Breaking News – Cyber Threats – 2026-09-29 03:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-29 03:00 PDT
- Kiteworks patches critical flaw, brings customer systems online
BleepingComputer • 2026-09-29 02:04 • www.bleepingcomputer.com
American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability. […]
https://www.bleepingcomputer.com/news/security/kiteworks-lifts-shutdown-warning-after-patching-critical-flaw/ - Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation
The Hacker News • 2026-09-29 01:35 • thehackernews.com
Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group.“It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters,” the Politie Landelijke Opsporing en Interventies said in an X post Monday.
Police said the individual is expected to appear before the
https://thehackernews.com/2026/09/dutch-police-arrest-24-year-old.html - Apple patches CoreGraphics zero-day flaw exploited in attacks
BleepingComputer • 2026-09-29 00:33 • www.bleepingcomputer.com
Apple released security updates to fix a zero-day vulnerability exploited in “extremely sophisticated” targeted attacks on iOS devices. […]
https://www.bleepingcomputer.com/news/security/apple-patches-coregraphics-zero-day-flaw-exploited-in-attacks/ - Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
The Hacker News • 2026-09-28 23:08 • thehackernews.com
A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK’s maintainers said in a security advisory.Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and
https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html - OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions
The Hacker News • 2026-09-28 22:12 • thehackernews.com
OpenAI on Monday shelved plans to release GPT-6.1 Astra, a next-generation artificial intelligence (AI) model that was planned for an October launch, after it failed internal safety and alignment audits.The development was first reported by The Wall Street Journal. The move “marks a rare case of a major AI developer ditching a new release because of safety concerns,” the news publication said.
https://thehackernews.com/2026/09/openai-shelves-gpt-61-astra-after-tests.html - OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot
The Hacker News • 2026-09-28 21:45 • thehackernews.com
OpenAI said it has made the decision to pause training of its most powerful models after one of its agents during reinforcement learning (RL) training contacted an external chatbot by exploiting a loophole in its internet-access restrictions.“An agent attempting to complete a search-based training task queried a public chatbot service through a gap in our internet-access restrictions:
https://thehackernews.com/2026/09/openai-pauses-tool-use-after-agent.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.