
Daily Cybersecurity News – October 9, 2026
CyberRecaps is supported by its readers. We may earn an affiliate commission at no extra cost to you if you buy through a link on this page.

Three Teams Remotely Hack Fully Patched Google Pixel 10 at Pwn2Own
HighWhat happened
Three research teams remotely compromised fully patched Google Pixel 10 phones on October 8 at Pwn2Own Ireland in Cork. Contest rules require targets to be fully patched and pay for working exploits that are then passed to vendors.
Ikotas Labs won the top prize of $300,000 and overall victory with a multi-issue chain labeled a collision. Xint earned $150,000 for a single-bug collision, and a third team of Dimitrios Valsamaras, Ken Gannon and Tenia Valsamara received $112,500 for a two-bug chain mixing a collision and a zero-day. Total payouts for the three Pixel wins reached $562,500.
All entries were registered as remote exploits via the default browser or radio interfaces (NFC, Wi-Fi, Bluetooth or baseband). Trend Micro's Zero Day Initiative (ZDI) has not published technical details of the exploits.
Who is affected
Owners and users of Google Pixel 10 devices, particularly those exposed to remote attack surfaces such as browsing untrusted web content or radio interfaces. The demonstrations used contest phones that were fully patched at the time.
Enterprise and consumer fleets running Pixel 10 hardware face potential risk once details emerge and until vendor patches land. Google’s October 6 Pixel security bulletin predated the contest and did not address these issues.
Why it matters
Successful remote compromise of a current, fully patched flagship Android device shows that high-value mobile targets remain reachable even after the latest security updates. Builders and operators of mobile fleets, MDM solutions, and apps that handle sensitive data on Pixel hardware should treat this as a signal that defense-in-depth beyond OS patches is required.
The 90-day disclosure window after ZDI hands material to vendors means technical details and patches are coming; unpatched devices will become higher-risk once public. Prize amounts and collision handling also illustrate how known-but-unfixed issues still deliver impact.
How it could have been prevented
Apply Google Pixel security updates promptly as soon as they are released following the vendor disclosure window. Restrict untrusted web content and unnecessary radio interfaces (NFC, Bluetooth) via MDM or user policy where feasible.
Monitor ZDI and Google security bulletins for the forthcoming advisories and CVEs tied to these contest entries. Prefer devices and configurations with strong exploit mitigations and keep browser and system components current.
Relevant professional terms
- Pwn2Own
- A live hacking contest where researchers demonstrate working exploits against fully patched popular software and devices for cash prizes, with findings then given to the vendors.
- Bug collision
- In contest rules, an exploit entry that relies on a vulnerability already known to the vendor or organizer, typically resulting in a reduced prize rather than full credit for a pure zero-day.
Tensorlake npm Package Hit in ChainDrop Supply Chain Attack
HighWhat happened
The npm package tensorlake, a TypeScript SDK for Tensorlake applications, was compromised in a ChainDrop / Shai-Hulud supply chain attack. Malicious version 0.5.144 shipped obfuscated malware that harvested credentials, exfiltrated secrets, established persistence, and could run remotely supplied code.
Targeted data included npm and GitHub tokens, AWS and Kubernetes credentials, SSH keys, cryptocurrency wallets, and configuration files for AI tools such as Anthropic Claude. The malware also dropped the HackBrowserData binary and used an Ethereum contract for command-and-control with GitHub as fallback.
Propagation involved enumerating associated packages, building Sigstore provenance, and republishing compromised versions, extending the campaign into AI agent infrastructure.
Who is affected
Developers and organizations that installed tensorlake version 0.5.144 or pulled it as a dependency. Anyone whose environments held npm/GitHub tokens, cloud credentials, SSH keys, crypto wallets, or AI tool configs on systems that ran the malicious package.
The incident particularly touches teams building on or integrating with Tensorlake and broader AI agent tooling that consumes npm packages.
Why it matters
Supply chain compromises of popular or niche SDKs give attackers a direct path into developer workstations and CI/CD pipelines, where high-value secrets and cloud access commonly live. Extending this pattern to AI agent infrastructure raises the stakes as more automated systems hold powerful credentials and tool access.
