Microsoft has released a massive security update addressing 974 flaws across its software ecosystem. This marks a record-breaking Patch Tuesday, with the company confirming that two Windows zero-day vulnerabilities are already being exploited in the wild.
The update covers 723 Windows flaws, 111 Office vulnerabilities, and 62 SQL issues. Of the total vulnerabilities addressed, over 110 have been classified as critical severity.
With two zero-days already active, immediate patching is non-negotiable.
@edited
Please open Telegram to view this post
VIEW IN TELEGRAM
Cybercriminals have compromised several Brazilian government and educational servers to build a sophisticated reverse-proxy network. According to Dark Reading, the attackers are repurposing these trusted domains to host phishing sites themed around online gambling.
The operation, attributed to a Chinese-language group, uses the hijacked infrastructure to mask malicious activity and bypass security filters. By leveraging legitimate government URLs, the group increases the success rate of their fraudulent schemes.
Using state infrastructure to host scams is a massive breach of trust.
@edited
Please open Telegram to view this post
VIEW IN TELEGRAM
A Ukrainian national has received a four-year prison sentence in the United States for his involvement in the Conti ransomware operation. The group was responsible for targeting more than 1,000 victims globally before its operations ceased in 2022.
The sentence follows a multi-year investigation into the group's high-impact extortion tactics. Prosecutors linked the defendant to the sophisticated infrastructure used to execute the widespread attacks.
A relatively light sentence for a group that paralyzed global networks.
@edited
Please open Telegram to view this post
VIEW IN TELEGRAM
A new wave of Android-based cyberattacks is combining traditional malware with ransomware tactics to target mobile users globally. The hybrid approach aims to infect devices before locking files or sensitive data for ransom.
Security researchers warn that this cocktail of techniques makes detection more difficult as the malware spreads through the system before the final payload is triggered.
Is your mobile OS ready for this dual-threat approach?
@edited
Please open Telegram to view this post
VIEW IN TELEGRAM
Anthropic has warned that threat actors are leveraging Claude models to automate exploitation, weapons design, and mass surveillance. Between December 2025 and August 2026, these 'Generative Threat Groups'—ranging from state-sponsored actors to financially motivated criminals—have used the AI to scale cyber attacks and propaganda efforts.
The company identified these diverse actors as Generative Threat Groups (GTGs), noting their ability to use the models for sophisticated data theft and high-impact cyber operations.
As AI becomes a weapon, the line between human and automated hacking blurs.
@edited
Please open Telegram to view this post
VIEW IN TELEGRAM
Anthropic has disrupted a sophisticated cyber espionage campaign where threat actors used Claude to automate malware development. The group, identified as GTG-20006, leveraged AI-assisted workflows to rapidly iterate and rebuild malicious code whenever it was detected by defenders.
The operation has been linked to the Midnight cluster, a known Russian state-sponsored actor. By using generative AI to stay ahead of the detection curve, the group effectively turned LLMs into a tool for rapid-response malware engineering.
The era of the automated, self-evolving malware loop has arrived.
@edited
Please open Telegram to view this post
VIEW IN TELEGRAM
Innovative attackers are increasingly integrating AI to automate the entire lifecycle of a breach. The 'Papercut' concept describes a swarm-based approach where agentic AI handles everything from initial reconnaissance to lateral movement and data exfiltration.
By creating autonomous lab environments to stage these attacks, hackers can scale sophisticated operations with minimal human intervention. This shift suggests a move toward highly coordinated, self-evolving exploits that challenge traditional defense-in-depth strategies.
Is the human element becoming the weakest link in an automated kill chain?
@edited
Please open Telegram to view this post
VIEW IN TELEGRAM
Japan’s Digital Agency announced Friday that unauthorized access to a government network system may have compromised approximately 246,000 sets of personal information. The leaked data includes the names and email addresses of government employees.
According to JiJi Press, no secondary damage or misuse of the breached information has been confirmed so far. The agency is currently investigating the scope of the unauthorized access.
A massive scale for a single network breach.
@edited
Please open Telegram to view this post
VIEW IN TELEGRAM
Bitcoin briefly spiked to $79,837 following the release of August CPI data that matched projections, but volatile intraday trading triggered over $732 million in crypto liquidations. Volatile Trading Triggers $732M in Liquidations Bitcoin briefly reclaimed $79,000 Friday after the U.S. Bureau of Labor Statistics released August Consumer Price Index (CPI) data that aligned with economists’ […]
Worth watching as more details come out.
@edited
Please open Telegram to view this post
VIEW IN TELEGRAM
Robinhood Chain revenue dropped to $943,728 on September 10, down from a peak of $5.44 million on September 4. Despite the revenue dip, decentralized exchange volume rose 27% over the past week.
Gas costs have also shifted significantly, falling to an average of $0.077 per transaction compared to the $0.43 peak. While transaction counts remained flat, the network is seeing a divergence between fee generation and trading activity.
Is the revenue drop a sign of efficiency or cooling interest?
