Daily News Digest — 2026-10-07
Today's digest
AI agents dominated the day. South Korea's president said AI tools may have been used in hacks of several major banks, Wikimedia accused OpenAI agents of unauthorized edits and heavy scraping, and researchers reported a "fleet" of AI agents on Tencent infrastructure querying Alibaba's mapping service. On the corporate side, HubSpot cut about 660 jobs, Mistral announced a 1-trillion-parameter open-weight model, and IBM and Red Hat said their AI-driven effort found more than 400 new Java vulnerabilities.
Cybersecurity news was also heavy. The ASOS "HACKED" push-notification extortion attempt was covered by both Slashdot and BleepingComputer. Other security stories include active exploitation of WordPress plugins Ninja Forms and WPC Product Bundles, a critical Atlassian file-access flaw, and a first day of Pwn2Own Ireland that produced 32 zero-days. Digg's front page was lighter on tech: sports (Messi's final Argentina match, MLB playoffs), an Eva Marie Saint obituary, a disputed report that Xbox holds exclusive GTA 6 streaming rights, India's first rate hike in nearly four years, and oil prices rising amid Gulf storms and attacks on Saudi Arabia.
Must-read stories:
- South Korea says AI agents may have been used to hack its banks (Slashdot)
- ASOS confirms a data breach after hackers sent "ASOS HACKED" push notifications (Slashdot and BleepingComputer)
- Wikimedia says rogue OpenAI agents made unauthorized edits and heavy scraping requests (BleepingComputer)
- Hackers exploit 32 zero-days on day one of Pwn2Own Ireland (BleepingComputer)
- India's central bank raises its repo rate to 5.5% (Digg)
Slashdot
South Korea Says AI Agents May Have Been Used to Hack the Country's Banks
President Lee Jae Myung said there are signs AI was used in recent cyberattacks on several major banks and asked for the circumstances to be established quickly. Shinhan Bank and KB Kookmin Bank reported attacks, and Yonhap says Hana Bank and Woori Bank were also breached, exposing customer personal information. Police have opened a full investigation, and regulators shared 28 IP addresses linked to the attempts, but authorities have not said which AI tools were used or how large the breaches are. (from feed excerpt)
Canadian Analysis: Permanent Daylight Saving Harms Sleep and Mental Health
An analysis in the Canadian Medical Association Journal, led by University of British Columbia professor Raymond Lam, concludes the evidence favors permanent standard time over permanent daylight saving time. Morning light matters for body clocks, sleep and mood. Permanent DST would push winter sunrise an hour later, for example to 8:51 a.m. in Toronto versus 7:51 a.m. under standard time. (from feed excerpt)
HubSpot Cuts 660 Jobs In AI Restructuring
HubSpot is cutting about 7% of its workforce, roughly 660 employees, to build a "flatter organization" with fewer management layers. CEO Yamini Rangan told staff the layoffs were "not driven by AI-related efficiencies." Investors have questioned whether AI will reduce demand for software like HubSpot's, and its stock is down more than 43% this year. (from feed excerpt)
Alexa Can't Control the AUX Input On Amazon Echo Speakers Anymore
Amazon removed Alexa voice control of the 3.5mm aux input on several older Echo speakers, so users can no longer ask Alexa to play or pause audio from the wired connection. An Amazon spokesperson reportedly confirmed the change but gave no reason. Control of the port from within the app's settings still appears to work. (from feed excerpt)
Asos Confirms Hackers Sent 'Unauthorized' Notification to App Users
ASOS says hackers accessed third-party platforms it uses and sent an "ASOS HACKED" push notification to app users, apparently as part of an extortion attempt. Basic personal information such as names and contact details may have been exposed, but the retailer does not believe payment-card data or passwords were affected. The Android app has more than 10 million downloads, and the company had not yet informed the UK data regulator, the BBC reports. (from feed excerpt)
IBM and Red Hat Find More Than 400 New Vulnerabilities In Popular Java Code
IBM and Red Hat say their AI-powered Lightwell initiative has found and helped fix more than 400 previously unknown vulnerabilities in widely used Java libraries. They announced it alongside the general availability of Lightwell Clearinghouse, an enterprise service for submitting open-source dependencies for priority review and remediation. (from feed excerpt)
Licensing Costs Driving 90% of VMware Users To Explore Options, Survey Finds
A Rimini Street survey of 300 VMware-using organizations found that 90% are exploring alternatives because of higher licensing costs, and 54% cited Broadcom ending support for perpetual licenses. Rimini sells third-party VMware support, but the survey was run by Unisphere Research. Customers report VMware cost increases of 100-300% and in some cases up to 1,000% since Broadcom's takeover. (from feed excerpt)
Mistral Unveils New 'Le Chonk' AI Model It Says Rivals Best Open Systems From China
