Security Affairs newsletter Round 599 by Pierluigi Paganini – INTERNATIONAL EDITION

Pierluigi Paganini October 11, 2026

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.

Anthropic Restricts Live Internet Access After Claude Evaluation Failures
Silent Ransom Group Allegedly Extorted $207 Million Without Encrypting Files
US Sentences Empire Market Co-Creator Over $430 Million Criminal Marketplace
Germany Arrests Suspected Qilin Ransomware Leader After Japan Detention
Claude Helps Secure Open Source as Anthropic Offers Free Vulnerability Scanning
US Disrupts China-Linked Integrity Tech ‘s Cyber Espionage Tools
CVE-2026-107406: Citrix Fixes Critical NetScaler ADC and Gateway Vulnerability
Italy’s Foreign Ministry Under Cyberattack as Embassy Sites Come Under Review
Hunt.io Finds New Infrastructure Of BraZetsu Access Broker Months Before Disclosure
MonsterCloud Owner Charged With Secretly Paying Ransomware Demands
U.S. Offers $10 Million Reward for Alleged HAFNIUM Hacker Zhang Yu
Atlassian Vulnerability Comes Under Attack Hours After Details Go Public
SonicWall Fixes Max Severity Pre-Auth Flaw in SMA1000 Appliances
FortiBleed hit 86,000 firewalls by exploiting something nobody can patch away
CERT-UA: Fake Cloudflare Checks Deliver LunexStealer Malware
Anthropic Creates Three Tiers for Claude Cyber Access
Wikimedia Finds Unauthorized OpenAI Agent Activity on Wikipedia
CVE-2026-96940: Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely
FBI Drops Accenture Contractor After Sensitive Data Breach
Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root Access
ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure
Anthropic Mythos Found A Bug in Rejetto HFS. Attackers Are Now Exploiting It.
Denmark ’s Population Registry Breached, 8.8 Million Affected
U.S. CISA adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog
MI5 Raises Alarm Over Chinese Funding of UK Academic Research
Iranian hacker accused of draining 31TB from university inboxes extradited to the US
Another OpenAI Safety Expert Quits and Raises New AI Safety Concerns
ShinyHunters Suspect Detained in Jordan Helps FBI Track Down the Group
Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

International Press – Newsletter

Cybercrime

ShinyHunters hacker in FBI data theft detained in Jordan, cooperating with bureau, sources say  

Iranian accused of hacking American universities extradited from Montenegro 

Hackers access data of 8.8 million people in Denmark in ‘extremely serious’ breach 

ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits

Apprehended Venezuelan Tren de Aragua Leader on FBI’s 10 Most Wanted Fugitives List Appears in Nebraska Court Following Homeland Security Task Force Investigation  

Behind the Connect Button: The Fake AI Ads Campaign

Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia

Known Cybersecurity Expert and Owner of Florida Ransomware Remediation Company Charged with Defrauding Clients

Brazilian Access Broker Targeting Latin America: Mapping BraZetsu Infrastructure via TLS Certificates  

Justice Department and FBI Seize Vulnerability Scanning and Spear Phishing Tools Operated and Used by China-State Sponsored Hackers  

Germany arrests alleged core Qilin ransomware member after extradition 

Co-Creator of Dark Web Marketplace Sentenced to 40 Years in Federal Prison  

Can you really make more than $200M in six months without encrypting victims? It seems Silent Ransom Group can. (1)  

Friend of suspected FBI data thief says he warned ‘crazy’ teen not to hack bureau

ShinyHunters Extorted Boeing Spin-off Prior to Arrests     

Malware

ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure  

MALFEX – A malicious npm postinstall no advisory has caught for fourteen months  

Canto incognito: tracking the PoeLLM malware

Never Deleted, Only Re-Pointed: Inside the 17,600-Repo FakeGit Fleet That Re-Arms Overnight

The phone was compromised before the user turned it on: the rise of Midnight Mimosa      

Hacking

New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

Horizon3’s Tales from the Trenches: Anthropic’s Mythos and Rejetto HFS

OpenAI “rogue” agent activities found on Wikimedia projects  

Request, Aggregate, Bypass: How Attackers Can Evade LLM Safety Classifiers

FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts  

You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589)  

Pwn2Own Ireland 2026 – Day Three Results & Master of Pwn  

Chrome’s Response to Recent ccTLD Registry Hijacks  

Vercel Confirms KVM Zero-Day VM Escape, Awards Researcher $50,000  

Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance

Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer

Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

Intelligence and Information Warfare  

MI5 issues Espionage Alert – CGTRI 中国通用技术研究院  

Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles  

Horizon3’s Tales from the Trenches: Anthropic’s Mythos and Rejetto HFS  

The Silent Electronic Battleground Shaping the Future of Warfare

UAC-0277: ClickFix on compromised websites to spread LUNEXSTEALER          

US Offers $10 Million Reward for Chinese Hacker Accused of State-Backed Cyberattacks

The Ministry of Foreign Affairs has fended off fresh attempts at cyber-attacks on its website and national infrastructure  

Investigating unintended model actions in our evaluations and internal use 

Ukraine takes aim at Russia’s AI data infrastructure  

Cybersecurity

South Korea probes bank breaches amid suspected AI-powered attacks

Accenture contractor removed from FBI following damaging data breach, sources say  

Introducing the Anthropic Cyber Mission  

Updates to Full Disk Access in macOS  

Launching an opt-in vulnerability-finding service for open-source software     

Quantum computing and cryptocurrencies 

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



you might also like

leave a comment