Cyber security news October 2026

This posting is here to collect cyber security news in October 2026.

I post links to security vulnerability news to comments of this article.

You are also free to post related links to comments.

16 Comments

  1. Tomi Engdahl says:

    Huomaatko eron А:n ja A:n välillä? Jos et, voit olla vaarassa
    Aktian, Lähi-Tapiolan ja S-Pankin nimissä on liikkeellä paljon huijauksia. Aktia-huijauksen voi tunnistaa kyrillisestä A-kirjaimesta pankin nimessä.
    https://www.iltalehti.fi/digiuutiset/a/a4a9af2c-c18f-4fbf-9159-d034110f255b

    Pankkien ja vakuutusyhtiöiden nimiä hyödynnetään aktiivisesti huijauksissa, selviää jo yli 200 000 suomalaisen lataaman Kilpi-sovelluksen ilmoituksista.

    Kilpi on Suomen Telemarkkinointiliitto ry:n kehittämä älypuhelimiin ladattava sovellus, joka tunnistaa ei-toivotut puhelut, tekstiviestit ja sähköpostit ja estää ne automaattisesti.

    Havaintoja on tehty muun muassa Aktian, Lähi-Tapiolan ja S-Pankin nimissä. Sovelluksen havaintojen perusteella samaan aikaan liikkeellä on useita rinnakkaisia huijausyrityksiä.

    Reply
  2. Tomi Engdahl says:

    FTC is Investigating OpenAI and Anthropic Over Possible Risks to Consumers
    An FTC spokesperson confirmed the investigation but declined further comment.
    https://www.securityweek.com/ftc-is-investigating-openai-and-anthropic-over-possible-risks-to-consumers/

    Reply
  3. Tomi Engdahl says:

    Risk Management
    Four Cyber Threats Harboring Big Plans for the Future

    – AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations.

    https://www.securityweek.com/four-cyber-threats-harboring-big-plans-for-the-future/

    Reply
  4. Tomi Engdahl says:

    Artificial Intelligence
    Google Launches Gemini 4 Argon With Guardrail-Free Access for Vetted Defenders

    The company says its new frontier AI model found a critical vulnerability in software used by hospitals worldwide.

    https://www.securityweek.com/google-launches-gemini-4-argon-with-guardrail-free-access-for-vetted-defenders/

    Reply
  5. Tomi Engdahl says:

    Application Security
    500,000 Active Credentials Left Exposed on GitHub

    Roughly 200,000 of the credentials were exposed after GitHub enabled push protections by default.
    https://www.securityweek.com/500000-active-credentials-left-exposed-on-github/

    Reply
  6. Tomi Engdahl says:

    Artificial Intelligence
    Zammad Zero-Days Exploited in AI-Powered DIVD Hack

    The flaws were chained to hijack sessions, achieve remote code execution, and elevate privileges to root.

    https://www.securityweek.com/zammad-zero-days-exploited-in-ai-powered-divd-hack/

    Reply
  7. Tomi Engdahl says:

    Artificial Intelligence
    Google: AI Is Changing the Pace and Profile of Vulnerability Discovery

    Google’s analysis found that AI-discovered vulnerabilities are more likely to enable remote code execution.

    https://www.securityweek.com/google-ai-is-changing-the-pace-and-profile-of-vulnerability-discovery/

    Reply
  8. Tomi Engdahl says:

    Experts issue warning after voice scam AI attacks skyrocket
    Data from Microsoft’s digital defence report has also reported a jump in attacks where hackers impersonate business contacts in order to gain information or access to services
    https://www.independent.co.uk/tech/voice-phishing-scam-ai-microsoft-cyber-attack-b3059969.html?fbclid=IwdGRjcAUsL6ljbGNrBSwvg2V4dG4DYWVtAjExAHBkb2YFc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeG5yhVThIuHoe3B-Q-HvhtMOuVYUiBNd4Q5ps5yhiA7z60HLtVhZTIMLdzzo_aem_YuPE97qWilrw1jfPQOBOfA

    Voice phishing incidents have sharply increased over the past year as cyber attackers increasingly leverage AI technology to execute scams, according to research.

    Data from Microsoft’s digital defence report highlights a rise in incidents where hackers impersonate business contacts to obtain information or service access.

    Security experts at Microsoft noted that 27 per cent of cyber threat activity targeted government agencies or services, pointing to heightened concerns over cyber warfare.

    The report found that expanding AI use is altering how “vulnerabilities are identified, how attacks are developed, how defenders prioritise risk, and how organisations respond to emerging threats”.

    Reply
  9. Tomi Engdahl says:

    Epäily: Kansanedustajien kodeissa käyty – Stubb kertoo karusta kokemuksestaan
    Presidentti Alexander Stubb sanoi tietävänsä, miltä kotiin tunkeutuminen tuntuu. Taustalla ovat yli kymmenen vuoden takaiset tapahtumat.
    https://www.iltalehti.fi/politiikka/a/46aef0a4-7f04-496f-b51e-b9a27c207afe

    Reply
  10. Tomi Engdahl says:

    Voiko AI tehdä turvallisuuskriittisiä päätöksiä verkon reunalla?
    https://etn.fi/index.php/13-news/19357-voiko-ai-tehdae-turvallisuuskriittisiae-paeaetoeksiae-verkon-reunalla

    Tekoälyä viedään yhä pienempiin laitteisiin verkon reunalle, mutta kuinka paljon päätösvaltaa sille voidaan antaa? Pretzl Connect -tapahtuman paneelissa kysymykseen suhtauduttiin varauksella. AI voi auttaa päätöksenteossa, mutta viimeistä sanaa sille ei vielä haluta antaa.

    Silicon Labsin tuotepäällikkö Tamas Daranyin mukaan ongelma tulee tekoälyn perusluonteesta. AI perustuu tilastolliseen päättelyyn, joten sen tulos ei koskaan ole sataprosenttisen varma. Siksi esimerkiksi auton ABS-järjestelmän kaltaista turvallisuuskriittistä toimintoa ei hänen mukaansa voida rakentaa samalla tavalla AI päätöksenteon varaan kuin determinististä algoritmia.

    Reply
  11. Tomi Engdahl says:

    For years, one of Android’s selling points was that it was the more open alternative to Apple’s tightly controlled ecosystem. However, the tightening of Google’s environment has made it nearly impossible for small app developers to reach users.

    Read more: https://cnews.link/google-android-developer-verification-backlash-1/

    Reply
  12. Tomi Engdahl says:

    Artificial Intelligence
    AI Agents Aimed SQL Injection at US and Canadian Government Sites

    The attacks targeted the US Department of Education and Library and Archives Canada, and researchers linked some agents to OpenAI.

    https://www.securityweek.com/ai-agents-aimed-sql-injection-at-us-and-canadian-government-sites/

    Reply
  13. Tomi Engdahl says:

    Malware & Threats
    Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks

    The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025.

    https://www.securityweek.com/warlock-expands-sharepoint-exploitation-in-critical-infrastructure-attacks/

    Reply
  14. Tomi Engdahl says:

    Cybercrime
    In Rare Move, Alleged Iranian State Hacker Extradited to US

    Amir Barati, an alleged member of the Mabna Institute, was indicted for targeting universities, private organizations, and government entities in the US and abroad.

    https://www.securityweek.com/in-rare-move-iranian-hacker-accused-of-working-for-irgc-extradited-to-us/

    Reply

Leave a Comment

Your email address will not be published. Required fields are marked *

*

*