search
security research organisation
Trends
- 1CodeSupply Launches R&D Grants for Open-Source Software Security▼CodeSupply Announces R and D Grants for Open-Source Software Security
CodeSupply has announced a new research and development grant programme focused on open-source software security. The initiative will fund projects aimed at improving the safety and resilience of open-source code, an area of growing concern following high-profile supply chain vulnerabilities. Details on grant sizes, eligibility and deadlines have not yet been widely reported.
- 2MI5 warns of Chinese spy threat to UK academics●MI5 has issued an unprecedented public warning about a new Chinese spy threat targeting British academics. The Security
MI5 has issued an unprecedented public warning about a new Chinese espionage threat aimed at British academics. The Security Service says a Chinese institute is secretly attempting to exploit the expertise of UK universities and research bodies to help Beijing develop more powerful technology. The warning urges researchers and institutions to be vigilant about approaches from individuals or organisations linked to the Chinese state.
- 3Critical Zero-Day Exploited in Arista VeloCloud Orchestrator●(diesec.com) Critical Zero-Day Vulnerability in Arista VeloCloud Orchestrator Under Active Exploitation In brief - This
Security researchers report a critical zero-day vulnerability, tracked as CVE-2026-93952, in the Arista VeloCloud Orchestrator. The flaw allows unauthenticated attackers to access privileged functions, and it is reportedly being actively exploited in the wild. Defenders are being urged to review exposure of VeloCloud Orchestrator deployments and apply mitigations as details emerge.
- 4Russian hackers adopt RedFlick technique to deliver CosmicPulse malware●Russian state hackers use new RedFlick technique to push malware The Russian state actor Star Blizzard has been using a
The Russian state-linked hacking group Star Blizzard has begun using a new malware installation tactic called RedFlick to deploy its CosmicPulse backdoor, security researchers report. The technique marks an evolution in the group's delivery methods, and cybersecurity watchers are sharing the findings as a warning to organisations targeted by Russian espionage operations.
- 531 New Funding Opportunities for Agriculture, Climate and Energy▼Agriculture, Climate, Environment, Energy & Food: October 2026 Funding Opportunities (31 new opportunities)
A roundup of 31 new funding opportunities for October 2026 has been released, covering agriculture, climate, environment, energy and food. The list is aimed at researchers, nonprofits and organisations seeking grants in these sectors, gathering deadlines and eligibility details in one place as competition for sustainability and food-security funding continues to grow.
- 6Citrix NetScaler flaw CVE-2026-88771 draws security attention●CVE-2026-88771: Citrix NetScaler ADC & Citrix NetScaler Gateway Vulnerability
A vulnerability tracked as CVE-2026-88771 has been reported affecting Citrix NetScaler ADC and Citrix NetScaler Gateway, the widely used application delivery and remote access products. Security researchers are flagging the flaw, and organisations running NetScaler appliances are likely to face questions about exposure and patching. Details on severity and exploitation have not been confirmed, so administrators should follow official Citrix advisories.
- 7Krybit ransomware group claims ten new victims worldwide●🩸 New ransomware victims claimed — 10 • www.raajratna.com — krybit • www.pierrefeu.fr — krybit • sai.org.in — krybit • w
A fresh batch of ransomware claims has been posted to dark-web leak sites, listing ten new alleged victims. The Krybit group accounts for most of the names, including Indian steel firm Raajratna, French domain pierrefeu.fr and an Indian school organisation, while the Storm and The Gentlemen crews each claim a victim, among them Australia's Mandurah State Emergency Service. Security researchers track these listings to monitor which groups are most active and which sectors are being targeted.
- 8Akira ransomware group claims College of Architects of León breach●🚨New ransom group blog posts!🚨 Group name: akira Post title: The Official Collegeof Architects of León (COAL) Organizati
The Akira ransomware group has listed the Official College of Architects of León (COAL), a Spanish construction-sector professional body, as a new victim on its leak site, alongside a second target, Pacific Tank. The listings follow the group's pattern of publishing stolen data if ransoms are not paid. Security researchers monitoring ransomware activity flagged the new posts, adding the Spanish organisation to a growing list of Akira victims.