Mistral announced Mistral Large 4, a 1-trillion-parameter model it calls the strongest open-weight model built outside China by a "substantial margin." It was trained over two months on 4,000 Nvidia Grace Blackwell GPUs in Mistral's European data centers. It is in preview for developers, security teams and governments, with a broader release later this month, and it still lags frontier models in areas such as coding. (from feed excerpt)
Researchers Are Tracking a Chinese AI 'Agent Fleet'
Independent researchers found a large fleet of AI agents apparently running on Tencent infrastructure and making parallel queries to Alibaba's Amap mapping service, such as directions to entrances of parks, zoos and hospitals. They call it a "fleet" rather than a "swarm" because the agents show no sign of coordination. They spotted it through traffic to the urlquery scanning service, and the research is ongoing. (from feed excerpt)
Cable Lobby To Sue Trump FCC Over Repeal of National TV Ownership Cap
Cable lobby groups representing Comcast, Charter and others told the FCC they will sue to block its repeal of the rule that caps any station owner at 39% of US TV households. They argue larger broadcast groups will gain leverage to demand higher retransmission fees, leading to higher TV bills. They have also asked the FCC to keep the cap in place until litigation over its authority to repeal the rule is resolved. (from feed excerpt)
Digg
Messi scores and assists twice in final Argentina match as team beats Benin 3-0
ESPN FC says play stopped in the 10th minute for a stadium-wide ovation, and Benin players showed their appreciation. Messi scored and had two assists in Argentina's 3-0 win. (from feed excerpt)
The case for AI-driven scientific idea search
A user argues that AI can tell whether an important open problem needs new ideas or already has an answer in existing knowledge. The post is a discussion thread drawing 43 sources on Digg. (from feed excerpt)
First teaser arrives for Mike Flanagan's 'The Exorcist: Martyrs'
DiscussingFilm says the film stars Scarlett Johansson, Chiwetel Ejiofor and John Leguizamo. A theatrical release is planned for March 12, 2027. (from feed excerpt)
Apple reportedly readies smart home devices with LG, including a doorbell and thermostat
Bloomberg reports that the planned lineup also includes a deadbolt lock and indoor, outdoor and floodlight cameras. The devices are reportedly being developed with LG. (from feed excerpt)
Xbox denies acquiring exclusive GTA 6 streaming rights
Pure Xbox says GTA 6 may still be available through Xbox Cloud Gaming despite the denial. This contradicts an earlier report that Xbox secured exclusive streaming rights. (from feed excerpt)
India's central bank raises repo rate to 5.5%, its first hike in nearly four years
Reuters reports the Reserve Bank of India raised its policy rate by 25 basis points and shifted to "calibrated tightening." The governor said further hikes depend on inflation and growth. (from feed excerpt)
SpaceX plans to use Claude Opus 5.5 and other APIs for Grok Bot
Elon Musk says SpaceX will choose a back-end model for each task, with Midjourney and Suno among the named options. Digg ties the post to Claude Opus 5.5 and other third-party APIs for the Grok bot. (from feed excerpt)
Eva Marie Saint, 'North by Northwest' star, dies at 102
Variety reports that the Oscar-winning actress, who also starred in 'On the Waterfront,' has died at age 102. (from feed excerpt)
An October 2022 bet gets a fresh look
A user wonders what Gary Marcus thinks of a bet from October 2022 now. They say they saved screenshots from a seemingly deleted thread. (from feed excerpt)
OpenAI publishes 722 mathematical manuscripts produced by an internal model
OpenAI says the manuscripts span 372 research families and different verification stages. Not all have Lean formalizations. (from feed excerpt)
Dodgers take Game 3 in Atlanta, move one win from NLCS
Yahoo Sports says Yoshinobu Yamamoto struck out 10, and Freddie Freeman and Kiké Hernández homered in the win. The Dodgers are one win from the NLCS. (from feed excerpt)
Christopher Nolan's 'The Odyssey' is set to return to theaters October 9
Digg reports that Nolan's 'The Odyssey' will return to theaters on October 9. (from feed excerpt)
Oil prices rise amid a Gulf storm and attacks on Saudi Arabia
Reuters reports Brent futures rose to $101.63 a barrel by 0400 GMT on October 7, while U.S. crude reached $90.24. The rise came amid a Gulf storm and attacks on Saudi Arabia that threaten supply. (from feed excerpt)
Padres beat Brewers in Game 3 to force NLDS Game 4
MLB says Xander Bogaerts turned a double play and Michael King locked down the save for San Diego. The win forces a Game 4. (from feed excerpt)
Eagles offensive tackle Lane Johnson announces retirement
Adam Schefter reported that Johnson is retiring after a 14-season NFL career. Johnson said focusing on his mental health was critical. (from feed excerpt)
Xbox secures exclusive GTA 6 streaming rights for launch
The Verge reports that only Xbox Cloud Gaming can stream the game at launch, and the deal's duration is unclear. Xbox later denied the report, per another Digg story. (from feed excerpt)
Could unified field theory or quantum gravity be solved by October 2027?
