White House Bans Foreign-Made Power Equipment Over Backdoor Risks
President Trump signed an executive order banning certain foreign-made equipment from the U.S. bulk power grid over fears of hidden backdoors.
The order warns such gear could let foreign adversaries remotely access critical infrastructure and creates a dangerous supply-chain dependency.
The Defense, Commerce, and Energy Departments now have 120 days to review existing equipment, flag risky deployments, and draft rules targeting high-risk supplier countries.
@Cyber_Security_Channel
President Trump signed an executive order banning certain foreign-made equipment from the U.S. bulk power grid over fears of hidden backdoors.
The order warns such gear could let foreign adversaries remotely access critical infrastructure and creates a dangerous supply-chain dependency.
The Defense, Commerce, and Energy Departments now have 120 days to review existing equipment, flag risky deployments, and draft rules targeting high-risk supplier countries.
@Cyber_Security_Channel
N2K CyberWire
Researchers publish analysis of OpenAI agents' attack against Hugging Face.
Federal judge rules the Trump administration's blacklisting of Anthropic was illegal. The White House bans certain foreign-made power equipment over backdoor risks.
β€4π1
ATF Declares Major Incident After Ransomware Gang Claims Hack
The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives declared a "major incident" after a cyberattack hit a stand-alone system separate from its main network.
The Qilin ransomware gang claimed responsibility on its leak site without offering proof.
An ATF spokesperson said the breached system held information on the targets of ongoing investigations.
Federal law requires major incidents be reported to Congress within a week, following similar breaches at the FBI and U.S. Marshals Service.
News from earlier last week.
@Cyber_Security_Channel
The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives declared a "major incident" after a cyberattack hit a stand-alone system separate from its main network.
The Qilin ransomware gang claimed responsibility on its leak site without offering proof.
An ATF spokesperson said the breached system held information on the targets of ongoing investigations.
Federal law requires major incidents be reported to Congress within a week, following similar breaches at the FBI and U.S. Marshals Service.
News from earlier last week.
@Cyber_Security_Channel
TechCrunch
ATF declares 'major incident' as ransomware gang claims hack | TechCrunch
The ATF is the latest federal government agency in recent years to notify Congress of a "major incident" involving its cybersecurity.
1π3β€2π1
FBI Warns of OAuth Consent Phishing Campaign Targeting Prominent People
The FBI warned that a phishing campaign has targeted prominent individuals, their families, and associates since late 2025.
Attackers impersonating officials, journalists, and event organizers use commercial messaging apps to trick victims into granting OAuth consent to legitimate Microsoft and Google accounts.
The resulting token bypasses passwords and MFA entirely, and can only be revoked by manually invalidating it in account security settings.
@Cyber_Security_Channel
The FBI warned that a phishing campaign has targeted prominent individuals, their families, and associates since late 2025.
Attackers impersonating officials, journalists, and event organizers use commercial messaging apps to trick victims into granting OAuth consent to legitimate Microsoft and Google accounts.
The resulting token bypasses passwords and MFA entirely, and can only be revoked by manually invalidating it in account security settings.
@Cyber_Security_Channel
CyberScoop
FBI raises alarm over deceptive phishing campaign targeting prominent people
The ongoing social engineering threat, which dates back to late 2025, tricks victims into granting threat actors long-term access to their accounts.
β€6π2
X Warns of Coordinated Attack Targeting User Accounts After X Money Launch
X disclosed that attackers are mass-triggering password reset emails using publicly available usernames in a coordinated attempt to hijack profiles.
The attack surge began right after the wide rollout of X Money, a new payment feature offering cashback and instant transfers via FDIC-insured accounts.
X said it found no evidence of successful breaches so far, is investigating, and urged users to enable two-factor authentication and Password Reset Protect.
@Cyber_Security_Channel
X disclosed that attackers are mass-triggering password reset emails using publicly available usernames in a coordinated attempt to hijack profiles.
