Urgent.News

What's breaking now, across thousands of outlets.

Tech

Three citeable security samples from Time Signals

Three items taken from pages that already return full HTML on Time Signals . Not a “trending” listicle — each row is a canonical URL plus the primary sources you should open. Written in early October 2026; always re-check the live page. 1. Bitget large theft — multi-source incident page EN: https://timeline.snamibo.com/en/incidents/f11786d0fea34650d0d29088406aa47f/ ZH:…

1. Bitget, a cryptocurrency exchange, suffered a multi-million dollar theft. The incident, reported on October 3, 2026, involved attackers exploiting third-party security products to steal $387 million from the exchange. The breach also involved North Korea, as reported in both English and Chinese versions of the timeline page. Evidence of the theft can be found at https://rekt.news/bitget-rekt and on X at https://x.com/TheBlockCo/status/2104585324362084504.

Additional information on the theft can be found at https://blocksec.com/blog/bitget-387m-off-chain-breach and https://www.chainalysis.com/blog/387m-bitget-theft-2026/.

2. The Technical University of Denmark (DTU) was targeted by attackers who gained access to its identity and access management system. The attackers downloaded a large amount of data, potentially exposing up to 200,000 users. The attack occurred on October 3, 2026, as evidenced by the timestamp on the BleepingComputer brief. The full report can be accessed at https://timeline.snamibo.com/en/briefs/febb6546f603e94a39df4d2991005671/.

3. A vulnerability in GoAnywhere MFT, a file management system, was exploited in a recent incident. The vulnerability, CVE-2025-10035, allowed for deserialization issues and possible command injection through forged license response signature forgery. The remediation text references vendor mitigations and BOD 22-01, with a due date of October 20, 2025.

The full incident report can be found at https://timeline.snamibo.com/en/incidents/e46990710227cb3ae67f463feb468a48/. Additional information on the vulnerability can be found on the CISA known exploited vulnerabilities catalog at https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-10035.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

How we built a verifiable public intelligence timeline

Exchange hacks, CISA Known Exploited entries, sudden QDII subscription reopenings — the primary sources are scattered. Another paraphrasing portal is easy to ship.

  • Time Signals presents facts without JavaScript, linking to public sources
  • Snamibo owns Time Signals and Colorful Toolhub projects
  • Incident pages feature consolidated evidence tables for comprehensive perspective

How to Set Up Graftcode's AI Coding Rules in Any IDE

Coding assistants are becoming important in development workflows. Developers use tools like Claude Code, Cursor, GitHub Copilot, and Windsurf to generate code and automate tasks that are often…

  • Graftcode simplifies backend function calls in any IDE.
  • Install Graftcode rules once per project for coding agents.
  • Set up Graftcode Gateway locally to expose modules.

Keep the original text when a PDF page falls back to OCR

A PDF extraction failure becomes harder to investigate when the fallback result replaces the first output. You eventually have readable text, but cannot tell which page needed help or where the…

  • Each result kept separate to examine extraction without altering visible wording
  • Missing Unicode mapping removed 56 Chinese characters from extraction output
  • Keeping separate page records preserved distinction without OCR scheduler

The best engineer on my team ships the least code.

The best engineer on my team almost got a bad review last quarter for shipping too little code. I'm not being cute. I pulled the numbers before his review because I knew the numbers were going to be…

  • Engineers evaluated based on code output, not true value
  • Cheap code production masks scarce review skills
  • Review process fails to capture prevention-focused engineers

Feature Flag SDK Design for Multi-Language Consistency and Performance

You see inconsistent experiment numbers, customers who get different behavior on mobile vs server, and alerts that point to "the flag" — but not which SDK made the wrong call.

  • Enforce deterministic evaluation with canonical JSON and SHA-256 hash function
  • Optimize initialization with non-blocking default path and blocking option
  • Implement reliable updates via streaming with SSE and resilient reconnection

More from Monday 5 October →