@edited
Please open Telegram to view this post
VIEW IN TELEGRAM
A critical path traversal vulnerability in GitLab is prompting attackers to scan the internet for unpatched self-managed installations. The flaw allows unauthenticated attackers to read sensitive files directly from a server.
GitLab has urged operators to upgrade their installations immediately to prevent unauthorized access. Security researchers note that the flaw is already being actively probed by automated scanners globally.
Is your self-managed instance patched and secure?
@edited
Please open Telegram to view this post
VIEW IN TELEGRAM
Two employees of the Lamesa Independent School District have been arrested following a law enforcement investigation into a computer security breach. The arrests, involving 54-year-old staff members, were confirmed Friday morning via a district press release.
The Lamesa Police Department coordinated the arrests alongside the Texas Rangers to address the alleged breach of district systems.
The scope of the data exposure remains under investigation.
@edited
Please open Telegram to view this post
VIEW IN TELEGRAM
Just use /buy, /sell or /trade — the bot will manage the rest.
Post your offer, discover matching deals, connect directly and grow your community ranking.
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥 WILD: From cyber hacks to bioweapons: The rising scale of Claude misuse
Security researchers are tracking an expanding scope of misuse involving Anthropic's Claude AI. According to Wired, the model is being leveraged across diverse domains, ranging from traditional cyberattacks to the theoretical design of bioweapons.
The shift suggests that as LLMs become more sophisticated, the barrier to executing complex, multi-stage exploits is lowering for bad actors globally.
As AI capabilities scale, the definition of a 'cyber incident' is expanding.
@edited
Security researchers are tracking an expanding scope of misuse involving Anthropic's Claude AI. According to Wired, the model is being leveraged across diverse domains, ranging from traditional cyberattacks to the theoretical design of bioweapons.
The shift suggests that as LLMs become more sophisticated, the barrier to executing complex, multi-stage exploits is lowering for bad actors globally.
As AI capabilities scale, the definition of a 'cyber incident' is expanding.
@edited
The U.S. Cybersecurity and Infrastructure Security Agency has added five new vulnerabilities to its Known Exploited Vulnerabilities catalog. The flaws impact JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS, following reports of active exploitation in the wild.
Among the new entries is CVE-2026-42016, an authorization flaw with a CVSS score of 8.1. The addition to the KEV catalog signals that these vulnerabilities are being actively leveraged by attackers to breach systems.
Are your critical infrastructure assets patched against these latest exploits?
@edited
Please open Telegram to view this post
VIEW IN TELEGRAM
A dual-threat breach has struck Cisco Firewall Manager, involving both the Sandworm espionage group and the Qilin ransomware gang. The incident has triggered worldwide coverage as attackers leveraged the vulnerability to deploy sophisticated implants.
The breach combines high-level state-sponsored espionage with the disruptive force of ransomware, creating a complex security crisis for affected network infrastructures.
A dangerous fusion of silent spying and loud extortion.
@edited
Please open Telegram to view this post
VIEW IN TELEGRAM
fragment.com has completely disappeared from Google search results, while it still appears in other search engines.
Previously, Fragment appeared incorrectly in Google search results. Sometimes the query was displayed in a language other than English, sometimes the page contained a referral link or led directly to a specific username auction.
@edited
Previously, Fragment appeared incorrectly in Google search results. Sometimes the query was displayed in a language other than English, sometimes the page contained a referral link or led directly to a specific username auction.
@edited
⚠️ JUST IN: Discord Experiencing Worldwide Outage on Desktop and Mobile
Discord is currently unavailable for users across both desktop and mobile applications, with individuals encountering a Session Unavailability error upon opening the app. According to the source, the underlying cause behind the service disruption remains unknown.
Downdetector figures indicate that over 12,000 reports have been submitted within 10 minutes following the onset of the worldwide connectivity issues.
@edited
Discord is currently unavailable for users across both desktop and mobile applications, with individuals encountering a Session Unavailability error upon opening the app. According to the source, the underlying cause behind the service disruption remains unknown.
Downdetector figures indicate that over 12,000 reports have been submitted within 10 minutes following the onset of the worldwide connectivity issues.
@edited
⚠️ JUST IN: 6 Nigerians Extradited to US Over $6M+ Romance Scams.
Six Nigerian nationals linked to the Black Axe criminal network are being extradited to the U.S. after allegedly defrauding more than 100 American women of over $6 million through online romance scams.
The victims reportedly included pensioners and businesspeople who were targeted through sophisticated online relationships. The suspects are set to face wire fraud and money laundering charges in the U.S.
Authorities say the men were arrested in Cape Town in 2021 and are being handed over to FBI and U.S. Secret Service officials.
@edited
Six Nigerian nationals linked to the Black Axe criminal network are being extradited to the U.S. after allegedly defrauding more than 100 American women of over $6 million through online romance scams.
The victims reportedly included pensioners and businesspeople who were targeted through sophisticated online relationships. The suspects are set to face wire fraud and money laundering charges in the U.S.
Authorities say the men were arrested in Cape Town in 2021 and are being handed over to FBI and U.S. Secret Service officials.
@edited