<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>CISO Intelligence — Signalen</title><description>Automatisch geselecteerd security-nieuws en analyses, elke twee uur ververst. Niet redactioneel beoordeeld.</description><link>https://nieuws.aegiscore.nl/</link><language>nl</language><item><title>Citrix waarschuwt voor actief misbruik van nieuw beveiligingslek</title><link>https://www.security.nl/posting/955844/Citrix+waarschuwt+voor+actief+misbruik+van+nieuw+beveiligingslek?channel=rss</link><guid isPermaLink="true">https://www.security.nl/posting/955844/Citrix+waarschuwt+voor+actief+misbruik+van+nieuw+beveiligingslek?channel=rss</guid><description>Bron: Security.nl (Prioriteit 2).

Citrix waarschuwt klanten voor actief misbruik van een nieuw beveiligingslek in Citrix NetScaler ADC en Citrix NetScaler ...</description><pubDate>Sun, 04 Oct 2026 13:58:36 GMT</pubDate></item><item><title>User Agent Strings Curiosities, (Sun, Oct 4th)</title><link>https://isc.sans.edu/diary/rss/33394</link><guid isPermaLink="true">https://isc.sans.edu/diary/rss/33394</guid><description>Bron: SANS Internet Storm Center (Prioriteit 2).

Sometimes I have to smile, or my interest is triggered, when I review new User Agent Strings in the honeypot logs.</description><pubDate>Sun, 04 Oct 2026 07:58:51 GMT</pubDate></item><item><title>ShinyHunters hacker reportedly detained in Jordan, aiding FBI</title><link>https://www.bleepingcomputer.com/news/security/shinyhunters-hacker-reportedly-detained-in-jordan-aiding-fbi/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/shinyhunters-hacker-reportedly-detained-in-jordan-aiding-fbi/</guid><description>Bron: BleepingComputer (Prioriteit 2).

A suspected ShinyHunters hacking group member known online as &quot;Rey&quot; has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members of the extortion group. [...]</description><pubDate>Sat, 03 Oct 2026 19:09:38 GMT</pubDate></item><item><title>Reuters: belangrijke hacker ShinyHunters aangehouden, werkt samen met FBI</title><link>https://nos.nl/l/2633543</link><guid isPermaLink="true">https://nos.nl/l/2633543</guid><description>Bron: NOS (Prioriteit 3).

Een prominent lid van de hackersgroep ShinyHunters is deze week in Jordanië opgepakt, melden drie ingewijden aan het internationale persbureau Reuters. Het hackerscollectief claimde eind vorige maand de gegevens van duizenden medewerkers en sollicitanten van de Amerikaanse veiligheidsdienst FBI te hebben bemachtigd . Volgens twee bronnen werkt de verdachte inmiddels samen met de FBI bij het opsporen van andere leden van de hackersgroep. Het gaat volgens de bronnen om Saif al-Din Khader, die door de Jordaanse autoriteiten zou zijn opgepakt. Twee bronnen zeggen dat hij dinsdag is aangehouden. He</description><pubDate>Sat, 03 Oct 2026 16:06:40 GMT</pubDate></item><item><title>YARA-X 1.21.0 Release, (Sat, Oct 3rd)</title><link>https://isc.sans.edu/diary/rss/33392</link><guid isPermaLink="true">https://isc.sans.edu/diary/rss/33392</guid><description>Bron: SANS Internet Storm Center (Prioriteit 2).

YARA-X&amp;&amp;#x23;x26;&amp;#x23;39;s 1.21.0 release brings 5 improvements and 4 bugfixes.</description><pubDate>Sat, 03 Oct 2026 14:40:21 GMT</pubDate></item><item><title>Danish university DTU breach exposes data of up to 200,000 people</title><link>https://www.bleepingcomputer.com/news/security/danish-university-dtu-breach-exposes-data-of-up-to-200-000-people/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/danish-university-dtu-breach-exposes-data-of-up-to-200-000-people/</guid><description>Bron: BleepingComputer (Prioriteit 2).

The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data. [...]</description><pubDate>Sat, 03 Oct 2026 14:35:20 GMT</pubDate></item><item><title>doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures</title><link>https://www.securityweek.com/doxx-net-raises-38-million-to-prevent-ai-agent-on-the-internet-misadventures/</link><guid isPermaLink="true">https://www.securityweek.com/doxx-net-raises-38-million-to-prevent-ai-agent-on-the-internet-misadventures/</guid><description>Bron: SecurityWeek (Prioriteit 2).

doxx.net’s new ADN platform prevents agentic misadventure while the agent is operating under the user’s authority. The post doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures appeared first on SecurityWeek .</description><pubDate>Sat, 03 Oct 2026 11:45:00 GMT</pubDate></item><item><title>Judge dismisses spyware case brought by Salvadoran journalists targeted with Pegasus</title><link>https://therecord.media/judge-dismisses-spyware-case-brought-by-salvadoran-journalists</link><guid isPermaLink="true">https://therecord.media/judge-dismisses-spyware-case-brought-by-salvadoran-journalists</guid><description>Bron: The Record (Recorded Future News) (Prioriteit 2).

The plaintiffs, who all worked for the independent and Salvadoran news outlet El Faro, failed to convince the court that their case had jurisdiction in California, according to the judge’s order.</description><pubDate>Fri, 02 Oct 2026 20:30:00 GMT</pubDate></item><item><title>RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail</title><link>https://www.darkreading.com/cybersecurity-operations/remotethreat-bets-security-teams-need-to-test-what-happens-after-defenses-fail</link><guid isPermaLink="true">https://www.darkreading.com/cybersecurity-operations/remotethreat-bets-security-teams-need-to-test-what-happens-after-defenses-fail</guid><description>Bron: Dark Reading (Prioriteit 2).

The offensive cyber operations startup looks to evolve red teaming beyond traditional methods to simulate attackers&apos; increasingly advanced capabilities.</description><pubDate>Fri, 02 Oct 2026 20:18:37 GMT</pubDate></item><item><title>Bipartisan backlash to ALPRs grows as two high-profile bills are introduced</title><link>https://therecord.media/alpr-legislation-hawley-sanders-merkley-aoc</link><guid isPermaLink="true">https://therecord.media/alpr-legislation-hawley-sanders-merkley-aoc</guid><description>Bron: The Record (Recorded Future News) (Prioriteit 2).

Republican Sen. Josh Hawley has new legislation on limiting automated license plate readers (ALPRs), while Democratic Sens. Bernie Sanders and Jeff Merkley, with Rep. Alexandria Ocasio-Cortez, have teed up a broader bill.</description><pubDate>Fri, 02 Oct 2026 19:30:00 GMT</pubDate></item><item><title>Frontline Education breach exposes school district employee data</title><link>https://www.bleepingcomputer.com/news/security/frontline-education-data-breach-impacts-school-district-employees/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/frontline-education-data-breach-impacts-school-district-employees/</guid><description>Bron: BleepingComputer (Prioriteit 2).

Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers. [...]</description><pubDate>Fri, 02 Oct 2026 19:01:40 GMT</pubDate></item><item><title>Warlock ransomware breach SharePoint in water, telecom operator attacks</title><link>https://www.bleepingcomputer.com/news/security/warlock-ransomware-breach-sharepoint-in-water-telecom-operator-attacks/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/warlock-ransomware-breach-sharepoint-in-water-telecom-operator-attacks/</guid><description>Bron: BleepingComputer (Prioriteit 2).

The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access. [...]</description><pubDate>Fri, 02 Oct 2026 18:33:01 GMT</pubDate></item><item><title>Bedrijven massaal gehackt, consument maakt het weinig uit: &apos;We zijn datalekmoe&apos;</title><link>https://nos.nl/l/2633445</link><guid isPermaLink="true">https://nos.nl/l/2633445</guid><description>Bron: NOS (Prioriteit 3).

De boodschap van de cybercriminelen die vorige week thuisbezorgdienst Flink hackten was helder: er moet worden betaald, anders worden alle buitgemaakte klantgegevens gepubliceerd op het dark web. Hoewel de hackers hoopten hiermee meer dan twee ton op te halen, maakte niemand de geëiste 10 tot 15 euro in cryptogeld over. Het roept de vraag op of mensen zich nog druk maken om hun persoonsgegevens die in de openbaarheid komen. Volgens cybersecurity-expert Paul Pols valt dat mee. Mensen zijn &apos;datalekmoe&apos; en dat is begrijpelijk, zegt hij. &quot;We gaan er inmiddels van uit dat onze persoonsgegevens vroe</description><pubDate>Fri, 02 Oct 2026 16:49:31 GMT</pubDate></item><item><title>SWIFT Banking &amp; Government Middleware Enables RCE</title><link>https://www.darkreading.com/cybersecurity-operations/swift-banking-govt-middleware-rce</link><guid isPermaLink="true">https://www.darkreading.com/cybersecurity-operations/swift-banking-govt-middleware-rce</guid><description>Bron: Dark Reading (Prioriteit 2).

Patch middleware vulnerabilities now to avoid hardware-based MFA exploits in ultra-sensitive environments.</description><pubDate>Fri, 02 Oct 2026 16:27:54 GMT</pubDate></item><item><title>Is Your Organization Ready for 2027&apos;s AI Accountability Era?</title><link>https://www.darkreading.com/cybersecurity-operations/is-your-organization-ready-for-2027-s-ai-accountability-era-</link><guid isPermaLink="true">https://www.darkreading.com/cybersecurity-operations/is-your-organization-ready-for-2027-s-ai-accountability-era-</guid><description>Bron: Dark Reading (Prioriteit 2).

Organizations may face an artificial intelligence (AI) reckoning over the next year. Omdia and Gartner weigh in on how to tackle the governance, security, and value challenges ahead.</description><pubDate>Fri, 02 Oct 2026 16:01:22 GMT</pubDate></item><item><title>Is It Fair to Blame &apos;Rogue&apos; AI for Security Failures?</title><link>https://www.darkreading.com/insider-threats/blame-rogue-ai-security-failures</link><guid isPermaLink="true">https://www.darkreading.com/insider-threats/blame-rogue-ai-security-failures</guid><description>Bron: Dark Reading (Prioriteit 2).

&quot;Rogue AI&quot; terminology anthropomorphizes LLMs and shifts risk responsibility from vendors. Defenders should treat agents as untrusted, nondeterministic software systems, not sentient beings with malicious intent.</description><pubDate>Fri, 02 Oct 2026 15:51:33 GMT</pubDate></item><item><title>US sanctions Tren de Aragua gang members in ATM hacks crackdown</title><link>https://www.bleepingcomputer.com/news/security/us-sanctions-tren-de-aragua-members-in-atm-jackpotting-crackdown/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/us-sanctions-tren-de-aragua-members-in-atm-jackpotting-crackdown/</guid><description>Bron: BleepingComputer (Prioriteit 2).

The U.S. Treasury Department has sanctioned eight members of the Venezuelan gang Tren de Aragua (TdA) for their role in the theft of millions of dollars in ATM jackpotting attacks across the United States. [...]</description><pubDate>Fri, 02 Oct 2026 15:20:53 GMT</pubDate></item><item><title>Cyber Brief 26-10 - September 2026</title><link>https://cert.europa.eu/publications/threat-intelligence/cb26-10/</link><guid isPermaLink="true">https://cert.europa.eu/publications/threat-intelligence/cb26-10/</guid><description>Bron: CERT-EU (Prioriteit 1).

Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.</description><pubDate>Fri, 02 Oct 2026 15:00:00 GMT</pubDate></item><item><title>In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats</title><link>https://www.securityweek.com/in-other-news-15k-icloud-spoofing-bugs-ai-policy-experts-phished-adblocker-spies-on-ai-chats/</link><guid isPermaLink="true">https://www.securityweek.com/in-other-news-15k-icloud-spoofing-bugs-ai-policy-experts-phished-adblocker-spies-on-ai-chats/</guid><description>Bron: SecurityWeek (Prioriteit 2).

Noteworthy stories that might have slipped under the radar: Kiteworks patches over 100 vulnerabilities, Microsoft publishes 2026 Digital Defense Report, AI finds 24 Android app flaws. The post In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats appeared first on SecurityWeek .</description><pubDate>Fri, 02 Oct 2026 14:30:00 GMT</pubDate></item><item><title>Mississippi mayor says ransomware incident led city to shut down systems</title><link>https://therecord.media/vicksburg-mississippi-government-ransomware-attack</link><guid isPermaLink="true">https://therecord.media/vicksburg-mississippi-government-ransomware-attack</guid><description>Bron: The Record (Recorded Future News) (Prioriteit 2).

Government services were temporarily disrupted by ransomware in Vicksburg, Mississippi. Mayor Willis Thompson said the FBI and other authorities are investigating.</description><pubDate>Fri, 02 Oct 2026 14:06:00 GMT</pubDate></item><item><title>&apos;Warlock&apos; ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries</title><link>https://therecord.media/warlock-ransomware-used-in-critical-infrastructure-attacks</link><guid isPermaLink="true">https://therecord.media/warlock-ransomware-used-in-critical-infrastructure-attacks</guid><description>Bron: The Record (Recorded Future News) (Prioriteit 2).

