Daily digest,
FBI Seizes Domains and Tools Used by Chinese Hackers (+5 more)
Vulnerabilities
XRP Ledger Patches Critical Vulnerability Allowing Creation of New XRP
The XRP Ledger (XRPL) patched a critical vulnerability that could have allowed attackers to create new, spendable XRP without funding. This flaw, dating back to 2015, was discovered by researcher Cayden Liao and Veria AI and reported on September 22, 2026. The vulnerability exploited a counting error in the payment engine, potentially enabling attackers to generate billions of XRP by manipulating order books. RippleX confirmed no evidence of exploitation on public networks and released the patch in version 3.4.1 on September 25. Additionally, a second vulnerability affecting the Batch transaction feature was also addressed, which could have disrupted transaction validation but did not affect user balances. Both vulnerabilities were disclosed in a report on October 9, 2026.
Vulnerability · 7 sources · score 58
Anthropic's OSS Scanner Flags 29,000 Vulnerabilities, Including Critical Curl Flaw
On October 8, 2026, Anthropic launched its free OSS Scanner, which has identified 29,439 potential vulnerabilities in open-source software since November 2025. Among these, a serious flaw in the curl project was highlighted by maintainer Daniel Stenberg as one of the worst in years. The scanner operates without human review, meaning reports may contain inaccuracies. As of October 2, 2026, external security firms had reviewed 6,123 of the flagged vulnerabilities, resulting in 584 security advisories. The initiative aims to enhance security for critical infrastructure operators, including partners like CrowdStrike and Palo Alto Networks. However, nearly 5,000 unverified reports were sent directly to maintainers, raising concerns about the reliability of the findings. The program reflects lessons learned from previous efforts that failed to reduce cyber risk effectively.
Critical Infrastructure · 2 sources · score 51 · Akrites, Cyber Mission, Gold Eagle
Threat actors and malware
FBI Seizes Domains and Tools Used by Chinese Hackers
On October 8, 2026, the FBI and Justice Department seized seven domains linked to Chinese hackers associated with Integrity Technology Group, which allegedly provided tools for cyber operations targeting critical infrastructure. The seized tools, MicroScan and FishHub, were used for network scanning and spear-phishing attacks against U.S. and foreign entities, including power companies and universities. This operation follows previous disruptions of the Flax Typhoon botnet, which infected over 200,000 devices in September 2024. The seizure aims to disrupt the hackers' capabilities, although the compromised devices remain unaffected. The FBI has indicated that the operation is part of a broader strategy to target malicious cyber actors linked to state-sponsored activities. The Chinese government has denied the allegations, calling them politically motivated.
APT · 3 sources · score 60 · Flax Typhoon, Flax Typhoon Botnet, Mirai
Tinubu Administration's Lobbying Firm Linked to Hacking of Activists
A US court filing revealed that DCI Group, a lobbying firm for Nigerian President Bola Tinubu, is linked to a hacking operation targeting climate-change advocates and critics of ExxonMobil. The operation, managed by Israeli operator Aviram Azari, reportedly used spearphishing emails to compromise over 100 victims, including government officials and activists. The allegations surfaced in a sentencing memorandum filed on October 8, 2026, in a case involving transparency activist Aaron Greenspan. DCI Group has not been confirmed to have targeted African officials or to have financed any hacking operations. The lobbying firm Von Batten-Montague-York also released documents suggesting a connection between DCI Group and the hacking of American activists, raising concerns about foreign interference and transnational repression. The situation is evolving as more documents are disclosed and investigations continue.
Phishing · 2 sources · score 58
Also worth knowing
UAE Faces Over 800,000 Daily Cyberattacks Amid Growing Threat Landscape
The UAE is experiencing over 800,000 cyberattacks daily, as reported by the UAE Cyber Security Council. This alarming figure highlights the urgent need for a robust defense framework to protect critical infrastructure. In response, the UAE has launched initiatives such as the UAE Cyber Factory, which aims to develop advanced AI-powered cybersecurity capabilities. Additionally, a specialized cybersecurity center of excellence was established in Abu Dhabi to enhance real-time threat detection. The Dubai Police have also initiated an interactive cybersecurity awareness platform at Dubai Mall to educate the public on online scams and threats. These efforts reflect a strategic approach to digital transformation and cybersecurity preparedness in the UAE.
Critical Infrastructure · 2 sources · score 58 · Dubai Cyber Challenge – Government Edition, Make It In The Emirates 2026, Safe UAE Through Your Digital Awareness
King Charles III Addresses Evolving Cyber Threats on NCSC Anniversary
King Charles III issued a letter to the National Cyber Security Centre (NCSC) on its 10th anniversary, highlighting the evolving tactics of malicious online actors and the threats posed by disinformation and automated technologies. He praised the NCSC's achievements in defending against cyber attacks and safeguarding democratic institutions. The letter coincided with a recent high-profile hack of online retailer Asos, where hackers sent unauthorized notifications to millions of users, compromising sensitive personal information. The NCSC is currently assisting Asos in its investigation into the breach, which reportedly involves detailed user profiles. The King emphasized the urgent need for robust cybersecurity measures in the face of advancing technologies, particularly AI, which he warned could pose existential risks if misused.
Disinfo & Influence · 3 sources · score 54
New on leak sites
14 victims listed on ransomware leak sites by 9 groups in the 24 hours before this issue. The most active:
Also moving
- APT groups: Flax Typhoon
- Campaigns: Absolute Isolation Campaign, Akrites
- CVEs: CVE-2023-20585, CVE-2024-36064, CVE-2026-107806, CVE-2026-19666, CVE-2026-19667
Get the next one by email
The digest is free and arrives every morning. One click to leave.
A free account turns the digest into a personal watchlist: choose what you want to follow.