This posting is here to collect cyber security news in October 2026.
I post links to security vulnerability news to comments of this article.
You are also free to post related links to comments.
This posting is here to collect cyber security news in October 2026.
I post links to security vulnerability news to comments of this article.
You are also free to post related links to comments.
16 Comments
Tomi Engdahl says:
Huomaatko eron А:n ja A:n välillä? Jos et, voit olla vaarassa
Aktian, Lähi-Tapiolan ja S-Pankin nimissä on liikkeellä paljon huijauksia. Aktia-huijauksen voi tunnistaa kyrillisestä A-kirjaimesta pankin nimessä.
https://www.iltalehti.fi/digiuutiset/a/a4a9af2c-c18f-4fbf-9159-d034110f255b
Pankkien ja vakuutusyhtiöiden nimiä hyödynnetään aktiivisesti huijauksissa, selviää jo yli 200 000 suomalaisen lataaman Kilpi-sovelluksen ilmoituksista.
Kilpi on Suomen Telemarkkinointiliitto ry:n kehittämä älypuhelimiin ladattava sovellus, joka tunnistaa ei-toivotut puhelut, tekstiviestit ja sähköpostit ja estää ne automaattisesti.
Havaintoja on tehty muun muassa Aktian, Lähi-Tapiolan ja S-Pankin nimissä. Sovelluksen havaintojen perusteella samaan aikaan liikkeellä on useita rinnakkaisia huijausyrityksiä.
Tomi Engdahl says:
https://www.uusiteknologia.fi/2026/10/01/tekoaly-iski-f-securen-toimintoihin/
Tomi Engdahl says:
FTC is Investigating OpenAI and Anthropic Over Possible Risks to Consumers
An FTC spokesperson confirmed the investigation but declined further comment.
https://www.securityweek.com/ftc-is-investigating-openai-and-anthropic-over-possible-risks-to-consumers/
Tomi Engdahl says:
Risk Management
Four Cyber Threats Harboring Big Plans for the Future
– AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations.
https://www.securityweek.com/four-cyber-threats-harboring-big-plans-for-the-future/
Tomi Engdahl says:
Artificial Intelligence
Google Launches Gemini 4 Argon With Guardrail-Free Access for Vetted Defenders
The company says its new frontier AI model found a critical vulnerability in software used by hospitals worldwide.
https://www.securityweek.com/google-launches-gemini-4-argon-with-guardrail-free-access-for-vetted-defenders/
Tomi Engdahl says:
Application Security
500,000 Active Credentials Left Exposed on GitHub
Roughly 200,000 of the credentials were exposed after GitHub enabled push protections by default.
https://www.securityweek.com/500000-active-credentials-left-exposed-on-github/
Tomi Engdahl says:
Artificial Intelligence
Zammad Zero-Days Exploited in AI-Powered DIVD Hack
The flaws were chained to hijack sessions, achieve remote code execution, and elevate privileges to root.
https://www.securityweek.com/zammad-zero-days-exploited-in-ai-powered-divd-hack/
Tomi Engdahl says:
https://www.securityweek.com/ftc-is-investigating-openai-and-anthropic-over-possible-risks-to-consumers/
Tomi Engdahl says:
Artificial Intelligence
Google: AI Is Changing the Pace and Profile of Vulnerability Discovery
Google’s analysis found that AI-discovered vulnerabilities are more likely to enable remote code execution.
https://www.securityweek.com/google-ai-is-changing-the-pace-and-profile-of-vulnerability-discovery/
Tomi Engdahl says:
Experts issue warning after voice scam AI attacks skyrocket
Data from Microsoft’s digital defence report has also reported a jump in attacks where hackers impersonate business contacts in order to gain information or access to services
https://www.independent.co.uk/tech/voice-phishing-scam-ai-microsoft-cyber-attack-b3059969.html?fbclid=IwdGRjcAUsL6ljbGNrBSwvg2V4dG4DYWVtAjExAHBkb2YFc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeG5yhVThIuHoe3B-Q-HvhtMOuVYUiBNd4Q5ps5yhiA7z60HLtVhZTIMLdzzo_aem_YuPE97qWilrw1jfPQOBOfA
Voice phishing incidents have sharply increased over the past year as cyber attackers increasingly leverage AI technology to execute scams, according to research.
Data from Microsoft’s digital defence report highlights a rise in incidents where hackers impersonate business contacts to obtain information or service access.
Security experts at Microsoft noted that 27 per cent of cyber threat activity targeted government agencies or services, pointing to heightened concerns over cyber warfare.
The report found that expanding AI use is altering how “vulnerabilities are identified, how attacks are developed, how defenders prioritise risk, and how organisations respond to emerging threats”.
Tomi Engdahl says:
Epäily: Kansanedustajien kodeissa käyty – Stubb kertoo karusta kokemuksestaan
Presidentti Alexander Stubb sanoi tietävänsä, miltä kotiin tunkeutuminen tuntuu. Taustalla ovat yli kymmenen vuoden takaiset tapahtumat.
https://www.iltalehti.fi/politiikka/a/46aef0a4-7f04-496f-b51e-b9a27c207afe
Tomi Engdahl says:
Voiko AI tehdä turvallisuuskriittisiä päätöksiä verkon reunalla?
https://etn.fi/index.php/13-news/19357-voiko-ai-tehdae-turvallisuuskriittisiae-paeaetoeksiae-verkon-reunalla
Tekoälyä viedään yhä pienempiin laitteisiin verkon reunalle, mutta kuinka paljon päätösvaltaa sille voidaan antaa? Pretzl Connect -tapahtuman paneelissa kysymykseen suhtauduttiin varauksella. AI voi auttaa päätöksenteossa, mutta viimeistä sanaa sille ei vielä haluta antaa.
Silicon Labsin tuotepäällikkö Tamas Daranyin mukaan ongelma tulee tekoälyn perusluonteesta. AI perustuu tilastolliseen päättelyyn, joten sen tulos ei koskaan ole sataprosenttisen varma. Siksi esimerkiksi auton ABS-järjestelmän kaltaista turvallisuuskriittistä toimintoa ei hänen mukaansa voida rakentaa samalla tavalla AI päätöksenteon varaan kuin determinististä algoritmia.
Tomi Engdahl says:
For years, one of Android’s selling points was that it was the more open alternative to Apple’s tightly controlled ecosystem. However, the tightening of Google’s environment has made it nearly impossible for small app developers to reach users.
Read more: https://cnews.link/google-android-developer-verification-backlash-1/
Tomi Engdahl says:
Artificial Intelligence
AI Agents Aimed SQL Injection at US and Canadian Government Sites
The attacks targeted the US Department of Education and Library and Archives Canada, and researchers linked some agents to OpenAI.
https://www.securityweek.com/ai-agents-aimed-sql-injection-at-us-and-canadian-government-sites/
Tomi Engdahl says:
Malware & Threats
Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks
The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025.
https://www.securityweek.com/warlock-expands-sharepoint-exploitation-in-critical-infrastructure-attacks/
Tomi Engdahl says:
Cybercrime
In Rare Move, Alleged Iranian State Hacker Extradited to US
Amir Barati, an alleged member of the Mabna Institute, was indicted for targeting universities, private organizations, and government entities in the US and abroad.
https://www.securityweek.com/in-rare-move-iranian-hacker-accused-of-working-for-irgc-extradited-to-us/