What Is the GhostAction Attack? GhostAction is a supply-chain attack campaign that hijacks trusted GitHub maintainer accounts and uses them to plant a credential-stealing workflow into open-source repositories. The malicious file is disguised as a routine “security audit,” but its only job is to harvest secrets: GitHub Actions tokens, AWS keys, AI API keys, and…
Telegram Desktop One-Click Account Takeover (CVE-2026-107181): What Happened and How to Stay Safe
If you use Telegram Desktop, update it now. A security flaw in versions before 7.2.9 lets an attacker hijack your account with a single click on a crafted link. The bug is tracked as CVE-2026-107181, it scores 8.6 out of 10 on the CVSS severity scale, and a working proof of concept is public. If…
Midnight Mimosa Malware: Why Thousands of Budget Android Phones Arrived Hacked Out of the Box
Bitdefender Labs disclosed on October 8, 2026, that it had found malware baked into the firmware of thousands of low-cost Android phones. Dubbed Midnight Mimosa, the operation has been running for roughly two years and touched devices in more than 150 countries, including the United States. The malware sits in the phone’s system partition before…
AhsayCBS Zero-Day Exploited in the Wild: Attackers Turn Backup Servers Into Crypto Miners
Short answer: Hackers are actively exploiting two unpatched vulnerabilities in AhsayCBS backup management software to break into servers without any login credentials, install web shells, and run cryptocurrency miners with full SYSTEM privileges. The flaws are tracked as CVE-2026-105133 and CVE-2026-105134, in-the-wild attacks began on October 7, 2026, and at least five organizations have been…
FBI Seizes Flax Typhoon Hacking Tools MicroScan and FishHub: What Happened and What to Do
In short: On October 8, 2026, the FBI and the U.S. Department of Justice seized seven internet domains used to run two hacking tools, MicroScan and FishHub, operated by a Beijing-based company called Integrity Technology Group and tied to the China-linked hacking collective Flax Typhoon. A day later, CISA added five exploited flaws to its…
Anthropic Cyber Mission Explained: Free AI Security Scans for Open Source and Critical Infrastructure Defense
On October 8, 2026, Anthropic launched the Anthropic Cyber Mission, a long-term security initiative that puts frontier AI models to work defending the systems the public relies on. The short version: Anthropic will give free AI-powered vulnerability scans to open-source projects through a service called OSS Scanner, and it is backing a Critical Infrastructure Defense…
Denmark Deepfake Law Explained: What the New Bill Means for AI Replicas of Your Face and Voice
Denmark is about to do something no other country has tried: give every citizen a legal right over their own face and voice, enforced through copyright law. On October 8, 2026, Culture Minister Zenia Stampe announced she would table a bill banning the digital copying and sharing of lifelike representations of a person, including their…
SonicWall SMA 1000 CVSS 10.0 SSRF Flaw (CVE-2026-102255): What Happened and How to Patch
SonicWall has patched a maximum-severity security flaw in its SMA 1000 remote-access appliances that lets an attacker reach internal systems without a login. The vulnerability, tracked as CVE-2026-102255, carries a CVSS score of 10.0, the highest possible, and it is the third pre-authentication SSRF bug found in the same appliance interface this year. The two…
PoeLLM Malware Explained: How a GitHub Poem Turned 3,400 AI Servers Into Crypto Miners
The short answer: PoeLLM is a new Linux malware campaign that has quietly taken over more than 3,400 internet-exposed AI servers since April 2026, turning them into cryptocurrency miners. Its most unusual trick is hiding its command-and-control server addresses inside a poem hosted on GitHub, so it can move its infrastructure without ever updating the…
Manus Raises Over $500M After Meta’s $2B Acquisition Was Blocked: What Happens Next
Manus is back on its own and investors are betting big on it. The AI agent startup’s parent company, Butterfly Effect, said on Thursday it has completed a funding round of more than $500 million, the first since Meta was forced to unwind its $2 billion-plus acquisition of the company. Here is the short version:…









