Cussins Enterprises LLC

Technology is a paint brush on the canvas of life. 
What can we paint for you?

Cybersecurity News

Awareness of what is happening is the 1st to a secure system.

Threat Post

WP HTTP Error: cURL error 52: Empty reply from server

Beeping Computer

https://www.bleepingcomputer.com/feed/ is invalid XML, likely due to invalid characters. XML error: XML_ERR_NAME_REQUIRED at line 1, column 1342

Motherboard

WP HTTP Error: A valid URL was not provided.

Data Breeches

AI breach puts cyber insurance notification rules under scrutiny

On September 25, 2026Source: DataBreaches.NetBy Dissent
Categories: Commentaries and Analyses, Miscellaneous, cyber insurance, cyberinsurance

Roxanne Libatique writes: An OpenAI agent accessed Australian government health data in June 2026. T… Read more

DIVD Dutch Institute for Vulnerability Disclosure investigating agentic AI-powered attack

On September 25, 2026Source: DataBreaches.NetBy Dissent
Categories: Artificial Intelligence, Miscellaneous, Non-U.S.

A Dutch non-profit that has helped so many over the years has discovered it become the victim of wha… Read more

OpenAI agent breached Australian government health website, Albanese says

On September 24, 2026Source: DataBreaches.NetBy Dissent
Categories: Artificial Intelligence, Breach Incidents

Alexander Martin reports: An OpenAI agent gained “unauthorized access” to “non-public files” from an… Read more

Stevens Point servers go offline, city officials not sure if caused by a cyberattack

On September 24, 2026Source: DataBreaches.NetBy Dissent
Categories: Government Sector

Brandi Makuski reports: Stevens Point officials are investigating a possible cyberattack after sever… Read more

Kosovar National Pleads Guilty to Operating Cybercrime Marketplace Offering Tools and Products to Cybercriminals

On September 24, 2026Source: DataBreaches.NetBy Dissent
Categories: Miscellaneous, Rydox

From the DOJ: Ardit Kutleshi, 28, a Kosovar national, pleaded guilty to charges related to his creat… Read more

Two Maryland hospitals still dealing with system issues after cyberattack

On September 24, 2026Source: DataBreaches.NetBy Dissent
Categories: Health Data, Malware, U.S.

On September 22, WYPR reported: Luminis Health says it’s making considerable progress on restoring s… Read more

Wyoming courts investigate extent of personal data exposed in cybersecurity breach

On September 24, 2026Source: DataBreaches.NetBy Dissent
Categories: Government Sector, Hack, Subcontractor, U.S.

Maggie Mullen reports: The Wyoming Judicial Branch says it’s awaiting more details regarding the sco… Read more

Error on North Carolina jury duty website exposed people’s social security numbers, medical records, more

On September 24, 2026Source: DataBreaches.NetBy Dissent
Categories: Exposure, Government Sector, Health Data, U.S., IDOR

Kudos to WBTV for following up on an astute observer’s vulnerability report. David Hodges repo… Read more

FBI Hack Exposed FBI’s Own Hacking Unit

On September 23, 2026Source: DataBreaches.NetBy Dissent
Categories: Government Sector, Hack, Of Note, U.S., FBI, ShinyHunters

Joseph Cox reports: The catastrophic hack of at least thousands of FBI officials’ personal data, inc… Read more

Canva hacked via vendor’s Salesforce instance; Other customers affected as well

On September 23, 2026Source: DataBreaches.NetBy Dissent
Categories: Business Sector, Commentaries and Analyses, Hack, Canny, Canva, Salesforce

A new dedicated leak site by threat actors calling themselves “The Seven Deadly Sins” li… Read more

Cyberscoop

House and Senate members propose legislation for CISA to step up cyber defenses for biotech

On September 24, 2026Source: CyberScoopBy Tim Starks
Categories: Policy, Government, Healthcare, Amgen, biotechnology, Boston Scientific, Congress, critical infrastructure, cyber strategy, Cybersecurity and Infrastructure Security Agency (CISA), Department of Homeland Security (DHS), maggie hassan, National Infrastructure Protection Plan, Ro Khanna, Todd Young

Biotechnology doesn’t have its own critical infrastructure designation, so the bipartisan group of l… Read more

New bill would create federal investigative body for AI-driven hacks 

On September 24, 2026Source: CyberScoopBy djohnson
Categories: AI, Cybersecurity, Government, Policy, Technology, AI hacking, Anthropic, Artificial Intelligence (AI), Congress, legislation, Meta, OpenAI, oversight

A new Democratic bill in Congress would establish a federal Cybersecurity and AI Board of Investigat… Read more

Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ alleges

On September 24, 2026Source: CyberScoopBy Tim Starks
Categories: Government, Privacy, Access Now, cellphones, Department of Defense (DOD), Department of Homeland Security (DHS), Department of Justice (DOJ), Homeland Security Investigations, Oxygen, Russia, Secret Service, U.S. courts

The Justice Department said two leaders of the company have been arrested and face conspiracy to com… Read more

Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks

On September 24, 2026Source: CyberScoopBy Tim Starks
Categories: Exclusive, Government, Threats, Policy, Mark Warner, NTIA, telecommunications, Senate Intelligence Committee, Senate Commerce Committee, standards, Salt Typhoon, Ted Cruz

The legislation from Senate Intelligence Vice-Chairman. Mark Warner, D-Va., and Senate Commerce Chai… Read more

How tax policy can stop threat actors from breaching US water systems

On September 24, 2026Source: CyberScoopBy Greg Otto
Categories: Uncategorized, Commentary, critical infrastructure, op-ed, cybersecurity funding, tax code

New federal programs take years to launch and fund. State and local governments need cybersecurity s… Read more

CISA outlines improvement plan for CVE program

On September 24, 2026Source: CyberScoopBy Tim Starks
Categories: Government, Technology, Threats, Policy, National Institute of Standards and Technology (NIST), CVE, National Vulnerability Database, OWASP, Cybersecurity and Infrastructure Security Agency (CISA), VulnCheck, Chris Butera, Sonatype

The white paper is the latest step in trying to create a “Quality Era” for the Common Vulnerabilitie… Read more

Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack

On September 23, 2026Source: CyberScoopBy Tim Starks
Categories: Government, Threats, Policy, Federal IT, Inspector general, Binding Operational Directive, multi-factor authentication (MFA), Department of Homeland Security (DHS), Cybersecurity and Infrastructure Security Agency (CISA), Cloud, SCuBa

The DHS inspector general said CISA lacks the power to compel agencies to implement its Binding Oper… Read more

Pentagon cyber chief: The demand far exceeds supply

On September 23, 2026Source: CyberScoopBy Greg Otto
Categories: AI, Government, Cyber Command, Department of Defense (DOD), Artificial Intelligence (AI), DefenseTalks

At DefenseTalks on Tuesday, Katie Sutton said the Pentagon now receives far more requests to use cyb… Read more

Ryuk ransomware operator sentenced to 2 years in prison

On September 23, 2026Source: CyberScoopBy Matt Kapko
Categories: Cybersecurity, Ransomware, Cybercrime, Armenia, Ryuk, Department of Justice (DOJ), Ukraine, cybercrime, Russia, ransomware

The Armenian national was extradited from Ukraine to the United States last year and pleaded guilty… Read more

OpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systems 

On September 23, 2026Source: CyberScoopBy djohnson
Categories: Government, Technology, Policy, Geopolitics, Cybersecurity, AI, Russia, critical infrastructure, Ukraine, Sandworm, Artificial Intelligence (AI), OpenAI, Daybreak, Russia-Ukraine War

A Ukrainian official said the government will use the tools to automate cybersecurity functions in c… Read more

Krebs On Security

The Hacker News

Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

On September 25, 2026Source: The Hacker NewsBy

Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million… Read more

Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.  "At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving a limited number of hot wallets," BitGet said in a post shared on X. "Bitget's cold wallets and the overwhelming majority of platform assets remain

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

On September 25, 2026Source: The Hacker NewsBy

The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability… Read more

The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. The issue stems from a preg_replace() backslash

Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data

On September 25, 2026Source: The Hacker NewsBy

A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had… Read more

A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday. The data came from disk space that earlier containers had used and given up, not from any live workload, and an attacker could not choose whose data they got, according to Cloudflare. The company

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

On September 25, 2026Source: The Hacker NewsBy

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical se… Read more

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in  WSO2 API Control Plane,

Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

On September 24, 2026Source: The Hacker NewsBy

A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one th… Read more

A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access, the highest level of control over an Android phone. OnePlus told him the same flaws affect many more of its own devices and those of OPPO, though it has not

ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories

On September 24, 2026Source: The Hacker NewsBy

This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A… Read more

This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked a hundred times before. That is the thread running through the pile. Trusted paths get poisoned. Old bugs find new jobs. AI tools leak more than expected. Fake prompts look real enough. And some attacks barely need an exploit at all — just

Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

On September 24, 2026Source: The Hacker NewsBy

The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serv… Read more

The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users. "third-party[.]com has been a generic documentation placeholder for years, the same role example.com plays," Manifold Security's Head of Research, Ax Sharma, said. "Unlike 'example[.]com,' third-party[.]com

Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

On September 24, 2026Source: The Hacker NewsBy

An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to… Read more

An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic. "When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into the

Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls

On September 24, 2026Source: The Hacker NewsBy

The logistics sector has become the target of a new malicious cyber campaign that distributes an And… Read more

The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM. According to Have I Been Squatted, the campaign uses fake Google Play pages branded as CEVA and TKW Logistics to distribute an Android Package Kit (APK) file that's dressed up as a system service. The delivered app has the package name "com.corp.mdm" Corp MDM

Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore

On September 24, 2026Source: The Hacker NewsBy

AI coding agents are changing how quickly developers can build and ship software as well as how quic… Read more

AI coding agents are changing how quickly developers can build and ship software as well as how quickly credentials can become exposed. According to GitGuardian’s 2026 State of Secrets Sprawl Report, commits identified as AI-assisted are leaking secrets at approximately twice the rate of human-written ones. Most of the fastest-growing categories of leaked credentials are now connected to AI

How Can We Help?

15 + 10 =

Share This