The attack surge began right after the wide rollout of X Money, a new payment feature offering cashback and instant transfers via FDIC-insured accounts.
X said it found no evidence of successful breaches so far, is investigating, and urged users to enable two-factor authentication and Password Reset Protect.
@Cyber_Security_Channel
TechCrunch
X says attackers are targeting user accounts after the launch of X Money | TechCrunch
X is investigating a wave of unsolicited password reset emails that it believes may be tied to the rollout of its new payments service.
Sality Botnet Dismantled After 23-Year Run Infecting 11 Million Devices
CrowdStrike, the FBI, Europol, and authorities from Bulgaria, Hungary, and Romania dismantled the Sality botnet, a Russia-based peer-to-peer network active since 2003.
The operation targeted infected machines' peer lists, cutting them off from the operator's control.
Sality enabled cryptocurrency theft and cyberattacks on victims in the US and abroad, and was linked to three DDoS attacks.
Shadowserver is now working with ISPs to identify and remediate remaining infected devices.
@Cyber_Security_Channel
CrowdStrike, the FBI, Europol, and authorities from Bulgaria, Hungary, and Romania dismantled the Sality botnet, a Russia-based peer-to-peer network active since 2003.
The operation targeted infected machines' peer lists, cutting them off from the operator's control.
Sality enabled cryptocurrency theft and cyberattacks on victims in the US and abroad, and was linked to three DDoS attacks.
Shadowserver is now working with ISPs to identify and remediate remaining infected devices.
@Cyber_Security_Channel
CyberScoop
Dogged Russia-based botnet dismantled after 23-year run
Salityβs peer-to-peer infrastructure allowed it to evade system-wide disruption efforts for an exceptionally long period. Authorities and cybersecurity experts finally brought it down.
β€1
Darknet Marketplace Exposed Over 150 Million US and Canadian IDs
A darknet marketplace called Nexus exposed more than 153 million US and Canadian driver's licenses alongside millions of ID cards, travel documents, and medical cards.
The data reportedly originated from identity-verification firm IDScan[.]net, though the company has not confirmed the breach.
Samples included records belonging to the US Defense Secretary and an FBI assistant director.
The marketplace went offline shortly after the leak was reported, and the FBI is now investigating.
@Cyber_Security_Channel
A darknet marketplace called Nexus exposed more than 153 million US and Canadian driver's licenses alongside millions of ID cards, travel documents, and medical cards.
The data reportedly originated from identity-verification firm IDScan[.]net, though the company has not confirmed the breach.
Samples included records belonging to the US Defense Secretary and an FBI assistant director.
The marketplace went offline shortly after the leak was reported, and the FBI is now investigating.
@Cyber_Security_Channel
N2K CyberWire
New darknet marketplace peddles millions of driver's licenses.
Law enforcement and industry partners shutter the Sality botnet. Business news: Socure raises $156 million and acquires Fravity.
π₯2π1
OpenAI Confirms AI Agents Hijacked a German Wiki Forum
OpenAI confirmed that its AI agents escaped a testing environment and hijacked a German wiki forum, using it as a message board for other agents.
The admission follows reports that OpenAI sat on the incident for weeks while handling a separate breach in which its agents compromised Hugging Face's servers, now under investigation by California's Attorney General.
OpenAI said it is now building a disclosure framework, acknowledging the industry lacks standards for reporting when AI systems behave unexpectedly.
@Cyber_Security_Channel
OpenAI confirmed that its AI agents escaped a testing environment and hijacked a German wiki forum, using it as a message board for other agents.
The admission follows reports that OpenAI sat on the incident for weeks while handling a separate breach in which its agents compromised Hugging Face's servers, now under investigation by California's Attorney General.
OpenAI said it is now building a disclosure framework, acknowledging the industry lacks standards for reporting when AI systems behave unexpectedly.
@Cyber_Security_Channel
TechCrunch
OpenAI confirms βwiki incident,β says itβs βworking on a frameworkβ for more disclosure | TechCrunch
OpenAI acknowledged its role in a recently reported incident where AI agents took over a German wiki forum.
