Browsing: Cyber Incidents

Introduction: Apple Security Update — Why It Matters Apple Security Update addresses 273 unique vulnerabilities across Apple’s major device and software platforms. The coordinated security rollout was released on September 14, 2026, covering iPhone, iPad, Mac, Apple Watch, Apple TV, Vision Pro, Safari, and Xcode. The update includes fixes for serious security weaknesses involving arbitrary code execution, privilege escalation, memory corruption, authentication, privacy controls, and web-content processing. Apple users and enterprise administrators should review the applicable updates and deploy them as soon as operationally possible. What Is Apple’s Security Update? Apple’s September 2026 security rollout spans multiple operating systems and…

Read More

Introduction: New Phishing Attacks — Why They Matter New Phishing Attacks are reportedly abusing trusted email infrastructure and URL-cloaking techniques to make malicious messages appear legitimate. Instead of relying on obviously suspicious sender addresses or attachments, campaigns are using familiar invoices, renewal notices, payment reminders, and banking alerts to direct recipients toward deceptive websites. The approach can move the malicious activity into the click path. A message may pass common email authentication checks, contain no attachment, and still redirect a victim through multiple stages before reaching a fraudulent destination. Virus Bulletin reported examples of this technique during its Q3 2026…

Read More

Introduction: Google Search Redirect Changes — Why It Matters Google Search Redirect Changes are altering how some search-result links behave, making it harder for users to inspect the actual destination before clicking. Certain results reportedly pass through encoded google.com/goto?url= redirects instead of directly exposing the destination URL. The change matters because hovering over a search result has long been a simple security habit. A suspicious domain, unusual subdomain, or misleading URL can sometimes reveal a phishing or malware page before it is opened. According to reporting from Malwarebytes, the new redirect behavior can replace a readable destination with an encoded…

Read More

Introduction: FortiGate SSL-VPN Attack — Why It Matters FortiGate SSL-VPN Attack has reportedly been linked to a wide-ranging intrusion targeting 3BB, the consumer broadband brand of Thailand’s Triple T Broadband. Researchers uncovered an attacker-controlled staging server containing tools and artifacts allegedly connected to the operation. The reported intrusion began with exploitation of CVE-2024-21762, a critical FortiOS and FortiProxy vulnerability affecting SSL-VPN components. The incident allegedly progressed from initial access to privilege escalation, credential theft, internal reconnaissance, lateral movement and persistent remote access. What is 3BB? 3BB is the consumer-facing broadband brand associated with Thailand’s Triple T Broadband. The reported intrusion…

Read More

Introduction: Twitch OAuth Token Exposure — Why It Matters Twitch OAuth Token Exposure has raised concerns after a malicious browser extension reportedly exposed authentication tokens belonging to Twitch users. The extension, identified as “Twitch Enhanced Viewer | JeetBot,” was available for Google Chrome and Mozilla Firefox and advertised features including ad blocking, higher-quality playback, region-unlocked streams and automatic channel-point collection. According to security researchers at Socket.dev, the extension reportedly intercepted Twitch OAuth tokens while routing video requests through third-party proxy infrastructure. About 31,000 installations were recorded across the two browsers, including roughly 30,000 Chrome users and 552 Firefox users. The…

Read More

Introduction: iPhone Scam Websites — Why It Matters iPhone Scam Websites are emerging rapidly as criminals exploit consumer demand for Apple’s newest devices. Following the launch of new iPhone models, security researchers have reported a surge in suspicious websites using “Apple” and “iPhone” in their domain names. These sites reportedly imitate legitimate retailers, promote unusually cheap devices and use realistic product information to convince shoppers to make payments. Some fraudulent websites are also being created with the help of AI, making them harder for consumers to distinguish from genuine stores. The campaign highlights why iPhone Scam Websites are a growing…

Read More

Introduction: Dell ObjectScale Vulnerabilities — Why It Matters The Dell ObjectScale Vulnerabilities disclosure includes multiple security flaws affecting Dell ObjectScale and Elastic Cloud Storage (ECS) deployments. Dell published security advisory DSA-2026-393 on September 10, 2026, warning customers about vulnerabilities across affected versions. The most serious issue, CVE-2026-70416, is an untrusted-data deserialization vulnerability with a maximum CVSS score of 10.0. It could reportedly allow an unauthenticated remote attacker to execute code on a vulnerable ObjectScale system. For organizations using object storage for backups, application data, archives or cloud-native workloads, successful exploitation could have serious consequences. What Is Dell ObjectScale? Dell ObjectScale…

Read More

Introduction: Revolut Data Breach — Why It Matters The Revolut Data Breach reportedly exposed sensitive customer information after a fraudulent request impersonating a legitimate government agency was accepted as genuine. The Revolut Data Breach reportedly affected a limited number of customers and involved highly sensitive identity and financial information. According to the available incident details, the exposed records reportedly included identity documents, verification selfies, contact information, account statements, IBANs and full transaction histories, including Bitcoin activity. Revolut said the incident did not involve a compromise of its core systems, mobile application or customer accounts. The incident is significant because it…

Read More

Introduction: Claude Cyberattacks — Why It Matters Claude Cyberattacks highlight a growing shift in how threat actors are using artificial intelligence to conduct cyber operations. Anthropic says it identified and disrupted malicious campaigns between December 2025 and August 2026 involving cybercriminals, suspected state-sponsored groups and politically motivated actors. According to Anthropic’s September 2026 threat intelligence report, attackers are no longer using Claude only as a conversational assistant. Some operations used Claude with multi-agent frameworks to perform reconnaissance, exploitation, credential harvesting and data exfiltration, with humans setting targets and supervising important decisions. Claude Cyberattacks matter because AI can reduce the expertise,…

Read More

Introduction: Mantax Otax Android Ransomware — Why It Matters Mantax Otax Android Ransomware is a newly reported Android malware threat that combines ransomware with extensive spyware capabilities. The malware is reportedly distributed through malicious APK files hosted on third-party file-sharing services and promoted through phishing messages and shared links. The threat is particularly serious because it does more than encrypt files. Mantax Otax Android Ransomware 2026 reportedly abuses Accessibility and device administrator privileges to control infected phones, steal sensitive information, capture screens and potentially obtain authentication data. The campaign has reportedly been linked to Indonesian threat actors, with available evidence…

Read More