IT News Analysis

// AI-powered news analysis

Latest Top 10 Articles

1
LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings

LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings

A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro. The attack works only when the program's Java support is enabled. So far, it has only been shown as a proof of concept, and there are no reports of its use in real attacks. LibreOffice has already  fixed the flaw , which it tracks as CVE-2026-63277, in updates released on October 5. It recommends that users move to version 26.2.5 or 26.8.0. Versions before those are affected. Apache OpenOffice has not fixed the matching flaw, which it tracks as CVE-2026-59265. Every version up to and including its current release, 4.1.16, is affected, and the project  says a fix is expected  in version 4.1.17, which is still being tested. Until then, Apache OpenOffice users can block the attack by turning off Java in the program's settings, or by...

Oct 06, 2026
2
Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies

Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies

The Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, and edit Wikipedia pages. "The unauthorized bot activities included edits to our wikis, some unsuccessful attempts to exploit a public note-taking tool we host, and heavy traffic," the Foundation said in a post. The investigation, it added, was prompted by recent public reports involving Hugging Face and DseWiki where OpenAI's agents turned Artifactory and the German wiki forum into an unsanctioned bulletin board to communicate with each other, while taking steps to chained together online services to gain access to the internet and cover up evidence of their exploits. To that end, Wikimedia said it identified edits to Wikimedia wikis suspected to be from agents operated by OpenAI. The agents are said to have been testing edits in " sandbox ...

Oct 06, 2026
3
Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers

Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers

In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterprises plugged them into agent workflows. The ecosystem around it fell short. Earlier this year, our team at OX Security ,  traced critical vulnerabilities in Anthropic's MCP source code, downloaded more than 150 million times. This time, we looked at what people actually install: community-published servers across the most popular MCP marketplaces. We found no guardrails and no review. Security is a recommendation, not a policy. A Marketplace With No Bouncer In 2012, Google ran Bouncer, an automated scanner that checked Android apps for malware before they reached users. It wasn't perfect: researchers slipped malware past it . But it existed. MCP marketplaces have no equivalent. Anyone can write a server, push it, and publish it. Even a review wouldn'...

Oct 06, 2026
5
Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports

Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports

Google has stopped accepting product vulnerability reports through its bug bounty program for its open-source software. The change, in effect since October 1, means researchers can no longer submit security flaws in the code of projects such as Go, Angular, and Protocol Buffers there for a reward. Reports about supply chain compromises are still accepted, and reports filed before October 1 are not affected. Google called the stop temporary in a  post on X  on October 1 and said it was due to "a significant rise in automated submissions, the vast majority of which are not valid." The post gave no figures. It did not say whether the submissions were produced with AI tools. The  rules of the program , called the Open Source Software Vulnerability Reward Program (OSS VRP), now carry a notice of the stop. It commits Google to an update in the first quarter of 2027 while it reworks this part of the program. Neither the post nor the notice gives a date for accepting p...

Oct 06, 2026
6
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must already know a file's exact name and path and cannot list what the directory holds. Atlassian  disclosed the flaw , CVE-2026-21589 , on October 5, rated it 9.3 out of 10, and listed a fixed version for each product. The web application root directory is the folder on the server that holds the web application itself. In some configurations, it may contain sensitive files, which raises the risk, according to Atlassian. Atlassian's cloud products affected by the flaw have already been patched, and cloud customers do not need to take any action. Atlassian advises customers who cannot upgrade all at once to take the instance offline if possible. Any instance reachable from the public internet, including one that requires a login, should be restricted from ...

Oct 06, 2026
8
FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the theft of personal details of thousands of bureau employees. That's according to a report from Reuters, citing two sources familiar with the matter. "To date, our review has determined that the incident occurred as the result of a security failure ​of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the ​platform," Brett Leatherman, assistant director of the FBI's cyber division, was quoted as saying to Reuters. "As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce." Although the name of the third-party organization was not disclosed by the FBI, Reuters reported that it's Oracle PeopleSoft, which the ShinyHunters group said it exploited...

Oct 06, 2026
9
Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account

Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account

Unauthorized parties have gained access to the names, addresses, and personal identification numbers of about 8.8 million people, living and dead, in Denmark's national population register, the country's digitalization ministry  said on October 5 . They used a private Danish company's lawful right to look up records in the Central Person Register (CPR). The ministry has told people never to give passwords or other confidential information to anyone who calls or emails, even someone who seems to know those details. The register's administration has stopped the company's access and reported the case to Datatilsynet, Denmark's data protection authority. Police are investigating. A very large number of automated lookups were made in the register to identify valid personal identification numbers, known as CPR numbers, Datatilsynet  said in a notice  on October 5. Its account comes from the notification it received from the register a day earlier. It has not y...

Oct 06, 2026
10
ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits

ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits

A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser's cache. "Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file," the Microsoft Threat Intelligence team said in a post on X. Thus, when the victim is prompted to paste and execute a malicious command – as is the case with ClickFix attacks – it executes the cached website content that's already on the device.  What's notable about this browser cache smuggling approach is that it allows the attackers to conceal the payload script and bypass character limit restrictions imposed on Windows Run (aka the Run dialog). The Windows Run dialog, triggered by Win + R, truncates any input that exceeds approximately 260 characters. In the attack chain observed by Microsoft, the staged payload is a ...

Oct 06, 2026

Get a summary by Chaplin or Kilmister Get a summary