mandiant confirms AuraInspector misuse and notes that detection in logs does not guarantee a breach.
Anthropic says three Chinese labs used a distillation technique to siphon Claude's capabilities through about 16 million exchanges and 24,000 fake accounts, circumventing export controls and raising national-security concerns; OpenAI has issued similar charges, prompting calls for coordinated industry and government action to counter illicit access and safeguard safety guardrails.
Oracle released an emergency patch for a critical vulnerability (CVE-2025-61882) in its E-Business Suite, which has been exploited by the Cl0p ransomware group in recent data theft attacks. The flaw allows remote code execution without authentication, and indicators suggest involvement of the LAPSUS$ group. Organizations are advised to check for compromises, as exploitation has already occurred.
Oracle has issued a critical security update for a zero-day vulnerability (CVE-2025-61882) in its E-Business Suite, actively exploited by the Clop ransomware gang to steal data. The flaw allows unauthenticated remote code execution and has been linked to recent data theft attacks, with threat actors sharing exploit code and indicators of compromise. Oracle urges immediate patching to prevent further exploitation.
The FBI has issued alerts about two cybercriminal groups, UNC6040 and UNC6395, targeting Salesforce platforms through various methods, including OAuth token exploitation and vishing campaigns, leading to data theft and extortion activities, with threat groups like ShinyHunters potentially re-emerging after a recent shutdown.
China's Salt Typhoon cyberattack, spanning years and targeting over 80 countries, may have stolen data from nearly every American, highlighting China's advanced cyber capabilities and potential for global surveillance.
Federal and state officials are investigating a ransomware attack in Nevada that disrupted key government services and resulted in data theft, with ongoing efforts to analyze the stolen information and restore security, involving CISA and FBI assistance.
Researchers have discovered a new AI attack that embeds hidden instructions in images through downscaling, which can lead to data theft and unauthorized actions when processed by AI systems. The attack exploits artifacts created during image resampling to hide malicious prompts that are interpreted by AI models, potentially compromising user data and system integrity. Mitigation strategies include imposing image dimension limits, providing preview feedback, and requiring user confirmation for sensitive operations. The researchers also released an open-source tool to demonstrate the attack.
Over 1,000 CrushFTP servers are vulnerable to hijack attacks due to a critical security flaw (CVE-2025-54309) affecting versions below 10.8.5 and 11.3.4_23, with attackers exploiting the bug for potential data theft and unauthorized access. The vendor recommends updating and monitoring logs, as unpatched servers remain at risk, and ongoing attacks have been observed in the wild.
Aflac disclosed a cybersecurity breach likely caused by the Scattered Spider group, targeting insurance companies across the U.S., potentially exposing sensitive personal and health information. The company responded quickly, confirming no ransomware impact and continuing normal operations, while external experts investigate the incident.
A malware campaign targeting Minecraft players involves malicious GitHub repositories masquerading as mods, delivering Java loaders that download second-stage stealers capable of exfiltrating credentials, tokens, and system information, affecting over 1,500 devices and highlighting risks in gaming communities.