📡 Tech & Security Digest — 2026-10-08
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland — On the second day of Pwn2Own Ireland 2026, security researchers collected $232,500 in cash awards after exploiting 45 unique zero-day vulnerabiliti…
- Hackers exploit critical Atlassian flaw after public PoC release — A critical vulnerability (CVE-2026-21589) affecting multiple Atlassian product families, including Jira, Confluence, and Bitbucket, is being exploited…
- ASOS links data breach to social engineering attack, credential theft — ASOS is sending updates to affected customers about the cybersecurity incident it suffered earlier this week, confirming that hackers accessed some pe…
- Ninja Forms plugin flaw exploited to hack WordPress sites — Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for W…
- PoeLLM malware infects exposed AI servers in cryptomining attacks — A cryptomining campaign targeting exposed AI services is using PoeLLM malware to turn compromised servers into scanners and exploit launchpads. […]…
- Hackers hijack Google domains after breaching ccTLD registries — Hackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains in the country-code top-level domains (ccTLDs) for Gh…
Hacker News
- OpenAI Withdraws 3 Math Papers (66 pts)
- If somebody tries to hot-patch an already-hot-patched function (61 pts)
- Claude Haiku 5.5 (931 pts)
- Port of the TypeScript compiler, checker and lsp to Rust, by LLM (77 pts)
- Meta and Microsoft take steps to reduce employee usage of Claude AI (347 pts)
Krebs on Security
- ShinyHunters Extorted Boeing Spin-off Prior to Arrests — A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group ShinyHunters has been detained and is reportedly cooper…
- Two Alleged ‘TeamPCP’ Hackers Arrested in Australia — Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrati…
- Microsoft Plugs Nearly 400 Security Holes — Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including on…
The Hacker News
- Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes — The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Know…
- New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline — Citrix has released security updates for a high-severity security flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targe…
- Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes — Cybersecurity researchers have disclosed details of a “human-operated phishing platform” that impersonates advertising products for artificial intelli…
- Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes — Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad …
- Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2 — Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK…
- Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE — A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck.
The vulnerabili…
- Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer — Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote acces…
- Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details — Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensi…
- Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users’ Mailboxes — Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escal…
- Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware — The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and ne…