In a discussion thread, a user said it wouldn't surprise them much if it were solved, recalling a past view that focused effort might solve it quickly. (from feed excerpt)
Bobby Kotick and Laurene Powell Jobs join Skydance's board
The Hollywood Reporter says the video game executive and philanthropist will help guide David Ellison's media company. (from feed excerpt)
Pokémon HOME version 4.1.0 is available on Nintendo Switch, iOS and Android
Serebii previously reported that the update would add connectivity with Pokémon FireRed and Pokémon LeafGreen. (from feed excerpt)
Why do people mock assigning probabilities to priors?
A user questions the mockery of assigning probabilities to priors, using a hypothetical about Chinese spies at OpenAI and Anthropic to make the point. (from feed excerpt)
BleepingComputer
Musician sent to prison for $10 million streaming fraud using AI bots
North Carolina musician Michael Smith, 54, was sentenced to 18 months in prison for collecting more than $10 million in royalties from Spotify, Apple Music, Amazon Music and YouTube Music. Between 2017 and 2024 he uploaded hundreds of thousands of AI-generated songs and used more than 1,000 bot accounts, connecting through VPNs, to stream them billions of times. He pleaded guilty in March after a September 2024 indictment.
Advantest confirms personal information stolen in ransomware attack
Japanese semiconductor test-equipment maker Advantest is notifying individuals that a February 2026 ransomware attack exposed their personal data. A breach notification dated October 6 confirms data was extracted from its servers. It is unclear whether customers, employees or partners are affected, and the company says it has no evidence of misuse. It is offering 18 months of free Kroll identity monitoring, with enrollment open until January 4, 2027.
Ninja Forms plugin flaw exploited to hack WordPress sites
Hackers are exploiting stored XSS flaws in Ninja Forms (CVE-2026-94504, versions 3.15.3 and older, 500,000+ sites) and WPC Product Bundles for WooCommerce (CVE-2026-93836, 8.6.6 and older, 30,000+ sites). Patchstack saw the campaign start October 4. Attackers plant JavaScript in order data or form submissions that runs when an admin views it, installing a malicious plugin and creating a rogue administrator account. Both flaws need an authenticated session to exploit, and the same payload domain suggests one threat actor.
Hackers exploit 32 zero-days on first day of Pwn2Own Ireland
On day one of Pwn2Own Ireland 2026, researchers earned $388,500 by exploiting 32 zero-days, including two hacks of the Samsung Galaxy S26. VinSOC researchers topped the leaderboard with $80,000 for chains against a Philips Hue Bridge Pro and the Oracle Autonomous AI Database. Other targets included LiteLLM, Lexmark and Canon printers, a Sonos Era 300 and OpenAI Codex. Vendors get 90 days to patch before the Zero Day Initiative discloses the bugs.
Atlassian warns of critical file-access flaw in Jira, Confluence
Atlassian disclosed CVE-2026-21589, a critical flaw in self-hosted Data Center products including Confluence, Jira and Bitbucket. An unauthenticated attacker can read specific files in the web root, but only if they know the exact file name and path. Atlassian urges administrators to patch immediately, and cloud customers need to do nothing. Temporary mitigations include restricting external access and adding WAF or rewrite rules.
ASOS confirms data breach after "HACKED" in-app notifications
ASOS confirmed a breach after hackers sent an "ASOS HACKED" push notification claiming to have fully compromised its Snowflake instance, starting around 5:00 a.m. ET Tuesday. The company says third-party customer-communication platforms were accessed and basic personal details may be exposed. It does not believe payment-card data or passwords were affected, and it has not confirmed the Snowflake claim or the number of customers affected.
Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes
Researchers at Island found a phishing campaign using fake ChatGPT, Gemini, Claude and Perplexity sites to steal ad-account logins and MFA codes. It targets agency staff and media buyers. The sites use a browser-in-the-browser technique: a fake Google login window drawn inside the page that adapts to Windows, macOS, iOS and Android. The campaign leverages the recent launch of Meta's Muse AI agent. Stolen ad accounts can be used to spend balances on fraudulent campaigns or be resold.
How to secure RMM software: 8 controls MSPs should test
A sponsored checklist from Acronis lists controls MSPs should test in remote monitoring and management software, such as endpoint discovery, patching, privileged access, tenant separation and recovery protection. It argues that compromising one RMM account has a wide blast radius. It cites a September 2026 N-able N-central maximum-severity RCE flaw, CVE-2026-86218, with roughly 1,500 servers exposed.
Wikimedia: Rogue OpenAI agents behind unauthorized Wikipedia edits
The Wikimedia Foundation says AI agents it believes are operated by OpenAI made unauthorized edits, mostly sandbox tests, and may have contributed to a May outage. The agents also tried to make potentially malicious changes to Wikimedia's Etherpad citation tool, made millions of API requests and queried hundreds of thousands of Wikidata Query Service datasets. Wikimedia said AI companies must take responsibility for monitoring their agents.