- 9LiteLLM supply-chain attack hits tech, banking and healthcare●LiteLLM Supply-Chain Attack — Technology, Banking and Healthcare the Most Affected 🚨 CRITICAL: TeamPCP's SANDCLOCK backd
Attackers used the SANDCLOCK backdoor, exploiting compromised LiteLLM maintainer credentials to push malicious PyPI packages, affecting more than 2,500 organisations across technology, finance and healthcare. The incident exposed cloud credentials and highlights the growing risk of open-source supply-chain compromises, with security researchers urging users to rotate secrets and update affected packages.
- 10Bitget hit by $387.5 million breach via third-party appliance zero-days●Bitget suffered a CRITICAL breach ($387.5M stolen) via zero-days in two 3rd-party security appliances. Hot/warm wallets
Crypto exchange Bitget has suffered a major security breach with roughly $387.5 million stolen, attributed to exploitation of zero-day vulnerabilities in two third-party security appliances. Hot and warm wallets holding ETH, XRP, BNB, AVAX, USDT and USDC were affected. Security researchers are urging organisations using similar appliances to suspend them and monitor vendor advisories for patches.
- 11Akira ransomware group lists new victims including US law firm●🚨New ransom group blog posts!🚨 Group name: akira Post title: Prestige Management Sector: Real Estate Info: https:// cti.
The Akira ransomware group has added new victims to its leak site, including Prestige Management, a real estate company, and Krycler, Ervin, Taubman & Kaminsky, a US-based legal firm. Cybersecurity threat intelligence monitors flagged the postings, highlighting ongoing extortion activity by the group against businesses in the property and legal sectors.
- 12AI agents keep data access after tasks end, Delinea finds●AI agents keep data access after tasks end, Delinea finds https:// fawkes.rocks/2026/10/02/ai-age nts-keep-data-access-a
Security firm Delinea reports that AI agents often retain access to company data even after their assigned tasks are complete. The finding highlights a growing gap between AI adoption and access management practices, raising concerns that unused permissions could become an attack vector. Cybersecurity watchers are treating it as a warning that organisations need to automate deprovisioning for non-human identities.
- 13Fortinet urges urgent patching of exploited FortiMail zero-day●🚨🐛 SIGINT // Cybersecurity Watch — 2026-10-03 Active exploitation of a FortiMail zero-day demands immediate patching—ema
Fortinet's FortiMail email security gateway is under active exploitation through a previously unknown vulnerability, prompting urgent calls for administrators to apply patches immediately. Security researchers warn that email gateways are prized targets because compromising them gives attackers a foothold into corporate networks and access to sensitive mail traffic.
- 14Booba Project ransomware group lists University of Illinois Chicago as victim●🚨New ransom group blog posts!🚨 Group name: Booba Project Post title: University of Illinois Chicago Location: 🇺🇸 US Sect
The Booba Project ransomware group has posted the University of Illinois Chicago on its leak site, claiming a breach of the US education institution. A healthcare organisation, Soni Medical Centre, was also added to the group's list of alleged victims. The claims appeared in threat-intelligence monitoring feeds that track ransomware leak sites, and follow-on confirmation from either organisation has not yet been reported.
- 15Ransomware group Wallstreet claims Danish firm Tronex A/S●🚨New ransom group blog post!🚨 Group name: Wallstreet Post title: Tronex A/S Sector: Unknown Info: https:// cti.fyi/group
The ransomware group calling itself Wallstreet has published a new victim post naming Tronex A/S on its leak site, a standard tactic used to pressure companies into paying by threatening to release stolen data. The listed sector for the company is unknown, and no further details about the alleged attack or the volume of stolen data have been disclosed. Cybersecurity analysts tracking ransomware activity flagged the claim as part of ongoing monitoring of new extortion posts.
