Severity: HighAction: Be aware

ASOS links data breach to social engineering attack, credential theft

ASOS is sending updates to affected customers about the cybersecurity incident it suffered earlier this week, confirming that hackers accessed some personal data.

Excerpt from the primary source: BleepingComputer

Who is affected

Security professionals

What you should do · Be aware

No immediate action is indicated. Share this with the relevant teams and watch for updates.

Automated guidance based on this story's classification. Check the linked advisories for specifics.

Sources

We link to original and authoritative sources. Headlines and excerpts belong to their publishers.

Original reporting

ASOS links data breach to social engineering attack, credential theft BleepingComputer · bleepingcomputer.com · Oct 8, 2026 · Primary source
Severity: HighAction: Be aware

UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing

Cisco Talos identified an APT spear-phishing campaign against individuals affiliated with Taiwan research organizations. The operation leveraged legitimate public event themes and impersonated reputable academic and policy institutions.

Severity: HighAction: ReviewExploitation: Suspected

Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland

​​​On the second day of Pwn2Own Ireland 2026, security researchers collected $232,500 in cash awards after exploiting 45 unique zero-day vulnerabilities.

Why it matters

There are signs this may already be exploited, which usually shortens the time available to patch.

Severity: HighAction: Be aware

Hackers hijack Google domains after breaching ccTLD registries

Hackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains in the country-code top-level domains (ccTLDs) for Ghana, American Samoa, and Sierra Leone after compromising third-party operators and modifying authoritative DNS records.