
In today’s cybersecurity news…
Google pauses open-source bug bounties amid AI spam
Google temporarily stopped accepting product vulnerability reports for its Open Source Software Vulnerability Rewards Program after a surge of automated submissions, many of them invalid. The program covers Google-maintained projects like Go, Angular, and Fuchsia, along with critical 3rd-party dependencies. Supply chain reports and reports submitted before October 1st aren’t affected. You can still submit fixes through Patch Rewards, or report qualifying Google Cloud issues through Cloud VRP before a planned update of the program in the first quarter of next year. (BleepingComputer)
Update: Chinese hackers posed as US officials to target AI experts
Proofpoint researchers found China-aligned group TA419 impersonating US policymakers to steal cloud credentials from AI policy experts at think tanks, universities, and law firms. In July, attackers posed as former White House science official Lynne Edwards Parker and economist Heidi Crebo-Rediker, inviting targets to an AI advisory committee or to contribute to a Senate report. After building a relationship, they sent links to fake OneDrive pages that could capture an authenticated session even when the victim completed multifactor authentication. The researchers recommend verifying unexpected outreach through another channel and using passkeys. (Dark Reading)
Ukraine’s largest grocery chain hit by extortion attack
Ukraine’s largest grocery chain, ATB, confirmed a cyberattack after hackers posted a $400,000 extortion demand on its website. The group DataSuckers claimed it stole records for 7.9 million customers and more than 11 million orders, including contact details and password hashes, along with employees’ passport information. ATB denied that customer data was compromised and temporarily took some online services offline. The attackers later posted alleged samples and said they would sell the database. The Record couldn’t independently verify the data or the scale of the claimed breach. ATB operates more than 1,300 stores. (The Record)
Pentagon finally stops using Anthropic
The Pentagon told the BBC it’s stopped using Anthropic’s AI products, months after it designated the company a national security supply chain risk and set a late-August deadline to phase it out. Sources tell the BBC that Claude was still being used as recently as last week for research, intelligence analysis, and military operations against Iran. It was embedded in Palantir’s Maven Smart System. The dispute began when Anthropic refused to remove safeguards over concerns about mass surveillance and autonomous weapons. Anthropic is challenging the designation in court. (BBC)
Huge thanks to our sponsor, Vanta

Meta rushed to fix Muse virtual machine escapes
Meta engineers found serious security flaws in its Muse AI agent shortly before launch, according to internal documents reviewed by 404 Media. At least one could have let a user escape the virtual machine running their agent and reach sensitive internal Meta databases. Teams are said to have worked around the clock on a security push starting August 27th, just 11 days before launch. Meta says it’s strengthened Muse through internal testing, red teaming, and its bug bounty program. Security researcher Patrick Wardle warned that a failure in the virtualization boundary could turn user code into access to production systems. (404 Media)
Exchange flaw exposes other users’ mailboxes
Microsoft released emergency updates for an Exchange Server authorization flaw that lets an authenticated attacker read other users’ email and attachments within the same organization. It doesn’t allow access across tenants. Microsoft has already applied a service-side fix to Exchange Online, so those customers don’t need to act. On-premises administrators should update Exchange Server Subscription Edition RTM, Exchange 2016 CU23, and Exchange 2019 CU14 or CU15. There’s no evidence of exploitation in the wild, but Microsoft says exploitation is more likely. (The Hacker News)
FBI confirms multiple arrests in ShinyHunters investigation
The FBI told The Register that, along with law enforcement partners, it arrested multiple suspects in an investigation into a September cyber incident allegedly involving ShinyHunters. The bureau declined to identify those arrested or comment on the Reuters report that Saif al-Din Khader, known online as Rey, was detained in Jordan and is cooperating with investigators. Dutch police also arrested a 24-year-old alleged ShinyHunters leader last month. The group claimed responsibility for stealing sensitive information from the FBIJobs.gov portal in September. FBI Cyber Division chief Brett Leatherman has urged remaining members to contact the bureau. (The Register)
Another Citrix flaw triggers urgent patch warnings
Citrix says another actively exploited NetScaler flaw can crash appliances and keep services unavailable if triggered repeatedly. It affects some customer-managed deployments using SAML authentication and is separate from the two NetScaler vulnerabilities disclosed last week. Citrix has released updates and temporary mitigations, and says it hasn’t identified an impact on the integrity of customer data. CISA ordered US federal agencies to patch by Wednesday and conduct forensic triage. Citrix credited Bishop Fox and watchTowr with helping identify the issue. Customers reported incidents even on appliances patched for the earlier vulnerabilities. (The Record)