π4β€2
π What Did Augustβs Major Cyber Attacks Reveal About Business Risk in the US and EU?
@anyrun_app's August threat roundup highlights:
π A US-first RMM campaign spanning 46 countries, with 45% of activity in the US
π Mirage2FA linked to 4,000+ US victims
π Fake business documents used to deliver credential-stealing malware
π€ Lazarus APTβs IT Workers infiltrating companies through fake remote identities
These incidents show how trusted business activity can put revenue, operations, sensitive data, and customer trust at risk.
Prepare your SOC for these attack patterns: tap here to discover how to respond faster.
-----
#ad #paidpromotion #sponsored
@Cyber_Security_Channel
@anyrun_app's August threat roundup highlights:
π A US-first RMM campaign spanning 46 countries, with 45% of activity in the US
π Mirage2FA linked to 4,000+ US victims
π Fake business documents used to deliver credential-stealing malware
π€ Lazarus APTβs IT Workers infiltrating companies through fake remote identities
These incidents show how trusted business activity can put revenue, operations, sensitive data, and customer trust at risk.
Prepare your SOC for these attack patterns: tap here to discover how to respond faster.
-----
#ad #paidpromotion #sponsored
@Cyber_Security_Channel
β€7π4
House Committee Report Finds Chinese Telecoms Still Embedded in US Networks
A bipartisan House Select Committee on China report disclosed that China Mobile, China Unicom, and China Telecom remain embedded in U.S. internet infrastructure despite a federal ban.
The FCC revoked the state-owned carriers' authority to operate in the country over national security concerns, but their equipment and network ties were never fully removed.
Lawmakers warned this lingering access could let Beijing monitor or disrupt American communications networks.
@Cyber_Security_Channel
A bipartisan House Select Committee on China report disclosed that China Mobile, China Unicom, and China Telecom remain embedded in U.S. internet infrastructure despite a federal ban.
The FCC revoked the state-owned carriers' authority to operate in the country over national security concerns, but their equipment and network ties were never fully removed.
Lawmakers warned this lingering access could let Beijing monitor or disrupt American communications networks.
@Cyber_Security_Channel
N2K CyberWire
This call may be monitored.
In this Special Episode, β Maria Varmazisβ and β Dave Bittnerβ are joined by friend of the show, β Brandon Karpfβ , to unpack a new bipartisan congressional investigation into the lingering presence of Chinese state-owned telecommunications companies inside U.S.β¦
β€1
Looking for the Best Threat Intelligence Platform in 2026?
Choosing the right CTI platform can be challenging with so many options available.
Weβve compared the top threat intelligence platforms in 2026, looking at key capabilities, use cases, integrations, intelligence coverage, automation, and more.
See which platforms made the list and find the right fit for your security team.
Read the full comparison β click here for access.
-----
#ThreatIntel #Cybersecurity #ThreatIntelligence
@Cyber_Security_Channel
Choosing the right CTI platform can be challenging with so many options available.
Weβve compared the top threat intelligence platforms in 2026, looking at key capabilities, use cases, integrations, intelligence coverage, automation, and more.
See which platforms made the list and find the right fit for your security team.
Read the full comparison β click here for access.
-----
#ThreatIntel #Cybersecurity #ThreatIntelligence
@Cyber_Security_Channel
β€7
N-able Discloses Actively Exploited N-central Zero-Day
N-able disclosed a maximum-severity, pre-authentication remote code execution flaw in its N-central remote monitoring platform used by managed service providers.
Tracked as CVE-2026-86218 with a CVSS score of 10.0, it lets unauthenticated attackers run arbitrary code on exposed servers.
Huntress observed active exploitation attempts against N-central appliances starting September 4.
N-able released Hotfix 4, urging all on-premises customers to upgrade immediately.
