Bitget Reports $388M Theft Linked to Third-Party Security Flaw
According to Bitget, the cryptocurrency exchange, the individual responsible for the theft of approximately $388 million accessed the platform via a vulnerability in a third-party security product utilized by the exchange, as stated on Monday. The attacker took advantage of this flaw to acquire high-level internal credentials, which were then used on September 24 to…
Apple Fixes CoreGraphics Vulnerability Potentially Used in Targeted Attacks
Apple has issued security updates to rectify a flaw in older versions of iOS, iPadOS, and macOS, which it indicated might have been utilized in targeted attacks. The flaw, identified as CVE-2026-86950, pertains to an out-of-bounds write affecting the CoreGraphics component, potentially allowing arbitrary code execution when handling a maliciously crafted file. The company stated…
Keio Corporation in Japan Acknowledges Ransomware Attack Disrupting Operations
Keio Corporation, a prominent private railway operator in Japan, reported that its network experienced a ransomware attack over the weekend, leading to disruptions in several of its business systems. After a system failure occurred early Saturday morning, the company confirmed the attack and took measures to shut down its network to mitigate further damage. Keio…
Counterfeit LastPass Authenticator Installer Exploits Microsoft-Signed Driver to Disable Antivirus and EDR
A counterfeit LastPass Authenticator installer available on GitHub installs a Windows kernel driver that disables antivirus and other security applications before a password theft program executes, according to researchers from LastPass and Delphos Labs on September 17. The driver is signed by Microsoft’s hardware compatibility program, received zero detections on VirusTotal during an August check…
CISA warns of ongoing exploitation of three Linux kernel vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the exploitation of three vulnerabilities in the Linux kernel, one of which is classified as critical. These three security flaws were individually reported last week and have severity ratings that range from medium to critical. Notably, one of them, identified as CVE-2025-39964,…
BigBear Microsoft 365 Phishing Service Circumvents MFA at 258 Organizations
A phishing-as-a-service platform known as BigBear 2.0 has successfully circumvented multi-factor authentication (MFA) for 258 organizations, resulting in the theft of over 5,000 Microsoft 365 credentials. Researchers from the cybersecurity firm CloudSEK gained administrative access to the control panel and discovered that the service operated 42 VPS nodes, all specifically configured to target Microsoft 365…
Executives Targeted by Phony IT Calls in Microsoft 365 Data Theft and Extortion Schemes
Threat hunters have revealed information about a large-scale data theft and extortion threat group that is focusing on Microsoft 365 and other software-as-a-service (SaaS) platforms through IT help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. This activity primarily targets directors, vice presidents, and other high-ranking officials, and is being monitored by Arctic Wolf…
Exploitation of Magento StyleSmuggler Zero-Day Leads to Linux Backdoor Deployment
A zero-day flaw known as “StyleSmuggler,” which impacts all versions of Magento and Adobe Commerce, is currently being exploited in attacks aimed at deploying a backdoor. The initial incident of exploitation was documented on September 4, targeting a system that had the latest security updates installed. According to e-commerce security firm Sansec, Adobe Enterprise Support…
Microsoft Exchange Online outage leads to email disruptions and authentication problems
Microsoft is currently looking into a significant service disruption that is resulting in authentication difficulties, connection issues, delays in email delivery, and various other complications for users of Microsoft 365. The company first acknowledged this situation (identified as EX1464935 in the admin center) at 5:30 PM UTC, following a surge of reports from users on…
Microsoft alerts about TerminalFix attacks utilizing reverse tunnels
A new variant of ClickFix, named TerminalFix, employs deceptive Cloudflare CAPTCHA prompts on compromised sites to deceive victims into running harmful PowerShell commands within Windows Terminal. In contrast to standard ClickFix attacks that frequently result in infostealer malware infections, this operation utilizes a multi-stage intrusion process that ultimately provides attackers with a reverse tunnel into…
