Flock cuts staff today amid growing privacy backlash
The company declined to say whether CEO Garrett Langley will take a pay cut following the workforce reduction, TechCrunch reports.
Independent technology news and analysis from TechGlobal.news.
The company declined to say whether CEO Garrett Langley will take a pay cut following the workforce reduction, TechCrunch reports.
Patches exist for CVE-2024-21887 in Ivanti Connect Secure, CVE-2024-3400 in PAN-OS GlobalProtect, and CVE-2023-4966 in NetScaler ADC and Gateway, which continue to draw attacker interest.
Searchlight Cyber discloses the bug on October 8; the attack needs only public information to recover the controlling key, The Hacker News reports.
The on premises flaw enables unauthenticated admin creation and remote code execution, patches are available now and Atlassian Cloud is not affected.
Ongoing intrusions through unpatched ConnectWise Control servers enable ransomware affiliates to pivot into downstream tenants; defenders are urged to validate versions, hunt for persistence, and rotate credentials.
Defenders should prioritize patching and isolation of remote access tools, sweep for persistence, and rotate credentials after weekend dwell time.
The edge device bug exposes internet facing appliances to takeover, Cisco urges customers to patch ASA and Firepower Threat Defense today or disable clientless SSL VPN as a stopgap.
Enterprises report ongoing campaigns abusing Microsoft 365 and Google Workspace consent flows and session tokens, exploiting misconfigured app policies to maintain persistent access.
Security firms say Midnight Blizzard and financially motivated crews are leaning on malicious Entra ID applications with high privilege Graph scopes, neutral to password resets and MFA.
Politie Landelijke Opsporing en Interventies confirms the arrest in a Monday X post, The Hacker News reports.
Incident responders say ransomware crews still enter networks through unpatched self hosted ScreenConnect servers, urging immediate version verification and compromise hunting.

Russia's attacks on Kyiv test civilian resilience as winter looms

Cambodian rice farmers help to conserve threatened cranes

The King spoke of "threats to our international order" in a letter marking the 10th anniversary of the National Cyber Security Centre.
  submitted by   <a href="https://www.reddit.com/user/utrecht1976"> /u/utrecht1976 </a> <br/> <span><a href="https://cphpost.dk/2026-10-10/news/round-up/123456-password-used-in-massive-danish-cpr-data-breach/">[link]</a></span>   <span><a href="https://www.reddit.com/r/technology/comments/1x2ig3c/123456_password_used_in_massive_danish_cpr_data/">[comments]</a></span>

Anti-cybercrime initiatives are increasingly using AI to scam the scammers by tricking them into talking to lifelike bots that they think are real victims.

In environments studied for the 2026 State of Agent Security Report, roughly 1,280 third-party products now embed AI. About 282 of them sit behind single sign-on. The other thousand are invisible to identity infrastructure by default, not because anyone hid them, but because an identity stack can only govern what authenticates through it, and most agents never do. That gap is the clearest
<b>Filed:</b> 2026-10-09 <b>AccNo:</b> 0001193125-26-419229 <b>Size:</b> 181 KB <br>Item 5.07: Submission of Matters to a Vote of Security Holders <br>Item 8.01: Other Events <br>Item 9.01: Financial Statements and Exhibits
<b>Filed:</b> 2026-10-09 <b>AccNo:</b> 0001104659-26-115111 <b>Size:</b> 654 KB <br>Item 1.01: Entry into a Material Definitive Agreement <br>Item 5.03: Amendments to Articles of Incorporation or Bylaws; Change in Fiscal Year <br>Item 5.07: Submission of Matters to a Vote of Security Holders <br>Item 9.01: Financial Statements and Exhibits
<b>Filed:</b> 2026-10-09 <b>AccNo:</b> 0001493152-26-046595 <b>Size:</b> 1 MB <br>Item 1.01: Entry into a Material Definitive Agreement <br>Item 3.02: Unregistered Sales of Equity Securities <br>Item 3.03: Material Modifications to Rights of Security Holders <br>Item 5.03: Amendments to Articles of Incorporation or Bylaws; Change in Fiscal Year <br>Item 9.01: Financial Statements and Exhibits
<b>Filed:</b> 2026-10-09 <b>AccNo:</b> 0001213900-26-108579 <b>Size:</b> 606 KB <br>Item 1.01: Entry into a Material Definitive Agreement <br>Item 9.01: Financial Statements and Exhibits
<b>Filed:</b> 2026-10-09 <b>AccNo:</b> 0001437749-26-032455 <b>Size:</b> 342 KB <br>Item 5.02: Departure of Directors or Certain Officers; Election of Directors; Appointment of Certain Officers: Compensatory Arrangements of Certain Officers <br>Item 5.07: Submission of Matters to a Vote of Security Holders <br>Item 9.01: Financial Statements and Exhibits

Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories. "Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC," StepSecurity

The FBI has arrested another suspected co-conspirator of ShinyHunters, FBI Director Kash Patel said on October 9 in a post on X. ShinyHunters is the extortion group that said in September it had breached the FBI's jobs portal and stolen sensitive data on almost all FBI agents and job applicants. The FBI has not named the suspect, and no charges have been made public. The

Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword. "Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker's infrastructure," iVerify said in a new report published Thursday. The name

French authorities recorded 90 crypto-related cases involving kidnapping, extortion, threats and violent theft in seven months. What makes France such a hotspot?

Four more U.S. states sued router maker TP-Link Systems on October 6, bringing the total to five, with Texas filing a suit in February. Florida, Iowa, Montana and Nebraska allege the California company misled buyers about how secure its routers are and how separate it is from China. TP-Link denies the claims and says it will fight them in court. TP-Link Systems is based in

Security researchers have published a full working exploit for a pre-authentication remote code execution flaw in AnyDesk Linux that gives attackers root access before anyone approves the connection. AnyDesk patched the flaw in version 8.0.3 in June, but its changelog described the fix only as "fixed a bug that could lead to a crash," with no CVE assigned and no security

Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners. Details of the flaws are below - CVE-2026-105133 (CVSS v4 score: 5.5) - An improper authentication vulnerability in the checkSysPwd() function in the "com/ahsay/obs/api/ApiStructsAction.java"

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their abuse by a China-linked threat actor known as Flax Typhoon. The vulnerabilities in question are listed below - CVE-2015-3306 (CVSS score: 10.0) - An improper access control vulnerability in ProFTPD that could allow

A bug in GoBalance, a tool many dark-web sites use to stay reachable during attacks, lets anyone work out the secret key that controls a site's .onion address using only public information, and then take that address over. Searchlight Cyber, which disclosed the flaw on October 8, says an attacker who recovers the key can redirect the site's visitors to a copy of the site they control.

Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched. The contest pays researchers to show working exploits and passes the flaws to the vendors. One of the three Pixel exploits earned Ikotas Labs $300,000, the contest's top prize, and made the team the overall winner. Trend Micro's Zero

Citrix has released patches for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions. "CVE-2026-107406 is a memory overflow vulnerability that may lead to remote code execution or denial-of-service under specific configuration conditions," Citrix said. The vulnerability

Discover how Sophos uses OpenAI’s Daybreak to cut cyber-threat investigation time by 96% and automate 52% of MDR cases while preserving human oversight.

The U.S. Federal Bureau of Investigation (FBI) and Department of Justice (DoJ) have announced the disruption of malicious tools used by a China-linked advanced persistent threat group known as Flax Typhoon. To that end, the agencies seized several domains and blocked access to platforms that were used to scan, and in some cases infiltrate, U.S. critical infrastructure. The list of seized