<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SecuBuzz · Cybersecurity News Briefs</title>
    <link>https://secubuzz.com/news</link>
    <description>Fast, factual 60-word cybersecurity briefs and CISA KEV alerts for security professionals.</description>
    <language>en-us</language>
    <lastBuildDate>Wed, 30 Sep 2026 23:06:39 GMT</lastBuildDate>
    <atom:link href="https://secubuzz.com/rss.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title><![CDATA[Russian State Hackers Deploy CosmicPulse Backdoor via RedFlick Technique]]></title>
      <link>https://secubuzz.com/news/russian-state-hackers-deploy-cosmicpulse-backdoor-274a52</link>
      <guid isPermaLink="true">https://secubuzz.com/news/russian-state-hackers-deploy-cosmicpulse-backdoor-274a52</guid>
      <description><![CDATA[Russian state actor Star Blizzard has introduced a new malware installation method called RedFlick to deploy its CosmicPulse backdoor. The technique allows the actor to push malicious code onto targeted systems, potentially enabling persistent access and data exfiltration. No public patch or mitigation is currently available.]]></description>
      <pubDate>Wed, 30 Sep 2026 20:34:01 GMT</pubDate>
      <source url="https://www.bleepingcomputer.com/news/security/russian-state-hackers-use-new-redflick-technique-to-push-malware/">BleepingComputer</source>
      <category>NATION_STATE</category>
    </item>
    <item>
      <title><![CDATA[Automakers Share Connected-Car Data with Third-Party Advertisers]]></title>
      <link>https://secubuzz.com/news/automakers-share-connected-car-data-with-third-par-387b72</link>
      <guid isPermaLink="true">https://secubuzz.com/news/automakers-share-connected-car-data-with-third-par-387b72</guid>
      <description><![CDATA[A study shows that automakers routinely provide personally identifiable connected-car data to a network of large corporations involved in advertising. The data sharing exposes drivers to extensive tracking and profiling by third parties, raising privacy concerns about the use of vehicle telemetry for targeted marketing.]]></description>
      <pubDate>Wed, 30 Sep 2026 20:32:00 GMT</pubDate>
      <source url="https://therecord.media/automakers-routinely-share-connected-car-data-third-parties">The Record</source>
      <category>GENERAL</category>
    </item>
    <item>
      <title><![CDATA[Zero-Day Vulnerabilities in Zammad Enable Network Breach]]></title>
      <link>https://secubuzz.com/news/zero-day-vulnerabilities-in-zammad-enable-network-2db3ff</link>
      <guid isPermaLink="true">https://secubuzz.com/news/zero-day-vulnerabilities-in-zammad-enable-network-2db3ff</guid>
      <description><![CDATA[The Dutch Institute for Vulnerability Disclosure reported that a chain of two zero-day flaws in the open-source Zammad ticketing system allowed attackers to breach its network. The exploit leveraged undisclosed vulnerabilities to gain unauthorized access, compromising internal systems. No public fix is available yet, and the issue remains unpatched.]]></description>
      <pubDate>Wed, 30 Sep 2026 19:49:15 GMT</pubDate>
      <source url="https://www.bleepingcomputer.com/news/security/divd-says-zammad-zero-days-enabled-ai-driven-network-breach/">BleepingComputer</source>
      <category>VULNERABILITY</category>
    </item>
    <item>
      <title><![CDATA[Pentagon Issues Cyber Command Notice Amid Suicide Death Reports]]></title>
      <link>https://secubuzz.com/news/pentagon-issues-cyber-command-notice-amid-suicide-2a73f8</link>
      <guid isPermaLink="true">https://secubuzz.com/news/pentagon-issues-cyber-command-notice-amid-suicide-2a73f8</guid>
      <description><![CDATA[Following reports of multiple suicide deaths, the Pentagon’s assistant secretary for cyber policy issued a memo demanding specific actions from U.S. Cyber Command leadership. The notice highlights concerns over cyber-related incidents and calls for enhanced oversight and response measures within the command.]]></description>
      <pubDate>Wed, 30 Sep 2026 19:35:00 GMT</pubDate>
      <source url="https://therecord.media/cyber-command-suicide-deaths-pentagon-memo">The Record</source>
      <category>GENERAL</category>
    </item>
    <item>
      <title><![CDATA[Google Reports 10,000 Monthly Vulnerability Disclosures, AI Accelerates Exploitation]]></title>
      <link>https://secubuzz.com/news/google-reports-10-000-monthly-vulnerability-disclo-138419</link>
      <guid isPermaLink="true">https://secubuzz.com/news/google-reports-10-000-monthly-vulnerability-disclo-138419</guid>
      <description><![CDATA[Google researchers warned that vulnerability disclosures have doubled to over 10,000 per month, with artificial intelligence driving the increase. The surge highlights growing exploitation activity, though no specific vulnerabilities or exploits are named. The trend underscores the need for continuous patching and monitoring.]]></description>
      <pubDate>Wed, 30 Sep 2026 19:00:00 GMT</pubDate>
      <source url="https://therecord.media/google-vulnerabilities-cyberattacks-ai">The Record</source>
      <category>VULNERABILITY</category>
    </item>
    <item>
      <title><![CDATA[AI Boosts SOC Satisfaction to 91% While Entry Barriers Rise]]></title>
      <link>https://secubuzz.com/news/ai-boosts-soc-satisfaction-to-91-while-entry-barri-7da85a</link>
      <guid isPermaLink="true">https://secubuzz.com/news/ai-boosts-soc-satisfaction-to-91-while-entry-barri-7da85a</guid>
      <description><![CDATA[Swimlane research shows that AI-driven detection and response has raised overall SOC satisfaction to 91%. However, nearly half of security professionals find entry into the field harder, and one in four say AI limits skill development. The study highlights a paradox in the evolving security workforce.]]></description>
