HomeTagsCritical national infrastructure

critical national infrastructure - Page 8

Stories from critical national infrastructure come first, newest first, then stories from connected topics (Cybersecurity, Tech News), each labelled with where it comes from. This view is not indexed by search engines.

Latest

The FBI Takes Down Two Hacking Tools Tied to “Flax Typhoon”: What Happened and Why It Matters

On 8 October 2026 the US Justice Department and FBI seized web domains behind two hacking tools allegedly run by China-based Integrity Technology Group, linked to "Flax Typhoon". Eleven agencies from seven countries issued a joint advisory, and CISA added five old flaws to its exploited-vulnerabilities list. What was done, what is alleged, and what defenders are told.

AI Agent Security, 8 October (Evening): Disputed AgentCore Research, Claude Code’s Fail-Closed Hooks and Malware Aimed at AI Analysts

Three agent-security stories from 8 October. Zenity says one prompt to an exposed AWS AgentCore agent could lead to control of every agent in the same account and region, and AWS disputes it. Claude Code adds an option that blocks an action when a safety hook fails. Cisco Talos finds malware that writes to AI analysts. What each shows, and what it does not.

Gemini for Mac Tests a Hidden “Full Access” Setting

An unreleased "Additional sandbox options" setting found in Google's Gemini desktop app for Mac would let the AI reach files, apps and network connections beyond the folders users connect today. It is hidden, unconfirmed by Google and arrives just as Apple is tightening Full Disk Access.

Post-Quantum Readiness: GAO Finds No Agency Fully Prepared as Chrome and OpenSSH Add Quantum-Safe Tools

A GAO audit found none of 24 major US agencies had fully done three basic steps to prepare for quantum-safe encryption, and only one had a complete inventory of vulnerable systems. The same day, Chrome 155 gave web developers built-in post-quantum algorithms and OpenSSH 10.6 added quantum-resistant login signatures; Surfshark says its WireGuard VPN is now post-quantum for authentication too. What each means, and why quantum-safe website certificates are a separate, later job.

AI Agent Security: Langflow’s Critical Flaw, Copilot’s Encrypted-Instruction Finding and the New Guardrails

A critical Langflow flaw let MCP server settings run any command. Researchers say GitHub's Copilot CLI followed encrypted instructions that it refused in plain text; GitHub says that is not a vulnerability. Meanwhile Atlassian has split its 220+ agent tools into read, write and destructive tiers, and OpenAI has made Codex Auto-review free. What each one confirms.

Anthropic’s Cyber Verification Program: Three Tiers of Looser Guardrails for Vetted Defenders

Anthropic has expanded its Cyber Verification Program into three tiers, Defense, Red Team and Specialized, that relax Claude's cyber safety blocks for vetted security teams on Opus 5.5, Sonnet 5.5 and Mythos 5.1. Specialized applicants are reviewed with the US government. What each tier allows, and what Anthropic's own test shows.

Cyber Breaches: SoftBank Cloud Ransomware, Qilin’s 53 Japanese Victims, Asos’s Bigger Leak and Denmark’s Register

A ransomware attack on SoftBank's IDC Frontier knocked out services for 495 customers, halting Nissui's logistics and Ibaraki's websites. Japan's police say Qilin has hit 53 Japanese firms. MrMax, GMO's infoQ and Nikkei disclosed breaches; Asos says hackers took detailed customer profiles; Oracle Health's count may near 20 million; and Denmark says its population register was looked up for 8.8 million people. What each organisation confirmed.

AI Agent Security: A Hijacked SDK Goes After Agent Keys as Copilot, Bitdefender and Citadel Add Guardrails

A hijacked release of the tensorlake npm package stole tokens and AI-tool config files, and booby-trapped the stolen GitHub token so that revoking it wipes the victim's home folder. The same week, GitHub made local sandboxing for Copilot generally available, Bitdefender released a free agent guard for macOS, and Citadel AI opened early access to agent monitoring. LangChain and past.dev shipped agent tooling with access controls built in. What each one confirms.

Cyber breaches, 8 October: court files, hijacked domains, a patched-but-probed flaw, church records and a $10m reward

Arizona’s courts confirm data on 1.3 million people was copied; ccTLD registry hijacks let attackers obtain certificates for Google and other domains; exploitation attempts follow a public Atlassian PoC; Yoido Full Gospel Church confirms 850,000 members’ data exposed; the Double Counter Discord bot is breached; a MonsterCloud owner is charged; and the US offers $10m for accused HAFNIUM hacker Zhang Yu. Confirmed vs alleged, case by case.

Cyber breaches this week: credential reuse, retail alerts, campus ransomware and edge-gear risk

From FortiBleed credential harvesting and ASOS customer notifications to UIC ransomware, Citrix NetScaler KEV deadlines and a new NetScaler flaw, CVE-2026-107406 (patch out; no known exploitation), Southern Company portal access and Advantest’s delayed PII notices — what is confirmed, what is alleged, and the patterns linking initial access to disclosure timing.

Latest on TSN

Free TSN tools: crypto calculator, Flux dashboard and more.