The group is exploiting a variety of vulnerabilities impacting Microsoft SharePoint, according to a new report from Symantec Threat Hunter Team.</description><pubDate>Fri, 02 Oct 2026 14:05:00 GMT</pubDate></item><item><title>macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor</title><link>https://www.securityweek.com/macos-users-targeted-by-fake-zoom-installer-carrying-cloudsyncd-backdoor/</link><guid isPermaLink="true">https://www.securityweek.com/macos-users-targeted-by-fake-zoom-installer-carrying-cloudsyncd-backdoor/</guid><description>Bron: SecurityWeek (Prioriteit 2).

The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime. The post macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor appeared first on SecurityWeek .</description><pubDate>Fri, 02 Oct 2026 13:15:00 GMT</pubDate></item><item><title>Malicious Linux Implants Mimic Asian Mail Security Products</title><link>https://www.darkreading.com/threat-intelligence/malicious-linux-implants-mimic-asian-mail-security</link><guid isPermaLink="true">https://www.darkreading.com/threat-intelligence/malicious-linux-implants-mimic-asian-mail-security</guid><description>Bron: Dark Reading (Prioriteit 2).

A trio of newly discovered backdoors walk and quack like legitimate edge solutions, so it&apos;s hard to tell they&apos;re not.</description><pubDate>Fri, 02 Oct 2026 13:00:00 GMT</pubDate></item><item><title>Finse organisaties gehackt via Citrix-lekken meldt Finse overheid</title><link>https://www.security.nl/posting/955656/Finse+organisaties+gehackt+via+Citrix-lekken+meldt+Finse+overheid?channel=rss</link><guid isPermaLink="true">https://www.security.nl/posting/955656/Finse+organisaties+gehackt+via+Citrix-lekken+meldt+Finse+overheid?channel=rss</guid><description>Bron: Security.nl (Prioriteit 2).

Meerdere organisaties in Finland zijn via kwetsbaarheden in Citrix NetScaler gehackt, zo heeft de Finse overheid gisterenavond ...</description><pubDate>Fri, 02 Oct 2026 12:47:00 GMT</pubDate></item><item><title>AI is giving attackers a head start, Microsoft warns</title><link>https://www.helpnetsecurity.com/2026/10/02/ai-cybersecurity-threats-microsoft-report/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/10/02/ai-cybersecurity-threats-microsoft-report/</guid><description>Bron: Help Net Security (Prioriteit 2).

Threat actors are using AI to find bugs, build malware and run intrusions faster than defenders can keep up. Microsoft’s 2026 Digital Defense Report, covering July 2025 to June 2026, describes a near-term period in which attackers collect the benefits of AI first and defenders have to move quickly to close the gap. “AI is changing the physics of cybersecurity,” the company said. Bugs found faster than they get fixed Vulnerability discovery and weaponization once … More → The post AI is giving attackers a head start, Microsoft warns appeared first on Help Net Security .</description><pubDate>Fri, 02 Oct 2026 12:47:00 GMT</pubDate></item><item><title>Crypto Scammers Hijack Microsoft’s Official X Account</title><link>https://www.securityweek.com/crypto-scammers-hijack-microsofts-official-x-account/</link><guid isPermaLink="true">https://www.securityweek.com/crypto-scammers-hijack-microsofts-official-x-account/</guid><description>Bron: SecurityWeek (Prioriteit 2).

Hackers used the account, which has 13 million followers, to amplify a Clippy-themed cryptocurrency account. The post Crypto Scammers Hijack Microsoft’s Official X Account appeared first on SecurityWeek .</description><pubDate>Fri, 02 Oct 2026 11:46:10 GMT</pubDate></item><item><title>In Rare Move, Alleged Iranian State Hacker Extradited to US</title><link>https://www.securityweek.com/in-rare-move-iranian-hacker-accused-of-working-for-irgc-extradited-to-us/</link><guid isPermaLink="true">https://www.securityweek.com/in-rare-move-iranian-hacker-accused-of-working-for-irgc-extradited-to-us/</guid><description>Bron: SecurityWeek (Prioriteit 2).

Amir Barati, an alleged member of the Mabna Institute, was indicted for targeting universities, private organizations, and government entities in the US and abroad. The post In Rare Move, Alleged Iranian State Hacker Extradited to US appeared first on SecurityWeek .</description><pubDate>Fri, 02 Oct 2026 11:14:34 GMT</pubDate></item><item><title>Debian waarschuwt voor ruim 1300 beveiligingslekken in Linux-kernel</title><link>https://www.security.nl/posting/955618/Debian+waarschuwt+voor+ruim+1300+beveiligingslekken+in+Linux-kernel?channel=rss</link><guid isPermaLink="true">https://www.security.nl/posting/955618/Debian+waarschuwt+voor+ruim+1300+beveiligingslekken+in+Linux-kernel?channel=rss</guid><description>Bron: Security.nl (Prioriteit 2).

Linux-distributie Debian waarschuwt gebruikers voor ruim dertienhonderd beveiligingslekken in de Linux-kernel en roept ...</description><pubDate>Fri, 02 Oct 2026 11:13:06 GMT</pubDate></item><item><title>Chinese spies impersonate White House, Anthropic figures to phish AI policy experts</title><link>https://www.helpnetsecurity.com/2026/10/02/china-aligned-ta419-phishing-ai-policy-experts/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/10/02/china-aligned-ta419-phishing-ai-policy-experts/</guid><description>Bron: Help Net Security (Prioriteit 2).

A China-aligned espionage group has been posing as a former White House official and a prominent economist to get into the cloud accounts of AI policy experts in the US, Proofpoint have found. The group, which the researchers track as TA419, ran several credential phishing campaigns in July 2026. “In July 2026, TA419 impersonated multiple individuals, including a former member of the White House Office of Science and Technology Policy leadership team, in credential phishing … More → The post Chinese spies impersonate White House, Anthropic figures to phish AI policy experts appeared first on H</description><pubDate>Fri, 02 Oct 2026 10:21:55 GMT</pubDate></item><item><title>Officieel X-account Microsoft gehackt en gebruikt voor cryptoscam</title><link>https://www.security.nl/posting/955609/Officieel+X-account+Microsoft+gehackt+en+gebruikt+voor+cryptoscam?channel=rss</link><guid isPermaLink="true">https://www.security.nl/posting/955609/Officieel+X-account+Microsoft+gehackt+en+gebruikt+voor+cryptoscam?channel=rss</guid><description>Bron: Security.nl (Prioriteit 2).

Aanvallers zijn erin geslaagd om het officiële X-account van Microsoft te hacken en vervolgens te gebruiken voor een ...</description><pubDate>Fri, 02 Oct 2026 09:58:00 GMT</pubDate></item><item><title>Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks</title><link>https://www.securityweek.com/warlock-expands-sharepoint-exploitation-in-critical-infrastructure-attacks/</link><guid isPermaLink="true">https://www.securityweek.com/warlock-expands-sharepoint-exploitation-in-critical-infrastructure-attacks/</guid><description>Bron: SecurityWeek (Prioriteit 2).

The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025. The post Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks appeared first on SecurityWeek .</description><pubDate>Fri, 02 Oct 2026 09:34:41 GMT</pubDate></item><item><title>Microsoft’s X account hacked in crypto pump-and-dump scheme</title><link>https://www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-in-crypto-token-pump-and-dump-scheme/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-in-crypto-token-pump-and-dump-scheme/</guid><description>Bron: BleepingComputer (Prioriteit 2).

On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token. [...]</description><pubDate>Fri, 02 Oct 2026 09:29:56 GMT</pubDate></item><item><title>AI Agents Aimed SQL Injection at US and Canadian Government Sites</title><link>https://www.securityweek.com/ai-agents-aimed-sql-injection-at-us-and-canadian-government-sites/</link><guid isPermaLink="true">https://www.securityweek.com/ai-agents-aimed-sql-injection-at-us-and-canadian-government-sites/</guid><description>Bron: SecurityWeek (Prioriteit 2).

The attacks targeted the US Department of Education and Library and Archives Canada, and researchers linked some agents to OpenAI. The post AI Agents Aimed SQL Injection at US and Canadian Government Sites appeared first on SecurityWeek .</description><pubDate>Fri, 02 Oct 2026 08:38:46 GMT</pubDate></item><item><title>Criminal recruiters want people on your payroll</title><link>https://www.helpnetsecurity.com/2026/10/02/intel-471-insider-threat-recruitment-report/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/10/02/intel-471-insider-threat-recruitment-report/</guid><description>Bron: Help Net Security (Prioriteit 2).

Legitimate employee access can let criminals circumvent security controls that would be difficult to overcome from outside an organization. Routine actions such as information lookups, account resets, transaction approvals and shipment changes can become services sold to criminal customers, according to Intel 471’s Insiders for Hire: Underground Recruitment, Access Claims and Insider-Enabled Services report. A market for insider capabilities Cybercriminals sought employees at specific organizations, offered payments to brokers and referrers to find suitable personnel, … More → The post Crimina</description><pubDate>Fri, 02 Oct 2026 06:00:05 GMT</pubDate></item><item><title>Android 17 makes it harder for spyware to cover its tracks</title><link>https://www.helpnetsecurity.com/2026/10/02/android-17-advanced-protection-features/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/10/02/android-17-advanced-protection-features/</guid><description>Bron: Help Net Security (Prioriteit 2).

When a journalist suspects their phone has been hacked, the first question is whether any trace of the attack is left. Google has added six features to Advanced Protection in Android 17, including one that keeps a copy of that evidence off the device. Existing users will receive a notification when the new capabilities become available on their devices. Forensic logging and data retention Intrusion Logging records security and network events, including app activity. Users … More → The post Android 17 makes it harder for spyware to cover its tracks appeared first on Help Net Security .</description><pubDate>Fri, 02 Oct 2026 05:30:37 GMT</pubDate></item><item><title>Botnets, adversarial attacks and data poisoning top leaders’ AI threat list</title><link>https://www.helpnetsecurity.com/2026/10/02/pwc-attacks-on-ai-systems/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/10/02/pwc-attacks-on-ai-systems/</guid><description>Bron: Help Net Security (Prioriteit 2).

Companies are putting more money into AI while naming attacks on AI systems as the threat they are least ready to face. PwC surveyed 3,934 business and technology leaders in 71 countries between May and July 2026. Half of the security and technology executives among them ranked such attacks in their top five preparedness gaps, ahead of every other threat on the list. More than half of the leaders asked about AI-enabled attacks put three … More → The post Botnets, adversarial attacks and data poisoning top leaders’ AI threat list appeared first on Help Net Security .</description><pubDate>Fri, 02 Oct 2026 05:00:28 GMT</pubDate></item><item><title>AI agents keep access to company data after their work is done</title><link>https://www.helpnetsecurity.com/2026/10/02/delinea-ai-policy-adoption-enforcement-report/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/10/02/delinea-ai-policy-adoption-enforcement-report/</guid><description>Bron: Help Net Security (Prioriteit 2).

IT teams responsible for identity security are concerned about AI agents’ ongoing access to company systems and the actions they take on users’ behalf, according to a Delinea’s 2026 Identity Security Report: The AI Enforcement Gap. “Written policy is only as good as your ability to enforce it at the moment an AI agent acts,” said Art Gilliland, CEO of Delinea. “Our research echoes what I hear from leaders constantly: they have the AI policies … More → The post AI agents keep access to company data after their work is done appeared first on Help Net Security .</description><pubDate>Fri, 02 Oct 2026 04:30:21 GMT</pubDate></item><item><title>New infosec products of the week: October 2, 2026</title><link>https://www.helpnetsecurity.com/2026/10/02/new-infosec-products-of-the-week-october-2-2026/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/10/02/new-infosec-products-of-the-week-october-2-2026/</guid><description>Bron: Help Net Security (Prioriteit 2).

Here’s a look at the most interesting products from the past week, featuring releases from BlackFog, Genea, Vega, and Thales. Vega II brings security-trained AI and lasting memory to the SOC Vega has introduced Vega II, its biggest platform release since emerging from stealth. The update brings frontier AI trained for security operations into the SOC, gives teams a lasting record of what they have learned, and removes the legacy SIEM and data pipeline barriers … More → The post New infosec products of the week: October 2, 2026 appeared first on Help Net Security .</description><pubDate>Fri, 02 Oct 2026 04:00:35 GMT</pubDate></item><item><title>Authorities dismantle KillSec group</title><link>https://risky.biz/RBNEWS618/</link><guid isPermaLink="true">https://risky.biz/RBNEWS618/</guid><description>Bron: Risky Business News (Prioriteit 2).