A single malicious package version can silently collect tokens and enable further lateral movement or account takeover across multiple services.
How it could have been prevented
Immediately remove tensorlake version 0.5.144 if installed. Rotate all potentially exposed credentials: npm tokens, GitHub tokens, AWS keys, Kubernetes credentials, SSH keys, and any AI tool or wallet secrets.
Pin package versions, enable lockfiles, use npm audit and similar scanners, prefer packages with verified provenance/Sigstore attestations, and restrict install scripts in CI. Monitor for unexpected network activity to Ethereum or unusual GitHub usage from build hosts.
Relevant professional terms
- Supply chain attack
- An attack that compromises a trusted third-party component, such as an open-source package, so that downstream users unknowingly install malicious code.
- Sigstore provenance
- Cryptographic attestation that records how a software artifact was built and by whom, intended to help verify authenticity and detect tampering when packages are republished.
Chinese Hacker Uses AI Pentesting Tool in South Korean Bank Attacks
HighWhat happened
CrowdStrike reported that a suspected China-based, financially motivated threat actor used the open-source agentic pentesting tool ARTEX together with Anthropic’s Claude model in a campaign against South Korean financial organizations from late September to early October 2026.
ARTEX was used primarily to discover vulnerabilities and compromise services. The actor also queried Claude for help locating Korean Telegram data-sales groups to monetize stolen data. Infrastructure linked to a single IP hosted an ARTEX instance and open directories with Chinese-language pentesting prompts, Claude Code materials, and session histories. Backends included DeepSeek, GLM, and Grok models.
Breaches reported at Shinhan Bank and Yegaram Savings Bank affected roughly 25,000 and 40,000 people respectively; other firms were also hit. South Korea’s Financial Services Commission issued a consumer alert about phishing and loan scams.
Who is affected
South Korean financial institutions and their customers, including Shinhan Bank and Yegaram Savings Bank customers whose data was reportedly exposed. Brokers and employees using compromised loan-inquiry or mobile work-support systems.
Exact total number of organizations remains unconfirmed. Consumers of the affected banks face elevated phishing and scam risk.
Why it matters
This shows financially motivated actors rapidly adopting agentic AI pentesting tools to scale vulnerability discovery and intrusion across multiple targets in a short window. Combining open-source offensive agents with commercial and Chinese LLMs lowers the skill and time barriers for multi-victim campaigns.
Banks and other high-value targets must assume attackers will use AI to accelerate recon and exploitation, increasing pressure on detection, segmentation, and rapid response. Stolen data fueling Telegram markets multiplies downstream fraud risk for customers.
How it could have been prevented
Harden external-facing and broker-facing services with strong authentication, least privilege, and continuous vulnerability management. Monitor for unusual scanning and exploitation patterns consistent with automated pentesting agents.
Segment employee mobile work systems and loan-inquiry portals; enforce MFA and anomaly detection on privileged access. Customers of affected banks should treat unsolicited loan or account messages with high suspicion and follow official FSC guidance. Rotate credentials and review logs if compromise is suspected.
Relevant professional terms
- Agentic AI
- AI systems that can plan and take multi-step actions toward a goal, such as running tools or chaining commands, rather than only answering single prompts.
- Pentesting tool
- Software designed to discover and exploit security weaknesses in systems the same way an authorized tester or attacker would, often automating recon and vulnerability checks.
Critical Atlassian Flaw in Jira and Confluence Exploited in Wild
CriticalAffected products
- Bitbucket Data Center
- Confluence Data Center
- Jira Service Management Data Center
- Jira Software Data Center
- Bamboo Data Center
- Crowd Data Center
- Crucible
- Fisheye
What happened
A critical arbitrary file access vulnerability tracked as CVE-2026-21589, scored CVSS 9.3 by Atlassian, is reported as exploited in the wild. It affects eight self-managed Data Center products: Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible, and Fisheye.
Unauthenticated attackers can read specific files under each product’s web application root by bypassing path-traversal protections in the shared atlassian-plugins-webresource library. WatchTowr showed the flaw can expose Crowd credentials stored in integrated products’ configuration files, potentially enabling further identity abuse.