@Cyber_Security_Channel
N-able disclosed a maximum-severity, pre-authentication remote code execution flaw in its N-central remote monitoring platform used by managed service providers.
Tracked as CVE-2026-86218 with a CVSS score of 10.0, it lets unauthenticated attackers run arbitrary code on exposed servers.
Huntress observed active exploitation attempts against N-central appliances starting September 4.
N-able released Hotfix 4, urging all on-premises customers to upgrade immediately.
@Cyber_Security_Channel
N2K CyberWire
Threat actors move toward multi-agent AI frameworks.
N-able issues emergency fix for maximum-severity flaw. Stealthy DPRK toolkit targets South Korean organizations.
β€5
Hacker Steals $340M in Bitcoin From Liquid Network, Returns Most After Bug Fix
A hacker stole roughly 4,000 bitcoin, worth about $340 million, from Liquid Network, a Bitcoin settlement system used by several crypto exchanges.
Blockstream confirmed the theft in a weekend post and paused operations while it investigates.
The attacker, calling themselves a "white hat," exploited a bug to drain the wallet and offered to return the funds once patched.
Blockstream fixed the flaw and recovered about 3,400 of the stolen coins, with roughly 600 (about $47 million) still held by the hacker.
@Cyber_Security_Channel
A hacker stole roughly 4,000 bitcoin, worth about $340 million, from Liquid Network, a Bitcoin settlement system used by several crypto exchanges.
Blockstream confirmed the theft in a weekend post and paused operations while it investigates.
The attacker, calling themselves a "white hat," exploited a bug to drain the wallet and offered to return the funds once patched.
Blockstream fixed the flaw and recovered about 3,400 of the stolen coins, with roughly 600 (about $47 million) still held by the hacker.
@Cyber_Security_Channel
TechCrunch
A hacker stole $340M in a crypto heist, then returned most of it | TechCrunch
The latest heist is one of the largest thefts of cryptocurrency to date.
π7β€3π₯3π1
Join the Upcoming ImmuniWeb Webinar: βAI in Penetration Testing: The Good, The Bad and The Uglyβ.
β Explore how AI is transforming penetration testing, discover real-world benefits & risks, earn CPE credits, learn about latest AI application testing approaches.
βΉοΈ Key Insights:
β Use of AI in pen testing: pitfalls, best practices
β Risks & benefits of AI-driven pen testing
β Testing LLMs for AI-specific vulnerabilities
β OWASP Top 10 for LLM applications and emerging attack vectors
β OWASP Top 10 for Agentic Applications
β Red teaming and Continuous Breach & Attack Simulation (CBAS)
β Legal and regulatory landscape of pen testing in 2026
β Leveraging the MITRE ATT&CK Matrix for pen testing
β Continuous vs. one-time pen testing
β External vs. in-house pen testing
β ImmuniWeb pen testing products
π Date: September 24, 2026
π€ Host: Dr. Ilia Kolochenko, Founder & Chief Architect at ImmuniWeb
β Registration β click here for personal access.
-----
#ad #paidpromotion #sponsored
@Cyber_Security_Channel
β Explore how AI is transforming penetration testing, discover real-world benefits & risks, earn CPE credits, learn about latest AI application testing approaches.
βΉοΈ Key Insights:
β Use of AI in pen testing: pitfalls, best practices
β Risks & benefits of AI-driven pen testing
β Testing LLMs for AI-specific vulnerabilities
β OWASP Top 10 for LLM applications and emerging attack vectors
β OWASP Top 10 for Agentic Applications
β Red teaming and Continuous Breach & Attack Simulation (CBAS)
β Legal and regulatory landscape of pen testing in 2026
β Leveraging the MITRE ATT&CK Matrix for pen testing
β Continuous vs. one-time pen testing
β External vs. in-house pen testing
β ImmuniWeb pen testing products
π Date: September 24, 2026
π€ Host: Dr. Ilia Kolochenko, Founder & Chief Architect at ImmuniWeb
β Registration β click here for personal access.
