Contact Zero

News & advisories

Security news and vendor advisories from the last 30 days.

Cyber exec arrested in case allegedly tied to ShinyHunters hackers
BleepingComputer · 2026-10-10

Canadian cybersecurity executive Edward Dubrovsky has been arrested in Pennsylvania in connection with alleged extortion activity that multiple reports have linked to the FBI's ongoing crackdown on the ShinyHunters hacking group. [...]

ARTEX AI, Claude agents used in cyberattacks on South Korean banks
BleepingComputer · 2026-10-10

The cyberattacks that shook the South Korean financial sector earlier this month were launched by a Chinese hacker using the ARTEX AI penetration testing suite and Claude agents. [...]

Criminal IP Introduces AITEM as the Next Evolution of Attack Surface Management
BleepingComputer · 2026-10-10

Traditional attack surface management helps organizations discover exposed assets, but visibility alone is not enough to address threats. Criminal IP introduces AITEM, an AI-powered approach that connects exposure discovery with investigation, risk prioritization, and response. [...]

Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks
BleepingComputer · 2026-10-09

Hackers are abusing legitimate Bing search-result redirects as click URLs in Google search ads to direct users to fake Claude installers that deliver ClickFix attacks. [...]

Japan confirms arrest of Russian Qilin operative, extradition to Germany
The Record · 2026-10-09

Japan’s National Police Agency confirmed the arrest and extradition to Germany of a Russian national accused of being involved in the Qilin ransomware gang.

Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto
BleepingComputer · 2026-10-09

Threat actors are exploiting one critical and one medium-severity vulnerability still unpatched in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners. [...]

FBI arrests another suspected ShinyHunters hacker after agency breach
BleepingComputer · 2026-10-09

The FBI has arrested another suspected member of the ShinyHunters extortion group believed to be involved in the recent breach of FBI systems, Director Kash Patel announced Friday. [...]

Hundreds of thousands impacted by data breach at biosensor firm iRhythm
The Record · 2026-10-09

A company known for wearable cardiac sensors, iRhythm, has begun notifying states of the impact of a data breach from the summer.

Leader of vast money mule operation that laundered cybercriminal proceeds pleads guilty
The Record · 2026-10-09

Oleg Korniev, a 42-year-old dual citizen of Ukraine and Russia, was a principal of Your Mule Cashout, or “YMCO,” which from 2007 until 2014 set up a sophisticated network of mules in the U.S. and Europe.

FBI touts another ShinyHunters arrest in response to data breach
The Record · 2026-10-09

“We will continue to work closely with our partners to disrupt what’s left of the ShinyHunters group and their associates, no matter where they operate," FBI Director Kash Patel said.

Germany arrests alleged core Qilin ransomware member after extradition
BleepingComputer · 2026-10-09

Germany has arrested a Russian national suspected of being a leading member of the Qilin ransomware group following extradition from Japan earlier this month. [...]

Belarusian hacktivists admit to 2023 breach of Russian state healthcare network
The Record · 2026-10-09

The Belarusian Cyber Partisans concurred with Russian research that they indeed spent months inside the network for the Moscow Department of Health.

How to keep AI agents within their permissions
BleepingComputer · 2026-10-09

AI agents can use valid credentials to perform actions beyond their assigned permissions, creating risks that traditional access controls may not prevent. Token Security explains how organizations can enforce agent-specific policies without sacrificing autonomy. [...]

Max severity SonicWall SMA1000 flaw now exploited in attacks
BleepingComputer · 2026-10-09 · CVE-2026-102255

Attackers are exploiting a maximum-severity vulnerability in SonicWall SMA1000 appliances (CVE-2026-102255) that was patched on Tuesday, three days ago. [...]

Man admits to running network of 15,000 money mules for cybercriminals
BleepingComputer · 2026-10-09

​A Ukrainian-Russian dual citizen has pleaded guilty to running a massive money laundering operation that laundered millions for cybercriminals worldwide. [...]

Microsoft: Outdated Windows devices will stop receiving security updates
BleepingComputer · 2026-10-09

Microsoft says devices running unsupported versions of Windows will stop receiving security updates after next year's Windows Update certificate rotation. [...]

Citrix warns admins to patch new NetScaler RCE flaw immediately
BleepingComputer · 2026-10-09

Citrix has warned IT administrators to patch systems immediately against a new critical vulnerability affecting NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions. [...]

Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland
BleepingComputer · 2026-10-09

The Pwn2Own Ireland 2026 hacking contest has concluded, with hackers collecting $1,262,000 in rewards after exploiting 98 zero-day flaws. [...]

FBI disrupts Chinese hacking tools used to breach critical infrastructure
BleepingComputer · 2026-10-08

The FBI has seized seven domains used by Chinese state-sponsored hackers known as Flax Typhoon to operate two hacking tools, MicroScan and FishHub, used in attacks that breached critical infrastructure and other organizations worldwide. [...]

Ransomware attack disrupts Japan's IDCF Cloud used by govt clients
BleepingComputer · 2026-10-08

IDC Frontier, a major Japanese cloud and digital infrastructure company, disclosed that its IDCF Cloud service was targeted in a ransomware attack that caused an outage at a data center cluster serving the eastern part of the country. [...]

Low-cost Android phones ship with residential proxy malware
BleepingComputer · 2026-10-08

A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies. [...]

FakeGit malware campaign returns with 17,610 malicious GitHub repos
BleepingComputer · 2026-10-08

More than 17,000 fake repositories on GitHub are distributing the SmartLoader malware after the FakeGit campaign reactivated earlier this month to push the StealC infostealer. [...]

Cisco warns of critical flaws allowing Nexus switch takeover
BleepingComputer · 2026-10-08

Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privileges on Nexus switches. [...]

Improper limitation of a pathname to a restricted directory
Fortinet PSIRT · 2026-10-01

CVSSv3 Score: 9.8 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.This has been reported to be exploited in the wild, customers are urged to apply the…