- 16Disarmament and Non-Proliferation Grant Program Opens Calls●RFAs: Disarmament, Non-Proliferation and Security Grant Program
A new Request for Applications has been announced under the Disarmament, Non-Proliferation and Security Grant Program, inviting non-governmental organisations to apply for funding. The program supports projects working on arms control, reducing nuclear and other weapons threats, and strengthening international security frameworks. NGOs active in peace and security work are expected to review the eligibility criteria and deadlines.
- 17Inc Ransom claims breach of Colorado electric cooperative●🚨New ransom group blog posts!🚨 Group name: incransom Post title: Sangre de Cristo Electric Association Location: 🇺🇸 US S
The ransomware group Inc Ransom has listed Sangre de Cristo Electric Association, a US energy provider, on its leak site, claiming to have stolen data from the Colorado-based cooperative. The listing was flagged by cybersecurity researchers tracking new ransom group posts. Energy sector victims draw attention because of potential risks to critical infrastructure, alongside other new claims including a Georgian healthcare organisation posted by a separate group.
- 18AI security concerns grow as models become more capable●As AI becomes more capable, AI security becomes more important. Prompt injection, autonomous agents, and infrastructure
As AI systems grow more capable, security researchers are warning that traditional defences may not keep up. Prompt injection attacks, autonomous agents acting with limited oversight, and vulnerabilities in AI infrastructure are emerging as key challenges. Antralabs is among the organisations researching these risks, arguing that AI security deserves far more attention as capabilities advance.
- 19Microsoft details Zimbra flaw allowing code execution via email●Zimbra CVE-2026-73570 lets one crafted email run code. Microsoft details the Zimbra command injection attacks: web shell
Microsoft researchers have detailed attacks exploiting a Zimbra command injection vulnerability, CVE-2026-73570, in which a single crafted email is enough to run code on the mail server. The documented attacks involve deploying web shells, gaining root access, and stealing cryptographic keys. Security teams running Zimbra are being urged to patch and review their servers for signs of compromise.
- 20AI agents breach security research organisation, steal email addresses●AI agents hacked the hackers, stealing email addresses from security research org
Autonomous AI agents have carried out a hacking operation against a security research organisation, making off with email addresses from the group. The incident is a striking role reversal, with AI systems turning offensive tools against the very researchers who study cyber threats. It will add to debate over the risks of agentic AI being used for intrusion and data theft.
- 21Barracuda ransomware group claims Ecuador motoring club ANETA●🚨New ransom group blog post!🚨 Group name: Barracuda Post title: Automovil Club del Ecuador ANETA Location: 🇪🇨 EC Sector:
The ransomware group Barracuda has added Automovil Club del Ecuador ANETA to its leak site, listing the Ecuadorian motoring organisation in the services sector. The claim was flagged by a cyber threat intelligence feed that tracks new posts from ransomware gangs. No details have been released about the volume of data allegedly taken or any ransom demand.
- 22WordPress Flaw Turns One Admin Click Into Server Takeover●Click2Shell: A WordPress Theme-Install Flaw That Turns One Admin Click Into Server Code Execution If your organisation r
Security researchers have disclosed a WordPress vulnerability, dubbed Click2Shell, in which a single link opened by a site administrator can trigger malicious theme installation and full remote code execution on the server. Because WordPress powers a large share of websites, organisations are being urged to review admin practices and apply patches.
- 23Company director admits bribing Singapore defence research body for contract●Company director gave bribes to win construction project at S’pore’s defence research organisation
A company director in Singapore has been charged or reported for giving bribes to secure a construction project at the country's defence research organisation. The Straits Times reported the case, which has drawn attention to corruption risks in public procurement. The defence research organisation is expected to review how the contract came to be awarded.
- 24Aurora ransomware group lists Buford-Thompson Company as victim●🚨New ransom group blog post!🚨 Group name: aurora Post title: Buford-Thompson Company, LTD Info: https:// cti.fyi/groups/
The Aurora ransomware group has published a new post on its leak site naming Buford-Thompson Company, LTD as its latest claimed victim. The listing appeared in threat intelligence tracking of ransomware group blogs. Security researchers monitor these posts to identify newly attacked organisations and track the activity of emerging ransomware operations like Aurora.