Authorities dismantle the KillSec hacking group, South Africa thwarts a ransomware attack against air traffic control systems, the US sanctions Venezuelan ATM hackers and a Chinese APT targets AI experts. Show notes Risky Bulletin: Authorities dismantle KillSec group, arrest members across Europe</description><pubDate>Fri, 02 Oct 2026 02:57:07 GMT</pubDate></item><item><title>ISC Stormcast For Friday, October 2nd, 2026 https://isc.sans.edu/podcastdetail/10120, (Fri, Oct 2nd)</title><link>https://isc.sans.edu/diary/rss/33390</link><guid isPermaLink="true">https://isc.sans.edu/diary/rss/33390</guid><description>Bron: SANS Internet Storm Center (Prioriteit 2).

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.</description><pubDate>Fri, 02 Oct 2026 02:00:02 GMT</pubDate></item><item><title>Alleged KillSec Ransomware Mastermind a 16-Year-Old</title><link>https://www.darkreading.com/cyberattacks-data-breaches/killsec-ransomware-mastermind-16-year-old</link><guid isPermaLink="true">https://www.darkreading.com/cyberattacks-data-breaches/killsec-ransomware-mastermind-16-year-old</guid><description>Bron: Dark Reading (Prioriteit 2).

Law enforcement from multiple countries collaborated to disrupt a cybercrime operation that has claimed some 500 victims worldwide in the past two years.</description><pubDate>Thu, 01 Oct 2026 21:37:50 GMT</pubDate></item><item><title>Autonomous AI agents tried to hack US, Canadian government websites</title><link>https://www.bleepingcomputer.com/news/security/autonomous-ai-agents-tried-to-hack-us-canadian-government-websites/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/autonomous-ai-agents-tried-to-hack-us-canadian-government-websites/</guid><description>Bron: BleepingComputer (Prioriteit 2).

Autonomous AI agents using aggressive strategies attempted to hack U.S. and Canadian government websites to find school and divorce statistics. [...]</description><pubDate>Thu, 01 Oct 2026 20:52:50 GMT</pubDate></item><item><title>Iranian accused of hacking American universities extradited from Montenegro</title><link>https://therecord.media/iran-montenegro-hacker-extradition</link><guid isPermaLink="true">https://therecord.media/iran-montenegro-hacker-extradition</guid><description>Bron: The Record (Recorded Future News) (Prioriteit 2).

An Iranian national accused by the U.S. of taking part in dozens of breaches involving the theft of academic data and intellectual property has been extradited from Montenegro.</description><pubDate>Thu, 01 Oct 2026 20:15:00 GMT</pubDate></item><item><title>Microsoft says threat actors are ahead in the early AI race</title><link>https://www.bleepingcomputer.com/news/security/microsoft-says-threat-actors-are-ahead-in-the-early-ai-race/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/microsoft-says-threat-actors-are-ahead-in-the-early-ai-race/</guid><description>Bron: BleepingComputer (Prioriteit 2).

Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace. [...]</description><pubDate>Thu, 01 Oct 2026 19:32:47 GMT</pubDate></item><item><title>OpenAI software attempted to secretly scrape data from dozens of prominent websites</title><link>https://therecord.media/openai-software-attempted-to-secretly-scrape-data-from-dozens-of-websites</link><guid isPermaLink="true">https://therecord.media/openai-software-attempted-to-secretly-scrape-data-from-dozens-of-websites</guid><description>Bron: The Record (Recorded Future News) (Prioriteit 2).

The findings, released Thursday by Asymmetric Security, are just the latest example of rogue behavior spurred by OpenAI’s software.</description><pubDate>Thu, 01 Oct 2026 19:25:00 GMT</pubDate></item><item><title>Researchers find Chinese hacking campaigns targeting AI firms, Asian governments</title><link>https://therecord.media/china-linked-phishing-scheme-backdoor-taiwan</link><guid isPermaLink="true">https://therecord.media/china-linked-phishing-scheme-backdoor-taiwan</guid><description>Bron: The Record (Recorded Future News) (Prioriteit 2).

Two separate reports by cybersecurity companies highlight China-linked hacking operations, including a phishing campaign that impersonated Western experts.</description><pubDate>Thu, 01 Oct 2026 18:16:00 GMT</pubDate></item><item><title>Give yourself room to be human</title><link>https://blog.talosintelligence.com/give-yourself-room-to-be-human/</link><guid isPermaLink="true">https://blog.talosintelligence.com/give-yourself-room-to-be-human/</guid><description>Bron: Cisco Talos (Prioriteit 1).

In this week’s edition, Amy reflects on the importance of prioritizing family and personal well-being over the pressure to remain constantly productive.</description><pubDate>Thu, 01 Oct 2026 18:00:52 GMT</pubDate></item><item><title>Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks</title><link>https://www.securityweek.com/zero-trust-creator-says-model-holds-firm-against-ai-assisted-attacks/</link><guid isPermaLink="true">https://www.securityweek.com/zero-trust-creator-says-model-holds-firm-against-ai-assisted-attacks/</guid><description>Bron: SecurityWeek (Prioriteit 2).

Fifteen years after coining the framework, John Kindervag insists zero trust still works in the AI era—if you get the implementation right. The post Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks appeared first on SecurityWeek .</description><pubDate>Thu, 01 Oct 2026 18:00:00 GMT</pubDate></item><item><title>Osavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical Domains</title><link>https://www.securityweek.com/osavul-lands-10-million-to-spot-hostile-intent-across-cyber-physical-domains/</link><guid isPermaLink="true">https://www.securityweek.com/osavul-lands-10-million-to-spot-hostile-intent-across-cyber-physical-domains/</guid><description>Bron: SecurityWeek (Prioriteit 2).

Hybrid risk intelligence company Osavul has raised $10 million in a Series A funding round led by 33N Ventures. The post Osavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical Domains appeared first on SecurityWeek .</description><pubDate>Thu, 01 Oct 2026 17:16:41 GMT</pubDate></item><item><title>Police disrupt KillSec ransomware, arrest suspected teenage leader</title><link>https://therecord.media/killsec-ransomware-raas-arrests-europe</link><guid isPermaLink="true">https://therecord.media/killsec-ransomware-raas-arrests-europe</guid><description>Bron: The Record (Recorded Future News) (Prioriteit 2).

European police said raids against the KillSec ransomware-as-a-service operation included the arrest of a high-profile teen suspect.</description><pubDate>Thu, 01 Oct 2026 15:55:00 GMT</pubDate></item><item><title>Amnesty beschuldigt Marokko van spyware-aanvallen via telecomprovider</title><link>https://www.security.nl/posting/955534/Amnesty+beschuldigt+Marokko+van+spyware-aanvallen+via+telecomprovider?channel=rss</link><guid isPermaLink="true">https://www.security.nl/posting/955534/Amnesty+beschuldigt+Marokko+van+spyware-aanvallen+via+telecomprovider?channel=rss</guid><description>Bron: Security.nl (Prioriteit 2).

De Marokkaanse autoriteiten hebben spyware-aanvallen uitgevoerd tegen activisten, journalisten en andere critici, waarbij ...</description><pubDate>Thu, 01 Oct 2026 15:20:29 GMT</pubDate></item><item><title>Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass</title><link>https://www.securityweek.com/hacker-conversations-rob-juncker-a-knock-at-the-door-and-a-moral-compass/</link><guid isPermaLink="true">https://www.securityweek.com/hacker-conversations-rob-juncker-a-knock-at-the-door-and-a-moral-compass/</guid><description>Bron: SecurityWeek (Prioriteit 2).

Rob Juncker is chief product and technology officer at Mimecast. Is he a hacker? “Unequivocally yes,” he says. The post Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass appeared first on SecurityWeek .</description><pubDate>Thu, 01 Oct 2026 14:30:00 GMT</pubDate></item><item><title>Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says</title><link>https://www.securityweek.com/enterprises-struggle-to-prepare-for-ai-and-quantum-threats-pwc-says/</link><guid isPermaLink="true">https://www.securityweek.com/enterprises-struggle-to-prepare-for-ai-and-quantum-threats-pwc-says/</guid><description>Bron: SecurityWeek (Prioriteit 2).

PwC’s survey found that only 22% of leaders would use fully autonomous AI for cyber defense, while just 21% are implementing quantum-resistant security measures. The post Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says appeared first on SecurityWeek .</description><pubDate>Thu, 01 Oct 2026 14:30:00 GMT</pubDate></item><item><title>Police dismantle KillSec ransomware gang allegedly led by 16-year-old</title><link>https://www.bleepingcomputer.com/news/security/police-dismantle-killsec-ransomware-gang-allegedly-led-by-16-year-old/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/police-dismantle-killsec-ransomware-gang-allegedly-led-by-16-year-old/</guid><description>Bron: BleepingComputer (Prioriteit 2).

An international law enforcement operation dubbed &quot;Operation KillSwitch&quot; seized the KillSec ransomware gang&apos;s data leak site and servers, led to three arrests, and identified a 16-year-old as the group&apos;s alleged administrator. [...]</description><pubDate>Thu, 01 Oct 2026 14:25:14 GMT</pubDate></item><item><title>Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader</title><link>https://www.securityweek.com/police-shut-down-killsec-ransomware-identify-alleged-teen-leader/</link><guid isPermaLink="true">https://www.securityweek.com/police-shut-down-killsec-ransomware-identify-alleged-teen-leader/</guid><description>Bron: SecurityWeek (Prioriteit 2).

Police took control of KillSec’s leak site and secured at least 110 terabytes of data stolen from victims. The post Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader appeared first on SecurityWeek .</description><pubDate>Thu, 01 Oct 2026 14:17:07 GMT</pubDate></item><item><title>The Day-One Hole in Zero Trust Architecture</title><link>https://www.bleepingcomputer.com/news/security/the-day-one-hole-in-zero-trust-architecture/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/the-day-one-hole-in-zero-trust-architecture/</guid><description>Bron: BleepingComputer (Prioriteit 2).

Zero Trust can verify users once they are established, but onboarding creates a gap where organizations must decide who to trust before strong authentication exists. Specops explains why identity verification should begin before credentials, MFA methods, and access are issued. [...]</description><pubDate>Thu, 01 Oct 2026 14:01:11 GMT</pubDate></item><item><title>Preparing governments for an era of interconnected cyber risk</title><link>https://blogs.microsoft.com/on-the-issues/2026/10/01/preparing-governments-for-an-era-of-interconnected-cyber-risk/</link><guid isPermaLink="true">https://blogs.microsoft.com/on-the-issues/2026/10/01/preparing-governments-for-an-era-of-interconnected-cyber-risk/</guid><description>Bron: Microsoft Security Blog (Prioriteit 1).

According to this year’s Microsoft Digital Defense Report, government agencies and services were the sector most impacted by cyber threats in 2026, accounting for 27% of observed activity, up from 17% in 2025. The post Preparing governments for an era of interconnected cyber risk appeared first on Microsoft Security Blog .</description><pubDate>Thu, 01 Oct 2026 14:00:00 GMT</pubDate></item><item><title>Insights from the 2026 Microsoft Digital Defense Report</title><link>https://www.microsoft.com/en-us/security/blog/2026/10/01/insights-from-the-2026-microsoft-digital-defense-report/</link><guid isPermaLink="true">https://www.microsoft.com/en-us/security/blog/2026/10/01/insights-from-the-2026-microsoft-digital-defense-report/</guid><description>Bron: Microsoft Security Blog (Prioriteit 1).

Read highlights from the 2026 Microsoft Digital Defense Report, which reflects a security environment that continues to grow more interconnected. The post Insights from the 2026 Microsoft Digital Defense Report appeared first on Microsoft Security Blog .</description><pubDate>Thu, 01 Oct 2026 14:00:00 GMT</pubDate></item><item><title>16-year-old suspected leader of KillSec ransomware group arrested</title><link>https://www.helpnetsecurity.com/2026/10/01/killsec-ransomware-16-year-old-main-operator-arrested/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/10/01/killsec-ransomware-16-year-old-main-operator-arrested/</guid><description>Bron: Help Net Security (Prioriteit 2).

A 16-year-old is suspected of being the main operator of KillSec, a ransomware group that Eurojust says is responsible for almost 1,000 attacks worldwide. Seizure notice (Source: Eurojust) According to Eurojust, KillSec has been active since 2024. The group got into organizations’ systems by exploiting poorly secured access, particularly access linked to cloud storage. “Once inside, the KillSec group stole data and copied it to their own infrastructure. They then threatened to make the stolen … More → The post 16-year-old suspected leader of KillSec ransomware group arrested appeared first on </description><pubDate>Thu, 01 Oct 2026 13:59:02 GMT</pubDate></item><item><title>DeepKeep’s AI Lens flags coding agent data leaks and routes destructive commands for approval</title><link>https://www.helpnetsecurity.com/2026/10/01/deepkeeps-ai-lens-flags-coding-agent-data-leaks-and-routes-destructive-commands-for-approval/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/10/01/deepkeeps-ai-lens-flags-coding-agent-data-leaks-and-routes-destructive-commands-for-approval/</guid><description>Bron: Help Net Security (Prioriteit 2).

