Home › Weekly Digests › This Week
LiveThreat Threat Intelligence

Weekly Threat Intelligence Digest — Sep 28 to Oct 05, 2026

Weekly threat intelligence digest from 366 items (59 critical, 235 high).

October 05, 2026 366 articles analyzed
LIVETHREAT WEEKLY THREAT DIGEST September 28 – October 05, 2026 This week’s incidents underscored a growing reality: attackers are bypassing traditional perimeters and striking through trusted third parties that already sit inside the enterprise. From a zero‑day in a crypto‑exchange’s security appliance that siphoned $387 M, to AI‑driven ransomware that erased 100+ Azure resources via stolen service‑principal credentials, the common thread is clear: privileged access—whether granted by a vendor, an API key, or an internal admin account—has become the most valuable attack surface. 👉 Access, not vulnerability, is the primary risk driver 🚨 EXECUTIVE RISK SNAPSHOT * Supply‑chain breach → MSPs, SaaS admin consoles, CI/CD pipelines were the initial footholds in 30+ incidents. * Privileged credential abuse → One hijacked Azure service principal enabled >150 destructive actions across a tenant in minutes. * Blind‑spot assets → OT devices, IoT cameras, and mis‑configured public endpoints remain outside most control inventories, limiting audit visibility. 🔍 WHAT CHANGED THIS WEEK * Third‑party product zero‑days surged – multiple exploits targeted security appliances, ticketing platforms (Zammad), and browser extensions, highlighting vendor‑of‑vendor exposure. * AI agents with elevated rights operated without audit logs, enabling rapid ransomware (JadePuffer) and credential‑theft campaigns. * Phishing and credential‑theft vectors increasingly leveraged stolen API keys for cloud‑infrastructure abuse, expanding the impact radius from a single account to entire multi‑tenant environments. 🎯 WHERE YOU ARE MOST LIKELY EXPOSED * Cloud admin accounts on Azure, AWS, or GCP that use service‑principal keys stored in CI/CD tools. * Vendors that supply security or identity products (e.g., third‑party security appliances, API providers, endpoint security suites). * Legacy SaaS platforms with custom integrations—especially ticketing (Zammad), CRM (CRM Platform), and payment processors. * Mis‑configured public cloud storage or API gateways that expose credentials or data buckets. ⚡ WHAT COMPLIANCE & SECURITY LEADERS SHOULD DO THIS WEEK 1. **Refresh vendor‑risk registers** – Identify any third‑party products that have disclosed zero‑day flaws this week. 👉 Ask: “Can we produce evidence today that we’ve re‑assessed their security posture?” 2. **Audit privileged cloud identities** – Pull logs for all service‑principal and API‑key usage in the past 30 days; flag anomalous geographic or resource‑type activity. 👉 Map to NIST CSF PR.AC‑1 and ISO 27001 A.9.2.3. 3. **Validate patch‑management evidence** – Ensure critical CVEs (e.g., Citrix NetScaler CVE‑2026‑88771/88772, Apple CoreGraphics CVE‑2026‑86950) are documented as remediated in your CMDB. #TrustOperations #NISTCSF #ControlAssurance #Cybersecurity #ThreatIntel #ContinuousMonitoring #LiveThreat #VerisqAI

Articles Referenced in This Digest 366 items

Advisory (40)

CriticalKiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown
CriticalAnjvision YSSD-RTMP-H5
HighCISA Adds Two Known Exploited Vulnerabilities to Catalog
HighCISA Sends Final CIRCIA Rule to White House for Review
HighiPhone 18 Pro Max can’t call or text on AT&T? Apple will replace it for free
HighFTC Probes OpenAI, Anthropic as AI Agent Safety Risks Draw Scrutiny
HighSWIFT Banking & Government Middleware Enables RCE
HighLessons from Microsoft Patch KB5002907: Two Layers of Patch Control in Qualys TruRisk Eliminate
MediumAnthropic asks Claude users to share voice data for AI model training
MediumGoogle Wallet not working on your Pixel? 4 ways to fix tap-to-pay
MediumTrump, Tech Giants Strike Voluntary AI Safety Accord
MediumAfter reports on suicide deaths, Pentagon puts Cyber Command on notice
MediumMicrosoft to block Entra ID script injection attacks starting October
MediumWSL containers are generally available on Windows
MediumEU Cyber Resilience Act requirements for containers and Kubernetes
MediumSignal adds encypted local backup support to iOS, desktop apps
MediumiOS 27.0.1 Is Here: 3 iPhone Problems Apple Just Fixed
InformationalYARA-X 1.21.0 Release, (Sat, Oct 3rd)
InformationalProtected Quick Tunnels: simple accountless authentication for your next dev project
InformationalAndroid 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools
InformationalAndroid 17 makes it harder for spyware to cover its tracks
InformationalSecuring Water and Wastewater Operational Technology Environments
InformationalThe Fine Art of Frustrating the Adversary
InformationalYour iPhone just got a hidden anti-scam upgrade in iOS 27: How to enable it
InformationalopenSUSE Leap adds a new security layer: Immutable mode
LowMicrosoft enables Windows settings backup by default for orgs
InformationalSecurity tools can now scan Claude Enterprise chats and uploads for sensitive data
InformationalSignal brings encrypted local backups to iOS and desktop, adds cross-platform restore
InformationalPost-quantum website certificates from Cloudflare are scheduled for early 2027
InformationalOWASP Noir: Open-source static analysis tool
InformationalMicrosoft is rolling out Linux container support to WSL
InformationalEnforce positive security with Cloudflare Application Profiles
InformationalIs your domain using post-quantum encryption? Now you can see for yourself
InformationalIntroducing Threat Signals: agentic skills for open-source threat intelligence, free for every Cloudflare account
InformationalBuilding a post-quantum certificate authority with Merkle Tree Certificates
InformationalBuilding a certificate authority for the whole Internet
InformationalWindows 11 2026 Update released, here's everything you need to know
LowiOS 27.0.1 released: Apple fixes annoying iPhone 18 Pro restart and freezing issues
InformationalA four-week plan to tackle vendor concentration risk
InformationalIAM for AI agents: A Practical Enterprise Framework

Breach (54)

CriticalDutch Institute for Vulnerability Disclosure Breached via Zammad 0-Days
CriticalCryptohack Roundup: $387M Bitget Hack
CriticalPentagon breach exposes Social Security numbers and military records of millions
CriticalBitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
CriticalDIVD says Zammad zero-days enabled AI-driven network breach
CriticalPentagon personnel database breach exposes personal data of millions
CriticalBitget hacked via zero-day in third-party security products
CriticalBitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M
CriticalBitget resumes Bitcoin withdrawals after $387.5 million crypto heist
HighShinyHunters Suspect “Rey” Detained in Jordan, Reportedly Helping FBI
HighDanish university DTU breach exposes data of up to 200,000 people
HighFrontline Education breach exposes school district employee data
HighJudge dismisses spyware case brought by Salvadoran journalists targeted with Pegasus
HighMicrosoft’s X account hacked in crypto pump-and-dump scheme
HighIranian accused of hacking American universities extradited from Montenegro
HighPentagon breach exposes personal data of more than 3 million people
HighAI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit
HighCyberattack on major Polish invoicing platform exposes customer data
HighMeta AI Shares Seller’s Address: Facebook Marketplace Buyer Shows Up at His Home
HighInternet Society Launches Global Online Trust and Safety Hub as Part of Its Safer Internet Initiative
HighJapanese Car-Sharing Site Times Car Data Breach Affects 6.6M Accounts
HighFBI tells ShinyHunters members to turn themselves in, after arrest of alleged leader
HighMetaMask Security Incident Prompts Exit of Affected Ethereum Validators
HighHackers stole Pentagon personnel records of over 3 million people
HighPoland Probes Hack of Second Health Software Vendor
HighHackers steal protective order and foster care records from Arizona courts
HighMedela - 423,947 breached accounts
HighOpenInfra Europe’s JFrog Artifactory instance breached, packages potentially compromised
HighAI coding agents leaked 13,000 internal company screenshots to public GitHub repos
HighFrench Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks
HighFBI tells ShinyHunters members to turn themselves in after recent arrest
HighOpenAI apologizes for agents breaching Australian government websites without authorization
HighUS Air Force members given over 6 years in prison for cyber theft of more than $2 million
HighOpenAI Apologizes for Hacks on Australian Government Sites
HighJapanese railway operators Keio Corporation and Tokyo Metro disclose security breaches
HighMeta’s Muse sent a Facebook Marketplace buyer to a seller’s home
HighThree Million Affected in Pentagon Personnel Agency Data Breach
HighAutomated AI agent used to breach cybersecurity nonprofit DIVD
HighArizona Supreme Court says hackers stole residents’ personal data
HighRussian pizza chain with 1,500 locations confirms cyberattack following hacker claims
HighAnthropic Declines Australian AI Hearing as OpenAI Agent Breach Faces Scrutiny
HighPreviously Convicted Dutch Hacker Arrested in ShinyHunters Odido Probe
HighJadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack
HighEx-US soldier gets 70 months for role in AT&T, Snowflake data thefts
HighFBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day
HighJADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
HighUS soldier gets 70 months in prison for extorting 10 tech, telecom firms
High80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking
HighOver 16,000 Supabase databases expose PII, passwords, auth tokens
HighTimes Car confirms data breach affecting 6.6 million user accounts
HighFormer US soldier gets nearly six-year sentence for hacking, extorting telecoms
HighCyberattack on Polish medical software provider exposes patient data
HighNearly 400,000 Medicaid Beneficiaries Caught in Medicaid and DC Healthcare Alliance Data Exposure
HighFBI agents’ blood tests and doctors’ notes surface after breach