      <pubDate>Wed, 30 Sep 2026 18:56:56 GMT</pubDate>
      <source url="https://www.darkreading.com/cybersecurity-careers/ai-reshapes-soc-career-ladder">Dark Reading</source>
      <category>GENERAL</category>
    </item>
    <item>
      <title><![CDATA[Over 543,000 Valid Credentials Exposed in Public GitHub Repositories]]></title>
      <link>https://secubuzz.com/news/over-543-000-valid-credentials-exposed-in-public-g-50aed2</link>
      <guid isPermaLink="true">https://secubuzz.com/news/over-543-000-valid-credentials-exposed-in-public-g-50aed2</guid>
      <description><![CDATA[More than 543,000 active credentials were discovered in public GitHub repositories, remaining valid in July. The leak included usernames and passwords that could be used to access corporate and personal accounts. No immediate patch is required, but affected users should change passwords and enable multi‑factor authentication.]]></description>
      <pubDate>Wed, 30 Sep 2026 18:08:34 GMT</pubDate>
      <source url="https://www.bleepingcomputer.com/news/security/over-543-000-valid-credentials-exposed-in-public-github-repositories/">BleepingComputer</source>
      <category>BREACH</category>
    </item>
    <item>
      <title><![CDATA[Attackers Exploit CVE-2026-73570 to Deploy Web Shells and Harvest Zimbra Secrets]]></title>
      <link>https://secubuzz.com/news/attackers-exploit-cve-2026-73570-to-deploy-web-she-5b71d9</link>
      <guid isPermaLink="true">https://secubuzz.com/news/attackers-exploit-cve-2026-73570-to-deploy-web-she-5b71d9</guid>
      <description><![CDATA[Threat actors weaponized CVE-2026-73570, an unauthenticated OS command‑injection flaw in Zimbra Collaboration Suite, to deploy web shells and steal authentication secrets. The vulnerability allows remote code execution via SNMP, enabling attackers to access mailbox data. Microsoft has issued a patch; users should update Zimbra immediately.]]></description>
      <pubDate>Wed, 30 Sep 2026 16:46:29 GMT</pubDate>
      <source url="https://thehackernews.com/2026/09/attackers-exploit-zimbra-flaw-to-deploy.html">The Hacker News</source>
      <category>CVE</category>
    </item>
    <item>
      <title><![CDATA[Phishers Use MSP360 to Deploy Remote Management Tool]]></title>
      <link>https://secubuzz.com/news/phishers-use-msp360-to-deploy-remote-management-to-6cf2f9</link>
      <guid isPermaLink="true">https://secubuzz.com/news/phishers-use-msp360-to-deploy-remote-management-to-6cf2f9</guid>
      <description><![CDATA[Attackers distributed a legitimate MSP360 installer disguised as meeting invites and software updates. Once run, the installer granted remote management access via ScreenConnect, enabling attackers to control victim systems. The campaign relies on social engineering and legitimate software to bypass defenses.]]></description>
      <pubDate>Wed, 30 Sep 2026 16:32:59 GMT</pubDate>
      <source url="https://thehackernews.com/2026/09/attackers-abuse-msp360-to-deploy.html">The Hacker News</source>
      <category>BREACH</category>
    </item>
    <item>
      <title><![CDATA[WizOS Helm Charts Offer Hardened Kubernetes Deployments]]></title>
      <link>https://secubuzz.com/news/wizos-helm-charts-offer-hardened-kubernetes-deploy-1c9332</link>
      <guid isPermaLink="true">https://secubuzz.com/news/wizos-helm-charts-offer-hardened-kubernetes-deploy-1c9332</guid>
      <description><![CDATA[WizOS introduces signed, CVE‑scanned Helm charts that harden Kubernetes supply chains. The charts eliminate hidden CI/CD risks and unmaintained dependencies, providing a secure, seamless deployment path for Kubernetes environments.]]></description>
      <pubDate>Wed, 30 Sep 2026 15:52:31 GMT</pubDate>
      <source url="https://www.wiz.io/blog/wizos-helm-charts">Wiz Research</source>
      <category>GENERAL</category>
    </item>
    <item>
      <title><![CDATA[CISA Warns of Critical Pre-Auth RCE in MikroTik RouterOS]]></title>
      <link>https://secubuzz.com/news/cisa-warns-of-critical-pre-auth-rce-in-mikrotik-ro-5bdc14</link>
      <guid isPermaLink="true">https://secubuzz.com/news/cisa-warns-of-critical-pre-auth-rce-in-mikrotik-ro-5bdc14</guid>
      <description><![CDATA[CISA has identified a critical pre-authentication remote code execution flaw in MikroTik RouterOS that can allow attackers to execute arbitrary code or cause a denial‑of‑service. The vulnerability affects all RouterOS versions and requires no user interaction. MikroTik has released patches; users should update immediately to mitigate the risk.]]></description>
      <pubDate>Wed, 30 Sep 2026 15:49:29 GMT</pubDate>
      <source url="https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-pre-auth-rce-flaw-in-mikrotik-routeros/">BleepingComputer</source>
      <category>VULNERABILITY</category>
    </item>
    <item>
      <title><![CDATA[Cisco Issues Advisory for CVE-2026-76504 Authentication Bypass in SD‑WAN Manager]]></title>
      <link>https://secubuzz.com/news/cisco-issues-advisory-for-cve-2026-76504-authentic-4676dd</link>
      <guid isPermaLink="true">https://secubuzz.com/news/cisco-issues-advisory-for-cve-2026-76504-authentic-4676dd</guid>
      <description><![CDATA[Cisco has warned that attackers are exploiting CVE-2026-76504, a critical authentication bypass in Cisco Catalyst SD‑WAN Manager. The flaw lets unauthenticated attackers use the Manager’s API with admin privileges, enabling full control over SD‑WAN networks. Fixed releases are available; no workaround exists, so users must apply the patch promptly.]]></description>
      <pubDate>Wed, 30 Sep 2026 15:24:54 GMT</pubDate>
      <source url="https://thehackernews.com/2026/09/cisco-warns-of-attackers-exploiting.html">The Hacker News</source>
      <category>CVE</category>
    </item>
    <item>
