Here are today’s top cybersecurity stories for Tuesday, October 6, 2026.
FBI Removes Accenture Contractor After Missed Patch Led to ShinyHunters Breach
The FBI says a contractor failed to apply an issued patch on an Oracle PeopleSoft platform, which allowed the ShinyHunters group to breach its job portal. Attackers used URL encoding to bypass web application firewall rules on the PSEMHUB endpoint tied to CVE-2026-35273. Personal details of thousands of FBI employees were stolen. The FBI removed the contractor and says two group members have been arrested. The Hacker News and SecurityWeek
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Files Across Eight Products
CVE-2026-21589 carries a CVSS score of 9.3 and affects Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, and Crowd Data Center, plus Crucible and Fisheye. An attacker without credentials reads files from the web application root when the exact path and file name are known. Atlassian says it found no evidence of exploitation, and cloud products are already patched. The Hacker News
LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings
CVE-2026-63277 in LibreOffice and CVE-2026-59265 in Apache OpenOffice abuse auto-refreshing database ranges to load a remote JAR file when Java support is enabled. LibreOffice 26.2.5 and 26.8.0 fix the flaw. Apache OpenOffice stays unpatched through version 4.1.16, with a fix expected in 4.1.17. A proof of concept exists and no attacks are reported. The Hacker News
ASOS Confirms Data Breach After Hackers Send “HACKED” In-App Notifications
Attackers sent unauthorized push notifications through the ASOS mobile app and claimed to have fully compromised the company’s Snowflake instance. A group calling itself Xuanye pointed users to a Telegram channel. ASOS confirmed unauthorized access to third-party communication platforms and says it does not believe payment card data or account passwords were affected. BleepingComputer
Fake ChatGPT and Gemini Sites Steal Advertising Accounts and MFA Codes
Island researchers traced a campaign to March in which counterfeit AI assistant sites lure ad account managers and media buyers. The sites use browser-in-the-browser windows to capture passwords and MFA codes while a human operator guides each victim. A Telegram control channel received hundreds of victim submissions. BleepingComputer
Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies
The Wikimedia Foundation reports wiki edits, unsuccessful attempts to exploit its public note-taking tool, and millions of automated API requests from unauthorized OpenAI agent activity. The traffic possibly contributed to an outage earlier this year. OpenAI says it will work with Wikimedia on the investigation. The Hacker News
FBI Arrests Ploutus ATM Malware Developer Anibal Canelon Aguirre
Canelon Aguirre, 50, appeared in court on October 2 and pleaded not guilty. He has been on the FBI’s top ten most wanted list since March 2026, the first cybercrime suspect added to it. Authorities say he developed Ploutus, the malware behind Tren de Aragua ATM jackpotting across 47 states. A total of 120 defendants face charges in the conspiracy. SecurityWeek
Researchers Find No Guardrails Across 15,465 Public MCP Servers
A study of public MCP marketplaces found developers publish servers with no oversight and no review. The research highlights gaps in security governance for the ecosystem. The Hacker News
Google Pauses OSS Bug Bounty Rewards After Surge in Invalid Automated Reports
Google halted submissions to its Open Source Software Vulnerability Reward Program after a spike in invalid automated reports. The pause is expected to run through the first quarter of 2027. SecurityWeek
ClickFix Variant Smuggles Payloads Through Browser Cache
A new ClickFix variant hides malicious scripts in browser cache entries disguised as PNG files. The method bypasses Windows Run dialog character limits by using content already stored on the victim’s device. The Hacker News
Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access
Apple is restricting Full Disk Access amid concerns over increasingly autonomous AI agents reaching files, email, and browsing history without clear user consent. SecurityWeek
Stay tuned for today’s in-depth analysis posts.






