<?xml version="1.0" encoding="UTF-8" ?><feed xmlns="http://www.w3.org/2005/Atom">
    <title>Babgond</title>
    <subtitle>Babgond</subtitle>
    <id>https://babgond.com/moonmoonApple_v9/</id>
    <link rel="self" type="application/atom+xml" href="https://babgond.com/moonmoonApple_v9/atom.php" />
    <link rel="alternate" type="text/html" href="https://babgond.com/moonmoonApple_v9/" />
    <updated>2026-10-05T01:12:04Z</updated>
    <author><name>Babgond</name></author>


    <entry>
        <title type="html">IT-Sentinel : Paylogix</title>
        <id>https://www.ransomware.live/id/cGF5bG9naXguY29tQDIwMjYtMTEtMTg=</id>
        <link rel="alternate" href="https://www.ransomware.live/id/cGF5bG9naXguY29tQDIwMjYtMTEtMTg="/>
        <published>2026-11-18T01:00:00+00:00</published>
        <updated>2026-11-18T01:00:00+00:00</updated>
        <author><name>akira</name></author>

        <content type="html"><![CDATA[<div>La société de gestion des avantages sociaux Paylogix a été victime d'une cyberattaque. Des pirates informatiques ont volé des informations sensibles, y compris des numéros de sécurité sociale, des données financières, des informations de santé et des numéros de passeport, appartenant à des dizaines de milliers de personnes. L'incident, qui a eu lieu entre le 13 et le 18 novembre, a été revendiqué par l'enseigne de ransomware Akira en janvier 2026.</div>]]></content>
    </entry>


    <entry>
        <title type="html">IT-Sentinel : Citrix patches NetScaler SAML zero-day exploited in attacks</title>
        <id>https://www.bleepingcomputer.com/news/security/citrix-patches-netscaler-saml-zero-day-exploited-in-attacks/</id>
        <link rel="alternate" href="https://www.bleepingcomputer.com/news/security/citrix-patches-netscaler-saml-zero-day-exploited-in-attacks/"/>
        <published>2026-10-04T23:58:00+00:00</published>
        <updated>2026-10-04T23:58:00+00:00</updated>
        <author><name>Lawrence Abrams</name></author>

        <content type="html"><![CDATA[<div>Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution. [...]</div>]]></content>
    </entry>


    <entry>
        <title type="html">IT-Sentinel : Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions</title>
        <id>https://techcrunch.com/2026/10/04/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions/</id>
        <link rel="alternate" href="https://techcrunch.com/2026/10/04/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions/"/>
        <published>2026-10-04T22:31:00+00:00</published>
        <updated>2026-10-04T22:31:00+00:00</updated>
        <author><name>Anthony Ha</name></author>

        <content type="html"><![CDATA[<div>AI slop seems to be overwhelming bug bounty programs.</div>]]></content>
    </entry>


    <entry>
        <title type="html">IT-Sentinel : Debian ruby-rack-session Important Auth Bypass and Escalation DSA-6542-1</title>
        <id>https://linuxsecurity.com/advisories/debian/debian-dsa-6542-1-ruby-rack-session</id>
        <link rel="alternate" href="https://linuxsecurity.com/advisories/debian/debian-dsa-6542-1-ruby-rack-session"/>
        <published>2026-10-04T20:47:00+00:00</published>
        <updated>2026-10-04T20:47:00+00:00</updated>
        <author><name>anonymous</name></author>

        <content type="html"><![CDATA[<div>It was discovered that incorrect error handling in ruby-rack-session may result in authentication bypass or privilege escalation in some setups. For the stable distribution (trixie), this problem has been fixed in version 2.1.1-0.1+deb13u1.</div>]]></content>
    </entry>


    <entry>
        <title type="html">IT-Sentinel : Debian Stable Wireshark DoS Arbitrary Code Exec Vulnerabilities DSA-6541-1</title>
        <id>https://linuxsecurity.com/advisories/debian/debian-dsa-6541-1-wireshark</id>
        <link rel="alternate" href="https://linuxsecurity.com/advisories/debian/debian-dsa-6541-1-wireshark"/>
        <published>2026-10-04T18:09:00+00:00</published>
        <updated>2026-10-04T18:09:00+00:00</updated>
        <author><name>anonymous</name></author>