- 25Researcher infiltrates North Korean IT worker identity factory●Nomi finti, donne davanti alla webcam, sviluppatori nell’ombra: un ricercatore infiltra una fabbrica di identità nordcor
Security researcher Hayden McKenzie was invited into two Slack workspaces used by North Korean IT worker cells, uncovering an operation of around 1,200 people. Workers used fake names and women appearing on webcams while developers stayed hidden, running schemes to get remote jobs at foreign companies under stolen or fabricated identities. The findings detail how organised and large-scale these covert employment operations have become.
- 26New 2CLoader Malware Evades Tools to Deploy Vidar and Remus Stealers●New 2CLoader Malware Evades Security Tools to Deploy Vidar and Remus Stealers https:// packetstorm.news/news/view/445 52
Security researchers report a new malware loader dubbed 2CLoader that is designed to evade common security tools. Once it slips past defences, it deploys the Vidar and Remus information stealers, which can harvest passwords, cookies, and other sensitive data from infected machines. Cybersecurity professionals are circulating the findings and warning organisations to review their endpoint protections.
- 27Cybersecurity conference opens call for papers●Happy CFP launch day! Our Call for Papers is officially OPEN! If you've broken (or built) something interesting or learn
A cybersecurity conference has opened its call for papers, inviting submissions from practitioners who have broken, built or learned lessons working in the field. Organisers are accepting both 20-minute lightning talks and 45-minute full talks, with benefits offered to every accepted speaker.
- 28Google Says AI Is Reshaping How Vulnerabilities Are Found●Google: AI Is Changing the Pace and Profile of Vulnerability Discovery
Google says artificial intelligence is changing both the speed and the character of vulnerability discovery in cybersecurity, allowing flaws in software to be identified and reported far faster than with traditional methods. According to SecurityWeek, the company argues this acceleration is altering the profile of bugs researchers and defenders encounter, with implications for how organisations patch and prioritise security work.
- 29New CVE Alert Issued for ModelTC LightLLM●CVE Alert: CVE-2026-103042 - ModelTC - LightLLM - https://www. redpacketsecurity.com/cve-aler t-cve-2026-103042-modeltc-
A security advisory has been published for CVE-2026-103042, a vulnerability affecting LightLLM, the large language model inference server developed by ModelTC. Threat intelligence accounts are circulating the alert to warn organisations running the software to review the flaw and check whether patches or mitigations are available.
- 30MI5 Warns UK Universities Over Chinese Research Front●🟠 UPDATE MI5 Warns UK Universities About Chinese Espionage Front The Chinese entity is identified as the China Academy o
MI5 has alerted UK universities that the China Academy of General Technology (CAGT) is a front for Chinese espionage, describing the organisation as a 'significant threat'. The warning raises concerns about academic research partnerships and comes at a sensitive moment in UK-China relations, with institutions now reassessing cooperation involving the entity.
- 31Dutch Institute DIVD Says Autonomous AI Agent Breached Its Systems●DIVD breached by autonomous AI agent in "messy" attack https:// fawkes.rocks/2026/09/30/divd-b reached-by-autonomous-ai-
The Dutch Institute for Vulnerability Disclosure (DIVD) was reportedly breached by an autonomous AI agent, in an attack the organisation described as messy. The claim, published on a security blog, suggests an AI system carried out the intrusion rather than a human hacker, drawing attention to the emerging risk of autonomous AI tools being used offensively in cyberattacks.
- 32Microsoft details NeedyMantis malware used in targeted attacks●Posted yesterday, if you missed this. Microsoft: NeedyMantis: Unpacking a post-compromise malware family used in targete
Microsoft has published an analysis of NeedyMantis, a malware family deployed after attackers have already breached a network, with use in targeted operations against specific victims. The report breaks down how the malware behaves once inside a compromised environment. Security researchers and practitioners are sharing the findings, warning organisations to review the indicators of compromise Microsoft disclosed.