Malicious Custom GPT on chatgpt.com lures users into installing a RAT

Malware peddlers are using sponsored Google results to push a malicious ChatGPT Custom GPT named “Plus 5.6,” created to lead users to a fake Cloudflare CAPTCHA check and, ultimately, make them download and run a remote access trojan (RAT). … Continue reading Malicious Custom GPT on chatgpt.com lures users into installing a RAT→

Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950)

Apple has shipped iOS and macOS security updates to fix an actively exploited zero-day vulnerability (CVE-2026-86950) in the operating systems’ Core Graphics framework. “Apple is aware of a report that this issue may have been exploited in … Continue reading Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950)→

FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day

The FBI’s online portals for job applicants (at apply.fbijobs.gov) and special agent applicants (at fbijobs.gov/special-agents) are still unavailable, following what appears to be successful compromises by the ShinyHunters cyber extortion group. … Continue reading FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day→

Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)

Citrix has patched eight critical and high-severity vulnerabilities in NetScaler ADC and NetScaler Gateway, two of which (CVE-2026-88771, CVE-2026-88772) have been exploited in zero-day attacks to plant webshells on compromised devices. Rumors about th… Continue reading Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)→

OpenAI agent hacking spree widens to Australia, targeting government website

Before the Hugging Face and RubyGems hacks, autonomous OpenAI agents attempted to hack into three other websites, including an Australian government public health website, independent research lab Transluce revealed on Wednesday. “Notably, the ta… Continue reading OpenAI agent hacking spree widens to Australia, targeting government website→

DarkMe RAT trades zero-days for plain phishing emails

DarkMe, a remote access trojan and info-stealer that has previously been associated with a threat group that targeted financial market traders and cryptocurrency users, has been spotted again. This time around, its distribution has been simplified: ins… Continue reading DarkMe RAT trades zero-days for plain phishing emails→

Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances

Check Point Software has released emergency fixes for a critical Check Point Management Server vulnerability (CVE-2026-93616) that has been exploited as far back as July 23, 2026. The company also confirmed that a pre-authentication remote code executi… Continue reading Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances→

Brief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” page

Three domains / web portals belonging to Dutch academic publishing company Elsevier have been redirecting users to a page branded “LAPSUS$ GROUP, Chapter II,” carrying a signed statement that taunted the FBI and counted down to a future vic… Continue reading Brief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” page→

Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)

A Chinese-speaking threat actor has exploited a vulnerability (CVE-2026-7273) in unpatched ZyXEL GS1900 Smart Managed Switches and has exfiltrated sensitive data from 996 devices across 48 countries, GreyNoise reported on Monday. The affected switches … Continue reading Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)→