News thumbnail
Technology / Fri, 09 Oct 2026 LinkedIn

Top level domain theft, Yandex attacked, Cisco Nexus flaws

Major Yandex data center in Russia allegedly hit by Ukrainian droneAccording to Russian state media, the facility was located in Sasovo in Russia's Ryazan region and was shut down following the attack. Yandex is one of Russia's largest internet and cloud computing companies, operating five data centers across the country. "The outage reportedly affected Yandex Cloud, the company's cloud computing platform, disrupting computing resources, networks, data storage, databases, and other services." Cisco warns of critical flaws allowing Nexus switch takeoverFive critical vulnerabilities in Cisco 's NX-OS data center network operating system could be exploited to run arbitrary code with root privileges on Nexus switches, the company says. The issues affect the NX-API, Next Generation OAM (NGOAM), and MPLS OAM features in Nexus 3000 and Nexus 9000 Series switches.

Today on CISO Series...

In todays cybersecurity news...

Attackers hijack three top level domains to obtain Google certificates

Unnamed attackers "compromised three country-code top-level domain (ccTLD) registries and obtained unauthorized HTTPS certificates covering several Google domains and sites belonging to other organizations." The domains in question are .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa), according to Google's Chrome Secure Web and Networking Team. The attackers were able to modify Domain Name System (DNS) records during the hijacks. Certificate Transparency (CT) logs have revealed additional organizations that Google believes were affected, including several leading global brands and widely used online services.

Major Yandex data center in Russia allegedly hit by Ukrainian drone

According to Russian state media, the facility was located in Sasovo in Russia's Ryazan region and was shut down following the attack. No injuries were reported. Yandex is one of Russia's largest internet and cloud computing companies, operating five data centers across the country. "The outage reportedly affected Yandex Cloud, the company's cloud computing platform, disrupting computing resources, networks, data storage, databases, and other services." Yandex representatives acknowledged a power outage at its facility but did not publicly link the disruption to a drone strike.

Cisco warns of critical flaws allowing Nexus switch takeover

Five critical vulnerabilities in Cisco 's NX-OS data center network operating system could be exploited to run arbitrary code with root privileges on Nexus switches, the company says. The issues affect the NX-API, Next Generation OAM (NGOAM), and MPLS OAM features in Nexus 3000 and Nexus 9000 Series switches. A list of the CVE numbered vulnerabilities is available in the show notes to this episode.

CVE-2026-76471, CVE-2026-76485, CVE-2026-76486, CVE-2026-76501, and CVE-2026-76465

Attackers target Atlassian vulnerability shortly after PoC publication

As posted at Security Week, "threat actors have started targeting CVE-2026-21589, a critical vulnerability in Atlassian 's self-hosted Data Center products. The attacks began shortly after technical details went public." The vulnerability, disclosed by Atlassian on October 5, has a CVSS score of 9.3 and affects Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye. Patches have been released for all affected versions. It lets remote, unauthenticated attackers access specific files in the web application's root directory, so long as attackers have "prior knowledge of the target file's exact name and path."

Big thanks to our sponsor, Vanta

Wazza Phishkit targets banking, government, and manufacturing

This new phishkit is targeting banking, manufacturing, and government organizations across the U.S., Europe, and Australia. It uses "a multi-stage routing chain to screen visitors and automated traffic before delivering an Adobe-themed Device Code phishing page." This makes Wazza more than just another malicious URL campaign, since it shows how attackers can "control the path to the final lure, making the initial link less informative and potentially complicating automated detection."

Shai-Hulud worm moves to AI infrastructure with Tensorlake compromise

According to multiple security researchers, this credential-hijacking worm has found its way into a popular AI agent platform, SDK, via an infection in a recent release of the npm package for version 0.5.144 of the platform, manufactured by Tensorlake . SDK is a package that has around 12,000 downloads per week. Analysis of the malicious release suggests "it shares code and techniques with the Shai-Hulud variant dubbed ChainDrop," and is designed to steal credentials including crypto wallets, browser passwords, GitHub Actions secrets, cloud credentials and to also self-propagate. Tensorlake "is a cloud-native platform for running isolated AI agents and untrusted AI-authored code."

Japan sees sharp rise in web data leaks

According to the JPCERT/CC Coordination Center in an alert released yesterday, Thursday, this rash of personal data leaks at Japanese organizations is the result of the abuse of APIs for mobile apps and the targeting of known software flaws. Besides consumer apps, other affected systems include business intelligence (BI) tools and employee-facing management systems. The report only names one product as a known target, being Metabase, a BI tool with a known flaw that attackers have exploited. A link to a detailed report on how this attack unfolded is available in the show notes to this episode.

DOJ charges ransomware recovery CEO for secretly paying hackers

According to the Justice Department, 50-year-old U.S. and Israeli national Zohar Pinhasi owned a company called MonsterCloud that provide incident response to help victims of ransomware attacks, specifically offering to help organizations recover their encrypted data without paying ransomware gangs. This was said to be achieved through "proprietary tools" and "advanced decryption techniques." Except now, the Department of Justice has levelled fraud charges against Pinhasi. Prosecutors said he "simply paid ransoms and charged victims a fee that was significantly more than the original ransom demand. After paying the ransomware gangs, he would get a decryption key and MonsterCloud employees would try to decrypt the organization's files." In total, he allegedly charged clients $19 million and paid about $8 million in ransom payments to cybercriminals. Pinhasi faces up to 20 years if convicted of wire fraud and wire fraud conspiracy.

Subscribe to Cybersecurity Headlines podcast

© All Rights Reserved.