        <content type="html"><![CDATA[<div>Multiple vulnerabilities have been discocvered in Wireshark, a network protocol analyzer which could result in denial of service or the execution of arbitrary code. For the stable distribution (trixie), these problems have been fixed in version 4.4.19-0+deb13u1.</div>]]></content>
    </entry>


    <entry>
        <title type="html">IT-Sentinel : SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 2</title>
        <id>https://securityaffairs.com/200367/ai/security-affairs-ai-cybersecurity-newsletter-round-2.html</id>
        <link rel="alternate" href="https://securityaffairs.com/200367/ai/security-affairs-ai-cybersecurity-newsletter-round-2.html"/>
        <published>2026-10-04T17:28:00+00:00</published>
        <updated>2026-10-04T17:28:00+00:00</updated>
        <author><name>Pierluigi Paganini</name></author>

        <content type="html"><![CDATA[<div>Security Affairs AI-CYBERSECURITY newsletter includes a collection of the best articles and research on AI in the international landscape



Artificial intelligence is rapidly changing cybersecurity, reshaping both the techniques used by attackers and the tools available to defenders. AI agents can automate tasks, analyze large amounts of data, discover vulnerabilities and accelerate offensive operations. At the same time, AI is creating new capabilities for threat detection, incident analysis and response. Security Affairs’ new newsletter follows this evolution, covering every week the latest threats, attacks, vulnerabilities and developments at the intersection of AI and cybersecurity.



AI-CYBERSECURITY Newsletter



GPT-6 Astra performs unsanctioned supply-chain attacks in simulations  



Claude Opus 5.5 uses 95% fewer em dashes, but its answers are getting longer



Scoop: Top AI companies probing tens of thousands of security incidents



80,000+ enterprises had employee AI logins stolen and ChatGPT is the front door  



Hackers hijack AI accounts and servers to fuel new cyber crime boom      



NVIDIA Launches Open Agent Safety Platform to Secure Agents From Testing to Deployment   



Trump launches America.gov with AI chatbots at its core



OpenAI CEO announces new AI agent and avoids mention of security concerns at developer conference 



Why can’t we just keep rogue AIs off the internet?



OpenAI benches GPT-6.1 Astra for overstepping the mark



DARPA Selects Xint to Use AI in Securing Military Messaging Apps  



Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix         



Trump, AI CEOs sign voluntary safety pact, back data center expansion



Cyber security skills in the UK labour market 2026  



Anthropic’s IPO prospectus shows sweeping AI vision, surging costs  



Vulnerability Discovery and Exploitation Trends in the AI Era  



Anthropic says rogue AI agents pose uncertain legal risk for the company  



GLM-5.3 and the spread of advanced cyber capabilities



Gemini 4 Argon: our next era of frontier intelligence      



Rogue Agents Investigation  



AI Agents Targeted U.S. and Canadian Government Websites  



Forget ‘superintelligence’: error-prone AI nearly sparked world war three this month Timnit Gebru and Emily M Bender  



AI’s Third Wave: Coworkers Break the Security Model That Worked for AgentsPixelLeak: How AI Agents Exposed Developer Screenshots from Leading Tech Companies



Follow me on Twitter: @securityaffairs and Facebook and Mastodon



Pierluigi Paganini



(SecurityAffairs – hacking, newsletter)</div>]]></content>
    </entry>


    <entry>
        <title type="html">IT-Sentinel : Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force</title>
        <id>https://www.securityweek.com/trump-names-national-intelligence-director-jay-clayton-to-lead-a-new-federal-ai-task-force/</id>
        <link rel="alternate" href="https://www.securityweek.com/trump-names-national-intelligence-director-jay-clayton-to-lead-a-new-federal-ai-task-force/"/>
        <published>2026-10-04T16:57:00+00:00</published>
        <updated>2026-10-04T16:57:00+00:00</updated>
        <author><name>Associated Press</name></author>

        <content type="html"><![CDATA[<div>The announcement comes after Trump hosted top executives of AI companies at the White House last week.
The post Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force appeared first on SecurityWeek.</div>]]></content>
    </entry>