VulnCheck and others have flagged exploitation activity. The vulnerability is not listed in CISA KEV at the time of the verified data.
Who is affected
Organizations running self-managed Atlassian Data Center editions of Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, or Fisheye, especially internet-exposed instances.
Enterprises that integrate Crowd for centralized auth are at higher risk of credential theft and follow-on account creation or modification. SaaS/cloud-hosted Atlassian products are outside the stated Data Center scope.
Why it matters
Unauthenticated file read on core collaboration, source control, CI/CD, and identity products can expose secrets, source, and configuration at massive blast radius inside enterprises. Chaining to Crowd credentials turns a file-read into potential identity takeover across the Atlassian stack.
Active exploitation reports mean lag in patching directly translates to real incident risk for teams that rely on these tools for development and IT service management.
How it could have been prevented
Apply Atlassian’s patches for CVE-2026-21589 immediately on all affected Data Center products. If patching is delayed, restrict network access to the instances, place them behind authentication gateways, and monitor web logs for anomalous path requests to web-resource endpoints.
Audit Crowd integrations and rotate any credentials that may have been readable from configuration files. Review access logs for suspicious file-read patterns and follow Atlassian’s official advisory for version-specific fixed releases.
Relevant professional terms
- Arbitrary file access
- A vulnerability that lets an attacker read files on the server that they should not be able to reach, often without logging in.
- Path traversal
- An attack technique that manipulates file path inputs (for example with ../ sequences) to escape a restricted directory and reach sensitive files elsewhere on the system.
Ransomware Recovery CEO Charged for Secretly Paying Hackers
MediumWhat it means
Recovery vendors that advertise decryption without payment must be contractually transparent about their actual methods. Victims should demand written clarity on whether any ransom will be paid, require detailed invoices that separate fees from any third-party payments, and prefer firms that align with law-enforcement guidance against paying ransoms when viable backups and IR retainers exist.
Due diligence on recovery partners now includes checking litigation history and public reporting, not only marketing claims about proprietary tools.
What happened
The U.S. Department of Justice charged Zohar Pinhasi, 50, owner of Florida-based ransomware recovery firm MonsterCloud, with wire fraud and wire fraud conspiracy. Prosecutors allege the company claimed proprietary tools and advanced decryption techniques that could restore data without paying ransoms.
Instead, Pinhasi allegedly paid the ransoms, obtained decryption keys, and charged victims far more than the original demand. Across cases he collected about $19 million from clients while paying roughly $8 million to cybercriminals. In one 2023 example he allegedly paid an $8,200 ransom and billed the client $150,000.
MonsterCloud had been spotlighted in a 2019 ProPublica investigation. Pinhasi faces up to 20 years if convicted.
Who is affected
Former MonsterCloud clients, including organizations that believed they were receiving non-payment decryption help. Local governments and police departments were among those previously reported as customers.
The broader ransomware victim community that turns to third-party recovery and negotiation firms.
Why it matters
Trust in incident-response and recovery vendors is critical when organizations are under extreme pressure. Secretly paying ransoms while advertising the opposite re-victimizes clients, inflates costs, and can channel funds to criminal groups contrary to stated policy.
The case continues DOJ focus on the opaque ransomware negotiation and recovery industry, following earlier sentences against negotiators who colluded with gangs. Operators choosing recovery partners need clear contractual transparency on whether ransoms will be paid.
Relevant professional terms
- Ransomware
- Malware that encrypts an organization’s files or systems and demands payment for the decryption key or for not leaking stolen data.
- Wire fraud
- A federal crime involving a scheme to obtain money or property through false pretenses that uses interstate electronic communications such as email or bank transfers.
New Scripts Reconstruct AI Agent Activity for Forensics
LowHow it works
- opencode-chat-replay.py: Lists sessions, then exports a chosen session (by ID, slug, or latest) as markdown transcript or structured data from the OpenCode SQLite DB.
- hermes_forensic_extract.py: Pulls conversations, model usage, API dumps, and app logs from Hermes home/evidence paths.
- Both support --start/--end time filters and pointing at a mounted image or collected directory via standard-library Python 3.10+.
