Close Menu
NCIJ Network NCIJ Network
    What's Hot

    UN says Pentagon plan to livestream execution of Fort Hood shooter would amount to torture – US politics live | Fort Hood shootings

    October 9, 2026

    Robert Jenrick launches scathing broadside against ‘Kensington Kemi’ | Politics

    October 9, 2026

    Dunking on Dating App Profiles Is Content Gold. People Are Getting Sick of It

    October 9, 2026
    Facebook X (Twitter) Instagram
    Trending
    • UN says Pentagon plan to livestream execution of Fort Hood shooter would amount to torture – US politics live | Fort Hood shootings
    • Robert Jenrick launches scathing broadside against ‘Kensington Kemi’ | Politics
    • Dunking on Dating App Profiles Is Content Gold. People Are Getting Sick of It
    • Max severity SonicWall SMA1000 flaw now exploited in attacks
    • ESMA Explores Tokenized Collateral for EU Clearinghouses
    • NASA, Energy Department Advance New Era of Nuclear-Powered Exploration
    • From the workplace to pop culture – why how we view women’s anger is changing
    • A chemical kept fishmeal from catching fire. Then scientists raised cancer concerns
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, October 9
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 Years

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 9, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape.

    This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers stay well-informed about the evolving cybersecurity environment.

    Here are this week’s highlights: 

    PoeLLM malware finds its C&C server hidden in a GitHub poem

    Black Lotus Labs has detailed PoeLLM, a malware active since at least April 2026 that targets exposed AI and open-source services (mainly LiteLLM, Ollama, Gotenberg and Gitea) to mine cryptocurrency and expand its botnet. Infected machines extract four keywords from a poem hosted on GitHub and convert them into the IP address of the current C&C server, so the operator can switch servers by changing those words. The operator, assessed to be Italian-speaking, has updated the poem 11 times.

    Advertisement. Scroll to continue reading.

    GhostAction secret theft spreads to 772 more GitHub repos

    GitGuardian says the GhostAction supply chain campaign pushed its secret-stealing GitHub Actions workflow to 772 public repositories (belonging to 373 users and organizations) between August 31 and September 30, targeting 2,577 secrets such as SSH keys and Azure, AWS and database credentials. Apart from a new exfiltration server, the attacker reused the 2025 playbook, and GitGuardian’s data shows the campaign never really stopped.

    Jury convicts Uranium Finance hacker 

    A jury has convicted Jonathan Spalletta, 36, of Maryland, of computer fraud and money laundering over two 2021 hacks of decentralized crypto exchange Uranium Finance. He abused smart contract flaws to take roughly $1.4 million and then $53.3 million (the second attack forced Uranium to shut down), laundered the funds through a series of crypto transactions that included Tornado Cash, and used them to buy collectibles such as rare Magic: The Gathering and Pokémon cards and antique Roman coins. He faces up to 10 years in prison on the fraud count and 20 years on the money laundering count.

    CISA narrows cyber retention pay

    CISA will keep its Cybersecurity Retention Incentive program (worth up to 25% of base salary) through fiscal 2027, but under new criteria staff must hold an “exceeds expectations” or higher rating and spend at least 51% of their time on cyber duties in one of three job series. Those outside the series who spend 75% or more on cyber work can apply to a review board. The overhaul follows a DHS inspector general finding that the program was mismanaged and applied too broadly.

    Coalition maps out what a CISA directive for federal OT should require

    The Operational Technology Cybersecurity Coalition (OTCC) has published a proposal for a CISA BOD focused solely on OT at federal civilian agencies, which rely on more than 8,000 GSA-managed facilities with HVAC, power management, access control and building automation systems. The group wants the directive to require agencies to designate a senior official or office accountable for OT security, apply relevant existing requirements, and prioritize CISA’s Cybersecurity Performance Goals. 

    Domino’s resets accounts hijacked with recycled passwords

    Domino’s is telling a small number of customers that their accounts were accessed by an unauthorized third party through credential stuffing, using email and password pairs leaked in unrelated breaches. The company says its systems were not compromised and it doesn’t store payment details, but it has reset the affected accounts.

