Here are today’s top cybersecurity stories for Wednesday, October 7, 2026.
Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
JFrog disclosed CVE-2026-105192, a critical flaw in LMCache, open-source software used to speed up LLM servers such as vLLM. JFrog scored it 9.8. The flaw affects versions 0.3.9 through 0.5.5 in multiprocess mode, where an unauthenticated ZeroMQ socket deserializes messages with pickle. No fixed version exists, and JFrog advises keeping the port on localhost or a trusted cluster network. The Hacker News
Georgia Power and Alabama Power Data Breach Hits 400,000 Accounts
Southern Company is notifying about 400,000 customers after an unauthorized third party accessed account information through its online customer portal. Roughly 300,000 Georgia Power customers and 100,000 Alabama Power customers are affected. Exposed data includes names, addresses, phone numbers, email addresses, and the last four digits of Social Security numbers. The company says bank account, payment card, and driver’s license numbers were not accessed. SecurityWeek
Ninja Forms and WPC Product Bundles Flaws Exploited to Hack WordPress Sites
Patchstack reports attackers are abusing stored XSS flaws CVE-2026-94504 in Ninja Forms and CVE-2026-93836 in WPC Product Bundles for WooCommerce. A malicious script runs when an administrator views poisoned content, installs a fake plugin, and creates rogue admin accounts. Fixes are in Ninja Forms 3.15.4 and WPC Product Bundles 8.6.7. Patchstack describes the exploitation as limited so far. BleepingComputer
PoeLLM Malware Infects 3,400+ Servers and Hides Its Command Server in a Poem
Lumen’s Black Lotus Labs says the botnet has compromised more than 3,400 servers since April 2026. It targets open-source AI and related services including LiteLLM, Ollama, Gotenberg, and Gitea for exploit scanning and cryptomining. The malware reads a poem posted on GitHub and extracts four words, which map to the command server’s IP address. Researchers believe the operator is Italian-speaking. CyberScoop and The Hacker News
FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials
The FBI and U.S. Secret Service say the credential-harvesting campaign against FortiGate firewalls and SSL VPN gateways is still ongoing. The activity uses credential stuffing, password spraying, and a Go-based sniffer called FortigateSniffer. Guidance tells victims to isolate affected devices, collect logs, and report incidents. Attackers who change or delete original accounts lock victims out. The Hacker News and CyberScoop
100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer
Ukraine’s CERT-UA tracks the activity as UAC-0277 and reports more than 100 websites injected with malicious JavaScript in September. Visitors see a forged verification page and are told to run a command, which installs a malicious MSI package. LunexStealer installs a browser extension disguised as a Word editor and steals cookies, history, and form credentials. The Hacker News
Chrome 155 Update Patches 247 Vulnerabilities
Google fixed 247 flaws in Chrome 155, including four critical use-after-free bugs: CVE-2026-106382, CVE-2026-106197, CVE-2026-106358, and CVE-2026-106347. Researchers reported 62 of the bugs, and Google paid roughly $33,000 in rewards. Google makes no mention of exploitation in the wild. Fixed builds are 155.0.8059.39 and 155.0.8059.40 for Windows and macOS. SecurityWeek
Qilin Ransomware Suspect Arrested in Japan, Extradited to Germany
A 28-year-old Russian national detained in Osaka in May was reportedly handed over to German authorities on October 2. Germany wants him over a September 2024 attack on a logistics company, in which data was encrypted and more than $160,000 in cryptocurrency was demanded. Qilin has operated as a ransomware-as-a-service group since August 2022. SecurityWeek
Anthropic Introduces Three-Tier Cyber Verification Program for AI Access
Anthropic is combining its Cyber Verification Program and Project Glasswing into one program with Defense Access, Red Team Access, and Specialized Access tiers. Anthropic says Glasswing partners found at least 129,000 verified vulnerabilities between April and July. Specialized Access is reserved for organizations authorized to test safety-critical systems. SecurityWeek and The Hacker News
Android’s October 2026 Updates Patch 25 Vulnerabilities
Google’s October update uses the 2026-10-01 patch level and fixes 7 Framework and 18 System flaws. Seven are rated critical, including a System bug allowing local privilege escalation without user interaction. Google does not say any of the flaws were exploited in the wild. SecurityWeek
Hackers Exploit 32 Zero-Days on First Day of Pwn2Own Ireland
Researchers used 32 zero-days on the first day of the competition, including two hacks of the Samsung Galaxy S26. BleepingComputer
Stay tuned for today’s in-depth analysis posts.






