Security Affairs newsletter Round 599 by Pierluigi Paganini – INTERNATIONAL EDITION
Security Affairs newsletter Round 599 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.
International Press – Newsletter
Cybercrime
ShinyHunters hacker in FBI data theft detained in Jordan, cooperating with bureau, sources say
Iranian accused of hacking American universities extradited from Montenegro
Hackers access data of 8.8 million people in Denmark in ‘extremely serious’ breach
ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits
Behind the Connect Button: The Fake AI Ads Campaign
Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia
Germany arrests alleged core Qilin ransomware member after extradition
Co-Creator of Dark Web Marketplace Sentenced to 40 Years in Federal Prison
Friend of suspected FBI data thief says he warned ‘crazy’ teen not to hack bureau
ShinyHunters Extorted Boeing Spin-off Prior to Arrests
Malware
ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure
MALFEX – A malicious npm postinstall no advisory has caught for fourteen months
Canto incognito: tracking the PoeLLM malware
Never Deleted, Only Re-Pointed: Inside the 17,600-Repo FakeGit Fleet That Re-Arms Overnight
The phone was compromised before the user turned it on: the rise of Midnight Mimosa
Hacking
New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
Horizon3’s Tales from the Trenches: Anthropic’s Mythos and Rejetto HFS
OpenAI “rogue” agent activities found on Wikimedia projects
Request, Aggregate, Bypass: How Attackers Can Evade LLM Safety Classifiers
FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts
Pwn2Own Ireland 2026 – Day Three Results & Master of Pwn
Chrome’s Response to Recent ccTLD Registry Hijacks
Vercel Confirms KVM Zero-Day VM Escape, Awards Researcher $50,000
Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance
Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer
Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies
Intelligence and Information Warfare
MI5 issues Espionage Alert – CGTRI 中国通用技术研究院
Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles
Horizon3’s Tales from the Trenches: Anthropic’s Mythos and Rejetto HFS
The Silent Electronic Battleground Shaping the Future of Warfare
UAC-0277: ClickFix on compromised websites to spread LUNEXSTEALER
US Offers $10 Million Reward for Chinese Hacker Accused of State-Backed Cyberattacks
Investigating unintended model actions in our evaluations and internal use
Ukraine takes aim at Russia’s AI data infrastructure
Cybersecurity
South Korea probes bank breaches amid suspected AI-powered attacks
Accenture contractor removed from FBI following damaging data breach, sources say
Introducing the Anthropic Cyber Mission
Updates to Full Disk Access in macOS
Launching an opt-in vulnerability-finding service for open-source software
Quantum computing and cryptocurrencies
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