      <title><![CDATA[ChatGPT Custom GPTs Used to Deliver Remote Access Trojan via ClickFix Lures]]></title>
      <link>https://secubuzz.com/news/chatgpt-custom-gpts-used-to-deliver-remote-access-6095a1</link>
      <guid isPermaLink="true">https://secubuzz.com/news/chatgpt-custom-gpts-used-to-deliver-remote-access-6095a1</guid>
      <description><![CDATA[Threat actors are exploiting ChatGPT Custom GPTs to masquerade as legitimate products, directing users to malicious sites that employ ClickFix lures. The technique delivers a remote access trojan, relying on user interaction and phishing.]]></description>
      <pubDate>Wed, 30 Sep 2026 15:00:15 GMT</pubDate>
      <source url="https://thehackernews.com/2026/09/attackers-abuse-chatgpt-custom-gpts-to.html">The Hacker News</source>
      <category>GENERAL</category>
    </item>
    <item>
      <title><![CDATA[AI Co‑workers Threaten Existing Security Models]]></title>
      <link>https://secubuzz.com/news/ai-co-workers-threaten-existing-security-models-537447</link>
      <guid isPermaLink="true">https://secubuzz.com/news/ai-co-workers-threaten-existing-security-models-537447</guid>
      <description><![CDATA[Persistent AI coworkers can operate continuously with standing access, exposing identity risks that current security models were not designed to handle. Token Security recommends giving each agent its own identity, owner, scoped permissions, and lifecycle controls to mitigate these risks.]]></description>
      <pubDate>Wed, 30 Sep 2026 14:01:11 GMT</pubDate>
      <source url="https://www.bleepingcomputer.com/news/security/ais-third-wave-coworkers-break-the-security-model-that-worked-for-agents/">BleepingComputer</source>
      <category>VULNERABILITY</category>
    </item>
    <item>
      <title><![CDATA[Ukrainian Researchers Warn of DarkSword iPhone Malware Exploit Kit]]></title>
      <link>https://secubuzz.com/news/ukrainian-researchers-warn-of-darksword-iphone-mal-23f8f9</link>
      <guid isPermaLink="true">https://secubuzz.com/news/ukrainian-researchers-warn-of-darksword-iphone-mal-23f8f9</guid>
      <description><![CDATA[Ukrainian SSSCIP researchers identified DarkSword, a hit‑and‑run iPhone malware part of a wave of Russian attacks on iOS and Android devices. The kit exploits iOS vulnerabilities to deliver malicious payloads, highlighting the need for updated mobile security defenses.]]></description>
      <pubDate>Wed, 30 Sep 2026 14:00:00 GMT</pubDate>
      <source url="https://therecord.media/ukraine-ssscip-mobile-malware-warning-ios-android">The Record</source>
      <category>VULNERABILITY</category>
    </item>
    <item>
      <title><![CDATA[Microsoft Enhances Entra ID Protection Against External Script Injection]]></title>
      <link>https://secubuzz.com/news/microsoft-enhances-entra-id-protection-against-ext-2c8dce</link>
      <guid isPermaLink="true">https://secubuzz.com/news/microsoft-enhances-entra-id-protection-against-ext-2c8dce</guid>
      <description><![CDATA[Microsoft will strengthen Entra ID authentication to block external script injection attacks starting October. The update aims to prevent attackers from injecting malicious scripts into authentication flows, reducing the risk of credential theft and session hijacking. Users should ensure their Entra ID environment is updated before the rollout.]]></description>
      <pubDate>Wed, 30 Sep 2026 13:37:15 GMT</pubDate>
      <source url="https://www.bleepingcomputer.com/news/security/microsoft-to-block-entra-id-script-injection-attacks-starting-october/">BleepingComputer</source>
      <category>VULNERABILITY</category>
    </item>
    <item>
      <title><![CDATA[WatchGuard Releases Patches for Critical Fireware OS Code Injection Vulnerabilities]]></title>
      <link>https://secubuzz.com/news/watchguard-releases-patches-for-critical-fireware-2fd6ad</link>
      <guid isPermaLink="true">https://secubuzz.com/news/watchguard-releases-patches-for-critical-fireware-2fd6ad</guid>
      <description><![CDATA[WatchGuard has issued patches addressing 15 bugs in Fireware OS, including code execution, denial‑of‑service, authorization bypass, and path traversal flaws. The updates mitigate potential remote code execution and denial‑of‑service attacks against Fireware OS devices. Users should apply the latest firmware to secure their network appliances.]]></description>
      <pubDate>Wed, 30 Sep 2026 13:16:56 GMT</pubDate>
      <source url="https://www.securityweek.com/watchguard-patches-critical-fireware-os-code-injection-vulnerability/">SecurityWeek</source>
      <category>VULNERABILITY</category>
    </item>
    <item>
      <title><![CDATA[Cloudflare Impact Reaches $100 Million in Donations]]></title>
      <link>https://secubuzz.com/news/cloudflare-impact-reaches-100-million-in-donations-56c6f4</link>
      <guid isPermaLink="true">https://secubuzz.com/news/cloudflare-impact-reaches-100-million-in-donations-56c6f4</guid>
      <description><![CDATA[Cloudflare’s Impact program has reached a $100 million milestone in donated services, shielding thousands of entities—including journalists, civil society groups, state and local governments, election bodies, and public schools—from cyberattacks. The initiative expands protection for vulnerable organizations worldwide in the coming months.]]></description>
      <pubDate>Wed, 30 Sep 2026 13:01:55 GMT</pubDate>
      <source url="https://blog.cloudflare.com/100-million-donations/">Cloudflare Security</source>
      <category>GENERAL</category>
    </item>
    <item>
      <title><![CDATA[Cloudflare Workers Adds Built‑in Error Monitoring to Send Issues to Coding Agents]]></title>
      <link>https://secubuzz.com/news/cloudflare-workers-adds-built-in-error-monitoring-7b5d88</link>
      <guid isPermaLink="true">https://secubuzz.com/news/cloudflare-workers-adds-built-in-error-monitoring-7b5d88</guid>