DeepKeep has announced AI Lens for Developers, a new extension to the company’s AI usage control and runtime protection modules to secure software developers and their coding agents that can write, modify, and execute code on their behalf. The capability gives security teams policy enforcement, audit visibility, and runtime security over coding agents such as Cursor and Claude Code, closing a critical gap most security programs have ever had to cover before. 90% of developers … More → The post DeepKeep’s AI Lens flags coding agent data leaks and routes destructive commands for approval appeare</description><pubDate>Thu, 01 Oct 2026 13:57:07 GMT</pubDate></item><item><title>Exabeam brings AI-assisted security investigations to data that must stay on-premises</title><link>https://www.helpnetsecurity.com/2026/10/01/exabeam-agentic-soc/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/10/01/exabeam-agentic-soc/</guid><description>Bron: Help Net Security (Prioriteit 2).

Exabeam has introduced a new wave of capabilities that bring the Agentic SOC to life in the cloud and on-premises environments, combining AI-driven investigation, execution, and governance. Analyst workflows alone can’t keep pace with machine-speed threats or the growing complexity of goal-driven AI agents and autonomous workflows. The future of the SOC is agentic. For more than a decade, Exabeam has built applied machine learning into security operations, beginning with its pioneering work in user … More → The post Exabeam brings AI-assisted security investigations to data that must stay on-p</description><pubDate>Thu, 01 Oct 2026 13:50:04 GMT</pubDate></item><item><title>Warning: Critical Cisco Catalyst SD-WAN Manager authentication bypass grants admin API access. Actively exploited, Patch Immediately!</title><link>https://ccb.belgium.be/advisories/warning-critical-cisco-catalyst-sd-wan-manager-authentication-bypass-grants-admin-api</link><guid isPermaLink="true">https://ccb.belgium.be/advisories/warning-critical-cisco-catalyst-sd-wan-manager-authentication-bypass-grants-admin-api</guid><description>Bron: CCB (Centre for Cybersecurity Belgium) (Prioriteit 1).

CCB Advisories</description><pubDate>Thu, 01 Oct 2026 13:42:09 GMT</pubDate></item><item><title>RadarFirst helps teams investigate AI bias, data exposure and unintended actions</title><link>https://www.helpnetsecurity.com/2026/10/01/radarfirst-ai-incident-management/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/10/01/radarfirst-ai-incident-management/</guid><description>Bron: Help Net Security (Prioriteit 2).

RadarFirst has announced the general availability of Radar AI Incident Management, a purpose-built solution that helps organizations investigate, manage, and document AI-related incidents. As organizations deploy AI across customer experiences, employee workflows, business operations, and decision-making processes, adverse events can create risks that span privacy, security, legal, compliance, and product teams. Harmful outputs, biased outcomes, sensitive data exposure, unexpected AI actions, and policy failures can quickly require a coordinated response. Radar AI Incident Management provides </description><pubDate>Thu, 01 Oct 2026 13:39:15 GMT</pubDate></item><item><title>Sophos uses agentic AI to show businesses which security fixes deserve funding</title><link>https://www.helpnetsecurity.com/2026/10/01/sophos-ciso-advantage/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/10/01/sophos-ciso-advantage/</guid><description>Bron: Help Net Security (Prioriteit 2).

Sophos has launched Sophos CISO Advantage, an agentic AI-enabled solution that connects security operations to security strategy. The solution gives organizations a picture of their cyber risk, a prioritized plan to reduce it, and measurable proof of progress, in plain language that business leaders can understand, fund, and act on. Sophos CISO Advantage defines a new category in the market, turning security data into strategy and measurable improvement, driven by agentic AI. The offering assesses … More → The post Sophos uses agentic AI to show businesses which security fixes deserve funding </description><pubDate>Thu, 01 Oct 2026 13:25:12 GMT</pubDate></item><item><title>Politie vindt 110 terabyte aan gestolen data op servers ransomwaregroep KillSec</title><link>https://www.security.nl/posting/955511/Politie+vindt+110+terabyte+aan+gestolen+data+op+servers+ransomwaregroep+KillSec?channel=rss</link><guid isPermaLink="true">https://www.security.nl/posting/955511/Politie+vindt+110+terabyte+aan+gestolen+data+op+servers+ransomwaregroep+KillSec?channel=rss</guid><description>Bron: Security.nl (Prioriteit 2).

Tijdens een internationale politieoperatie tegen ransomwaregroep KillSec hebben autoriteiten op servers van de criminelen 110 ...</description><pubDate>Thu, 01 Oct 2026 13:20:04 GMT</pubDate></item><item><title>AI Has Changed Attack Speed, Not Security Fundamentals</title><link>https://www.securityweek.com/ai-has-changed-attack-speed-not-security-fundamentals/</link><guid isPermaLink="true">https://www.securityweek.com/ai-has-changed-attack-speed-not-security-fundamentals/</guid><description>Bron: SecurityWeek (Prioriteit 2).

As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. The post AI Has Changed Attack Speed, Not Security Fundamentals appeared first on SecurityWeek .</description><pubDate>Thu, 01 Oct 2026 13:15:00 GMT</pubDate></item><item><title>Warlock Ransomware Hits Large Spanish, Portuguese Orgs</title><link>https://www.darkreading.com/cyberattacks-data-breaches/warlock-ransomware-spanish-portuguese</link><guid isPermaLink="true">https://www.darkreading.com/cyberattacks-data-breaches/warlock-ransomware-spanish-portuguese</guid><description>Bron: Dark Reading (Prioriteit 2).

A year-old Chinese threat actor looks like a cybercrime gang, acts like a state-associated APT, and attacks organizations in unexpected places.</description><pubDate>Thu, 01 Oct 2026 13:00:00 GMT</pubDate></item><item><title>Cyberattack on major Polish invoicing platform exposes customer data</title><link>https://therecord.media/poland-cyberattack-invoice-software</link><guid isPermaLink="true">https://therecord.media/poland-cyberattack-invoice-software</guid><description>Bron: The Record (Recorded Future News) (Prioriteit 2).

One of Poland’s major online invoicing platforms suffered a data breach that may have exposed information belonging to its users, their customers and business partners.</description><pubDate>Thu, 01 Oct 2026 12:30:00 GMT</pubDate></item><item><title>Pentagon breach exposes personal data of more than 3 million people</title><link>https://www.helpnetsecurity.com/2026/10/01/pentagon-dmdc-data-breach-3-million-people/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/10/01/pentagon-dmdc-data-breach-3-million-people/</guid><description>Bron: Help Net Security (Prioriteit 2).

The Pentagon’s Defense Manpower Data Center (DMDC) is notifying millions of people that hackers gained access to their personal data. The breach affects 2.76 million living individuals, a group that can include current and former defense personnel and their dependents, along with 294,000 deceased individuals, a Defense Department official told CNN. Established in 1974, DMDC serves as a central hub for US Department of Defense data on military personnel, service status and benefits eligibility. According … More → The post Pentagon breach exposes personal data of more than 3 million people appea</description><pubDate>Thu, 01 Oct 2026 12:21:03 GMT</pubDate></item><item><title>Securing Water and Wastewater Operational Technology Environments</title><link>https://www.nist.gov/blogs/cybersecurity-insights/securing-water-and-wastewater-operational-technology-environments</link><guid isPermaLink="true">https://www.nist.gov/blogs/cybersecurity-insights/securing-water-and-wastewater-operational-technology-environments</guid><description>Bron: NIST Cybersecurity (Prioriteit 1).

Recent cyberattacks on the U.S. water and wastewater systems (WWS) sector are highlighting the escalating threat to our nation’s critical infrastructure and the practical challenges of securing it. These incidents underscore an important challenge: the connectivity that utilities depend upon must be designed and operated with security as a core priority rather than a secondary consideration. They also provide a critical insight — that effective cybersecurity protections require a broad-based understanding and management of risks across people, processes, and technologies throughout the</description><pubDate>Thu, 01 Oct 2026 12:00:00 GMT</pubDate></item><item><title>Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation</title><link>https://www.securityweek.com/kevin-mandias-armadin-raises-255-million-at-2-5-billion-valuation/</link><guid isPermaLink="true">https://www.securityweek.com/kevin-mandias-armadin-raises-255-million-at-2-5-billion-valuation/</guid><description>Bron: SecurityWeek (Prioriteit 2).

The Series B brings the AI-powered offensive security startup’s total funding to roughly $445 million only seven months after its public launch. The post Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation appeared first on SecurityWeek .</description><pubDate>Thu, 01 Oct 2026 11:40:51 GMT</pubDate></item><item><title>Armadin raises $255.5 million to expand AI offensive security platform</title><link>https://www.helpnetsecurity.com/2026/10/01/armadin-raises-255-5-million-funding/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/10/01/armadin-raises-255-5-million-funding/</guid><description>Bron: Help Net Security (Prioriteit 2).

Armadin has raised $255.5 million in Series B funding co-led by Andreessen Horowitz (a16z) and Accel that brings the company’s valuation to over $2.5 billion. The round includes participation from new investors Bain Capital Ventures (BCV) and Redpoint. Existing investors 8VC, Ballistic Ventures, Google Ventures, In-Q-Tel, Kleiner Perkins, and Menlo Ventures also returned, reflecting their continued confidence, bringing Armadin’s total funding to $445 million. Seven months after emerging from stealth, Armadin is running agentic attack … More → The post Armadin raises $255.5 million to expand AI</description><pubDate>Thu, 01 Oct 2026 11:16:53 GMT</pubDate></item><item><title>Treasury Blacklists Most-Wanted ATM Malware Developer and His Network</title><link>https://www.securityweek.com/treasury-blacklists-most-wanted-atm-malware-developer-and-his-network/</link><guid isPermaLink="true">https://www.securityweek.com/treasury-blacklists-most-wanted-atm-malware-developer-and-his-network/</guid><description>Bron: SecurityWeek (Prioriteit 2).

The US government continues its crackdown on Tren de Aragua over its ATM jackpotting scheme. The post Treasury Blacklists Most-Wanted ATM Malware Developer and His Network appeared first on SecurityWeek .</description><pubDate>Thu, 01 Oct 2026 10:51:39 GMT</pubDate></item><item><title>The Fine Art of Frustrating the Adversary</title><link>https://blog.talosintelligence.com/the-fine-art-of-frustrating-the-adversary/</link><guid isPermaLink="true">https://blog.talosintelligence.com/the-fine-art-of-frustrating-the-adversary/</guid><description>Bron: Cisco Talos (Prioriteit 1).

What really frustrates an adversary? Eight Cisco Talos researchers share practical ways to make their next move slower and riskier. From deception and behavioral detection to breaking attack dependencies and resisting manufactured urgency.</description><pubDate>Thu, 01 Oct 2026 10:00:05 GMT</pubDate></item><item><title>Some car apps are slipping owners’ data to big tech companies</title><link>https://www.helpnetsecurity.com/2026/10/01/connected-car-apps-privacy-research/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/10/01/connected-car-apps-privacy-research/</guid><description>Bron: Help Net Security (Prioriteit 2).

The app that comes with your car may be sharing what it knows about you with some of the biggest tech companies. Northeastern University researchers tested 21 vehicles and 30 carmaker apps and found some sending vehicle identification numbers (VINs), email addresses, phone numbers or location data to advertising, tracking and analytics companies. The work was carried out with Consumer Reports, which gave them access to vehicles it had bought for testing. The 21 vehicles … More → The post Some car apps are slipping owners’ data to big tech companies appeared first on Help Net Security .</description><pubDate>Thu, 01 Oct 2026 09:52:14 GMT</pubDate></item><item><title>Minister gaat in gesprek met AP over aanpak van spyware-apps</title><link>https://www.security.nl/posting/955468/Minister+gaat+in+gesprek+met+AP+over+aanpak+van+spyware-apps?channel=rss</link><guid isPermaLink="true">https://www.security.nl/posting/955468/Minister+gaat+in+gesprek+met+AP+over+aanpak+van+spyware-apps?channel=rss</guid><description>Bron: Security.nl (Prioriteit 2).

Minister Van Weel van Justitie en Veiligheid gaat met de Autoriteit Persoonsgegevens (AP) in gesprek over de aanpak van ...</description><pubDate>Thu, 01 Oct 2026 09:51:32 GMT</pubDate></item><item><title>Hackers stole Pentagon personnel records of over 3 million people</title><link>https://www.bleepingcomputer.com/news/security/hackers-breach-pentagon-human-resources-management-system-steal-data-of-nearly-3-million-people/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/hackers-breach-pentagon-human-resources-management-system-steal-data-of-nearly-3-million-people/</guid><description>Bron: BleepingComputer (Prioriteit 2).

