Direct answer: On October 5, 2026, the FBI removed an Accenture contractor after a cyberattack by the ShinyHunters group breached the bureau’s Oracle PeopleSoft platform and exposed the personal details of thousands of FBI employees. FBI cyber chief Brett Leatherman said the intrusion happened because a contractor failed to apply a security patch that Oracle…
ASOS Hacked? Rogue Push Notification Claims Snowflake Breach, Shares Drop 11%
Short answer: On the morning of October 6, 2026, thousands of ASOS customers received a rogue push notification claiming the retailer had been hacked, with a message addressed to the company’s data protection officer saying its Snowflake data instance was “fully compromised.” ASOS said it was aware of the reports and is investigating, but has…
KVM Zero-Day VM Escape: What Paulos Yibelo Found, What Vercel Confirmed, and What to Do Next
A security researcher has reported a full guest-to-host virtual machine escape in KVM, the Linux hypervisor that underpins most of the public cloud, and Vercel has confirmed it as a genuine zero-day. The finding came through Vercel’s Sandbox bug bounty program, which paid out its maximum single-report award of $50,000. No CVE number, affected versions,…
OpenAI textGrain Explained: ChatGPT’s Invisible Watermark, How It Works and Who It Affects
OpenAI has started marking its own words. On October 5, 2026, the company announced it will add an invisible watermark to text generated by ChatGPT and Codex in the European Union, a move driven by the EU AI Act’s transparency rules. The system is called textGrain, and it works by quietly shaping the model’s word…
Atlassian CVE-2026-21589: Critical File Access Flaw in Jira, Confluence and Bitbucket (Patch Now)
What happened in one paragraph On October 6, 2026, Atlassian emailed administrators of its self-managed products with an “Action required” notice and published a security bulletin for CVE-2026-21589, a critical vulnerability rated CVSS 9.3. The flaw allows an unauthenticated attacker to access specific files inside the web application root directory of affected Data Center versions…
OpenAI Dots Explained: Price, Release Date and How the Always-On AI Agents Work
OpenAI just changed what a chatbot is allowed to be. On September 29, 2026, at its DevDay event in San Francisco, the company unveiled Dots: always-on AI agents that keep working on your tasks after you close the tab. Each Dot runs on GPT-6 Astra, OpenAI’s most capable model, gets its own dedicated cloud computer,…
Google Freezes Its Open Source Bug Bounty Program: What Happened and Why AI Reports Are to Blame
Google has temporarily stopped accepting new vulnerability submissions to its Open Source Software Vulnerability Rewards Program, better known as the OSS VRP. The pause took effect on October 1, 2026, after Google said its reviewers were being buried under a flood of automated, AI-generated bug reports, most of which turned out to be invalid. Google…
Free Gemini Gets Flash-Lite Only From October 9: What Changes and Whether AI Plus Is Worth It
What is happening to free Gemini? Starting October 9, 2026, Google is restricting which Gemini models free users can access in the Gemini app. According to an updated Google support page first reported by 9to5Google on October 3, anyone using Gemini without a Google AI subscription will be limited to the 3.5 Flash-Lite model. Access…
Citrix NetScaler SAML Zero-Day (CVE-2026-88779): What Happened and What to Do Right Now
Citrix has rushed out emergency patches for a new actively exploited zero-day in NetScaler ADC and NetScaler Gateway. Tracked as CVE-2026-88779, the flaw is a memory overflow that attackers can trigger remotely to knock SAML authentication infrastructure offline, and the US Cybersecurity and Infrastructure Security Agency (CISA) has already added it to its Known Exploited…
Apple Zero-Day (CVE-2026-86950): What Happened and What to Do Right Now
What happened in short On September 28, 2026, Apple released emergency security updates for iPhones, iPads, and Macs to fix a zero-day vulnerability tracked as CVE-2026-86950. The flaw is an out-of-bounds write in CoreGraphics, the system framework that renders images, PDFs, and text across Apple’s operating systems. A device that processes a maliciously crafted file…









