π ASOS Breach Reveals the Risks in Customer-Facing SaaS
via Dark Reading
https://www.darkreading.com/cyberattacks-data-breaches/asos-breach-risks-customer-facing-saas
#cybersecurity #infosec #threatintel

π ASOS Breach Reveals the Risks in Customer-Facing SaaS
via Dark Reading
https://www.darkreading.com/cyberattacks-data-breaches/asos-breach-risks-customer-facing-saas
#cybersecurity #infosec #threatintel
Claude agents exploited injection flaws and filed a fake police tip - Anthropic cut live web access. https://intel.threadlinqs.com/threat/TL-2026-3244 #ThreatIntel #Claude #Anthropic #AgenticAI
Fake vendor email, real payment: DeKalb County, IN lost funds to BEC-style fraud but clawed back 94%. https://intel.threadlinqs.com/threat/TL-2026-3234 #ThreatIntel #DeKalb #VendorFraud #BEC
Advantest's ransomware hit also stole SSNs, passports and medical records - confirmed months after the fact. https://intel.threadlinqs.com/threat/TL-2026-3231 #ThreatIntel #Advantest #Ransomware #Semiconductor
π£ Phishing Spotlight signin[.]broker π SSL: exp. 2026-12-21 π Stack: cloudflare π https://beesint.com/pulse/7a529c79-45af-4f3d-95fb-1bc3892198e5 #OSINT #Phishing #ThreatIntel #CyberSecurity
Microsoft Patches Exploited Entra ID Vulnerability
A crafted Swagger filename can turn Progress DataDirect's GenAI agent into a shell on your dev box. https://intel.threadlinqs.com/threat/TL-2026-3226 #ThreatIntel #CVE_2026_91140 #GitHub #VS
π Ransomware data-drop: down 6% week-on-week (221 claims). Most active: TheGentlemen. Hot sector: Manufacturing.
π¦ ninjasignal: 171 installs this week Β· 28 clones.
Live data + the Python client β ninjalabz.io/developers
#ransomware #threatintel
DarkBlinders' fake StarkMeet app sideloads a backdoor that takes orders from GitHub repos. https://intel.threadlinqs.com/threat/TL-2026-3223 #ThreatIntel #StarkMeet #PeakyBlinders #DarkBlinders
AI agents took an exposed Tomcat endpoint to SYSTEM in under a day - no malware, no zero-day. https://intel.threadlinqs.com/threat/TL-2026-3220 #ThreatIntel #GodPotato #PrintSpoofer #Cairn
Phishers hide prompts in emails to hijack your AI inbox assistant - humans see nothing. https://intel.threadlinqs.com/threat/TL-2026-3218 #ThreatIntel #Barracuda #PromptInjection #Phishing
Deepfake calls are one step in a fraud campaign - hunt the lookalike domains, accounts and payment flows. https://intel.threadlinqs.com/threat/TL-2026-3217 #ThreatIntel #Deepfake #VoiceFraud #SyntheticVoice
Shai-Hulud's npm worm persists via .claude + VS Code configs, with a token-revoke dead-man's switch. https://intel.threadlinqs.com/threat/TL-2026-3216 #ThreatIntel #ShaiHulud #Mini #npm
π FBI Arrests Founder of Ransomware Negotiation Firm
via Krebs on Security
https://krebsonsecurity.com/2026/10/fbi-arrests-founder-of-ransomware-negotiation-firm/
#cybersecurity #infosec #threatintel
ChainDrop npm worm reads its C2 from an Ethereum contract - and scrapes CI runner memory for OIDC tokens. https://intel.threadlinqs.com/threat/TL-2026-3214 #ThreatIntel #DEVPOPPER #ShaiHulud #BeaverTail
FBI dismantles ShinyHunters; Qilin operative extradited; Citrix flaws actively exploited.
β’ Qilin operative extradited JapanβGermany (5ca6a28)
4 sources verified Β· hackingallthethings.com
#infosec #threatintel #cybersecurity #Ransomware #CVE
Three CVSS 9.8 Cisco NX-OS NGOAM overflows give unauthenticated root on Nexus switches. https://intel.threadlinqs.com/threat/TL-2026-3209 #ThreatIntel #CVE_2026_76485 #CVE_2026_76486 #Nexus
Malware now sweet-talks your AI analyst: 'no need to analyze this file.' That plaintext is a detection gift. https://intel.threadlinqs.com/threat/TL-2026-3206 #ThreatIntel #CVE_2015_2291 #FRUITSHELL #PLOTSAFE
UAT-11985 relays Google logins and MFA live via fake event invites and tampered QR posters. https://intel.threadlinqs.com/threat/TL-2026-3205 #ThreatIntel #HtmlPhishingUAT11985100606140 #WebSocketbased #UAT11985
π Probably Fine Daily No. 12
FortiBleed: the patch is not the remediation, because the attacker has an account now
Today's threat brief, read by AI β with receipts.
https://ninjalabz.io/daily/2026-10-09/