The Pentagon&apos;s Defense Manpower Data Center (DMDC) is notifying millions of military service members that hackers stole their data after breaching the Pentagon&apos;s human resources management system in October 2025. [...]</description><pubDate>Thu, 01 Oct 2026 09:44:28 GMT</pubDate></item><item><title>500,000 Active Credentials Left Exposed on GitHub</title><link>https://www.securityweek.com/500000-active-credentials-left-exposed-on-github/</link><guid isPermaLink="true">https://www.securityweek.com/500000-active-credentials-left-exposed-on-github/</guid><description>Bron: SecurityWeek (Prioriteit 2).

Roughly 200,000 of the credentials were exposed after GitHub enabled push protections by default. The post 500,000 Active Credentials Left Exposed on GitHub appeared first on SecurityWeek .</description><pubDate>Thu, 01 Oct 2026 09:43:56 GMT</pubDate></item><item><title>&apos;Nederlander zegt 2FA en wachtwoordmanager te willen gebruiken maar doet dit niet&apos;</title><link>https://www.security.nl/posting/955463/%27Nederlander+zegt+2FA+en+wachtwoordmanager+te+willen+gebruiken+maar+doet+dit+niet%27?channel=rss</link><guid isPermaLink="true">https://www.security.nl/posting/955463/%27Nederlander+zegt+2FA+en+wachtwoordmanager+te+willen+gebruiken+maar+doet+dit+niet%27?channel=rss</guid><description>Bron: Security.nl (Prioriteit 2).

Nederlanders zeggen dat ze tweefactorauthenticatie (2FA) en wachtwoordmanagers willen gebruiken, maar in de praktijk komt het ...</description><pubDate>Thu, 01 Oct 2026 09:23:00 GMT</pubDate></item><item><title>Zerodaylekken in ticketsysteem Zammad gebruikt bij hack van DIVD</title><link>https://www.security.nl/posting/955436/Zerodaylekken+in+ticketsysteem+Zammad+gebruikt+bij+hack+van+DIVD?channel=rss</link><guid isPermaLink="true">https://www.security.nl/posting/955436/Zerodaylekken+in+ticketsysteem+Zammad+gebruikt+bij+hack+van+DIVD?channel=rss</guid><description>Bron: Security.nl (Prioriteit 2).

Het Dutch Institute for Vulnerability Disclosure (DIVD) is onlangs gehackt via twee zerodaylekken in helpdesksoftware en ...</description><pubDate>Thu, 01 Oct 2026 07:59:00 GMT</pubDate></item><item><title>Google Launches Gemini 4 Argon With Guardrail-Free Access for Vetted Defenders</title><link>https://www.securityweek.com/google-launches-gemini-4-argon-with-guardrail-free-access-for-vetted-defenders/</link><guid isPermaLink="true">https://www.securityweek.com/google-launches-gemini-4-argon-with-guardrail-free-access-for-vetted-defenders/</guid><description>Bron: SecurityWeek (Prioriteit 2).

The company says its new frontier AI model found a critical vulnerability in software used by hospitals worldwide. The post Google Launches Gemini 4 Argon With Guardrail-Free Access for Vetted Defenders appeared first on SecurityWeek .</description><pubDate>Thu, 01 Oct 2026 07:52:26 GMT</pubDate></item><item><title>Sentinel Envelope Plus adds software protection without source code changes</title><link>https://www.helpnetsecurity.com/2026/10/01/thales-sentinel-envelope-plus/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/10/01/thales-sentinel-envelope-plus/</guid><description>Bron: Help Net Security (Prioriteit 2).

Thales has announced Sentinel Envelope Plus, a new addition to its Sentinel Envelope software protection solution that significantly hardens compiled applications against AI-assisted reverse engineering, automated zero-day vulnerability discovery, and automated exploit generation. Sentinel Envelope Plus applies multiple layers of protection to software applications, without requiring source code changes or any special compilation environments. AI-assisted tools are making it faster and easier to analyze software for vulnerabilities, reducing the specialist expertise and time required for … Mor</description><pubDate>Thu, 01 Oct 2026 07:38:00 GMT</pubDate></item><item><title>Metamask discloses security incident affecting its infrastructure</title><link>https://www.bleepingcomputer.com/news/security/metamask-discloses-security-incident-affecting-its-infrastructure/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/metamask-discloses-security-incident-affecting-its-infrastructure/</guid><description>Bron: BleepingComputer (Prioriteit 2).

On Thursday, cryptocurrency wallet provider MetaMask has disclosed an ongoing infrastructure security incident affecting some of its infrastructure. [...]</description><pubDate>Thu, 01 Oct 2026 07:33:57 GMT</pubDate></item><item><title>BlackFog adds prompt protection and governance for agentic AI</title><link>https://www.helpnetsecurity.com/2026/10/01/blackfog-adx-vision-2-0/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/10/01/blackfog-adx-vision-2-0/</guid><description>Bron: Help Net Security (Prioriteit 2).

BlackFog has announced the launch of ADX Vision 2.0, expanding its AI security capabilities to help organizations govern and control the use of generative and agentic AI across the enterprise. As employees move from simply interacting with AI tools to deploying agents capable of making decisions and acting on corporate data, the security challenge for organizations is changing. Traditional controls were not designed to address risks such as prompt injection, unauthorized data exposure and limited … More → The post BlackFog adds prompt protection and governance for agentic AI appeared first on </description><pubDate>Thu, 01 Oct 2026 07:25:53 GMT</pubDate></item><item><title>Cyberveilig gedrag van werknemers blijft achter</title><link>https://www.ncsc.nl/nieuws/cyberveilig-gedrag-van-werknemers-blijft-achter</link><guid isPermaLink="true">https://www.ncsc.nl/nieuws/cyberveilig-gedrag-van-werknemers-blijft-achter</guid><description>Bron: NCSC-NL (Prioriteit 1).

Veel werknemers zijn overmoedig wanneer het aankomt op cyberveilig gedrag en maken daardoor nog te weinig gebruik van tweefactorauthenticatie (2FA). Als er binnen de organisatie een veilige meldcultuur is, melden werknemers vaker zelfgemaakte fouten (zoals het doorklikken op een verdachte link). En ongeveer de helft van de werknemers deelt persoonlijke documenten met AI-tools.</description><pubDate>Thu, 01 Oct 2026 06:00:00 GMT</pubDate></item><item><title>ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)</title><link>https://isc.sans.edu/diary/rss/33388</link><guid isPermaLink="true">https://isc.sans.edu/diary/rss/33388</guid><description>Bron: SANS Internet Storm Center (Prioriteit 2).

Threat Actors do not always use top-notch techniques or very complex malware to perform their attacks. Sometimes, they just abuse of existing applications...</description><pubDate>Thu, 01 Oct 2026 05:32:13 GMT</pubDate></item><item><title>Many expect AI in the SOC to make entry jobs harder to get</title><link>https://www.helpnetsecurity.com/2026/10/01/ai-soc-entry-jobs/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/10/01/ai-soc-entry-jobs/</guid><description>Bron: Help Net Security (Prioriteit 2).

A junior analyst in a security operations center, or SOC, has usually learned the job the slow way. You work the same phishing lure dozens of times, chase the same familiar malware pattern and write up the same case note at the end of the shift. Eventually you know what normal looks like, which is how you notice when something isn’t. AI tools handle a lot of that repetitive work, and the people doing the … More → The post Many expect AI in the SOC to make entry jobs harder to get appeared first on Help Net Security .</description><pubDate>Thu, 01 Oct 2026 05:30:08 GMT</pubDate></item><item><title>Employment scam victims tripled at financial firms in 21 countries</title><link>https://www.helpnetsecurity.com/2026/10/01/employment-scam-victims-research/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/10/01/employment-scam-victims-research/</guid><description>Bron: Help Net Security (Prioriteit 2).

Reported victims of employment scams more than tripled over the past 12 months at more than 370 banks and other financial institutions in 21 countries. The 258% rise outran every other scam type, while total reported scams across the same institutions grew 35%. Scams by the numbers (Source: BioCatch) Researchers at BioCatch, a fraud-detection vendor, compiled the figures from reports filed by the institutions that use its software. The numbers matter for anyone running fraud … More → The post Employment scam victims tripled at financial firms in 21 countries appeared first on Help Net Security</description><pubDate>Thu, 01 Oct 2026 04:30:35 GMT</pubDate></item><item><title>Product showcase: Proton Drive end-to-end encrypted cloud storage</title><link>https://www.helpnetsecurity.com/2026/10/01/product-showcase-proton-drive/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/10/01/product-showcase-proton-drive/</guid><description>Bron: Help Net Security (Prioriteit 2).

Proton Drive is an end-to-end encrypted cloud storage service for storing, synchronizing, backing up, and sharing files. It also includes Proton Docs and Proton Sheets, allowing users to create and collaborate on documents and spreadsheets within the same encrypted environment. Proton Drive is available through the web and dedicated apps for Windows, macOS, iOS/iPadOS, and Android. Proton also offers a command-line interface for Windows, macOS, and Linux. After signing in or creating a Proton Account, … More → The post Product showcase: Proton Drive end-to-end encrypted cloud storage appeared </description><pubDate>Thu, 01 Oct 2026 03:48:10 GMT</pubDate></item><item><title>Google’s SynthID Bio can watermark AI-designed protein binders without breaking them</title><link>https://www.helpnetsecurity.com/2026/10/01/synthid-bio-watermark/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/10/01/synthid-bio-watermark/</guid><description>Bron: Help Net Security (Prioriteit 2).

Google DeepMind has built SynthID Bio, a watermark for AI-designed proteins, and shown in wet-lab tests on protein binders that it leaves their function intact. The method hides a signature in the amino acid sequence of a designed protein and in the atomic coordinates of a predicted 3D structure. DeepMind says the signature can be checked on the physical protein after synthesis. DeepMind aims the watermark at DNA synthesis screening. Providers who turn digital protein … More → The post Google’s SynthID Bio can watermark AI-designed protein binders without breaking them appeared first on Help N</description><pubDate>Thu, 01 Oct 2026 03:31:14 GMT</pubDate></item><item><title>Srsly Risky Biz: “Rogue AI” isn’t going anywhere</title><link>https://risky.biz/SRB185/</link><guid isPermaLink="true">https://risky.biz/SRB185/</guid><description>Bron: Risky Business News (Prioriteit 2).

Amberleigh Jack and James Wilson chat about OpenAI agents’ recent escapades into Australian government websites. OpenAI has promised to “rebuild trust with Australians” but we’re likely getting a glimpse into the new normal, here. They also discuss how the ShinyHunters hacking group has found itself on law enforcement’s target list after breaching FBI systems. The group played some stupid games and they appear to be in the “stupid prizes” stage. This episode is also available on YouTube Show notes</description><pubDate>Thu, 01 Oct 2026 02:38:57 GMT</pubDate></item><item><title>ISC Stormcast For Thursday, October 1st, 2026 https://isc.sans.edu/podcastdetail/10118, (Thu, Oct 1st)</title><link>https://isc.sans.edu/diary/rss/33386</link><guid isPermaLink="true">https://isc.sans.edu/diary/rss/33386</guid><description>Bron: SANS Internet Storm Center (Prioriteit 2).

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.</description><pubDate>Thu, 01 Oct 2026 02:00:02 GMT</pubDate></item><item><title>FTC is Investigating OpenAI and Anthropic Over Possible Risks to Consumers</title><link>https://www.securityweek.com/ftc-is-investigating-openai-and-anthropic-over-possible-risks-to-consumers/</link><guid isPermaLink="true">https://www.securityweek.com/ftc-is-investigating-openai-and-anthropic-over-possible-risks-to-consumers/</guid><description>Bron: SecurityWeek (Prioriteit 2).

An FTC spokesperson confirmed the investigation but declined further comment. The post FTC is Investigating OpenAI and Anthropic Over Possible Risks to Consumers appeared first on SecurityWeek .</description><pubDate>Wed, 30 Sep 2026 23:43:51 GMT</pubDate></item><item><title>US sanctions 10 over ATM malware scheme tied to Tren de Aragua</title><link>https://therecord.media/us-sanctions-10-atm-jackpotting-tren-de-aragua</link><guid isPermaLink="true">https://therecord.media/us-sanctions-10-atm-jackpotting-tren-de-aragua</guid><description>Bron: The Record (Recorded Future News) (Prioriteit 2).

Treasury’s Office of Foreign Assets Control (OFAC) targeted multiple Venezuelan nationals and several companies they control that are part of the effort to launder the money stolen from dozens of ATMs.</description><pubDate>Wed, 30 Sep 2026 22:35:00 GMT</pubDate></item><item><title>Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure</title><link>https://www.darkreading.com/cyberattacks-data-breaches/malicious-custom-gpts-chatgpt-rat-delivery-lure</link><guid isPermaLink="true">https://www.darkreading.com/cyberattacks-data-breaches/malicious-custom-gpts-chatgpt-rat-delivery-lure</guid><description>Bron: Dark Reading (Prioriteit 2).