    <entry>
        <title type="html">IT-Sentinel : SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 117</title>
        <id>https://securityaffairs.com/200354/security/security-affairs-malware-newsletter-round-117.html</id>
        <link rel="alternate" href="https://securityaffairs.com/200354/security/security-affairs-malware-newsletter-round-117.html"/>
        <published>2026-10-04T16:00:00+00:00</published>
        <updated>2026-10-04T16:00:00+00:00</updated>
        <author><name>Pierluigi Paganini</name></author>

        <content type="html"><![CDATA[<div>Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape



Malware Newsletter



Lunex Unmasked: A New Information Stealer Deployed Through BYOVD  



Storm-3168: Agentic-driven cloud attacks using compromised service principals  



Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties  



PhantomSub: Malicious npm Campaign Secretly Adds Users to WhatsApp Spam Channels  



Warlock Ransomware Attackers Hit Water and Telecom Operators  



Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix



Star Blizzard refines phishing and malware delivery with the RedFlick technique  



China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor



CloudSyncD: a two-stage macOS backdoor that hides a phished password in zero-width Unicode



SC WordPress Malware: A Self-Healing Mesh of Loaders, Drop-Ins, and a Blockchain-Controlled Backdoor     



A Hybrid Approach to Malware Detection: Integrating Few-Shot Model-Agnostic Meta-Learning with Autoencoders



Characterizing and Codifying Malware Sophistication



Joint Trust-Aware Topology Adaptation and Resource-Constrained Patching for Malware Containment in the Social Internet of Things



HFS-SVE: A Hybrid Feature Selection and Soft Voting Ensemble for Android Malware Detection



Follow me on Twitter: @securityaffairs and Facebook and Mastodon



Pierluigi Paganini



(SecurityAffairs – hacking, newsletter)</div>]]></content>
    </entry>


    <entry>
        <title type="html">IT-Sentinel : ShinyHunters Suspect Detained in Jordan Helps FBI Track Down the Group</title>
        <id>https://securityaffairs.com/200338/cyber-crime/shinyhunters-suspect-detained-in-jordan-helps-fbi-track-down-the-group.html</id>
        <link rel="alternate" href="https://securityaffairs.com/200338/cyber-crime/shinyhunters-suspect-detained-in-jordan-helps-fbi-track-down-the-group.html"/>
        <published>2026-10-04T15:41:00+00:00</published>
        <updated>2026-10-04T15:41:00+00:00</updated>
        <author><name>Pierluigi Paganini</name></author>

        <content type="html"><![CDATA[<div>A suspected ShinyHunters member arrested in Jordan is reportedly cooperating with the FBI, helping investigators track down the group.



A suspected member of ShinyHunters, the group that claims to have stolen data on every FBI employee, was picked up in Jordan this week. 



The man is Saif al-Din Khader, detained by Jordanian authorities, with two sources placing the arrest on Tuesday. Reuters couldn’t confirm the exact circumstances or where he’s being held. 



“A suspected member of the ShinyHunters hacking group, which ​says it stole data on every FBI employee, was detained in Jordan this week and is cooperating with the FBI, three people familiar with the matter told Reuters.” the Reuters states.



Two sources said he’s now helping the FBI and international law enforcement track down the rest of the group.



One source told Reuters that Khader is showing investigators his own devices and digital communications to help identify former associates. That gives investigators real access to potential evidence, not just a general promise to cooperate. 



“The FBI declined to comment on any specific arrest or activity abroad but said that the bureau “continues to aggressively investigate ​the recent cyber incident allegedly involving ShinyHunters, having already worked with partners to arrest multiple subjects — and we will spare no resource in bringing each of the responsible individuals to justice.”” Reuters continues.



The case matters beyond Khader’s arrest. ShinyHunters claims to have stolen personal data on FBI employees, and Reuters’ earlier analysis found that the leaked sample included detailed personal information, sensitive job-related data, and psychiatric and medical records. Some have compared the incident to the 2015 OPM breach, in which a China-linked attack exposed security clearance data belonging to millions of Americans. If the ShinyHunters claims are even partly confirmed, that comparison would be justified.



