Breaking News – Cyber Threats – 2026-09-28 17:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-28 17:00 PDT
- Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950), (Mon, Sep 28th)
SANS ISC Diary (full) • 2026-09-28 15:35 • isc.sans.eduApple today released patches for all of its operating systems. However, only patches for older branches include a security fix. The vulnerability being addressed in iOS 26, macOS 26 and macOS 15 is already being exploited. iOS and macOS 27 are not affected. Today's update for the current “27” branch does not address security issues, but fixes some functional issues that got caught after the release two weeks ago. A 27.1 version was also expected to support the new foldable iPhone and will likely include specific features geared to the soon to be ava…
https://isc.sans.edu/diary/rss/33376 - Japan's Keio confirms ransomware attack disrupted business systems
BleepingComputer • 2026-09-28 13:56 • www.bleepingcomputer.com
Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems. […]
https://www.bleepingcomputer.com/news/security/japans-keio-confirms-ransomware-attack-disrupted-business-systems/ - Times Car confirms data breach affecting 6.6 million user accounts
BleepingComputer • 2026-09-28 13:31 • www.bleepingcomputer.com
Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. […]
https://www.bleepingcomputer.com/news/security/times-car-confirms-data-breach-affecting-66-million-user-accounts/ - Dutch police confirm arrest in ShinyHunters hacking investigation
BleepingComputer • 2026-09-28 12:49 • www.bleepingcomputer.com
Dutch police have confirmed that a 24-year-old Amsterdam man arrested earlier this month was detained as part of an investigation into the ShinyHunters hacking group. […]
https://www.bleepingcomputer.com/news/security/dutch-police-confirm-arrest-in-shinyhunters-hacking-investigation/ - Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
The Hacker News • 2026-09-28 12:18 • thehackernews.com
Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks.The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file.
The iPhone maker said the
https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html - Over 16,000 Supabase databases expose PII, passwords, auth tokens
BleepingComputer • 2026-09-28 11:50 • www.bleepingcomputer.com
Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens. […]
https://www.bleepingcomputer.com/news/security/misconfigured-supabase-apps-expose-data-in-over-16-000-databases/ - Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
The Hacker News • 2026-09-28 11:35 • thehackernews.com
Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis.The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Its use goes back to at least
https://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.html - IAM for AI agents: A Practical Enterprise Framework
The Hacker News • 2026-09-28 11:20 • thehackernews.com
What is IAM for AI agents?AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority. IAM for AI Agents is the identity-control architecture that governs those actors. This guide covers the limits of conventional provisioning, the components that matter, how to evaluate framework choices, and what runtime evidence proves an agent behaved as intended.
https://thehackernews.com/2026/09/iam-for-ai-agent.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.