In yet another ClickFix-style campaign, threat actors abuse legitimate domains from OpenAI and Google to fool unsuspecting users.</description><pubDate>Wed, 30 Sep 2026 21:25:47 GMT</pubDate></item><item><title>Trump, Tech Giants Strike Voluntary AI Safety Accord</title><link>https://www.darkreading.com/cyber-risk/trump-tech-giants-strike-voluntary-ai-safety-accord</link><guid isPermaLink="true">https://www.darkreading.com/cyber-risk/trump-tech-giants-strike-voluntary-ai-safety-accord</guid><description>Bron: Dark Reading (Prioriteit 2).

The new White House Accord on so-called &quot;Super Intelligence&quot; calls on companies to implement greater controls and oversight over AI safety.</description><pubDate>Wed, 30 Sep 2026 20:51:15 GMT</pubDate></item><item><title>Russian state hackers use new RedFlick technique to push malware</title><link>https://www.bleepingcomputer.com/news/security/russian-state-hackers-use-new-redflick-technique-to-push-malware/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/russian-state-hackers-use-new-redflick-technique-to-push-malware/</guid><description>Bron: BleepingComputer (Prioriteit 2).

The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed &quot;RedFlick&quot; to deploy its signature CosmicPulse backdoor. [...]</description><pubDate>Wed, 30 Sep 2026 20:34:01 GMT</pubDate></item><item><title>Automakers routinely share personally identifiable connected-car data with third parties, report says</title><link>https://therecord.media/automakers-routinely-share-connected-car-data-third-parties</link><guid isPermaLink="true">https://therecord.media/automakers-routinely-share-connected-car-data-third-parties</guid><description>Bron: The Record (Recorded Future News) (Prioriteit 2).

A new study reveals fresh details about how drivers are exposed to a web of large corporations participating in the advertising ecosystem.</description><pubDate>Wed, 30 Sep 2026 20:32:00 GMT</pubDate></item><item><title>Hackers Flink kregen, ondanks ultimatum, nog geen geld van slachtoffers</title><link>https://nos.nl/l/2633196</link><guid isPermaLink="true">https://nos.nl/l/2633196</guid><description>Bron: NOS (Prioriteit 3).

De cybercriminelen die vorige week inbraken bij boodschappenbezorger Flink, hebben nog niets verdiend met hun hack. De hackers benaderden medewerkers en klanten met een ultimatum: als ze niet betalen, worden hun gegevens gepubliceerd. Daar is nog niemand op ingegaan. RTL Nieuws kreeg van 32 Nederlandse Flink-klanten de afpersingsmail die de hackers hadden gestuurd. &quot;Je ontvangt deze e-mail omdat we jouw persoonlijke informatie via een hack van Flink hebben gestolen&quot;, schreven de criminelen. &quot;Als je weigert om 0,005 ETH (ethereum, een digitale munt - ongeveer 10 euro) te betalen voor 2 oktober </description><pubDate>Wed, 30 Sep 2026 19:54:04 GMT</pubDate></item><item><title>After reports on suicide deaths, Pentagon puts Cyber Command on notice</title><link>https://therecord.media/cyber-command-suicide-deaths-pentagon-memo</link><guid isPermaLink="true">https://therecord.media/cyber-command-suicide-deaths-pentagon-memo</guid><description>Bron: The Record (Recorded Future News) (Prioriteit 2).

An August 31 memo obtained by Recorded Future News shows that the Pentagon&apos;s assistant secretary for cyber policy made specific demands of U.S. Cyber Command leadership after reports of a cluster of suicide deaths.</description><pubDate>Wed, 30 Sep 2026 19:35:00 GMT</pubDate></item><item><title>​​Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026</title><link>https://www.microsoft.com/en-us/security/blog/2026/09/30/secure-whats-next-your-guide-to-microsoft-security-at-microsoft-ignite-2026/</link><guid isPermaLink="true">https://www.microsoft.com/en-us/security/blog/2026/09/30/secure-whats-next-your-guide-to-microsoft-security-at-microsoft-ignite-2026/</guid><description>Bron: Microsoft Security Blog (Prioriteit 1).

This year at Microsoft Ignite, we spotlight our AI-first, end-to-end security platform designed to protect identities, devices, data, applications, clouds, infrastructure, and the AI agents now working alongside your teams. The post ​​Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026 appeared first on Microsoft Security Blog .</description><pubDate>Wed, 30 Sep 2026 19:31:00 GMT</pubDate></item><item><title>As AI Reshapes the SOC Career Ladder, Satisfaction Rises for 91%, but Entry Gets Harder for Nearly Half</title><link>https://www.darkreading.com/cybersecurity-careers/ai-reshapes-soc-career-ladder</link><guid isPermaLink="true">https://www.darkreading.com/cybersecurity-careers/ai-reshapes-soc-career-ladder</guid><description>Bron: Dark Reading (Prioriteit 2).

New Swimlane research underscores a paradox: While AI detection and response is essential to giving defenders an edge, one in four security pros say AI limits their skill development.</description><pubDate>Wed, 30 Sep 2026 18:56:56 GMT</pubDate></item><item><title>Over 543,000 valid credentials exposed in public GitHub repositories</title><link>https://www.bleepingcomputer.com/news/security/over-543-000-valid-credentials-exposed-in-public-github-repositories/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/over-543-000-valid-credentials-exposed-in-public-github-repositories/</guid><description>Bron: BleepingComputer (Prioriteit 2).

More than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platform&apos;s security measures to prevent accidental leaks of sensitive data. [...]</description><pubDate>Wed, 30 Sep 2026 18:08:34 GMT</pubDate></item><item><title>Cisco Advance Notification for Publication of October 7, 2026, Security Advisories</title><link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-fBn58ELx?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Advance%20Notification%20for%20Publication%20of%20October%207,%202026,%20Security%20Advisories%26vs_k=1</link><guid isPermaLink="true">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-fBn58ELx?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Advance%20Notification%20for%20Publication%20of%20October%207,%202026,%20Security%20Advisories%26vs_k=1</guid><description>Bron: Cisco PSIRT (Prioriteit 1).

&lt;p&gt;On October 7, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products:&lt;/p&gt; &lt;ul&gt; &lt;li&gt;Application Policy Infrastructure Controller (security hardening release)&lt;/li&gt; &lt;li&gt;Finesse&lt;/li&gt; &lt;li&gt;License On-Prem, formerly Cisco Smart Software Manager On-Prem (security hardening release)&lt;/li&gt; &lt;li&gt;Meraki (security hardening release)&lt;/li&gt; &lt;li&gt;NX-OS Software for MDS 9000, Nexus 3000, 7000, and 9000 Series Switches, Nexus 9000 in ACI mode, and UCS Fabric Intercon</description><pubDate>Wed, 30 Sep 2026 16:00:00 GMT</pubDate></item><item><title>Microsoft: Zimbra-mailservers kort na uitkomen van patch gehackt</title><link>https://www.security.nl/posting/955370/Microsoft%3A+Zimbra-mailservers+kort+na+uitkomen+van+patch+gehackt?channel=rss</link><guid isPermaLink="true">https://www.security.nl/posting/955370/Microsoft%3A+Zimbra-mailservers+kort+na+uitkomen+van+patch+gehackt?channel=rss</guid><description>Bron: Security.nl (Prioriteit 2).

Een kwetsbaarheid in Zimbra-mailservers is kort na het uitkomen van de patch op 20 juli misbruikt bij aanvallen aldus ...</description><pubDate>Wed, 30 Sep 2026 15:12:10 GMT</pubDate></item><item><title>Russia&apos;s Star Blizzard Ditches ClickFix to Widen Phishing Net</title><link>https://www.darkreading.com/threat-intelligence/russia-star-blizzard-apt-ditches-clickfix-widen-phishing-net</link><guid isPermaLink="true">https://www.darkreading.com/threat-intelligence/russia-star-blizzard-apt-ditches-clickfix-widen-phishing-net</guid><description>Bron: Dark Reading (Prioriteit 2).

The APT actor is using a new tactic, dubbed &quot;RedFlick,&quot; against Ukrainian-linked targets such as NGOs, think tanks, and journalists to deploy its CosmicPulse backdoor.</description><pubDate>Wed, 30 Sep 2026 15:02:25 GMT</pubDate></item><item><title>AI&apos;s Third Wave: Coworkers Break the Security Model That Worked for Agents</title><link>https://www.bleepingcomputer.com/news/security/ais-third-wave-coworkers-break-the-security-model-that-worked-for-agents/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/ais-third-wave-coworkers-break-the-security-model-that-worked-for-agents/</guid><description>Bron: BleepingComputer (Prioriteit 2).

Persistent AI coworkers may operate continuously with standing access, creating identity risks that existing security models were not designed to handle. Token Security explains why these agents need their own identities, owners, scoped permissions, and lifecycle controls. [...]</description><pubDate>Wed, 30 Sep 2026 14:01:11 GMT</pubDate></item><item><title>Mobile malware warning from Ukrainian researchers includes iPhone exploit kit</title><link>https://therecord.media/ukraine-ssscip-mobile-malware-warning-ios-android</link><guid isPermaLink="true">https://therecord.media/ukraine-ssscip-mobile-malware-warning-ios-android</guid><description>Bron: The Record (Recorded Future News) (Prioriteit 2).

&apos;Hit and run&apos; iPhone malware known as DarkSword is part of a wave of Russian attacks on iOS and Android devices, according to Ukraine&apos;s SSSCIP.</description><pubDate>Wed, 30 Sep 2026 14:00:00 GMT</pubDate></item><item><title>Cisco waarschuwt voor misbruik van kritiek lek in Catalyst SD-WAN Manager</title><link>https://www.security.nl/posting/955351/Cisco+waarschuwt+voor+misbruik+van+kritiek+lek+in+Catalyst+SD-WAN+Manager?channel=rss</link><guid isPermaLink="true">https://www.security.nl/posting/955351/Cisco+waarschuwt+voor+misbruik+van+kritiek+lek+in+Catalyst+SD-WAN+Manager?channel=rss</guid><description>Bron: Security.nl (Prioriteit 2).

Cisco waarschuwt organisaties voor actief misbruik van een kritieke kwetsbaarheid in de Cisco Catalyst SD-WAN Manager en heeft ...</description><pubDate>Wed, 30 Sep 2026 13:51:59 GMT</pubDate></item><item><title>TeamViewer adviseert gebruikers om update zo snel mogelijk te installeren</title><link>https://www.security.nl/posting/955331/TeamViewer+adviseert+gebruikers+om+update+zo+snel+mogelijk+te+installeren?channel=rss</link><guid isPermaLink="true">https://www.security.nl/posting/955331/TeamViewer+adviseert+gebruikers+om+update+zo+snel+mogelijk+te+installeren?channel=rss</guid><description>Bron: Security.nl (Prioriteit 2).

TeamViewer adviseert alle gebruikers om gisteren uitgebrachte beveiligingsupdates voor kwetsbaarheden in de software zo snel ...</description><pubDate>Wed, 30 Sep 2026 12:45:09 GMT</pubDate></item><item><title>Russian FSB-linked hackers scale up phishing attacks against Ukraine supporters</title><link>https://therecord.media/russia-hackers-ukraine-blizzard</link><guid isPermaLink="true">https://therecord.media/russia-hackers-ukraine-blizzard</guid><description>Bron: The Record (Recorded Future News) (Prioriteit 2).

The Russian state-backed hacking group Star Blizzard has expanded its phishing operations this year, using a new technique that makes it easier to infect victims with malware.</description><pubDate>Wed, 30 Sep 2026 12:00:00 GMT</pubDate></item><item><title>AI coding agents leaked 13,000 internal company screenshots to public GitHub repos</title><link>https://www.helpnetsecurity.com/2026/09/30/ai-coding-agents-github-screenshot-leak/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/09/30/ai-coding-agents-github-screenshot-leak/</guid><description>Bron: Help Net Security (Prioriteit 2).

When developers ask AI coding agents to prove that a user interface fix works, some agents have been posting the evidence where anyone can find it, according to Glow Labs. Diagram showing how AI agents leak screenshots to public repos (Source: Glow Labs) The researchers found more than 13,000 internal images published openly on GitHub by developers at over 300 organizations. The images, spread over more than 900 code repositories, include customer billing records and … More → The post AI coding agents leaked 13,000 internal company screenshots to public GitHub repos appeared first on Help Net </description><pubDate>Wed, 30 Sep 2026 11:52:30 GMT</pubDate></item><item><title>Staatssecretaris: Rijksoverheid mogelijk gehackt via Citrix-lekken</title><link>https://www.security.nl/posting/955316/Staatssecretaris%3A+Rijksoverheid+mogelijk+gehackt+via+Citrix-lekken?channel=rss</link><guid isPermaLink="true">https://www.security.nl/posting/955316/Staatssecretaris%3A+Rijksoverheid+mogelijk+gehackt+via+Citrix-lekken?channel=rss</guid><description>Bron: Security.nl (Prioriteit 2).

