Skip to content

Home/Digest/Past issues

Daily digest,

FBI Seizes Domains and Tools Used by Chinese Hackers (+5 more)

Vulnerabilities

XRP Ledger Patches Critical Vulnerability Allowing Creation of New XRP

The XRP Ledger (XRPL) patched a critical vulnerability that could have allowed attackers to create new, spendable XRP without funding. This flaw, dating back to 2015, was discovered by researcher Cayden Liao and Veria AI and reported on September 22, 2026. The vulnerability exploited a counting error in the payment engine, potentially enabling attackers to generate billions of XRP by manipulating order books. RippleX confirmed no evidence of exploitation on public networks and released the patch in version 3.4.1 on September 25. Additionally, a second vulnerability affecting the Batch transaction feature was also addressed, which could have disrupted transaction validation but did not affect user balances. Both vulnerabilities were disclosed in a report on October 9, 2026.

Vulnerability · 7 sources · score 58

Anthropic's OSS Scanner Flags 29,000 Vulnerabilities, Including Critical Curl Flaw

On October 8, 2026, Anthropic launched its free OSS Scanner, which has identified 29,439 potential vulnerabilities in open-source software since November 2025. Among these, a serious flaw in the curl project was highlighted by maintainer Daniel Stenberg as one of the worst in years. The scanner operates without human review, meaning reports may contain inaccuracies. As of October 2, 2026, external security firms had reviewed 6,123 of the flagged vulnerabilities, resulting in 584 security advisories. The initiative aims to enhance security for critical infrastructure operators, including partners like CrowdStrike and Palo Alto Networks. However, nearly 5,000 unverified reports were sent directly to maintainers, raising concerns about the reliability of the findings. The program reflects lessons learned from previous efforts that failed to reduce cyber risk effectively.

Critical Infrastructure · 2 sources · score 51 · Akrites, Cyber Mission, Gold Eagle

Threat actors and malware

FBI Seizes Domains and Tools Used by Chinese Hackers

On October 8, 2026, the FBI and Justice Department seized seven domains linked to Chinese hackers associated with Integrity Technology Group, which allegedly provided tools for cyber operations targeting critical infrastructure. The seized tools, MicroScan and FishHub, were used for network scanning and spear-phishing attacks against U.S. and foreign entities, including power companies and universities. This operation follows previous disruptions of the Flax Typhoon botnet, which infected over 200,000 devices in September 2024. The seizure aims to disrupt the hackers' capabilities, although the compromised devices remain unaffected. The FBI has indicated that the operation is part of a broader strategy to target malicious cyber actors linked to state-sponsored activities. The Chinese government has denied the allegations, calling them politically motivated.

APT · 3 sources · score 60 · Flax Typhoon, Flax Typhoon Botnet, Mirai

Tinubu Administration's Lobbying Firm Linked to Hacking of Activists

A US court filing revealed that DCI Group, a lobbying firm for Nigerian President Bola Tinubu, is linked to a hacking operation targeting climate-change advocates and critics of ExxonMobil. The operation, managed by Israeli operator Aviram Azari, reportedly used spearphishing emails to compromise over 100 victims, including government officials and activists. The allegations surfaced in a sentencing memorandum filed on October 8, 2026, in a case involving transparency activist Aaron Greenspan. DCI Group has not been confirmed to have targeted African officials or to have financed any hacking operations. The lobbying firm Von Batten-Montague-York also released documents suggesting a connection between DCI Group and the hacking of American activists, raising concerns about foreign interference and transnational repression. The situation is evolving as more documents are disclosed and investigations continue.

Phishing · 2 sources · score 58

Also worth knowing

UAE Faces Over 800,000 Daily Cyberattacks Amid Growing Threat Landscape

The UAE is experiencing over 800,000 cyberattacks daily, as reported by the UAE Cyber Security Council. This alarming figure highlights the urgent need for a robust defense framework to protect critical infrastructure. In response, the UAE has launched initiatives such as the UAE Cyber Factory, which aims to develop advanced AI-powered cybersecurity capabilities. Additionally, a specialized cybersecurity center of excellence was established in Abu Dhabi to enhance real-time threat detection. The Dubai Police have also initiated an interactive cybersecurity awareness platform at Dubai Mall to educate the public on online scams and threats. These efforts reflect a strategic approach to digital transformation and cybersecurity preparedness in the UAE.

Critical Infrastructure · 2 sources · score 58 · Dubai Cyber Challenge – Government Edition, Make It In The Emirates 2026, Safe UAE Through Your Digital Awareness

King Charles III Addresses Evolving Cyber Threats on NCSC Anniversary

King Charles III issued a letter to the National Cyber Security Centre (NCSC) on its 10th anniversary, highlighting the evolving tactics of malicious online actors and the threats posed by disinformation and automated technologies. He praised the NCSC's achievements in defending against cyber attacks and safeguarding democratic institutions. The letter coincided with a recent high-profile hack of online retailer Asos, where hackers sent unauthorized notifications to millions of users, compromising sensitive personal information. The NCSC is currently assisting Asos in its investigation into the breach, which reportedly involves detailed user profiles. The King emphasized the urgent need for robust cybersecurity measures in the face of advancing technologies, particularly AI, which he warned could pose existential risks if misused.

Disinfo & Influence · 3 sources · score 54

New on leak sites

14 victims listed on ransomware leak sites by 9 groups in the 24 hours before this issue. The most active:

Also moving

  • APT groups: Flax Typhoon
  • Campaigns: Absolute Isolation Campaign, Akrites
  • CVEs: CVE-2023-20585, CVE-2024-36064, CVE-2026-107806, CVE-2026-19666, CVE-2026-19667

Get the next one by email

The digest is free and arrives every morning. One click to leave.

Subscribe to the digest

A free account turns the digest into a personal watchlist: choose what you want to follow.