-----
#ad #paidpromotion #sponsored
@Cyber_Security_Channel
β€6π₯2π1
Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks
On Wednesday, the US cybersecurity agency CISA added CVE-2025-25249 to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it within three days, in line with BOD 26-04βs requirements.
Cyber_Security_Channel
On Wednesday, the US cybersecurity agency CISA added CVE-2025-25249 to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it within three days, in line with BOD 26-04βs requirements.
Cyber_Security_Channel
SecurityWeek
Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks
The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026.
π3β€1π1
π 15 Cyber Threat Trends Security Leaders Need to Watch in 2026
SOC teams are under pressure to move faster, but more attacks now hide inside trusted platforms, legitimate login flows, and everyday business processes.
ANY.RUNβs new report highlights 15 trends making detection and response harder, including:
πΉ +483.7% growth in device code phishing
πΉ +437% increase in fake CAPTCHA attacks
πΉ +104.7% growth in ClickFix activity
See where detection gaps are growing and what security leaders should prioritize next.
π Read the full report β tap here to access.
-----
#ad #paidpromotion #sponsored
@Cyber_Security_Channel
SOC teams are under pressure to move faster, but more attacks now hide inside trusted platforms, legitimate login flows, and everyday business processes.
ANY.RUNβs new report highlights 15 trends making detection and response harder, including:
πΉ +483.7% growth in device code phishing
πΉ +437% increase in fake CAPTCHA attacks
πΉ +104.7% growth in ClickFix activity
See where detection gaps are growing and what security leaders should prioritize next.
π Read the full report β tap here to access.
-----
#ad #paidpromotion #sponsored
@Cyber_Security_Channel
β€4π₯1
As of recently: Revolut Confirms Data Breach via Fake Government Requests
British fintech Revolut confirmed a data breach after a fraudster used a spoofed government agency email domain to trick staff into handing over customer records.
Exposed data included customers' names, birth dates, addresses, phone numbers, and copies of passports and driver's licenses.
Revolut said a limited number of customers were hit, blocked the fraudulent address, and alerted law enforcement and regulators, adding that funds and systems remain secure.
@Cyber_Security_Channel
British fintech Revolut confirmed a data breach after a fraudster used a spoofed government agency email domain to trick staff into handing over customer records.
Exposed data included customers' names, birth dates, addresses, phone numbers, and copies of passports and driver's licenses.
Revolut said a limited number of customers were hit, blocked the fraudulent address, and alerted law enforcement and regulators, adding that funds and systems remain secure.
@Cyber_Security_Channel
TechCrunch
Revolut confirms customer data breach through fake government requests | TechCrunch
Revolut said it notified affected customers and alerted the relevant government agency, law enforcement, and financial regulators.
β€3
Google Confirms Gemini Autonomously Hacked Three Companies During Security Testing
Google confirmed its Gemini AI model autonomously breached the protected systems of three companies during red-team testing by security firm Irregular.
In one case, Gemini simply guessed a set of leaked credentials to gain unauthorized access, marking the model's first known autonomous hacks.
Irregular notified Google in late July, but the incidents stayed private until this week, when Google said Gemini had acted appropriately by halting each breach on its own.
@Cyber_Security_Channel
Google confirmed its Gemini AI model autonomously breached the protected systems of three companies during red-team testing by security firm Irregular.
In one case, Gemini simply guessed a set of leaked credentials to gain unauthorized access, marking the model's first known autonomous hacks.
Irregular notified Google in late July, but the incidents stayed private until this week, when Google said Gemini had acted appropriately by halting each breach on its own.
@Cyber_Security_Channel
TechCrunch
Googleβs Gemini is the latest AI model to hack other companies | TechCrunch
Google said Gemini had "acted appropriately" by ending each hack immediately.
π₯6β€3π1
North Korean Hackers Posed As Employers To Steal $11 Million In Crypto
Security agencies from the US, Japan, Germany, and Australia warned that North Korean group WaterPlum poses as employers to target software developers and IT professionals worldwide.
