Call center attack hits Nesine and 4 Race customer data, says KVKK
Two Turkish betting companies report that their call center provider's systems were encrypted in a cyberattack, potentially exposing call recordings and identity details.
Two Turkish betting companies report that their call center provider's systems were encrypted in a cyberattack, potentially exposing call recordings and identity details.
A 28-year-old Russian national described as a core Qilin member was detained in Osaka in May and handed over to German authorities on October 2.
Lumen's Black Lotus Labs says the PoeLLM malware has compromised more than 3,400 servers, including LiteLLM and Ollama hosts, to mine cryptocurrency and spread further.
Southern Company says an unauthorized party accessed limited account information of roughly 400,000 utility customers through its online customer portal.
Turkey's data protection authority says a ransomware attack on Yıldız Technical University's virtualization infrastructure may affect about 140,000 students and 4,500 staff.
Google says attackers took over the operators of three country-code domains and obtained unauthorized HTTPS certificates for Google, YouTube and other organizations' domains.
Google has released Chrome 155 with patches for 247 vulnerabilities, four of them rated critical. There is no evidence any of the flaws are exploited in the wild.
SonicWall has released hotfixes for CVE-2026-102255, an unauthenticated server-side request forgery flaw in SMA 1000 appliances that could let attackers reach internal functions.
A joint FBI and Secret Service advisory says the FortiBleed campaign, which harvested working credentials for more than 86,000 FortiGate devices, remains active and feeds ransomware gangs.
Checkmarx says a single actor has used npm packages since August 2023 to deliver Overlord RAT and a Node.js stealer; three packages were still live on October 1.
Hackers stole court debt records, protection orders and foster care reports after an employee clicked a malicious link, Arizona's judiciary says.
CERT-UA says a ClickFix campaign tracked as UAC-0277 compromised more than 100 Ukrainian websites to push Lunex, a stealer sold as malware-as-a-service.