Canadian Cyber Security Journal
SOCIAL:
Filed under: News

Cybersecurity Daily Brief — Thursday, October 8, 2026

Here are today’s top cybersecurity stories for Thursday, October 8, 2026.

Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains
Attackers compromised third-party operators for the Ghana, Sierra Leone, and American Samoa country-code domains and changed authoritative DNS records. The change let them pass certificate authority domain validation and obtain HTTPS certificates for Google domains and other brands. Google says its own systems were not breached. Chrome blocked the certificates through CRLSets, and Google worked with the issuing authorities to revoke them. BleepingComputer

Cisco Warns of Critical Flaws Allowing Nexus Switch Takeover
Cisco released advisories for five critical NX-OS flaws, CVE-2026-76471, CVE-2026-76485, CVE-2026-76486, CVE-2026-76501, and CVE-2026-76465. They affect Nexus 3000 and Nexus 9000 switches in standalone NX-OS mode and allow arbitrary code execution as root or a forced reload. Cisco found the flaws in internal testing and knows of no exploitation. Separate fixes for Cisco License, formerly Smart Software Manager, include CVE-2026-76482 with a CVSS score of 10.0. BleepingComputer

Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
Version 0.5.144 of the tensorlake npm SDK carried a preinstall hook which launched a self-propagating, credential-stealing worm. Socket and StepSecurity tie the attack to the ChainDrop and Shai-Hulud campaign. The version has been removed from the registry, and anyone who installed it is advised to rotate credentials. The Hacker News

SonicWall and Splunk Patch Critical Vulnerabilities
SonicWall fixed four flaws in SMA1000 appliances, led by CVE-2026-102255, a pre-authentication SSRF scored 10.0. Fixes ship in versions 12.5.0-03082 and 12.4.3-03670, and SonicWall reports no evidence of exploitation. Splunk fixed three critical flaws in Splunk Enterprise, along with issues in its MCP Server and Add-on for Amazon Web Services. SecurityWeek

Oracle Health Data Breach Tally Climbs to Nearly 20 Million
Bloomberg, citing a Texas attorney general report, says nearly 20 million people were affected by the breach of a legacy Cerner server in early 2025. Oracle believes the attacker used stolen customer credentials. Exposed data includes names, Social Security numbers, and medical records. Oracle has not confirmed the total. SecurityWeek

Fake Decryption Tools Masked $11M Markup in Ransomware Recovery Scheme
The Justice Department charged Zohar Pinhasi, owner of Florida firm MonsterCloud, with wire fraud and wire fraud conspiracy. Prosecutors allege he paid more than $8 million in ransoms for decryption keys while billing clients over $19 million for recovery with proprietary tools. In one case he allegedly paid about $8,200 and charged about $150,000. SecurityWeek

U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks
The State Department’s Rewards for Justice program is offering up to $10 million for information on Zhang Yu, a Chinese national charged over the 2021 Microsoft Exchange attacks. He remains at large. His co-defendant Xu Zewei was extradited from Italy in April 2026. SecurityWeek

Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks
JPCERT/CC reports attackers behind data leaks at Japanese organizations abused APIs used by mobile apps and exploited known software flaws. The alert names no attacker or victim. It includes IP addresses, User-Agent strings, and guidance on API controls. The Hacker News

Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia
ANY.RUN identified Wazza, a phishing kit with a multi-stage routing chain which screens out automated traffic. Qualified visitors reach an Adobe-themed device code phishing page. The Hacker News

16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases
Socket found 16 Firefox extensions disguised as wallet portals and browser tools. They intercept recovery phrases and private keys during wallet import and send them to attacker-controlled Cloudflare Workers. The Hacker News

Microsoft Outlook to Block MSIX Attachments Starting November
Outlook will add MSIX and MSIXBUNDLE files to its blocked attachment list in November. The change targets attacks which deliver malware through these package formats. BleepingComputer

Stay tuned for today’s in-depth analysis posts.

Enjoy this article? Don’t forget to share.