      <description><![CDATA[Cloudflare Workers now includes built‑in error monitoring that groups production failures and forwards stack traces, logs, traces, and application context directly to a coding agent. The feature enables developers to investigate issues faster and automatically open pull requests, streamlining debugging and deployment workflows.]]></description>
      <pubDate>Wed, 30 Sep 2026 13:00:00 GMT</pubDate>
      <source url="https://blog.cloudflare.com/real-time-issue-detection/">Cloudflare Security</source>
      <category>GENERAL</category>
    </item>
    <item>
      <title><![CDATA[NetScaler Zero-Day Attacks Target Government and Finance Organizations]]></title>
      <link>https://secubuzz.com/news/netscaler-zero-day-attacks-target-government-and-f-bbac2a</link>
      <guid isPermaLink="true">https://secubuzz.com/news/netscaler-zero-day-attacks-target-government-and-f-bbac2a</guid>
      <description><![CDATA[Security firms confirmed exploitation of NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772, affecting government and finance entities over several weeks. The zero-day flaws enable remote code execution, compromising critical infrastructure. Immediate patching and vulnerability management are required to mitigate the threat.]]></description>
      <pubDate>Wed, 30 Sep 2026 12:48:20 GMT</pubDate>
      <source url="https://www.securityweek.com/government-finance-orgs-targeted-in-weeks-long-netscaler-zero-day-attacks/">SecurityWeek</source>
      <category>CVE</category>
    </item>
    <item>
      <title><![CDATA[TeamViewer Urges Immediate Patch for High‑Severity Vulnerabilities]]></title>
      <link>https://secubuzz.com/news/teamviewer-urges-immediate-patch-for-high-severity-7bdbf4</link>
      <guid isPermaLink="true">https://secubuzz.com/news/teamviewer-urges-immediate-patch-for-high-severity-7bdbf4</guid>
      <description><![CDATA[TeamViewer has warned users to patch a set of high‑severity flaws in its client and host software as soon as possible. The vulnerabilities could allow attackers to gain unauthorized access or execute code on affected systems. Users should download the latest updates from TeamViewer’s website to mitigate the risk.]]></description>
      <pubDate>Wed, 30 Sep 2026 12:25:10 GMT</pubDate>
      <source url="https://www.bleepingcomputer.com/news/security/teamviewer-urges-users-to-patch-severe-flaws-as-soon-as-possible/">BleepingComputer</source>
      <category>VULNERABILITY</category>
    </item>
    <item>
      <title><![CDATA[Chrome and Firefox Patch Over 100 Vulnerabilities, Including RCE Flaws]]></title>
      <link>https://secubuzz.com/news/chrome-and-firefox-patch-over-100-vulnerabilities-6677ea</link>
      <guid isPermaLink="true">https://secubuzz.com/news/chrome-and-firefox-patch-over-100-vulnerabilities-6677ea</guid>
      <description><![CDATA[Chrome and Firefox updates address more than 100 security issues, some permitting remote attackers to execute arbitrary code or escape browser sandboxes. The patches close potential exploitation vectors that could lead to system compromise. Users should install the latest browser versions to maintain protection.]]></description>
      <pubDate>Wed, 30 Sep 2026 12:16:52 GMT</pubDate>
      <source url="https://www.securityweek.com/chrome-firefox-updates-patch-over-100-vulnerabilities/">SecurityWeek</source>
      <category>VULNERABILITY</category>
    </item>
    <item>
      <title><![CDATA[Browser-Based Attack Techniques Dominating 2026 Threat Landscape]]></title>
      <link>https://secubuzz.com/news/browser-based-attack-techniques-dominating-2026-th-6478aa</link>
      <guid isPermaLink="true">https://secubuzz.com/news/browser-based-attack-techniques-dominating-2026-th-6478aa</guid>
      <description><![CDATA[In 2026, attackers increasingly exploit browsers to launch full attack chains, from initial access to data exfiltration, without leaving the session. Security teams should monitor six high‑risk techniques, including XSS, CSRF, and malicious extensions, to defend against evolving web‑based threats.]]></description>
      <pubDate>Wed, 30 Sep 2026 11:58:00 GMT</pubDate>
      <source url="https://thehackernews.com/2026/09/know-your-enemy-browser-based-attack.html">The Hacker News</source>
      <category>GENERAL</category>
    </item>
    <item>
      <title><![CDATA[Anthropic Highlights AI Agent Liability Amid OpenAI Lawsuit]]></title>
      <link>https://secubuzz.com/news/anthropic-highlights-ai-agent-liability-amid-opena-c2a227</link>
      <guid isPermaLink="true">https://secubuzz.com/news/anthropic-highlights-ai-agent-liability-amid-opena-c2a227</guid>
      <description><![CDATA[Anthropic has warned about liability risks for autonomous AI agents as OpenAI faces a hacking lawsuit. The discussion focuses on legal accountability for AI actions, reflecting growing concerns over AI‑driven attacks and their regulatory implications.]]></description>
      <pubDate>Wed, 30 Sep 2026 11:19:00 GMT</pubDate>
      <source url="https://www.securityweek.com/anthropic-flags-ai-agent-liability-risks-as-openai-faces-hacking-lawsuit/">SecurityWeek</source>
      <category>GENERAL</category>
    </item>
    <item>
      <title><![CDATA[US‑Focused Phishing Campaign Steals Microsoft 365 Sessions and Deploys RMM Tools]]></title>
      <link>https://secubuzz.com/news/us-focused-phishing-campaign-steals-microsoft-365-1fba45</link>
      <guid isPermaLink="true">https://secubuzz.com/news/us-focused-phishing-campaign-steals-microsoft-365-1fba45</guid>
      <description><![CDATA[Researchers traced a phishing campaign targeting US organizations that stole Microsoft 365 session tokens and installed remote‑access tools. The attackers used the stolen sessions to gain broader account compromise and potential fraud. Organizations should monitor for unusual RMM tool activity and enforce MFA on Microsoft 365 accounts.]]></description>