Meerdere Rijksoverheidspartijen zijn mogelijk gehackt via kwetsbaarheden in Citrix NetScaler, zo heeft staatssecretaris Van der ...</description><pubDate>Wed, 30 Sep 2026 11:46:00 GMT</pubDate></item><item><title>Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit</title><link>https://www.securityweek.com/anthropic-flags-ai-agent-liability-risks-as-openai-faces-hacking-lawsuit/</link><guid isPermaLink="true">https://www.securityweek.com/anthropic-flags-ai-agent-liability-risks-as-openai-faces-hacking-lawsuit/</guid><description>Bron: SecurityWeek (Prioriteit 2).

Attacks by autonomous AI agents are moving out of the lab and into the courtroom, raising unsettled questions about who is liable for what agents do. The post Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit appeared first on SecurityWeek .</description><pubDate>Wed, 30 Sep 2026 11:19:00 GMT</pubDate></item><item><title>Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks</title><link>https://www.securityweek.com/russian-apt-star-blizzard-uses-redflick-infection-chain-in-recent-attacks/</link><guid isPermaLink="true">https://www.securityweek.com/russian-apt-star-blizzard-uses-redflick-infection-chain-in-recent-attacks/</guid><description>Bron: SecurityWeek (Prioriteit 2).

The state-sponsored group has launched larger-scale phishing campaigns to deploy the CosmicPulse backdoor. The post Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks appeared first on SecurityWeek .</description><pubDate>Wed, 30 Sep 2026 10:59:30 GMT</pubDate></item><item><title>ShinyHunters Defiant After FBI Calls on Members to Come Forward</title><link>https://www.securityweek.com/shinyhunters-defiant-after-fbi-calls-on-members-to-come-forward/</link><guid isPermaLink="true">https://www.securityweek.com/shinyhunters-defiant-after-fbi-calls-on-members-to-come-forward/</guid><description>Bron: SecurityWeek (Prioriteit 2).

In the wake of a suspected leader’s arrest, ShinyHunters says it never intended to publish data stolen from the FBI. The post ShinyHunters Defiant After FBI Calls on Members to Come Forward appeared first on SecurityWeek .</description><pubDate>Wed, 30 Sep 2026 10:20:02 GMT</pubDate></item><item><title>China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor</title><link>https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/</link><guid isPermaLink="true">https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/</guid><description>Bron: Cisco Talos (Prioriteit 1).

Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts.</description><pubDate>Wed, 30 Sep 2026 10:00:01 GMT</pubDate></item><item><title>&apos;Citrix-beveiligingslek al sinds begin september misbruikt bij aanvallen&apos;</title><link>https://www.security.nl/posting/955258/%27Citrix-beveiligingslek+al+sinds+begin+september+misbruikt+bij+aanvallen%27?channel=rss</link><guid isPermaLink="true">https://www.security.nl/posting/955258/%27Citrix-beveiligingslek+al+sinds+begin+september+misbruikt+bij+aanvallen%27?channel=rss</guid><description>Bron: Security.nl (Prioriteit 2).

Aanvallers maken al zeker sinds begin september misbruik van een kritieke kwetsbaarheid in Citrix NetScaler ADC en NetScaler ...</description><pubDate>Wed, 30 Sep 2026 09:35:23 GMT</pubDate></item><item><title>Signal brings encrypted local backups to iOS and desktop, adds cross-platform restore</title><link>https://www.helpnetsecurity.com/2026/09/30/signal-encrypted-backups-ios-8-30/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/09/30/signal-encrypted-backups-ios-8-30/</guid><description>Bron: Help Net Security (Prioriteit 2).

Signal users who switch from an Android phone to an iPhone, or the other way around, can take their message history with them, and backups can be restored on Android, iOS, Linux, macOS and Windows. The option is part of a set of backup updates the company finished rolling out with Signal for iOS version 8.30. The changes build on Signal Secure Backups, an optional end-to-end encrypted backup service introduced in September 2025. Signal said … More → The post Signal brings encrypted local backups to iOS and desktop, adds cross-platform restore appeared first on Help Net Security .</description><pubDate>Wed, 30 Sep 2026 09:31:00 GMT</pubDate></item><item><title>Advertorial: Telefoon verloren of gestolen: zo beperk je het security-risico</title><link>https://www.security.nl/posting/955125/Advertorial%3A+Telefoon+verloren+of+gestolen%3A+zo+beperk+je+het+security-risico?channel=rss</link><guid isPermaLink="true">https://www.security.nl/posting/955125/Advertorial%3A+Telefoon+verloren+of+gestolen%3A+zo+beperk+je+het+security-risico?channel=rss</guid><description>Bron: Security.nl (Prioriteit 2).

Een verloren of gestolen smartphone is geen praktisch ongemak, maar een acuut beveiligingsincident. Op het toestel staan vaak ...</description><pubDate>Wed, 30 Sep 2026 09:04:20 GMT</pubDate></item><item><title>This month in security with Tony Anscombe – September 2026 edition</title><link>https://www.welivesecurity.com/en/videos/month-security-tony-anscombe-september-2026/</link><guid isPermaLink="true">https://www.welivesecurity.com/en/videos/month-security-tony-anscombe-september-2026/</guid><description>Bron: ESET WeLiveSecurity (Prioriteit 1).

Autonomous AI agents go on a hacking spree, and Microsoft ships what used to be a year&apos;s worth of security patches in one go – here&apos;s how to keep pace</description><pubDate>Wed, 30 Sep 2026 08:00:00 GMT</pubDate></item><item><title>Former US Air Force members behind million-dollar BEC scheme head to prison</title><link>https://www.helpnetsecurity.com/2026/09/30/air-force-members-sentenced-bec-phishing/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/09/30/air-force-members-sentenced-bec-phishing/</guid><description>Bron: Help Net Security (Prioriteit 2).

Two men who ran BEC and phishing campaigns against US businesses while serving in the Air Force have been sentenced to a combined 189 months in federal prison. According to public documents and evidence presented at sentencing, Chijioke Timothy Odimegwu, 25, and Harafat Mogaji, 26, both from Delaware, spent nearly two years sending spam and phishing emails to businesses around the US to steal usernames and passwords for employee email accounts. They and their co-conspirators … More → The post Former US Air Force members behind million-dollar BEC scheme head to prison appeared first on Help Net</description><pubDate>Wed, 30 Sep 2026 07:42:11 GMT</pubDate></item><item><title>MikroTik-routers via kritiek beveiligingslek op afstand over te nemen</title><link>https://www.security.nl/posting/955221/MikroTik-routers+via+kritiek+beveiligingslek+op+afstand+over+te+nemen?channel=rss</link><guid isPermaLink="true">https://www.security.nl/posting/955221/MikroTik-routers+via+kritiek+beveiligingslek+op+afstand+over+te+nemen?channel=rss</guid><description>Bron: Security.nl (Prioriteit 2).

Een kritieke kwetsbaarheid maakt het mogelijk voor ongeauthenticeerde aanvallers om MikroTik-routers op afstand over te nemen. ...</description><pubDate>Wed, 30 Sep 2026 07:39:24 GMT</pubDate></item><item><title>South Africa Seeks Help After Cyberattack Targets Air Traffic Control</title><link>https://www.darkreading.com/cyberattacks-data-breaches/south-africa-help-cyberattack-air-traffic-control</link><guid isPermaLink="true">https://www.darkreading.com/cyberattacks-data-breaches/south-africa-help-cyberattack-air-traffic-control</guid><description>Bron: Dark Reading (Prioriteit 2).

As aviation infrastructure suffers more cyberattacks, air traffic systems are the latest target, with a ransomware toolkit installed on at least one operational network.</description><pubDate>Wed, 30 Sep 2026 07:00:00 GMT</pubDate></item><item><title>Genea brings AI agents to access control with role-based permissions</title><link>https://www.helpnetsecurity.com/2026/09/30/genea-mcp/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/09/30/genea-mcp/</guid><description>Bron: Help Net Security (Prioriteit 2).

Genea has announced the release of Genea MCP, a Model Context Protocol (MCP) server that connects AI agents directly to the Genea Access Control platform. Onboarding a new hire, setting up a contractor for two weeks, or unlocking the loading dock now takes one sentence instead of a dozen clicks. Genea is one of the first access control providers to launch a native MCP server. Most access control work isn’t hard, but it can be … More → The post Genea brings AI agents to access control with role-based permissions appeared first on Help Net Security .</description><pubDate>Wed, 30 Sep 2026 06:49:24 GMT</pubDate></item><item><title>Security tools can now scan Claude Enterprise chats and uploads for sensitive data</title><link>https://www.helpnetsecurity.com/2026/09/30/claude-compliance-api-integrations/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/09/30/claude-compliance-api-integrations/</guid><description>Bron: Help Net Security (Prioriteit 2).

More than 100 security and compliance vendors have integrations with the Claude Compliance API, which lets a company send Claude activity into the monitoring tools it already uses. CrowdStrike, Microsoft Purview, Splunk, Palo Alto Networks, Cloudflare and Zscaler are among them. For a Claude Enterprise customer, the feed includes the conversations themselves, the files people upload and their projects. It also covers Cowork and Claude Code sessions, down to prompts, responses and tool calls, plus … More → The post Security tools can now scan Claude Enterprise chats and uploads for sensitive da</description><pubDate>Wed, 30 Sep 2026 06:31:58 GMT</pubDate></item><item><title>OWASP Noir: Open-source static analysis tool</title><link>https://www.helpnetsecurity.com/2026/09/30/owasp-noir-open-source-static-analysis-tool/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/09/30/owasp-noir-open-source-static-analysis-tool/</guid><description>Bron: Help Net Security (Prioriteit 2).

OWASP Noir is an open-source static analysis tool that reads an application’s source code and lists the endpoints it exposes: paths, HTTP methods, parameters, headers, and cookies, each tied to the file and line it came from. Here’s where it gets useful. Shadow APIs, the endpoints that live in the code but never made it into any documentation, show up in Noir’s inventory right next to everything else, along with deprecated routes and undocumented handlers. … More → The post OWASP Noir: Open-source static analysis tool appeared first on Help Net Security .</description><pubDate>Wed, 30 Sep 2026 05:30:36 GMT</pubDate></item><item><title>EU Cyber Resilience Act requirements for containers and Kubernetes</title><link>https://www.helpnetsecurity.com/2026/09/30/rapidfort-cra-container-compliance/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/09/30/rapidfort-cra-container-compliance/</guid><description>Bron: Help Net Security (Prioriteit 2).

Starting in full force on Dec. 10, 2024, the EU Cyber Resilience Act (CRA) is a regulation (EU 2024/2847) that defines mandatory cybersecurity requirements for all products with digital elements sold in EU markets. Reporting obligations will begin on Sept. 11, 2026, with full enforcement kicking in on Dec. 11, 2027. The CRA brings new requirements for teams working with containers and Kubernetes regarding how cloud native applications are built, distributed, and maintained throughout their lifecycle. CRA scope in cloud … More → The post EU Cyber Resilience Act requirements for containers and K</description><pubDate>Wed, 30 Sep 2026 05:00:53 GMT</pubDate></item><item><title>In this new SME cybersecurity service, the AI assists and the consultants decide</title><link>https://www.helpnetsecurity.com/2026/09/30/bh-haven-sme-cybersecurity-service/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/09/30/bh-haven-sme-cybersecurity-service/</guid><description>Bron: Help Net Security (Prioriteit 2).

BH Consulting, the Irish cybersecurity and data protection consultancy, has launched BH Haven, an ongoing service that gives Irish small and medium-sized enterprises (SMEs) access to its specialist consultants, supported by a proprietary AI tool for analysis, evidence review, regulatory mapping and reporting. Ireland and the UK come first, with the Nordic countries and other EU markets to follow. The companies it targets answer to GDPR, the NIS2 Directive, the EU AI Act and the … More → The post In this new SME cybersecurity service, the AI assists and the consultants decide appeared first on </description><pubDate>Wed, 30 Sep 2026 04:30:17 GMT</pubDate></item><item><title>ShinyHunters suspect arrested in the Netherlands</title><link>https://risky.biz/RBNEWS617/</link><guid isPermaLink="true">https://risky.biz/RBNEWS617/</guid><description>Bron: Risky Business News (Prioriteit 2).

A ShinyHunters suspect has been arrested in the Netherlands, Apple fixes an iOS zero-day found by Meta, recent Citrix zero-days see mass exploitation within hours and NVIDIA launches an AI sandboxing platform. Show notes Risky Bulletin: Sanctions force CAs to revoke TLS certs in Iran, Russia</description><pubDate>Wed, 30 Sep 2026 03:56:03 GMT</pubDate></item><item><title>WSL containers are generally available on Windows</title><link>https://www.helpnetsecurity.com/2026/09/30/microsoft-wsl-containers-available/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/09/30/microsoft-wsl-containers-available/</guid><description>Bron: Help Net Security (Prioriteit 2).

