Latest NEWS

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign.
The affected GitHub Actions are listed below -
actions-cool/issues-helper
actions-cool/maintain-one-comment
Visiting either of the repositories now shows the message: "Access to this
26 September 2026
From:
info@thehackernews.com (The Hacker News) [The Hacker News]

Angry Birds: Toy Ghouls’ new toys
Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the other uses the Matrix-based Element messenger.
26 September 2026
From:
Kaspersky GERT, Kaspersky Security Services [Securelist]

Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data
A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday.
The data came from disk space that earlier containers had used and given up, not from any live workload, and an attacker could not choose whose data they got, according to Cloudflare. The company
26 September 2026
From:
info@thehackernews.com (The Hacker News) [The Hacker News]

Fake Google Security Team ad says 'no script reading' in voice phishing - then prints the script
More mockery and memes from the Dark Web Roast
26 September 2026
From:
[www.theregister.com - Articles]


.jpg)


