Ghostwire

Real-time cybersecurity intelligence fused and enriched from 200+ sources across 12+ languages

Last updated: Thu, 08 Oct 2026 16:01:21 GMT

Latest Articles (30 from 10 sources)

ReversingLabs

What RL Found Before Anthropic’s Midnight Blizzard Report

ReversingLabs identified and classified the malware weeks before the report was published — showing why behavioral intelligence and historical telemetry matter in the AI age.

The Hacker News

Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks

Attackers behind a string of personal data leaks at Japanese organizations have abused APIs for mobile apps and targeted known software flaws, the JPCERT Coordination Center (JPCERT/CC) said. The Tok...

Canadian Cyber Centre

Elastic security advisory (AV26-1021)

Serial number: AV26-1021Date: October 8, 2026 As of October 6, 2026, Elastic is affected by vulnerabilities in the following products: Elasticsearch Prior to or equal to 8.19.23 Prior to or equal...

Habr InfoSec

Как опубликовать внутренний API из DMZ, если соединения в LAN запрещены: пять подходов, которые мы проверили

Как опубликовать внутренний API из DMZ, если соединения в LAN запрещены: пять подходов, которые мы проверилиВсе пять схем мы собирали на NEOMSA APIM, российской платформе управления API от Neoflex. Св...

Infosecurity Magazine

Attackers Hijack Three ccTLDs to Obtain Google Certificates

Attackers compromised .gh, .sl and .as registries to obtain unauthorized HTTPS certificates

The Hacker News

UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML

The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN. According to TrendAI, the malware...

DOJ via Google News

Western District of Pennsylvania | Punxsutawney Man Indicted for Social Security Fraud - Department of Justice (.gov)

Western District of Pennsylvania | Punxsutawney Man Indicted for Social Security Fraud Department of Justice (.gov)

Habr InfoSec

Я полез в логи Mac после блокировки Claude, а починил только доступ к рабочим сайтам

1 октября мне заблокировали аккаунт Claude. До этого приложение месяц писало, что сервис недоступен в моём регионе. В логах Mac таких строк набралось 2 891. Первая версия была очевидной: VPN иногда от...

Infosecurity Magazine

ASOS Confirms Data Breach Linked to Stolen Employee Credentials

The ASOS hack comes from the compromise of agentic marketing platform Simon AI, said the attackers

The Hacker News

ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms

Cybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence (AI) pen testing tool named ARTEX to carry ou...

GBHackers

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8, 2026, embedding a new variant of the self-replicating Shai-Hulud supply-chain worm. The compromised release, te...

Habr InfoSec

Ошибочная блокировка на ТСПУ: как системному администратору решить проблему совместно с регулятором

Недавно часть наших клиентов не могла подключиться к серверам Монеты. Мы проверили межсетевые экраны, собрали трассировки с обеих сторон, но причина оказалась за пределами нашей инфраструктуры. При эт...

Infosecurity Magazine

Russia-Aligned UAC-0099 Evolves MATCHBOIL Malware

Russia-aligned UAC-0099 has steadily upgraded its MATCHBOIL downloader since 2024

Bitdefender Labs

The phone was compromised before the user turned it on: the rise of Midnight Mimosa

Bitdefender's security researchers have identified a malware campaign (dubbed Midnight Mimosa) running on low-cost, multi-brand Android devices built on MediaTek platforms.

GBHackers

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that can expose active users’ session cookies and enable remote code execution (RCE) as...

Habr InfoSec

Как использование нейросетей изменило игровую индустрию и homebrew-cцену

Игровая индустрия прошла максимально сложный путь развития: от чего-то максимально локального до мейнстрима у всех возрастов, по пути успев чуть не умереть в 1983 году и возродиться руками одной компа...

UK NCSC

China-linked malicious actors called out by UK and international partners for targeting sensitive data globally

Joint advisory with international partners highlights malicious targeting of organisations from a range of sectors across the globe.

Infosecurity Magazine

Chinese Hacker Deployed AI in Campaign Against South Korean Banks

CrowdStrike revealed that a Chinese-speaking hacker deployed agentic pentesting tool ARTEX and Claude to help breach data from South Korean financial firms

GBHackers

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process deployments by exploiting unsafe Python pickle deserialization. This flaw...

Habr InfoSec

Я написал сканер уязвимостей для вайбкода и проверил им 3 800 чужих репозиториев

Сегодня Telegram-бот для продажи VPN собирается за вечер: Cursor, пара промптов, и он уже принимает деньги. Только в config.py лежит токен бота, Postgres открыт наружу, а в истории git остался .env, к...

The Hacker News

Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia

Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials. Attackers are increasingly building filtering, session management, and traffic contr...

Infosecurity Magazine

Critical Flaw in Multiple Atlassian Products Exploited in the Wild

A critical vulnerability affecting eight Atlassian products, including Jira and Confluence, is being exploited in the wild, said VulnCheck

GBHackers

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys during wallet imports. Disguised as wallet portals, desktop utilities, and browse...

Habr InfoSec

Инструменты не спасут: как выстроить системную безопасность Kubernetes в условиях сотен разрозненных кластеров

Мы очень давно — более 10 лет — говорим о безопасности k8s. Это второй опенсорс‑проект в мире после Linux, а в РФ только «ванильным кубом» пользуются более 53% компаний (не считая коммерческие и облач...

Wired Security

The Man Behind a West Bank Telegram Channel Trying to Keep Palestinian Drivers Safe

With no accurate Big Tech mapping app to help him, Anas Hattab launched a Telegram group to get himself home at night. Now nearly 350,000 Palestinians rely on it to navigate the occupied West Bank.

Infosecurity Magazine

Europol and US Spending Watchdog Sound the Alarm Over Quantum Threats

Europol and US Government Accountability Office urge faster transition to post-quantum cryptography

GBHackers

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise iPhones and harvest cryptocurrency wallet secrets. Censys researchers uncove...

Habr InfoSec

Guardrails для LLM: как устроена защита языковых моделей

Привет, Хабр! Я Антон, инженер по информационной безопасности в Selectel. Представьте новость: защиту GPT-6 Astra обошли обычным транслитом. Сегодня это звучит как фантастика, а вот ранние LLM ломалис...

The Hacker News

U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks

The U.S. State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 20...

Infosecurity Magazine

FBI and Secret Service Warn of FortiBleed Lockout Threat

The FBI and Secret Service are warning Fortigate admins that their systems are still being targeted

About & Contact

Ghostwire is an independent project operated by a single security analyst. No corporate ownership, no investor funding, no advertising revenue. The platform fuses and enriches 200+ public cybersecurity intelligence sources across 12+ languages — including Chinese, Russian, Japanese, Korean, Spanish, Portuguese, French, German, Polish, Swedish, Ukrainian, and English — covering NVD, CISA KEV, CERTs, vendor advisories, research blogs, and threat actor disclosures into a unified real-time threat picture.

Daily briefings are AI-generated by automated analysis without human editorial oversight; treat them as a starting point and verify critical claims against primary sources. CVE enrichment uses NVD, FIRST EPSS, CISA KEV, and the nomi-sec PoC-in-GitHub database.

Contact & security disclosures: contact@ghostwire.news

Provided as-is for informational purposes. No warranty. Not affiliated with any vendor, government agency, or commercial threat-intelligence provider.