IT News Analysis

// AI-powered news analysis

Latest Top 10 Articles

1
French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks

French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks

An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July. Neither the tax administration nor France's national cybersecurity agency saw the data leave. The attack was not sophisticated, the agency, ANSSI, says in a  report  (in French) published on Tuesday: it worked because of weak login protection, poorly separated networks and gaps in monitoring. The tax administration, known as the DGFIP, runs France's tax website, impots.gouv.fr. The data came from E-Contact, the tool taxpayers use to message the tax administration. The stolen data covers  a little over 350,000 individuals  and  a little over 250,000 businesses , the DGFIP says. Taxpayers' own online accounts and passwords were not compromised. For individuals, the data that may have been viewed or copied includes their tax ID, contact details, family situation, reference taxable income and tax...

Sep 29, 2026
2
New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses

New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses

A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time ( JIT ) engines present in web browsers, language runtimes, and the operating system kernel, across multiple CPU vendors. The new Spectre-v2 variant has been codenamed Branch Target Reuse (BTR) . "The key insight is that, while modern CPUs restore architectural code coherence after self-modification, they do not necessarily invalidate stale indirect branch prediction entries (i.e., branch targets)," researchers Sander Wiebing, Yuhui Zhu, Alessandro Biondi, and Cristiano Giuffrida said in an accompanying paper. "In JIT engines, these stale targets can outlive the original code and later be reused when the code cache is repopulated, yielding a transient execute-after-free primitive. This allows attackers to hijack transient control flow to newly generated code at obsolete offsets, bypassing software hardening...

Sep 29, 2026
4
Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft. The campaigns, aimed at people and organizations tied to Ukraine, have affected more than 100 organizations since January, mostly in the U.S. and U.K. At least one computer was infected, but the number of breached organizations has not been disclosed. Security agencies in the U.S., U.K., Australia, Canada and New Zealand  said in December 2023  that Star Blizzard almost certainly works under Center 18 of Russia's Federal Security Service (FSB). The group has long stolen email passwords by posing as people its targets know. By 2023, it had already used  fake conference and event invitations  as bait, often exchanging messages with a target before sending a malicious link. Microsoft counted at least 13 larger campaigns this year, each with tens to hundreds of emails, on top of ...

Sep 29, 2026
5
Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown

Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown

Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during the scheduled precautionary shutdown . "During the shutdown, this activity led to the discovery of a previously unknown critical vulnerability confined to a capability that is enabled for less than 1% of the customer base," the company said in a statement. "Kiteworks developed and deployed a fix during the window, [and] applied an additional protective layer across all environments." There is no evidence that the vulnerability has ever been exploited in a malicious context. Other Kiteworks products are not affected by the flaw. The development comes days after Kiteworks, previously Accellion, urged customers to take their systems offline for a period of nine hours, in addition to shutting down environments it hosts on behalf of customers, after receiving intelligence about a potential imminent cybe...

Sep 29, 2026
6
101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent

101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent

Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub . "The malicious packages abuse the 'Baileys' WhatsApp open source project to add the victims to groups without their consent," OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko said in a technical write-up published Monday. These packages have been collectively downloaded 490,000 times, out of which 116,000 occurred in the last 30 days. The names of some of the packages are below - ourin-baileys @nexustechpro/baileys @badzz88/baileys @ostyado/baileys levvleys @vanzxy/baileys @yudzxml/baileys @chatunity/baileys @kelvdra/baileys neuralwhatsapp lilys-baileys @fyxzpediaa/baileys noxleyss @xrelly-stack/bails alipclutch-baileys kurobails eliteprotech-baileys @xayz/baileys chromestaff-baileys @sanzoffc/baileys @s...

Sep 29, 2026
8
Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation

Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation

Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. "It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters," the Politie Landelijke Opsporing en Interventies said in an X post Monday. Police said the individual is expected to appear before the Rotterdam District Court on September 29, 2026. Although law enforcement officials did not disclose any additional details, independent security journalist Brian Krebs and DataBreaches.Net identified the arrested man as Pepijn van der Stap (aka Umbreon), who was previously apprehended in 2023 for his role in a series of data thefts and extortions. Per DataBreaches.Net, van der Stap was arrested on September 15, 2026. In 2023, it emerged that the individual worked at cybersecurity company Hadrian and volunteered at the Dutch Institute for Vulnerability Disclosure (DIVD). ...

Sep 29, 2026
9
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

A malicious MCP server could trick an application built on the official  MCP Python SDK  into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory. Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and 2.2.0. The Model Context Protocol (MCP) is an open standard for connecting AI applications to outside tools and data, and this package is its official Python SDK for building MCP servers and clients. With the stolen credentials, the attacker can request a valid access token from the real login service. Cycode, the security firm that reported the flaw , demonstrated that full exchange in a test and says the resulting token carries whatever permissions the app was granted. The client secret is long-lived, so it keeps working until it is changed. The flaw is rated high (7.5) for the two prov...

Sep 29, 2026
10
OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions

OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions

OpenAI on Monday shelved plans to release GPT-6.1 Astra, a next-generation artificial intelligence (AI) model that was planned for an October launch, after it failed internal safety and alignment audits. The development was first reported by The Wall Street Journal. The move "marks a rare case of a major AI developer ditching a new release because of safety concerns," the news publication said. The ChatGPT maker said it made the decision to scrap its GPT-6.1 Astra model release after testing raised questions about whether it can follow user instructions without deviating from expected behavior. The Journal reported that the model exhibited higher levels of deception than its predecessor during evaluation, and failed to disclose what actions it had carried out. In some cases, it went ahead without seeking permission or attempted to use outside tools in scenarios where doing so could be deemed unsafe. "While (GPT-6.1 Astra) improved on axes such as model laziness...

Sep 29, 2026

Get a summary by Chaplin or Kilmister Get a summary