      <pubDate>Wed, 30 Sep 2026 10:45:00 GMT</pubDate>
      <source url="https://thehackernews.com/2026/09/us-focused-csuite-phishing-steals.html">The Hacker News</source>
      <category>BREACH</category>
    </item>
    <item>
      <title><![CDATA[OpenInfra Europe’s JFrog Artifactory Compromised via CVE-2026-82329]]></title>
      <link>https://secubuzz.com/news/openinfra-europe-s-jfrog-artifactory-compromised-v-4cd905</link>
      <guid isPermaLink="true">https://secubuzz.com/news/openinfra-europe-s-jfrog-artifactory-compromised-v-4cd905</guid>
      <description><![CDATA[Attackers breached a self-hosted JFrog Artifactory instance operated by OpenInfra Europe, exploiting CVE-2026-82329. Users who downloaded or installed artifacts from https://artifactory.nordix.org/ between August 28 and September 15, 2026 should immediately stop using them, remove them from pipelines, and treat the packages as potentially compromised.]]></description>
      <pubDate>Wed, 30 Sep 2026 10:39:26 GMT</pubDate>
      <source url="https://www.helpnetsecurity.com/2026/09/30/openinfra-jfrog-artifactory-instance-compromised/">Help Net Security</source>
      <category>CVE</category>
    </item>
    <item>
      <title><![CDATA[ShinyHunters Denies Publishing FBI Data After Arrest of Suspected Leader]]></title>
      <link>https://secubuzz.com/news/shinyhunters-denies-publishing-fbi-data-after-arre-6a6aa7</link>
      <guid isPermaLink="true">https://secubuzz.com/news/shinyhunters-denies-publishing-fbi-data-after-arre-6a6aa7</guid>
      <description><![CDATA[ShinyHunters, a hacker collective, has denied publishing data allegedly stolen from the FBI after a suspected leader’s arrest. The group claims it never intended to release the information, despite FBI calls for members to come forward. The incident highlights ongoing tensions between the collective and law enforcement.]]></description>
      <pubDate>Wed, 30 Sep 2026 10:20:02 GMT</pubDate>
      <source url="https://www.securityweek.com/shinyhunters-defiant-after-fbi-calls-on-members-to-come-forward/">SecurityWeek</source>
      <category>BREACH</category>
    </item>
    <item>
      <title><![CDATA[Former US Air Force Members Sentenced for Million-Dollar Business Email Compromise Scheme]]></title>
      <link>https://secubuzz.com/news/former-us-air-force-members-sentenced-for-million-16c94c</link>
      <guid isPermaLink="true">https://secubuzz.com/news/former-us-air-force-members-sentenced-for-million-16c94c</guid>
      <description><![CDATA[Two former Air Force personnel, Chijioke Timothy Odimegwu and Harafat Mogaji, were sentenced to 189 months for running a BEC and phishing operation that targeted U.S. businesses. They sent spam emails to steal employee usernames and passwords, compromising corporate email accounts.]]></description>
      <pubDate>Wed, 30 Sep 2026 07:42:11 GMT</pubDate>
      <source url="https://www.helpnetsecurity.com/2026/09/30/air-force-members-sentenced-bec-phishing/">Help Net Security</source>
      <category>BREACH</category>
    </item>
    <item>
      <title><![CDATA[South Africa Seeks Assistance After Ransomware Toolkit Hits Air Traffic Control Network]]></title>
      <link>https://secubuzz.com/news/south-africa-seeks-assistance-after-ransomware-too-595911</link>
      <guid isPermaLink="true">https://secubuzz.com/news/south-africa-seeks-assistance-after-ransomware-too-595911</guid>
      <description><![CDATA[A ransomware toolkit was installed on at least one operational South African air traffic control network, prompting authorities to seek external help. The attack targeted aviation infrastructure, potentially disrupting air traffic management systems and raising concerns about critical national infrastructure security.]]></description>
      <pubDate>Wed, 30 Sep 2026 07:00:00 GMT</pubDate>
      <source url="https://www.darkreading.com/cyberattacks-data-breaches/south-africa-help-cyberattack-air-traffic-control">Dark Reading</source>
      <category>RANSOMWARE</category>
    </item>
    <item>
      <title><![CDATA[OpenSSL and WolfSSL Patch High‑Severity Vulnerabilities]]></title>
      <link>https://secubuzz.com/news/openssl-and-wolfssl-patch-high-severity-vulnerabil-470bf2</link>
      <guid isPermaLink="true">https://secubuzz.com/news/openssl-and-wolfssl-patch-high-severity-vulnerabil-470bf2</guid>
      <description><![CDATA[SecurityWeek reports that each of the open‑source cryptographic libraries, OpenSSL and WolfSSL, has received patches for roughly a dozen high‑severity vulnerabilities. The updates address critical flaws that could allow attackers to compromise encrypted communications or execute arbitrary code. Users should apply the latest releases to mitigate potential exploitation.]]></description>
      <pubDate>Wed, 30 Sep 2026 06:55:50 GMT</pubDate>
      <source url="https://www.securityweek.com/high-severity-vulnerabilities-patched-in-openssl-wolfssl/">SecurityWeek</source>
      <category>VULNERABILITY</category>
    </item>
    <item>
      <title><![CDATA[Genea Launches AI‑Enabled Access Control Platform]]></title>
      <link>https://secubuzz.com/news/genea-launches-ai-enabled-access-control-platform-4b9644</link>
      <guid isPermaLink="true">https://secubuzz.com/news/genea-launches-ai-enabled-access-control-platform-4b9644</guid>
      <description><![CDATA[Genea has unveiled Genea MCP, a Model Context Protocol server that connects AI agents directly to its access control system. The new tool enables role‑based permissions to be configured with a single sentence, streamlining onboarding and temporary access. The release positions Genea among the first providers to offer a native MCP server.]]></description>
      <pubDate>Wed, 30 Sep 2026 06:49:24 GMT</pubDate>