    AI under suspicion as South Korea probes bank cyberattacks

    South Korean President Lee Jae Myung said there are signs that AI was used in some of the recent hacking incidents targeting the country’s banks. Police have reportedly launched a full-scale investigation into the attacks, which led to a breach of customers’ personal information. Authorities have yet to reveal which AI tools were used or the full scale of the breaches. CrowdStrike this week reported finding Claude Code session histories, ARTEX configuration files, and Claude memory files while analyzing the attack infrastructure. The security firm believes with moderate confidence that a Chinese-speaking financially motivated threat actor is likely behind the attacks. 

    Empire Market co-founder gets four decades behind bars

    Raheim Hamilton, 30, of Virginia, has been sentenced to 40 years in prison and fined $5 million after pleading guilty to a drug conspiracy charge over Empire Market, the dark web marketplace he co-created and ran with Thomas Pavey from 2018 to 2020. The site handled more than four million transactions worth over $430 million, mostly drug sales, and also sold stolen credentials and personal information, counterfeit currency and hacking tools. Pavey, who pleaded guilty last year, is scheduled to be sentenced later this month.

    Exposed Nvidia DCGM exporters leak telemetry from 12,000 GPUs

    Researchers have disclosed CVE-2026-47483, a high-severity flaw in Nvidia’s DCGM Exporter GPU monitoring tool. Unauthenticated attackers can flood its profiling endpoints with requests to exhaust resources and crash the service, potentially slowing AI workloads running on the same host. In scans between March and May 2026, the researchers found roughly 2,100 hosts exposing the exporter to the internet without authentication, leaking telemetry from more than 12,000 GPUs. Nvidia has addressed the flaw, and users are advised to update to version 4.8.2 or later.

    Shai-Hulud-style worm slips into Tensorlake’s npm SDK

    Version 0.5.144 of tensorlake, the npm SDK for Tensorlake’s AI agent sandboxes, was compromised to run a credential-stealing worm during installation, in what Socket describes as a ChainDrop/Shai-Hulud supply chain attack. Socket and Sonatype say the malware harvests npm, GitHub, AWS, Kubernetes and Vault credentials, as well as AI coding tool configurations. It can execute code supplied by the attacker and republish itself through other packages the victim can publish.

    Related: In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure

    Related: In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats

    Admin bank Botnet Breaches empire Korean News PoemGuided years
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Max severity SonicWall SMA1000 flaw now exploited in attacks

    Malaysia shuts schools as haze from Indonesian fires chokes Southeast Asia | Climate Crisis News

    Man admits to running network of 15,000 money mules for cybercriminals

    Microsoft: Outdated Windows devices will stop receiving security updates

    FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure Intrusions

    Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT Security

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    UN says Pentagon plan to livestream execution of Fort Hood shooter would amount to torture – US politics live | Fort Hood shootings

    October 9, 2026

    Robert Jenrick launches scathing broadside against ‘Kensington Kemi’ | Politics

    October 9, 2026

    Dunking on Dating App Profiles Is Content Gold. People Are Getting Sick of It

    October 9, 2026

    Max severity SonicWall SMA1000 flaw now exploited in attacks

    October 9, 2026
    Latest Posts

    Reform donor Arron Banks urged to set out extent of surveillance of journalists | Arron Banks

    August 10, 2026

    The Canadian Secessionists Who Love Trump

    August 10, 2026

    How ‘Harry Potter’ Fans Protected Dobby’s Grave From the Path of a U.K.-Ireland Power Line

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    UN says Pentagon plan to livestream execution of Fort Hood shooter would amount to torture – US politics live | Fort Hood shootings

    October 9, 2026

    Robert Jenrick launches scathing broadside against ‘Kensington Kemi’ | Politics

    October 9, 2026

    Dunking on Dating App Profiles Is Content Gold. People Are Getting Sick of It

    October 9, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.