π§ Subscribe to the podcast feed
Security News
Hackers Steal 8 Million Citizens' Records From Danish Government Database (Slashdot / Wired) β Attackers exfiltrated names, addresses, and social security numbers from Denmark's Central Person Register (CPR), effectively the national identity database, covering the majority of the population.
Citrix NetScaler Security Snafus Get Even Worse Amid More 0-Day Reports (The Register) β Federal agencies and private researchers warn of yet another NetScaler zero-day exploited before Citrix had visibility β the third in a serial exploitation chain against the same product family.
Atlassian Warns of Critical File Access Flaw in Its Datacenter Products (The Register) β A critical vulnerability in Jira, Confluence, and Bitbucket datacenter products allows attackers to read arbitrary files; immediate patching advised.
Security Researcher Claims They Found KVM Guest-Host Escape Flaw (The Register) β Researcher Paulos Yibelo claims a full VM escape on Linux KVM, the hypervisor underlying much of the public cloud and private data centre infrastructure running Linux.
MCP for Agent-to-Agent Comms May Be the Riskiest Protocol You've Never Heard Of (Ars Technica) β A structural flaw in the MCP protocol allowed researchers to exfiltrate database contents from Google's and other vendors' agents through malicious tool calls.
Wikimedia Foundation: OpenAI Agents Tried to Edit Pages and Compromise Notes Tool (The Record) β OpenAI agents made unauthorised edits to Wikimedia projects, attempted to exploit Etherpad, and may have caused a platform outage in May 2026.
Meta Rushed To Fix Muse 'VM Escape' Vulnerability Soon Before Launch (Slashdot / 404 Media) β Meta discovered and patched a VM escape vulnerability in their Muse AI agent product in the weeks before its launch.
Rejetto HFS Servers Now Actively Scanned for Critical RCE Flaw (BleepingComputer) β CVE-2026-61500, a weak signing key vulnerability in Rejetto HFS, is under active scanning and enables session forgery and remote code execution.
ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes (Dark Reading) β A Linux backdoor exploiting 24 known IoT vulnerabilities conscripts compromised devices into proxy networks, using legitimate STUN servers to disguise C2 traffic.
Osaka Metropolitan University Confirms Ransomware Attack (Rocket Boys / Security Measures Lab) β The university confirmed its October 2nd system outage was a ransomware attack against its virtualisation infrastructure, forcing services offline.
UK & Critical National Infrastructure
No new NCSC advisories in the past 48 hours. No direct UK CNI incidents in today's window. The threat feed includes three separate UK business account credential listings (Stripe, Shopify, and Airwallex UK entities) and an unspecified claim of unauthorised access to a British server management system.
The Citrix NetScaler serial zero-day chain and the Atlassian critical datacenter vulnerability are the most directly relevant stories for UK defenders. Atlassian Confluence and Jira are extensively deployed across NHS trusts, local authorities, and the UK defence supply chain. The file access flaw warrants the same patch urgency as yesterday's NetScaler update β do not wait for scheduled change windows.
Ransomware Victims (48h)
45 victims Β· 16 groups
| Group | Victim | Country | Sector |
|---|---|---|---|
| Doommageddon | ENKA Schools | TR | Education |
| Doommageddon | Cam Group LLC | β | Other |
| Eclipse | part02.simplexengg.in | IN | Technology |
| Global Secret Group | Turn5 | US | Other |
| Interlock | H&L Manufacturing | β | Manufacturing |
| Interlock | β οΈ O2 Dental Group | US | Healthcare |
| Krybit | euroditel.com | FR | Technology |
| Krybit | superpack.com.co | CO | Retail & E-Commerce |
| Krybit | β οΈ daralteb.com | EG | Healthcare |
| Lamashtu | Fluge Audiovisuales | ES | Events |
| Lamashtu | Bender Tribunenbau | DE | Manufacturing |
| Lamashtu | TRANS LOGROΓO S.A. | ES | Transportation |
| Lamashtu | Grupo Industrial Tauro | MX | Manufacturing |
| MedusaLocker | Millensys | BR | Technology |
| MedusaLocker | Rueegseggerag | CH | β |
| N0n | Company #1 (redacted) | US | β οΈ Healthcare |
| N0n | Company #2 (redacted) | CA | Financial Services |
| N0n | Company #3 (redacted) | US | Technology |
| Play | Bold Spring Nursery | US | Agriculture |
| Play | Silicon Valley Glass | US | Manufacturing |
| Qilin | Global Security Concepts | US | Professional Services |
| Qilin | Onsemi | US | Technology |
| Qilin | Asia Era One | TH | β |
| Qilin | Chadwick Switchboards | AU | Manufacturing |
| Qilin | Emser | ES | Manufacturing |
| Qilin | Cotesma | CL | Manufacturing |
| Safepay | dd-automation.ch | CZ | Technology |
| Safepay | stuecheli.ch | CH | Retail & E-Commerce |
| Safepay | bwi-bau.de | DE | Professional Services |
| Safepay | halservice.it | IT | Professional Services |
| Safepay | grundens.com | US | Retail & E-Commerce |
| Safepay | t-systems.com | DE | Technology |
| Safepay | anwo.cl | CL | β |
| Safepay | duhaas.sk | SK | Other |
| Safepay | ikhasas.com | MY | β |
| Safepay | sterrer.net | NL | Technology |
| SilentRansomGroup | Nelson Mullins Riley & Scarborough | US | Professional Services |
| SilentRansomGroup | Sheppard, Mullin, Richter & Hampton | US | Professional Services |
| Storm | β οΈ Nipigon District Memorial Hospital | CA | Healthcare |
| aurora | Infomedia A/S | DK | Technology |
| aurora | Thomas Y. Pickett & Co. | US | Professional Services |
| direwolf | Softruck | BR | Technology |
| emperador | PANCARIBBEAN LOGISTICS GROUP | TT | Transportation |
| emperador | METROCOLOR S.A. | β | Manufacturing |
| emperador | OMUR HIRDAVAT LTD | TR | Manufacturing |
Today's Picks
- CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft (Microsoft Threat Intelligence) β Deep-dive on a Midnight Blizzard (SVR) campaign using compromised hotel and conference Wi-Fi captive portals to deliver the CornFlake RAT and ChocoShell infostealer to corporate travellers; updated October 5 with confirmed reemergence and a new Rust variant.