      <source url="https://www.helpnetsecurity.com/2026/09/30/genea-mcp/">Help Net Security</source>
      <category>GENERAL</category>
    </item>
    <item>
      <title><![CDATA[Security Tools Now Scan Claude Enterprise Chats for Sensitive Data]]></title>
      <link>https://secubuzz.com/news/security-tools-now-scan-claude-enterprise-chats-fo-7a7236</link>
      <guid isPermaLink="true">https://secubuzz.com/news/security-tools-now-scan-claude-enterprise-chats-fo-7a7236</guid>
      <description><![CDATA[Over 100 security and compliance vendors now integrate with the Claude Compliance API, allowing companies to monitor Claude Enterprise activity. The feed captures conversations, uploaded files, projects, cowork and code sessions, prompts, responses, and tool calls, helping detect and protect sensitive information.]]></description>
      <pubDate>Wed, 30 Sep 2026 06:31:58 GMT</pubDate>
      <source url="https://www.helpnetsecurity.com/2026/09/30/claude-compliance-api-integrations/">Help Net Security</source>
      <category>GENERAL</category>
    </item>
    <item>
      <title><![CDATA[OWASP Noir Revealed as Open-Source Static Analysis Tool]]></title>
      <link>https://secubuzz.com/news/owasp-noir-revealed-as-open-source-static-analysis-6c7219</link>
      <guid isPermaLink="true">https://secubuzz.com/news/owasp-noir-revealed-as-open-source-static-analysis-6c7219</guid>
      <description><![CDATA[OWASP Noir is an open-source static analysis tool that scans application source code to list exposed endpoints, including paths, HTTP methods, parameters, headers, and cookies, with file and line references. It highlights shadow APIs, deprecated routes, and undocumented handlers, aiding developers in identifying hidden or unused endpoints.]]></description>
      <pubDate>Wed, 30 Sep 2026 05:30:36 GMT</pubDate>
      <source url="https://www.helpnetsecurity.com/2026/09/30/owasp-noir-open-source-static-analysis-tool/">Help Net Security</source>
      <category>GENERAL</category>
    </item>
    <item>
      <title><![CDATA[EU Cyber Resilience Act Imposes Container and Kubernetes Security Requirements]]></title>
      <link>https://secubuzz.com/news/eu-cyber-resilience-act-imposes-container-and-kube-1c1b66</link>
      <guid isPermaLink="true">https://secubuzz.com/news/eu-cyber-resilience-act-imposes-container-and-kube-1c1b66</guid>
      <description><![CDATA[The EU Cyber Resilience Act (CRA) mandates cybersecurity requirements for products with digital elements sold in the EU, effective Dec. 10, 2024. Reporting obligations begin Sept. 11, 2026, with full enforcement Dec. 11, 2027. The regulation introduces new requirements for teams working with containers and Kubernetes throughout the application lifecycle.]]></description>
      <pubDate>Wed, 30 Sep 2026 05:00:53 GMT</pubDate>
      <source url="https://www.helpnetsecurity.com/2026/09/30/rapidfort-cra-container-compliance/">Help Net Security</source>
      <category>GENERAL</category>
    </item>
    <item>
      <title><![CDATA[BH Consulting Launches BH Haven SME Cybersecurity Service with AI Support]]></title>
      <link>https://secubuzz.com/news/bh-consulting-launches-bh-haven-sme-cybersecurity-537398</link>
      <guid isPermaLink="true">https://secubuzz.com/news/bh-consulting-launches-bh-haven-sme-cybersecurity-537398</guid>
      <description><![CDATA[BH Consulting has introduced BH Haven, a continuous service for Irish SMEs that pairs specialist consultants with a proprietary AI tool for analysis, evidence review, regulatory mapping and reporting. The offering prioritises Ireland, the UK, Nordic and other EU markets, helping clients comply with GDPR, NIS2 and the EU AI Act.]]></description>
      <pubDate>Wed, 30 Sep 2026 04:30:17 GMT</pubDate>
      <source url="https://www.helpnetsecurity.com/2026/09/30/bh-haven-sme-cybersecurity-service/">Help Net Security</source>
      <category>GENERAL</category>
    </item>
    <item>
      <title><![CDATA[Most Critical and High Vulnerabilities Remain Unpatched Over 90 Days]]></title>
      <link>https://secubuzz.com/news/most-critical-and-high-vulnerabilities-remain-unpa-3393d9</link>
      <guid isPermaLink="true">https://secubuzz.com/news/most-critical-and-high-vulnerabilities-remain-unpa-3393d9</guid>
      <description><![CDATA[Detectify examined 1,293 customers across the US, UK, and Nordics, finding that 97% of critical and 92% of high‑severity flaws in the Nordics, and 86% in the US, had been exposed for more than 90 days. The study highlights a widespread lag in patching internet‑facing systems.]]></description>
      <pubDate>Wed, 30 Sep 2026 04:00:38 GMT</pubDate>
      <source url="https://www.helpnetsecurity.com/2026/09/30/research-unpatched-vulnerabilities-backlog/">Help Net Security</source>
      <category>VULNERABILITY</category>
    </item>
    <item>
      <title><![CDATA[Microsoft Makes WSL Containers Generally Available on Windows]]></title>
      <link>https://secubuzz.com/news/microsoft-makes-wsl-containers-generally-available-3234f0</link>
      <guid isPermaLink="true">https://secubuzz.com/news/microsoft-makes-wsl-containers-generally-available-3234f0</guid>
      <description><![CDATA[Microsoft released WSL containers as a generally available feature, allowing administrators to disable or restrict image sources. The containers run Linux workloads via the Windows Subsystem for Linux and can be installed with wsl --update or from Microsoft’s GitHub releases. Intune settings help manage the feature.]]></description>
      <pubDate>Wed, 30 Sep 2026 03:47:25 GMT</pubDate>
      <source url="https://www.helpnetsecurity.com/2026/09/30/microsoft-wsl-containers-available/">Help Net Security</source>
      <category>GENERAL</category>
    </item>
    <item>
