Skip to content

Sam's News — security — 2026-10-08

Security

8 FortiBleed vulnerability exploited to lock legitimate users out of Fortinet security appliances

The FortiBleed campaign has compromised approximately 86,644 Fortinet devices across 194 countries. Attackers lock organizations out of their appliances by changing passwords and deleting legitimate accounts, then maintain persistence for lateral movement within networks.

  • ~86,644 devices compromised across 194 countries
  • Campaign active since June 2026
  • Attackers use credential harvesting, brute force, offline cracking
  • FBI and US Secret Service joint advisory issued

Sources: SecurityWeek AI Web Searched

8 Tensorlake npm package compromised by Shai-Hulud credential-stealing worm

The npm package tensorlake version 0.5.144 was compromised with obfuscated malware that harvests credentials from local files, CI environments, Kubernetes, and Vault. The worm steals API tokens, SSH keys, cryptocurrency wallets, and AI tool credentials, then republishes compromised versions.

  • Steals npm, GitHub, AWS tokens; SSH keys; Vault secrets
  • Exfiltrates Anthropic Claude, Cursor, VS Code credentials
  • Drops HackBrowserData binary for additional credential harvesting
  • Uses Ethereum contract for command-and-control resolution

Sources: The Hacker News AI Web Searched

7.5 Wazza Phishing Kit Adds Infrastructure Controls to Target Banking and Government Sectors

Researchers identified Wazza, an advanced phishing kit using multi-stage routing to filter traffic and deliver Adobe Device Code login phishing pages. The kit targets banking, manufacturing, and government organizations across the US, Europe, and Australia.

  • Multi-stage routing obscures phishing link and complicates detection
  • Uses wildcard domain boegl-krysl[.]eu and Cloudflare Workers
  • Filters automated traffic before delivering final payload
  • Targets Device Code flow rather than password harvesting alone

Sources: The Hacker News AI Web Searched

7.5 16 Malicious Firefox Extensions Masquerade as Rabby and OKX Wallets to Steal Cryptocurrency Recovery Phrases

Researchers discovered 16 malicious Mozilla Firefox extensions designed to steal cryptocurrency recovery phrases and private keys from Rabby and OKX wallet users. Four cloned Rabby Wallet; twelve targeted OKX users, intercepting credentials during wallet import.

  • 16 malicious extensions: 4 Rabby clones, 12 OKX-targeting
  • Intercepts recovery phrases and private keys during import
  • Exfiltrates to *.icy-star-f45c.workers[.]dev Cloudflare Workers domain
  • All removed by October 5, 2026; continuation of August 2026 wave

Sources: The Hacker News AI Web Searched

7.5 Oracle Health data breach tally rises to nearly 20 million records

Oracle Health's confirmed breach now encompasses nearly 20 million records, far exceeding earlier disclosed figures.

Sources: SecurityWeek RSS

7.5 MonsterCloud owner charged with $19M+ fraud for secretly paying ransoms while billing victims for recovery

The U.S. Department of Justice charged a MonsterCloud executive with defrauding ransomware victims by paying attackers for decryptors while falsely claiming proprietary tools were recovering data.

Sources: The Hacker News RSS

7.5 Pwn2Own Ireland: 45 zero-days exploited in Samsung Galaxy S26 hacks

Security researchers at Pwn2Own Ireland 2026 earned $232,500 by exploiting 45 unique zero-day vulnerabilities across Samsung Galaxy S26 and other targets.

  • 32 zero-day vulnerabilities exploited on day 1
  • $388,500 earned
  • Samsung Galaxy S26 compromised twice

Sources: BleepingComputer RSS Update to: Security researchers exploit 32 zero-day vulnerabilities on first day of Pwn2Own Ireland 2026

7.5 EY data breach exposes Goldman Sachs and Man Group clients' tax and financial records

A breach of EY systems has compromised sensitive tax and financial data belonging to clients of Goldman Sachs and Man Group.

Sources: GBHackers News Web Search

7 Empire Market Co-Creator Sentenced to 40 Years for $430M Cybercrime Facilitation

The co-creator of Empire Market, a major dark web marketplace, received a 40-year prison sentence for enabling $430 million in illegal transactions between 2018 and 2020.

Sources: BleepingComputer RSS

Multiple US states filed lawsuits against TP-Link over ISP router flaws, with technical vulnerability details published by SEC Consult.

Sources: SecurityWeek RSS