Microsoft made WSL containers generally available and shipped the feature with controls that let administrators switch it off or limit where it pulls images from. WSL containers run Linux containers on Windows through the Windows Subsystem for Linux. They install with wsl --update or from Microsoft’s GitHub releases page. Source: Microsoft If your developers work on Windows laptops, the two Intune settings are the ones to look at first. Intune, Microsoft’s device management product, can … More → The post WSL containers are generally available on Windows appeared first on Help Net Security .</description><pubDate>Wed, 30 Sep 2026 03:47:25 GMT</pubDate></item><item><title>Most organizations need six months or longer to roll out new security controls</title><link>https://www.helpnetsecurity.com/2026/09/30/relentless-defense-cisco-cybersecurity-survey/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/09/30/relentless-defense-cisco-cybersecurity-survey/</guid><description>Bron: Help Net Security (Prioriteit 2).

Cisco surveyed 8,000 security professionals in 30 markets about how well their organizations defend against AI-era threats, and only 8% landed in the top group. Cisco gave the most weight in its scoring to internal friction, meaning the delays and turf problems inside a company that slow a security team when something changes. Cisco says frontier AI models can find software vulnerabilities at a scale and speed no human team working alone can match. Fewer … More → The post Most organizations need six months or longer to roll out new security controls appeared first on Help Net Security .</description><pubDate>Wed, 30 Sep 2026 03:30:01 GMT</pubDate></item><item><title>Post-quantum website certificates from Cloudflare are scheduled for early 2027</title><link>https://www.helpnetsecurity.com/2026/09/30/cloudflare-certificate-authority-2027/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/09/30/cloudflare-certificate-authority-2027/</guid><description>Bron: Help Net Security (Prioriteit 2).

Cloudflare plans to become a public certificate authority (CA), an organization that issues the digital certificates websites use to encrypt traffic and prove who they are. The company said that its CA will issue conventional certificates and a post-quantum type called Merkle Tree Certificates (MTCs), with production MTC issuance scheduled for the first quarter of 2027. Cloudflare says much of the web’s certificate issuing rests on a small set of dominant CAs, so one failure … More → The post Post-quantum website certificates from Cloudflare are scheduled for early 2027 appeared first on Help </description><pubDate>Wed, 30 Sep 2026 03:09:51 GMT</pubDate></item><item><title>ISC Stormcast For Wednesday, September 30th, 2026 https://isc.sans.edu/podcastdetail/10116, (Wed, Sep 30th)</title><link>https://isc.sans.edu/diary/rss/33384</link><guid isPermaLink="true">https://isc.sans.edu/diary/rss/33384</guid><description>Bron: SANS Internet Storm Center (Prioriteit 2).

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.</description><pubDate>Wed, 30 Sep 2026 02:00:03 GMT</pubDate></item><item><title>Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development</title><link>https://www.securityweek.com/trump-says-top-tech-firms-have-signed-accord-to-self-police-ai-development/</link><guid isPermaLink="true">https://www.securityweek.com/trump-says-top-tech-firms-have-signed-accord-to-self-police-ai-development/</guid><description>Bron: SecurityWeek (Prioriteit 2).

The accord opened the door to future regulation but focused on four voluntary steps for the companies to take. The post Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development appeared first on SecurityWeek .</description><pubDate>Wed, 30 Sep 2026 01:48:21 GMT</pubDate></item><item><title>Phishing Abuses RMM Tools for Persistent Access</title><link>https://www.microsoft.com/en-us/security/blog/2026/09/29/phishing-abuses-rmm-tools-persistent-access/</link><guid isPermaLink="true">https://www.microsoft.com/en-us/security/blog/2026/09/29/phishing-abuses-rmm-tools-persistent-access/</guid><description>Bron: Microsoft Security Blog (Prioriteit 1).

Microsoft observed phishing campaigns that abused MSP360 RMM to deploy ScreenConnect, creating redundant remote-access channels for follow-on activity The post Phishing Abuses RMM Tools for Persistent Access appeared first on Microsoft Security Blog .</description><pubDate>Tue, 29 Sep 2026 21:39:27 GMT</pubDate></item><item><title>US Air Force members given over 6 years in prison for cyber theft of more than $2 million</title><link>https://therecord.media/us-air-force-members-given-6-year-sentence-cyber</link><guid isPermaLink="true">https://therecord.media/us-air-force-members-given-6-year-sentence-cyber</guid><description>Bron: The Record (Recorded Future News) (Prioriteit 2).

According to court documents, both men pleaded guilty to wire fraud, identity theft and access device fraud charges in June.</description><pubDate>Tue, 29 Sep 2026 21:01:00 GMT</pubDate></item><item><title>Custom ChatGPTs push ClickFix attacks to deploy RAT malware</title><link>https://www.bleepingcomputer.com/news/security/custom-chatgpts-push-clickfix-attacks-to-deploy-rat-malware/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/custom-chatgpts-push-clickfix-attacks-to-deploy-rat-malware/</guid><description>Bron: BleepingComputer (Prioriteit 2).

Custom variants of OpenAI&apos;s ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware. [...]</description><pubDate>Tue, 29 Sep 2026 20:59:39 GMT</pubDate></item><item><title>Jonge hacker nu ook verdacht van moordopdrachten: wie is whizzkid Pepijn van der S.?</title><link>https://nos.nl/l/2633068</link><guid isPermaLink="true">https://nos.nl/l/2633068</guid><description>Bron: NOS (Prioriteit 3).

De 24-jarige Pepijn van der S. uit Amsterdam werd eerder deze maand opgepakt op verdenking van deelname aan ShinyHunters. Dat is het hackerscollectief dat onder meer bekend is van de grootschalige aanval op telecomprovider Odido waarbij in februari gegevens van miljoenen Nederlanders werden gestolen. Vandaag maakte de politie ook bekend dat Van der S. wordt verdacht van een poging tot het uitlokken van twee moorden in het buitenland. Wie is deze 24-jarige Amsterdammer en hoe raakte hij in de hackerswereld verzeild? Vier jaar celstraf Van der S. is een bekende van justitie: hij is 20 jaar als h</description><pubDate>Tue, 29 Sep 2026 20:53:10 GMT</pubDate></item><item><title>Controversial spyware firm Paragon to go public by end of year</title><link>https://therecord.media/controversial-spyware-firm-paragon-to-go-public</link><guid isPermaLink="true">https://therecord.media/controversial-spyware-firm-paragon-to-go-public</guid><description>Bron: The Record (Recorded Future News) (Prioriteit 2).

The company plans to close the deal around the end of the year at which point Paragon will begin trading on Nasdaq under the REDLattice umbrella.</description><pubDate>Tue, 29 Sep 2026 20:35:00 GMT</pubDate></item><item><title>OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference</title><link>https://www.securityweek.com/openai-ceo-announces-new-ai-agent-and-avoids-mention-of-security-concerns-at-developer-conference/</link><guid isPermaLink="true">https://www.securityweek.com/openai-ceo-announces-new-ai-agent-and-avoids-mention-of-security-concerns-at-developer-conference/</guid><description>Bron: SecurityWeek (Prioriteit 2).

Altman made a slew of product announcements and updates, including the company’s new agents, called Dots. The post OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference appeared first on SecurityWeek .</description><pubDate>Tue, 29 Sep 2026 20:14:44 GMT</pubDate></item><item><title>OpenAI apologizes for agents breaching Australian government websites without authorization</title><link>https://therecord.media/openai-apologizes-australia-medicare-breach</link><guid isPermaLink="true">https://therecord.media/openai-apologizes-australia-medicare-breach</guid><description>Bron: The Record (Recorded Future News) (Prioriteit 2).

The artificial intelligence giant acknowledged it botched its response to the incidents and should have done more to promptly notify and work with the Australian government in the days after it discovered the breaches.</description><pubDate>Tue, 29 Sep 2026 19:48:00 GMT</pubDate></item><item><title>Warning: Critical Cross-site Scripting (XSS) in Rancher - Kubernetes management platform, Patch Immediately!</title><link>https://ccb.belgium.be/advisories/warning-critical-cross-site-scripting-xss-rancher-kubernetes-management-platform-patch</link><guid isPermaLink="true">https://ccb.belgium.be/advisories/warning-critical-cross-site-scripting-xss-rancher-kubernetes-management-platform-patch</guid><description>Bron: CCB (Centre for Cybersecurity Belgium) (Prioriteit 1).

CCB Advisories</description><pubDate>Tue, 29 Sep 2026 18:44:59 GMT</pubDate></item><item><title>Former US Air Force members sent to prison over BEC attacks</title><link>https://www.bleepingcomputer.com/news/security/former-us-air-force-members-sent-to-prison-over-bec-attacks/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/former-us-air-force-members-sent-to-prison-over-bec-attacks/</guid><description>Bron: BleepingComputer (Prioriteit 2).

Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. [...]</description><pubDate>Tue, 29 Sep 2026 18:09:39 GMT</pubDate></item><item><title>DARPA Selects Xint to Use AI in Securing Military Messaging Apps</title><link>https://www.securityweek.com/darpa-selects-xint-to-use-ai-in-securing-military-messaging-apps/</link><guid isPermaLink="true">https://www.securityweek.com/darpa-selects-xint-to-use-ai-in-securing-military-messaging-apps/</guid><description>Bron: SecurityWeek (Prioriteit 2).

The AIxCC competition winner will analyze messaging app code and compiled binaries for vulnerabilities, with technology that could also help commercial customers secure their software. The post DARPA Selects Xint to Use AI in Securing Military Messaging Apps appeared first on SecurityWeek .</description><pubDate>Tue, 29 Sep 2026 17:24:04 GMT</pubDate></item><item><title>Cloudflare Announces Public Certificate Authority for the Post-Quantum Web</title><link>https://www.darkreading.com/cloud-security/cloudflare-announces-public-certificate-authority-post-quantum-web</link><guid isPermaLink="true">https://www.darkreading.com/cloud-security/cloudflare-announces-public-certificate-authority-post-quantum-web</guid><description>Bron: Dark Reading (Prioriteit 2).

Automated certificates for everyone, built for today, and hardened for the era of quantum computing.</description><pubDate>Tue, 29 Sep 2026 17:02:16 GMT</pubDate></item><item><title>New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks</title><link>https://www.securityweek.com/new-spectre-v2-variant-exposes-intel-amd-arm-cpus-to-data-leaks/</link><guid isPermaLink="true">https://www.securityweek.com/new-spectre-v2-variant-exposes-intel-amd-arm-cpus-to-data-leaks/</guid><description>Bron: SecurityWeek (Prioriteit 2).

Branch Target Reuse (BTR) is a new Spectre v2 attack targeting JIT compilers in web browsers, language runtimes, and the operating system kernel The post New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks appeared first on SecurityWeek .</description><pubDate>Tue, 29 Sep 2026 17:00:00 GMT</pubDate></item><item><title>​​Beyond source code: A path to the keys to the kingdom</title><link>https://www.microsoft.com/en-us/security/blog/2026/09/29/beyond-source-code-a-path-to-the-keys-to-the-kingdom/</link><guid isPermaLink="true">https://www.microsoft.com/en-us/security/blog/2026/09/29/beyond-source-code-a-path-to-the-keys-to-the-kingdom/</guid><description>Bron: Microsoft Security Blog (Prioriteit 1).

Explore how Storm-3068 turned a compromised identity into broader cloud access and the steps organizations can take to defend their identities, pipelines, and cloud infrastructure. The post ​​Beyond source code: A path to the keys to the kingdom appeared first on Microsoft Security Blog .</description><pubDate>Tue, 29 Sep 2026 16:00:00 GMT</pubDate></item><item><title>Automated AI agent used to breach cybersecurity nonprofit DIVD</title><link>https://www.bleepingcomputer.com/news/security/automated-ai-agent-used-to-breach-cybersecurity-nonprofit-divd/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/automated-ai-agent-used-to-breach-cybersecurity-nonprofit-divd/</guid><description>Bron: BleepingComputer (Prioriteit 2).

The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyberattack that the organization described as &quot;loud and very, very messy.&quot; [...]</description><pubDate>Tue, 29 Sep 2026 15:39:19 GMT</pubDate></item><item><title>&apos;NeedyMantis&apos; Provides Long-Term Access to Compromised Networks</title><link>https://www.darkreading.com/threat-intelligence/needymantis-long-term-access-compromised-networks</link><guid isPermaLink="true">https://www.darkreading.com/threat-intelligence/needymantis-long-term-access-compromised-networks</guid><description>Bron: Dark Reading (Prioriteit 2).

Microsoft observed a China-based actor using a previously unidentified malware framework in targeted intrusions against telcos, universities, medical, and government-related organizations.</description><pubDate>Tue, 29 Sep 2026 15:12:39 GMT</pubDate></item></channel></rss>