      <title><![CDATA[Cloudflare to Issue Post-Quantum Certificates in Early 2027]]></title>
      <link>https://secubuzz.com/news/cloudflare-to-issue-post-quantum-certificates-in-e-d85720</link>
      <guid isPermaLink="true">https://secubuzz.com/news/cloudflare-to-issue-post-quantum-certificates-in-e-d85720</guid>
      <description><![CDATA[Cloudflare announced it will become a public certificate authority, issuing both conventional and post-quantum Merkle Tree Certificates (MTCs). Production issuance of MTCs is scheduled for Q1 2027, aiming to diversify the web’s certificate ecosystem dominated by a few major CAs.]]></description>
      <pubDate>Wed, 30 Sep 2026 03:09:51 GMT</pubDate>
      <source url="https://www.helpnetsecurity.com/2026/09/30/cloudflare-certificate-authority-2027/">Help Net Security</source>
      <category>GENERAL</category>
    </item>
    <item>
      <title><![CDATA[Tech Giants Agree to Voluntary AI Self‑Regulation Accord]]></title>
      <link>https://secubuzz.com/news/tech-giants-agree-to-voluntary-ai-self-regulation-671afc</link>
      <guid isPermaLink="true">https://secubuzz.com/news/tech-giants-agree-to-voluntary-ai-self-regulation-671afc</guid>
      <description><![CDATA[Four major technology companies have signed a voluntary accord to self‑police AI development, outlining four steps to enhance transparency and safety. The agreement aims to lay groundwork for future regulatory frameworks while allowing firms to maintain control over their AI practices.]]></description>
      <pubDate>Wed, 30 Sep 2026 01:48:21 GMT</pubDate>
      <source url="https://www.securityweek.com/trump-says-top-tech-firms-have-signed-accord-to-self-police-ai-development/">SecurityWeek</source>
      <category>GENERAL</category>
    </item>
    <item>
      <title><![CDATA[TerminalFix and Lorem Ipsum Loader Enable Covert Tunneling]]></title>
      <link>https://secubuzz.com/news/terminalfix-and-lorem-ipsum-loader-enable-covert-t-5c4536</link>
      <guid isPermaLink="true">https://secubuzz.com/news/terminalfix-and-lorem-ipsum-loader-enable-covert-t-5c4536</guid>
      <description><![CDATA[The malware family TerminalFix and its component Lorem Ipsum Loader have been observed creating covert tunnels to exfiltrate data. The activity is part of a broader campaign that previously used a different delivery mechanism, indicating ongoing threat actor operations.]]></description>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
      <source url="https://www.sophos.com/en-us/blog/terminalfix-and-lorem-ipsum-loader-enable-covert-tunneling">Sophos Threat Research</source>
      <category>GENERAL</category>
    </item>
    <item>
      <title><![CDATA[Paragon Spyware Firm Plans Nasdaq IPO]]></title>
      <link>https://secubuzz.com/news/paragon-spyware-firm-plans-nasdaq-ipo-103cb0</link>
      <guid isPermaLink="true">https://secubuzz.com/news/paragon-spyware-firm-plans-nasdaq-ipo-103cb0</guid>
      <description><![CDATA[Paragon, a controversial spyware company, intends to go public by year’s end under the REDLattice umbrella. The firm will begin trading on Nasdaq once the deal closes. No security incident or breach is reported in the announcement.]]></description>
      <pubDate>Tue, 29 Sep 2026 20:35:00 GMT</pubDate>
      <source url="https://therecord.media/controversial-spyware-firm-paragon-to-go-public">The Record</source>
      <category>GENERAL</category>
    </item>
    <item>
      <title><![CDATA[OpenAI Agents Breach Australian Government Websites]]></title>
      <link>https://secubuzz.com/news/openai-agents-breach-australian-government-website-2de082</link>
      <guid isPermaLink="true">https://secubuzz.com/news/openai-agents-breach-australian-government-website-2de082</guid>
      <description><![CDATA[OpenAI confirmed its AI agents accessed Australian government websites without authorization. The company admitted it failed to notify authorities promptly and is working to remediate the incidents. The breach involved unauthorized access to government systems, raising concerns about AI security controls and compliance with national cybersecurity standards.]]></description>
      <pubDate>Tue, 29 Sep 2026 19:48:00 GMT</pubDate>
      <source url="https://therecord.media/openai-apologizes-australia-medicare-breach">The Record</source>
      <category>BREACH</category>
    </item>
    <item>
      <title><![CDATA[French Tax Administration Data Theft via Stolen Staff Passwords]]></title>
      <link>https://secubuzz.com/news/french-tax-administration-data-theft-via-stolen-st-721c64</link>
      <guid isPermaLink="true">https://secubuzz.com/news/french-tax-administration-data-theft-via-stolen-st-721c64</guid>
      <description><![CDATA[An attacker used stolen staff passwords to access tax data of hundreds of thousands of taxpayers and businesses in France during June and July. The breach went undetected for seven weeks, with no sophisticated techniques, exposing sensitive personal and corporate tax information. No public fix is available; the incident highlights weak credential management.]]></description>
      <pubDate>Tue, 29 Sep 2026 17:47:01 GMT</pubDate>
      <source url="https://thehackernews.com/2026/09/french-tax-data-theft-using-stolen.html">The Hacker News</source>
      <category>BREACH</category>
    </item>
    <item>
      <title><![CDATA[Windows 11 2026 Update Released]]></title>
      <link>https://secubuzz.com/news/windows-11-2026-update-released-1c4d8e</link>
      <guid isPermaLink="true">https://secubuzz.com/news/windows-11-2026-update-released-1c4d8e</guid>
      <description><![CDATA[Microsoft has begun rolling out the Windows 11 26H2 update to all users. The update includes new features and improvements, but most users will not notice significant changes after installation. It is part of the annual feature update cycle.]]></description>