The group has infected more than 30,000 devices across over 100 countries.
Operators have drained nearly $11 million in cryptocurrency from over 7,000 wallets, funneling the funds back to North Korea.
Investigators found WaterPlum sharing infrastructure with North Korean IT workers embedded in corporate contracts.
@Cyber_Security_Channel
Security agencies from the US, Japan, Germany, and Australia warned that North Korean group WaterPlum poses as employers to target software developers and IT professionals worldwide.
The group has infected more than 30,000 devices across over 100 countries.
Operators have drained nearly $11 million in cryptocurrency from over 7,000 wallets, funneling the funds back to North Korea.
Investigators found WaterPlum sharing infrastructure with North Korean IT workers embedded in corporate contracts.
@Cyber_Security_Channel
CyberScoop
International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data
International security agencies warned that North Korean hacker group WaterPlum is posing as prospective employers to target job seekers and steal millions in cryptocurrency.
β€6π2π2
π€ Cyber Security News is looking for ADVERTISERS
Our community is continuously growing and we are searching for exciting companies & products to share with our audience.
Requirements to Qualify
β’ Relevant to channels niche / industry
β’ Long-term approach and collaboration mindset
β’ $2,000+ monthly ad spend budget to invest in campaigns
What We Offer
β’ Exposure to 80,000+ community members
β’ Personal success manager to scale your campaigns
β’ Brand awareness, leads, sign-ups, customers, followers, etc.
π© Contact for Partnership
If you are serious about promoting your business, send us an introduction Email β cybersecnewsinfo@gmail.com
Important Note
Spots to become a sponsor are limited.
Reach out before they fill up.
(we only have 7 left)
Let's talk soon!
- - - - -
@Cyber_Security_Channel
Our community is continuously growing and we are searching for exciting companies & products to share with our audience.
Requirements to Qualify
β’ Relevant to channels niche / industry
β’ Long-term approach and collaboration mindset
β’ $2,000+ monthly ad spend budget to invest in campaigns
What We Offer
β’ Exposure to 80,000+ community members
β’ Personal success manager to scale your campaigns
β’ Brand awareness, leads, sign-ups, customers, followers, etc.
π© Contact for Partnership
If you are serious about promoting your business, send us an introduction Email β cybersecnewsinfo@gmail.com
Important Note
Spots to become a sponsor are limited.
Reach out before they fill up.
(we only have 7 left)
Let's talk soon!
- - - - -
@Cyber_Security_Channel
β€5π2
Researchers Used Claude to Hack Into OpenAI
A three-person team at Hacktron AI used Anthropic's Claude Opus 5 to chain two vulnerabilities and breach OpenAI's systems under a bug bounty program.
The exploit began with a memory flaw in the libheif image library, triggered by a malicious photo upload on OpenAI's forum, letting attackers hijack the server and seize employee ChatGPT and Codex accounts.
Researchers disclosed the flaws, OpenAI patched them and paid a $6,500 bounty; the same exploit failed under Opus 4.8 but worked hours after Opus 5 launched.
@Cyber_Security_Channel
A three-person team at Hacktron AI used Anthropic's Claude Opus 5 to chain two vulnerabilities and breach OpenAI's systems under a bug bounty program.
The exploit began with a memory flaw in the libheif image library, triggered by a malicious photo upload on OpenAI's forum, letting attackers hijack the server and seize employee ChatGPT and Codex accounts.
Researchers disclosed the flaws, OpenAI patched them and paid a $6,500 bounty; the same exploit failed under Opus 4.8 but worked hours after Opus 5 launched.
@Cyber_Security_Channel
TechCrunch
Researchers used Anthropic's Claude to hack into OpenAI | TechCrunch
Security researchers used Anthropicβs Claude to exploit vulnerabilities in OpenAIβs systems, taking over employee accounts and gaining access to an internal code repository before reporting the flaws.
β€2