エピソード

  • Trusted Microsoft 365 traffic hides a Windows espionage backdoor
    2026/10/02

    Daily Cyber News: Update 07 — English headline pending

    Government, defense, diplomatic, academic and policy organizations were compromised by a Windows backdoor that placed its native command channel inside Microsoft 365. By July 2026, the campaign had reached approximately 350 endpoints across eight countries. Investigators identified 10 confirmed and five probable affected institutional environments and linked the activity to China with high confidence.

    Key context: Tailored phishing emails and fake software installers delivered the malware.

    Additional detail: That use of common cloud services can make malicious traffic blend with legitimate business activity.

    For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
    Cybersecurity training, courses, books, and resources: BareMetalCyber.com.

    Topics: cybersecurity news, cybersecurity, cyber risk, phishing, malware, microsoft 365, windows.

    続きを読む 一部表示
    2 分
  • Enterprise file-sharing gateways exposed by maximum-severity flaw
    2026/10/02

    Daily Cyber News: Enterprise file-sharing gateways exposed by maximum-severity flaw

    Organizations using Kiteworks Email Protection Gateway face remote takeover if exposed appliances remain below version 9.4.1. Kiteworks released updates covering 126 vulnerabilities. The most serious is a maximum-severity chain that requires no login or user interaction and can let an attacker execute code before gaining full administrative control of the appliance.

    Key context: The wider update also fixes 11 critical weaknesses involving authentication, account takeover and access control.

    Additional detail: Nearly 400 Kiteworks instances were tracked as exposed to the internet, although their patch status was unknown.

    For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
    Cybersecurity training, courses, books, and resources: BareMetalCyber.com.

    Topics: cybersecurity news, cybersecurity, cyber risk, Enterprise, file-sharing, gateways, exposed, maximum-severity, flaw.

    続きを読む 一部表示
    2 分
  • AI-led attack reaches root access in seconds through helpdesk system
    2026/10/02

    Daily Cyber News: AI-led attack reaches root access in seconds through helpdesk system

    A Dutch vulnerability disclosure nonprofit suffered data access and exfiltration after an AI-powered attack chained two previously unknown flaws in its Zammad helpdesk system. Used together, the weaknesses allowed session hijacking, remote code execution and privilege escalation from the Zammad user to root within seconds. The attacker then reached other services before the response team intervened.

    Key context: Network segmentation and rapid containment limited deeper movement, but investigators are still assessing the damage.

    Additional detail: Support platforms should be treated as connected business systems because they may contain sensitive conversations and credentials.

    For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
    Cybersecurity training, courses, books, and resources: BareMetalCyber.com.

    Topics: cybersecurity news, cybersecurity, cyber risk, remote code execution, privilege escalation, vulnerability, AI-led, attack, reaches, root.

    続きを読む 一部表示
    2 分
  • Water and telecom operators hit as ransomware abuses trusted systems
    2026/10/02

    Daily Cyber News: Water and telecom operators hit as ransomware abuses trusted systems

    Water, telecom, government and education organizations face operational disruption as Warlock ransomware continues exploiting on-premises SharePoint systems. During the past two months, the campaign compromised at least four organizations: a water utility, a telecommunications provider, a regional government body and a university.

    Key context: The attackers planted web shells, extracted machine keys and used legitimate cloud and remote-access services to make their activity look more routine.

    Additional detail: This shows how one exposed collaboration server can become the starting point for domain-wide disruption.

    For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
    Cybersecurity training, courses, books, and resources: BareMetalCyber.com.

    Topics: cybersecurity news, cybersecurity, cyber risk, ransomware, Water, telecom, operators, abuses, trusted, systems.

    続きを読む 一部表示
    2 分
  • Attackers gain an early speed advantage in the AI security race
    2026/10/02

    Daily Cyber News: Attackers gain an early speed advantage in the AI security race

    Security teams are losing response time as attackers use AI to find weaknesses and move through compromised systems faster. Microsoft says attackers currently benefit from AI more quickly than defenders, particularly in vulnerability research and malware development. The median time between discovery in the wild and weaponization has fallen well below 24 hours.

    Key context: AI is also accelerating work after an attacker gets inside.

    Additional detail: The defensive challenge is that faster discovery doesn’t automatically create faster remediation.

    For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
    Cybersecurity training, courses, books, and resources: BareMetalCyber.com.

    Topics: cybersecurity news, cybersecurity, cyber risk, malware, vulnerability, windows, ai security.

    続きを読む 一部表示
    1 分
  • Millions face identity risk after Pentagon personnel breach
    2026/10/02

    Daily Cyber News: Millions face identity risk after Pentagon personnel breach

    Millions of current and former defense personnel and their dependents now face long-term identity risk after unauthorized users accessed Pentagon personnel files. The Defense Manpower Data Center says the breach affects 2.76 million living people and two hundred ninety four thousand deceased individuals. Access continued from October 2025 until the issue was discovered on July 16th, 2026, and involved a vulnerability in a file-sharing system.

    Key context: The exposed information varied by person.

    Additional detail: Personnel systems and file-sharing platforms need to be treated as high-value infrastructure rather than back-office tools.

    For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
    Cybersecurity training, courses, books, and resources: BareMetalCyber.com.

    Topics: cybersecurity news, cybersecurity, cyber risk, vulnerability, Millions, face, identity, risk, Pentagon, personnel.

    続きを読む 一部表示
    2 分
  • More than 543,000 live credentials remain exposed on GitHub
    2026/10/01

    Daily Cyber News: More than 543,000 live credentials remain exposed on GitHub

    An analysis found five hundred forty three thousand six hundred ninety nine unique working credentials exposed across public GitHub content. Researchers scanned 224 million repositories and more than 58 billion files. The median credential remained publicly accessible for 784 days, showing that many secrets survive far beyond the original development mistake.

    Key context: Removing a file isn’t enough because repository history, forks, and other copies may preserve the secret.

    For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
    Cybersecurity training, courses, books, and resources: BareMetalCyber.com.

    Topics: cybersecurity news, cybersecurity, cyber risk, live, credentials, remain, exposed, GitHub.

    続きを読む 一部表示
    2 分
  • AI coding agents publish 13,000 internal images to public GitHub
    2026/10/01

    Daily Cyber News: AI coding agents publish 13,000 internal images to public GitHub

    AI-assisted development workflows exposed more than thirteen thousand internal images from over 300 organizations in public GitHub repositories. The material appeared across more than 900 repositories and included customer records, credentials, internal dashboards, financial interfaces, and unreleased product features. In some cases, coding agents created or used public repositories because their command-line environment couldn’t attach review images through the normal browser process.

    Key context: A routine request to prove that work was completed became an uncontrolled publishing channel.

    For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
    Cybersecurity training, courses, books, and resources: BareMetalCyber.com.

    Topics: cybersecurity news, cybersecurity, cyber risk, coding, agents, publish, internal, images, public, GitHub.

    続きを読む 一部表示
    2 分