Dutch police confirmed this week that the 24-year-old man from Amsterdam was arrested earlier this month as part of an investigation into the cybercrime group ShinyHunters. The suspect appears before Rotterdam District Court today, September 29. Multiple sources, including KrebsOnSecurity, have identified him as Pepijn van der Stap, a Dutch hacker previously known online as “Umbreon.”



The connection to ShinyHunters runs through the “Umbreon” alias. Van der Stap used that handle and Pokémon imagery on BreachForums as early as 2021.



Source KrebsOnSecurity



Then the FBI jobs site defacement that ShinyHunters left after the FBIjobs.gov breach prominently featured an ASCII art version of the same Pokémon character, and the image appears identical to one used in a 2020 HackForums defacement attributed to ShinyHunters, a year before Van der Stap created his Umbreon account. That last detail cuts both ways: either the alias predates him in this context, or the timing coincidence is genuinely awkward. KrebsOnSecurity adds a more pointed interpretation: sources familiar with the investigation say the Umbreon imagery in the FBI defacement may have been a deliberate attempt by ShinyHunters’ current leader, a teenager from Amman, Jordan known as Rey, to pin the hack on Van der Stap. The two reportedly had ongoing bad blood over control of the ShinyHunters brand and data.



FBI Director Kash Patel had already hinted that more arrests were coming.



“FBI teams are working new leads RIGHT NOW. More arrests are on the table.” Patel wrote on X.




NO SAFE HAVEN.Working with our Dutch National Police partners, the FBI helped put an alleged leader of ShinyHunters—a global cybercrime threat actor—behind bars.And we’re not done.FBI teams are working new leads RIGHT NOW. More arrests are on the table.If you attack… pic.twitter.com/T7CK4KIKl9— FBI Director Kash Patel (@FBIDirectorKash) September 30, 2026




ShinyHunters’ own infrastructure has been wobbling since this week started. Reuters lost contact with the group’s usual communication account on Tuesday, the same day Khader was reportedly detained, and by Wednesday the group’s dark web leak site had gone offline entirely. The alleged leader of the group, Rey, told journalist Brian Krebs in November 2025 that he’d been quietly cooperating with law enforcement since June, well before any of this became public.



In November 2025, security journalist Brian Krebs reported that Rey was Saif Al-Din Khader after analyzing information obtained from infostealer logs and speaking directly with Khader over Signal.



What is new is what cooperation can look like when someone is in custody. An FBI Cyber Division official explained the situation last week: arrests can make people more willing to talk, while seized servers can reveal information about those who are still outside. Once someone’s laptop becomes evidence, loyalty can disappear very quickly.



A new ShinyHunters leak site reportedly came back online on Thursday, so the group itself isn’t dead, just missing one more member. 



Follow me on Twitter: @securityaffairs and Facebook and Mastodon



Pierluigi Paganini



(SecurityAffairs – hacking, ShinyHunters )</div>]]></content>
    </entry>


    <entry>
        <title type="html">IT-Sentinel : Weekly Update 524: Live From Copenhagen</title>
        <id>https://www.troyhunt.com/weekly-update-524/</id>
        <link rel="alternate" href="https://www.troyhunt.com/weekly-update-524/"/>
        <published>2026-10-04T13:52:00+00:00</published>
        <updated>2026-10-04T13:52:00+00:00</updated>
        <author><name>Troy Hunt</name></author>

        <content type="html"><![CDATA[<div>Presently sponsored by: Where are your AI agents? Origin's sensor finds every install on your fleet, grouped by owner, including the ones your MDM never sees.I'm in Denmark! Well, just, I'm now at Copenhagen airport ready to begin the long trek home, with the final event at GOTO now done and going just perfectly. This week, there are two ShinyHunters arrests in the news: Pepijn in the Netherlands and then Saif in Jordon. It's an inevitable outcome, of course, and as I say this week, it was also the most likely one. Time will tell how many more join their ranks, but the seriousness of the crimes, the length of time they were perpetrated over, and the motivations behind them will certainly see substantial custodial sentences.In other news, this week I'm properly introducing a new sponsor for the blog: Origin. One of our next AI frontiers is understanding what agents have actually done (and we've all seen news of where they're been a bit too, well, "creative" in executing their tasks), and Origin's solution gives you visiblity into just that. Check them out, and a big thanks to them for their ongoing support.</div>]]></content>
    </entry>


</feed>
