What RL Found Before Anthropic’s Midnight Blizzard Report
ReversingLabs identified and classified the malware weeks before the report was published — showing why behavioral intelligence and historical telemetry matter in the AI age.
Real-time cybersecurity intelligence fused and enriched from 200+ sources across 12+ languages
Last updated: Thu, 08 Oct 2026 16:01:21 GMT
ReversingLabs identified and classified the malware weeks before the report was published — showing why behavioral intelligence and historical telemetry matter in the AI age.
Attackers behind a string of personal data leaks at Japanese organizations have abused APIs for mobile apps and targeted known software flaws, the JPCERT Coordination Center (JPCERT/CC) said. The Tok...
Serial number: AV26-1021Date: October 8, 2026 As of October 6, 2026, Elastic is affected by vulnerabilities in the following products: Elasticsearch Prior to or equal to 8.19.23 Prior to or equal...
Как опубликовать внутренний API из DMZ, если соединения в LAN запрещены: пять подходов, которые мы проверилиВсе пять схем мы собирали на NEOMSA APIM, российской платформе управления API от Neoflex. Св...
Attackers compromised .gh, .sl and .as registries to obtain unauthorized HTTPS certificates
The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN. According to TrendAI, the malware...
Western District of Pennsylvania | Punxsutawney Man Indicted for Social Security Fraud Department of Justice (.gov)
1 октября мне заблокировали аккаунт Claude. До этого приложение месяц писало, что сервис недоступен в моём регионе. В логах Mac таких строк набралось 2 891. Первая версия была очевидной: VPN иногда от...
The ASOS hack comes from the compromise of agentic marketing platform Simon AI, said the attackers
Cybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence (AI) pen testing tool named ARTEX to carry ou...
A threat actor published a malicious version of the tensorlake npm package on October 8, 2026, embedding a new variant of the self-replicating Shai-Hulud supply-chain worm. The compromised release, te...
Недавно часть наших клиентов не могла подключиться к серверам Монеты. Мы проверили межсетевые экраны, собрали трассировки с обеих сторон, но причина оказалась за пределами нашей инфраструктуры. При эт...
Russia-aligned UAC-0099 has steadily upgraded its MATCHBOIL downloader since 2024
Bitdefender's security researchers have identified a malware campaign (dubbed Midnight Mimosa) running on low-cost, multi-brand Android devices built on MediaTek platforms.
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that can expose active users’ session cookies and enable remote code execution (RCE) as...
Игровая индустрия прошла максимально сложный путь развития: от чего-то максимально локального до мейнстрима у всех возрастов, по пути успев чуть не умереть в 1983 году и возродиться руками одной компа...
Joint advisory with international partners highlights malicious targeting of organisations from a range of sectors across the globe.
CrowdStrike revealed that a Chinese-speaking hacker deployed agentic pentesting tool ARTEX and Claude to help breach data from South Korean financial firms
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process deployments by exploiting unsafe Python pickle deserialization. This flaw...
Сегодня Telegram-бот для продажи VPN собирается за вечер: Cursor, пара промптов, и он уже принимает деньги. Только в config.py лежит токен бота, Postgres открыт наружу, а в истории git остался .env, к...
Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials. Attackers are increasingly building filtering, session management, and traffic contr...
A critical vulnerability affecting eight Atlassian products, including Jira and Confluence, is being exploited in the wild, said VulnCheck
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys during wallet imports. Disguised as wallet portals, desktop utilities, and browse...
Мы очень давно — более 10 лет — говорим о безопасности k8s. Это второй опенсорс‑проект в мире после Linux, а в РФ только «ванильным кубом» пользуются более 53% компаний (не считая коммерческие и облач...
With no accurate Big Tech mapping app to help him, Anas Hattab launched a Telegram group to get himself home at night. Now nearly 350,000 Palestinians rely on it to navigate the occupied West Bank.
Europol and US Government Accountability Office urge faster transition to post-quantum cryptography
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise iPhones and harvest cryptocurrency wallet secrets. Censys researchers uncove...
Привет, Хабр! Я Антон, инженер по информационной безопасности в Selectel. Представьте новость: защиту GPT-6 Astra обошли обычным транслитом. Сегодня это звучит как фантастика, а вот ранние LLM ломалис...
The U.S. State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 20...
The FBI and Secret Service are warning Fortigate admins that their systems are still being targeted
Ghostwire is an independent project operated by a single security analyst. No corporate ownership, no investor funding, no advertising revenue. The platform fuses and enriches 200+ public cybersecurity intelligence sources across 12+ languages — including Chinese, Russian, Japanese, Korean, Spanish, Portuguese, French, German, Polish, Swedish, Ukrainian, and English — covering NVD, CISA KEV, CERTs, vendor advisories, research blogs, and threat actor disclosures into a unified real-time threat picture.
Daily briefings are AI-generated by automated analysis without human editorial oversight; treat them as a starting point and verify critical claims against primary sources. CVE enrichment uses NVD, FIRST EPSS, CISA KEV, and the nomi-sec PoC-in-GitHub database.
Contact & security disclosures: contact@ghostwire.news
Provided as-is for informational purposes. No warranty. Not affiliated with any vendor, government agency, or commercial threat-intelligence provider.