π¨ BREAKING: Qilin has briefly published 6.3GB of data the ransomware group says it stole from the ATF, after a 72-hour countdown expired.
Files include Cellebrite extractions, dumps from an iPhone 6 and a Samsung Galaxy J3, and case folders naming investigation targets, phone numbers and IP addresses.
ATF is still investigating the claims and has not confirmed a breach.
Files include Cellebrite extractions, dumps from an iPhone 6 and a Samsung Galaxy J3, and case folders naming investigation targets, phone numbers and IP addresses.
ATF is still investigating the claims and has not confirmed a breach.
1β€14π±2π€£1
Security researcher Zachi says he found an exploit in an app and reported it.
After two months with no reply to his bug report,
he tried again β this time by emailing the vendor from its own email address, with the message: "I'M WRITING TO YOU RIGHT NOW FROM YOUR OWN EMAIL."
After two months with no reply to his bug report,
he tried again β this time by emailing the vendor from its own email address, with the message: "I'M WRITING TO YOU RIGHT NOW FROM YOUR OWN EMAIL."
π€£38β€6π4π₯1π©1
βΌοΈBREAKING: Nearly 22,000 Microsoft Exchange servers still miss the fix for a critical vulnerability that gets attackers into mailboxes without a password, Shadowserver says
The proof-of-concept exploit code is publicly available and easy to abuse.
Read:
https://shadowserver.org/what-we-do/network-reporting/vulnerable-exchange-server-report/
The proof-of-concept exploit code is publicly available and easy to abuse.
Read:
https://shadowserver.org/what-we-do/network-reporting/vulnerable-exchange-server-report/
π9π₯6π€£4π1π1
βΌοΈ Many X users got password-reset emails they never requested, fortunately X engineer Mridul Singhai says there is no evidence of a breach
He says attackers appear to be targeting accounts now X Money is widely available
You can use X's Password Reset Protect setting against these attacks
He says attackers appear to be targeting accounts now X Money is widely available
You can use X's Password Reset Protect setting against these attacks
π€£20β€1
βΌοΈ BREAKING: We now know what led to the major breach at Manchester Airports Group that exposed 8.7 million people's data. Turns out they made a serious error: they put API keys with access to everything in their frontend's JavaScript files.
π€£35π5π3π₯΄2
π¨ BREAKING: Defense Secretary Pete Hegsethβs driverβs license has leaked. A new dark-web service is selling scans of his and 153M+ U.S. and Canadian driverβs licenses.
Timestamps on the scans match victimsβ visits to Hertz rental counters and cannabis dispensaries. Evidence points to idscan[.]net, an ID-verification vendor used by Hertz, Target, FedEx and 1,000+ dispensaries.
The FBI opened an investigation on Tuesday. Nexus claims it has been exfiltrating for over a year and added ~400,000 licenses in 24 hours.
https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/
Timestamps on the scans match victimsβ visits to Hertz rental counters and cannabis dispensaries. Evidence points to idscan[.]net, an ID-verification vendor used by Hertz, Target, FedEx and 1,000+ dispensaries.
The FBI opened an investigation on Tuesday. Nexus claims it has been exfiltrating for over a year and added ~400,000 licenses in 24 hours.
https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/
π€£37π¨6
π³π΄ Norway's privacy regulator wants smart glasses pulled from sale. As a first step, Norway's Digitalisation Minister Karianne Tung is weighing a ban on facial recognition of strangers in public rather than on the glasses themselves, and is setting up an expert group to propose rules this autumn for the cameras and AI now built into glasses, earbuds and caps.
1β€29π₯6π1
βΌοΈ BREAKING: A major breach at Nordic/Benelux IT supplier Dustin has led it to take systems offline. Webshops are down, and orders and deliveries have stopped.
We have reason to believe Dustin also stores highly confidential government data, possibly exposing secret networks and hardware. They are a major supplier of IT hardware and software to government bodies across the Nordics and Benelux.
https://www.dustingroup.com/en/media#/pressreleases/dustin-investigates-a-serious-it-security-incident-3464571
We have reason to believe Dustin also stores highly confidential government data, possibly exposing secret networks and hardware. They are a major supplier of IT hardware and software to government bodies across the Nordics and Benelux.
https://www.dustingroup.com/en/media#/pressreleases/dustin-investigates-a-serious-it-security-incident-3464571
π€£11π1
βοΈA UK class action is seeking Β£2bn from Apple over its tracking prompts.
Since 2021 apps must ask permission before tracking Apple users β but those rules were less strict for Apple's own apps, says Hausfeld, which filed the claim on 3 September for thousands of UK developers. Apple denies any double standard.
Apple says it is "bound by the exact same requirements as all developers".
https://www.hausfeld.com/en-gb/news/apple-faces-2-billion-legal-action-over-app-tracking-transparency-att-framework
Since 2021 apps must ask permission before tracking Apple users β but those rules were less strict for Apple's own apps, says Hausfeld, which filed the claim on 3 September for thousands of UK developers. Apple denies any double standard.
Apple says it is "bound by the exact same requirements as all developers".
https://www.hausfeld.com/en-gb/news/apple-faces-2-billion-legal-action-over-app-tracking-transparency-att-framework
π€10π4π€£3π₯2π©1
A new documentary floats the idea that Elon Musk stole the 2024 election with satellite lasers.
The evidence, per Alex Gibney's film: an ex-partner recalling that Musk promised to unleash an "anomaly in the matrix," and one text onscreen β "I have ten thousand lasers in space."
The reality: those lasers are optical crosslinks that pass traffic between satellites. Vote tabulators are air-gapped and, in Georgia and North Carolina, barred by law from touching the internet.
The evidence, per Alex Gibney's film: an ex-partner recalling that Musk promised to unleash an "anomaly in the matrix," and one text onscreen β "I have ten thousand lasers in space."
The reality: those lasers are optical crosslinks that pass traffic between satellites. Vote tabulators are air-gapped and, in Georgia and North Carolina, barred by law from touching the internet.
π©23π₯5π4π€£1
βΌοΈ BREAKING: Serbia targeted activists with Pegasus spyware. At least 14 people, including student protesters and opposition figures, were infected.
Citizen Lab confirmed one iPhone was infected with NSO Groupβs Pegasus through an iMessage zero-click exploit.
Two NoviSpy infections were also confirmed. One Serbian student's Android phone was confiscated during police questioning. Amnesty International's Security Lab then found a new NoviSpy variant on it, rebuilt specifically to evade detection.
Serbia's intelligence office calls the findings "trivial sensationalism."
What led to these findings, are Apple's threat notifications, sent on Aug. 13, to users in 110 countries, prompting 12 of the Serbian targets to contact SHARE Foundation.
Serbian parliamentary elections are in October.
https://citizenlab.ca/research/pegasus-spyware-infection-of-serbian-activist/
Citizen Lab confirmed one iPhone was infected with NSO Groupβs Pegasus through an iMessage zero-click exploit.
Two NoviSpy infections were also confirmed. One Serbian student's Android phone was confiscated during police questioning. Amnesty International's Security Lab then found a new NoviSpy variant on it, rebuilt specifically to evade detection.
Serbia's intelligence office calls the findings "trivial sensationalism."
What led to these findings, are Apple's threat notifications, sent on Aug. 13, to users in 110 countries, prompting 12 of the Serbian targets to contact SHARE Foundation.
Serbian parliamentary elections are in October.
https://citizenlab.ca/research/pegasus-spyware-infection-of-serbian-activist/
π©13π€¬7π±4π2π―1π€ͺ1