CyberSecurity Updates

MATCHBOIL: New tricks, same old evil intentions

ESET researchers have documented the evolution of the MATCHBOIL malware, a custom C# downloader wielded by the Russia-aligned UAC-0099 APT group. The malware is used to download a payload from the group’s C&C server, install it, and establish its persistence. Although MATCHBOIL was first documented by CERT-UA in August 2025, our research indicates that it has been in development since at least 2024. The earliest versions of the malware that we analyzed are from April…

Read More

OpenAI Fires 3 Safety Researchers in Dispute Over AI Risks

OpenAI said on Friday that it fired three safety researchers for a “breach of trust,” defending the dismissals after the trio accused the company of putting its corporate interests before safety as the reason for removing them. The ChatGPT maker said in a post on X that it “parted ways” with the researchers after an investigation found “they violated clear policies on handling sensitive information.” The statement comes after the three researchers, Tomek Korbak, Jasmine…

Read More

Inside a brand deal scam targeting YouTube creators

Social Media A plausible-sounding sponsorship offer could mask an attempt to compromise your Google account Christian Ali Bravo 07 Oct 2026  •  , 6 min. read For a YouTuber, the approach may look like routine business: a personalized sponsorship email from a global brand and a brief negotiation over rates, followed by an invitation to visit a slick collaboration platform. In some cases, however, the sequence can mask a scam that could part social media…

Read More

Cisco Patches a Dozen Critical Vulnerabilities

Cisco on Wednesday announced patches for 35 vulnerabilities across its products, including over a dozen critical-severity bugs. A fresh Meraki security hardening release fixes multiple bugs grouped together under seven CVEs, based on the underlying weakness type. The most severe of these is CVE-2026-76464, which covers memory issues such as buffer overflows and out-of-bounds writes. Cisco also resolved eight bugs in License On-Prem, including five critical-severity issues. Two of them could lead to unauthorized access…

Read More

The quest for simplicity: Why SMBs want advanced protection without the complexity

Cybersecurity has never been easy. Threats evolve at breakneck speed. Corporate attack surfaces continue to expand with each new digital investment. Regulatory requirements add extra pressure on stretched teams. And behind it all, the unpredictability of human nature means there is no such thing as 100% security. But the market for security solutions doesn’t make things any easier for SMBs. Smaller organizations usually have fewer resources and less expertise to throw at the problem than…

Read More

Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts

Southern Company is notifying roughly 400,000 customers that their utility account information was accessed by an unauthorized third party through its online customer portal. The Atlanta-based energy holding company serves more than 9 million customers through electric utilities in three states and natural gas distribution businesses in four. Its electric subsidiaries are Georgia Power, Alabama Power and Mississippi Power. Roughly 300,000 of the affected accounts belong to Georgia Power customers. According to Southern Company, the…

Read More

ShinyHunters Extorted Boeing Spin-off Prior to Arrests

A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group ShinyHunters has been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang. KrebsOnSecurity has learned that the suspect, who uses the hacker handle “Rey,” was detained as ShinyHunters was in the process of extorting a business unit recently divested by the global aerospace company Boeing, which manufactures the fleet of planes used by…

Read More

FBI Blames Contractor’s Missed Patch for ShinyHunters Breach

The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees, Reuters reported on Tuesday, citing two people familiar with the matter. The FBI has not publicly named the contractor or the organization involved. However, a senior bureau official told Reuters that its review so far points to a security patch that had not been applied by the contractor responsible for the affected system. “To date,…

Read More

Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports

Google has temporarily closed its Open Source Software Vulnerability Reward Program (OSS VRP) to product vulnerability submissions, saying a growing number of automated reports, most of them invalid, prompted the move. The pause was announced on X on October 1. “This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” Google said. Only product vulnerabilities are covered by the pause. According to Google, it has no…

Read More

Introducing the New Small Business Cybersecurity Support Program Finder

For small businesses who are often confronted with limited resources, knowing how to get started and where to find support with planning, implementing, or evaluating a cybersecurity risk management strategy can be challenging — sometimes making cybersecurity feel like an insurmountable hurdle. However, there is good news. Many non-profit organizations across the United States have created programs for their local small business communities (in addition to local schools, municipal governments, and non-profits) that often extend…

Read More