Breaking News – Cyber Threats – 2026-09-28 08:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-28 08:00 PDT
- ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats
The Hacker News • 2026-09-28 07:00 • thehackernews.com
A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface.Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work for attackers. Nothing
https://thehackernews.com/2026/09/weekly-recap-387m-crypto-hack-citrix.html - 80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking
BleepingComputer • 2026-09-28 07:00 • www.bleepingcomputer.com
Infostealer logs exposed AI account credentials and sessions tied to more than 80,000 corporate domains, creating risks ranging from stolen conversations to LLMjacking. SOCRadar examines the growing market for stolen AI logins and how organizations can identify their exposure. […]
https://www.bleepingcomputer.com/news/security/80-000-plus-organizations-had-ai-logins-stolen-from-shadow-ai-to-llmjacking/ - Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI
The Hacker News • 2026-09-28 04:58 • thehackernews.com
AI agents are moving into production faster than security teams can govern them. They are connecting to apps, handling data, calling APIs, and acting across business systems—often without the same controls applied to human users.According to Okta’s Global CISO Insights 2026 report, only 47% of CISOs are confident they can identify every AI agent in their environment. Even among those who feel
https://thehackernews.com/2026/09/webinar-how-to-govern-ai-agents-reduce.html - Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent
The Hacker News • 2026-09-28 04:46 • thehackernews.com
Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that’s targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent.“The implant installs the framework unchanged, then overwrites its SOUL.md persona file,” ThreatDown said. “The 39-line prompt directs it to execute tasks received through
https://thehackernews.com/2026/09/carbonato-botnet-compromises-docker.html - New Attack Against RSA
Schneier on Security • 2026-09-28 04:02 • www.schneier.comArsTechnica is reporting on a “new” attack against RSA, one that bypasses factoring.
First, this attack isn’t new. The original research is from 2007. What is new is the implementation.
Second, it is a forgery attack. It allows an attacker to forge digital signatures. It does not recover the private key from the public key.
Third, the attack only works against pure signatures…
https://www.schneier.com/blog/archives/2026/09/new-attack-against-rsa.html - Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist
BleepingComputer • 2026-09-28 02:25 • www.bleepingcomputer.com
Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million. […]
https://www.bleepingcomputer.com/news/security/bitget-resumes-bitcoin-withdrawals-after-3875-million-crypto-heist/ - JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
The Hacker News • 2026-09-28 02:08 • thehackernews.com
The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals.Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor’s tradecraft. The attack took place in early June 2026 over a period of about 18 hours.
“The destructive operations
https://thehackernews.com/2026/09/jadepuffer-linked-attackers-used.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.