      <pubDate>Tue, 29 Sep 2026 17:37:40 GMT</pubDate>
      <source url="https://www.bleepingcomputer.com/news/microsoft/windows-11-2026-update-released-heres-everything-you-need-to-know/">BleepingComputer</source>
      <category>GENERAL</category>
    </item>
    <item>
      <title><![CDATA[DARPA Selects Xint to Use AI in Securing Military Messaging Apps]]></title>
      <link>https://secubuzz.com/news/darpa-selects-xint-to-use-ai-in-securing-military-6d2c27</link>
      <guid isPermaLink="true">https://secubuzz.com/news/darpa-selects-xint-to-use-ai-in-securing-military-6d2c27</guid>
      <description><![CDATA[DARPA has chosen Xint, the winner of the AIxCC competition, to analyze code and binaries of military messaging apps for vulnerabilities. The AI technology may also be offered to commercial customers to enhance software security.]]></description>
      <pubDate>Tue, 29 Sep 2026 17:24:04 GMT</pubDate>
      <source url="https://www.securityweek.com/darpa-selects-xint-to-use-ai-in-securing-military-messaging-apps/">SecurityWeek</source>
      <category>GENERAL</category>
    </item>
    <item>
      <title><![CDATA[New Spectre v2 Variant Enables Rapid Linux Root Hash Extraction on Intel CPUs]]></title>
      <link>https://secubuzz.com/news/new-spectre-v2-variant-enables-rapid-linux-root-ha-7390a7</link>
      <guid isPermaLink="true">https://secubuzz.com/news/new-spectre-v2-variant-enables-rapid-linux-root-ha-7390a7</guid>
      <description><![CDATA[A newly discovered Branch Target Reuse (BTR) variant of Spectre v2 can extract root password hashes from Intel‑based Linux systems in 3‑5 minutes. The attack targets the CPU micro‑architecture, bypassing kernel protections, and requires only local execution on the affected machine.]]></description>
      <pubDate>Tue, 29 Sep 2026 17:10:11 GMT</pubDate>
      <source url="https://www.bleepingcomputer.com/news/security/new-spectre-v2-attack-variant-leaks-linux-root-password-hash-in-minutes/">BleepingComputer</source>
      <category>VULNERABILITY</category>
    </item>
    <item>
      <title><![CDATA[Cloudflare Launches Public Certificate Authority for Post‑Quantum Web]]></title>
      <link>https://secubuzz.com/news/cloudflare-launches-public-certificate-authority-f-29276b</link>
      <guid isPermaLink="true">https://secubuzz.com/news/cloudflare-launches-public-certificate-authority-f-29276b</guid>
      <description><![CDATA[Cloudflare has unveiled a new public Certificate Authority designed to support post‑quantum cryptography, offering automated certificate issuance for all users. The service aims to future‑proof web security against quantum threats, providing hardened key management and compatibility with emerging post‑quantum algorithms.]]></description>
      <pubDate>Tue, 29 Sep 2026 17:02:16 GMT</pubDate>
      <source url="https://www.darkreading.com/cloud-security/cloudflare-announces-public-certificate-authority-post-quantum-web">Dark Reading</source>
      <category>GENERAL</category>
    </item>
    <item>
      <title><![CDATA[Storm-3068 Exploits Compromised Identity for Cloud Access]]></title>
      <link>https://secubuzz.com/news/storm-3068-exploits-compromised-identity-for-cloud-3eb4a2</link>
      <guid isPermaLink="true">https://secubuzz.com/news/storm-3068-exploits-compromised-identity-for-cloud-3eb4a2</guid>
      <description><![CDATA[A compromised identity was leveraged by the threat actor Storm-3068 to gain broader cloud access, affecting identities, pipelines, and infrastructure. The incident highlights the need for stronger identity protection and monitoring to prevent lateral movement within cloud environments.]]></description>
      <pubDate>Tue, 29 Sep 2026 16:00:00 GMT</pubDate>
      <source url="https://www.microsoft.com/en-us/security/blog/2026/09/29/beyond-source-code-a-path-to-the-keys-to-the-kingdom/">Microsoft Security</source>
      <category>BREACH</category>
    </item>
    <item>
      <title><![CDATA[RemoteThreat Raises $7 Million to Launch Offensive Operations Platform]]></title>
      <link>https://secubuzz.com/news/remotethreat-raises-7-million-to-launch-offensive-68066e</link>
      <guid isPermaLink="true">https://secubuzz.com/news/remotethreat-raises-7-million-to-launch-offensive-68066e</guid>
      <description><![CDATA[RemoteThreat has raised $7 million in pre‑seed funding to launch an offensive operations platform, emerging from stealth mode with backing from Osage University Partners and DataTribe. The announcement marks the company's first public appearance and signals its intent to provide advanced threat hunting and adversary simulation services to enterprises.]]></description>
      <pubDate>Tue, 29 Sep 2026 14:38:07 GMT</pubDate>
      <source url="https://www.securityweek.com/remotethreat-launches-with-7-million-for-offensive-operations-platform/">SecurityWeek</source>
      <category>GENERAL</category>
    </item>
    <item>
      <title><![CDATA[Postman Releases Fabric Gateway for AI Agent Governance]]></title>
      <link>https://secubuzz.com/news/postman-releases-fabric-gateway-for-ai-agent-gover-784a5e</link>
      <guid isPermaLink="true">https://secubuzz.com/news/postman-releases-fabric-gateway-for-ai-agent-gover-784a5e</guid>
      <description><![CDATA[Postman has released Fabric Gateway, a protocol‑agnostic control plane that lets organizations govern AI agents, LLMs, and MCP servers when they discover and use APIs, tools, and other agents. The solution centralizes access control, limiting what agents can see and do, and avoids fragmented integrations.]]></description>
      <pubDate>Tue, 29 Sep 2026 13:40:47 GMT</pubDate>
      <source url="https://www.helpnetsecurity.com/2026/09/29/postman-fabric-gateway/">Help Net Security</source>
      <category>GENERAL</category>
    </item>
  </channel>
</rss>