> ## Content Index
> Fetch the complete content index at: https://securexion.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Securexion Daily Brief - 30 Sept 2026
- URL: https://securexion.com/securexion-daily-brief-30-sept-2026/
- Published: 2026-09-29T19:21:59.000Z
- Updated: 2026-09-29T19:21:59.000Z
- Author: Securexion Team

Today's top cybersecurity stories from trusted sources.

### [Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks](https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html?ref=securexion.com)

Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write…

Source: [thehackernews.com](https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html?ref=securexion.com)

### [Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown](https://thehackernews.com/2026/09/kiteworks-fixes-critical-flaw-found.html?ref=securexion.com)

Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during the scheduled precautionary shutdown. "During the shutdown, this activity led to the…

Source: [thehackernews.com](https://thehackernews.com/2026/09/kiteworks-fixes-critical-flaw-found.html?ref=securexion.com)

### [Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks](https://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.html?ref=securexion.com)

Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at telecommunications…

Source: [thehackernews.com](https://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.html?ref=securexion.com)

### [Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M](https://thehackernews.com/2026/09/bitget-says-attacker-exploited-third.html?ref=securexion.com)

The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level…

Source: [thehackernews.com](https://thehackernews.com/2026/09/bitget-says-attacker-exploited-third.html?ref=securexion.com)

### [Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor](https://thehackernews.com/2026/09/russias-star-blizzard-targets-100.html?ref=securexion.com)

Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft. The campaigns, aimed at people and organizations tied to Ukraine, have…

Source: [thehackernews.com](https://thehackernews.com/2026/09/russias-star-blizzard-targets-100.html?ref=securexion.com)

### [New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses](https://thehackernews.com/2026/09/new-spectre-v2-btr-attack-leaks-linux.html?ref=securexion.com)

A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in web browsers, language runtimes, and the operating system kernel,…

Source: [thehackernews.com](https://thehackernews.com/2026/09/new-spectre-v2-btr-attack-leaks-linux.html?ref=securexion.com)

### [RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims](https://thehackernews.com/2026/09/rathat-android-malware-console-uses.html?ref=securexion.com)

RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026\. It said this fits a…

Source: [thehackernews.com](https://thehackernews.com/2026/09/rathat-android-malware-console-uses.html?ref=securexion.com)

### [French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks](https://thehackernews.com/2026/09/french-tax-data-theft-using-stolen.html?ref=securexion.com)

An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July. Neither the tax administration nor France's national cybersecurity agency saw the data…

Source: [thehackernews.com](https://thehackernews.com/2026/09/french-tax-data-theft-using-stolen.html?ref=securexion.com)

### [101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent](https://thehackernews.com/2026/09/101-malicious-npm-packages-add.html?ref=securexion.com)

Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub. "The malicious packages abuse the 'Baileys' WhatsApp open source project to add the…

Source: [thehackernews.com](https://thehackernews.com/2026/09/101-malicious-npm-packages-add.html?ref=securexion.com)

### [Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation](https://thehackernews.com/2026/09/dutch-police-arrest-24-year-old.html?ref=securexion.com)

Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. "It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group…

Source: [thehackernews.com](https://thehackernews.com/2026/09/dutch-police-arrest-24-year-old.html?ref=securexion.com)

### [Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials](https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html?ref=securexion.com)

A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory. Affected versions sent the client…

Source: [thehackernews.com](https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html?ref=securexion.com)

### [OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions](https://thehackernews.com/2026/09/openai-shelves-gpt-61-astra-after-tests.html?ref=securexion.com)

OpenAI on Monday shelved plans to release GPT-6.1 Astra, a next-generation artificial intelligence (AI) model that was planned for an October launch, after it failed internal safety and alignment audits. The development was first reported by The Wall…

Source: [thehackernews.com](https://thehackernews.com/2026/09/openai-shelves-gpt-61-astra-after-tests.html?ref=securexion.com)

---

*Securexion is brought to you by FutureOpsTech.*