What happened
SANS Internet Storm Center handler Jim Clausing released two Python forensic scripts to reconstruct activity from AI coding assistants and agents: opencode-chat-replay.py and hermes_forensic_extract.py. The work supports updated FOR577 material covering investigation of AI usage in incident response.
The scripts target OpenCode and Hermes artifacts. opencode-chat-replay.py turns SQLite session data (default ~/.local/share/opencode/opencode.db) into readable chat transcripts or structured exports, handling both legacy message/part tables and newer consolidated session_message storage. hermes_forensic_extract.py pulls a broader set including conversations, model usage, API request dumps, and application logs.
Both require Python 3.10+, use only the standard library, and support time-range filters and paths into mounted images or collected home directories. They are for review of recorded activity, not for live replay of agent actions.
Who is affected
Incident responders, DFIR analysts, and security teams that need to investigate developer workstations or servers where AI coding agents such as OpenCode or Hermes were used. Also relevant to SANS FOR577 students and organizations adopting AI pair-programming tools.
Anyone preserving evidence from systems that may contain AI agent session databases and logs.
Why it matters
AI coding agents leave rich local artifacts (prompts, tool calls, reasoning, API usage) that can explain how an intrusion started, what code or commands were suggested, or whether sensitive data was pasted into chats. Without purpose-built parsers, that evidence is easy to miss or hard to timeline.
As agentic tools spread in engineering environments, IR playbooks need reliable ways to extract and review this new class of artifacts alongside traditional browser and shell history.
Relevant professional terms
- Digital forensics
- The practice of collecting, preserving, and examining digital evidence from computers and devices so it can be used to understand what happened in an incident.
- Agent session artifact
- Persistent local records left by an AI coding agent, such as SQLite databases of prompts, tool calls, model responses, and logs, that investigators can parse after the fact.
Ransomware Disrupts Japan's IDCF Cloud Serving Government Clients
HighWhat happened
IDC Frontier, a SoftBank Group subsidiary, disclosed that its IDCF Cloud service suffered a ransomware attack beginning about 3:40 a.m. local time on October 7. The attack caused disruption in East Japan Region 1 and forced network and system shutdowns.
The company isolated affected systems to limit spread, disabled customer management-console access across regions while verifying security, and continues to investigate root cause and full scope. Customer screenshots showed a threat-actor message claiming a seven-minute breach, encryption of 225 databases (about 3.6 PB), reach to 239 hypervisors, sealing of 16,000 VM disks, and wiping of over 554,000 snapshots.
IDCF Cloud stated 495 companies and local governments using the service were impacted.
Who is affected
495 companies and local governments that use IDCF Cloud, especially workloads in East Japan Region 1. Customers relying on the IaaS platform for virtual servers, storage, and networking in Japanese data centers.
Government and enterprise tenants whose management consoles were locked and whose VMs, databases, or snapshots may have been encrypted or destroyed. Related reporting noted separate logistics disruption at Nissui Logistics tied to a third-party data center.
Why it matters
Ransomware against a major regional cloud provider creates simultaneous outage and potential data-loss impact for hundreds of tenants, including public-sector clients. Claims of rapid hypervisor- and snapshot-level damage highlight how cloud control-plane or infrastructure compromise can dwarf single-tenant incidents.
Operators who depend on one provider or region without tested cross-region failover and offline backups face extended recovery times and possible permanent loss of snapshots.
How it could have been prevented
Maintain offline or immutable backups that are independent of the primary cloud account and region. Test restoration regularly and document cross-region or multi-provider failover for critical government and business workloads.
Enforce strong identity controls on cloud management planes, least-privilege IAM, continuous monitoring for unusual hypervisor or snapshot activity, and rapid isolation playbooks. Tenants should monitor provider status, rotate credentials if console exposure is suspected, and verify integrity of restored systems before reopening access.
Relevant professional terms
- Ransomware
- Malicious software that encrypts systems or data and demands payment before the attacker will provide decryption or stop further harm.
- Hypervisor
- The software layer that runs and isolates multiple virtual machines on shared physical servers; compromise at this level can affect many customer workloads at once.