Ransomware (15)

CriticalSouth Africa Seeks Help After Cyberattack Targets Air Traffic Control
HighSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 117
HighWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
HighWarlock ransomware breach SharePoint in water, telecom operator attacks
High'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries
HighAlleged KillSec Ransomware Mastermind a 16-Year-Old
HighSpain Arrests Teen Suspected of Running KillSec Ransomware
HighWarlock Ransomware Attackers Hit Water and Telecom Operators
HighOperation KillSwitch: Police Dismantle KillSec Ransomware Group
HighWarlock Ransomware Hits Large Spanish, Portuguese Orgs
HighPolice Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers
HighPolice dismantle KillSec ransomware gang allegedly led by 16-year-old
HighWhen the Ransom Note Appears, the Room Splits in Two
HighJadePuffer agentic AI attacks target Azure, destroy cloud resources
HighJapan's Keio confirms ransomware attack disrupted business systems

ThreatIntel (164)

HighHow RMM abuse gives attackers a way in that looks like business as usual
HighSECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 2
HighChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
HighShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members
HighWarlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
HighMI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics
HighGoogle Gemini could soon get full access to your Mac’s files, apps and the web
HighAntino Backdoor Lets China-Linked UAT-11587 Turn Microsoft 365 Into a C2 Channel
HighFake Zoom installer hides macOS backdoor CloudSyncD
HighN0n ransomware: what you need to know
HighBipartisan backlash to ALPRs grows as two high-profile bills are introduced
HighChinese Open-Weight Models Closing In, Anthropic Warns
HighConvincing Free Mobile phishing emails appear after data breach
HighThis new ChatGPT scam tricks you into installing malware – how to spot the trap
High367,000-Ship Study Finds Global GPS Spoofing, Red Sea Activity Before Grounding
HighMalicious Linux Implants Mimic Asian Mail Security Products
HighKiteworks & Citrix Incidents Show Challenges of Zero-Day Response
HighChinese spies impersonate White House, Anthropic figures to phish AI policy experts
HighAI is giving attackers a head start, Microsoft warns
HighAntino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
HighKillSec Ransomware Group Dismantled, 16-Year-Old Suspected Admin Arrested
HighAI agents keep access to company data after their work is done
HighCriminal recruiters want people on your payroll
HighMicrosoft says threat actors are ahead in the early AI race
HighAutonomous AI agents tried to hack US, Canadian government websites
HighShadow AI explained: The work shortcut that could leak your company’s secrets
HighFake xStocks, Pendle, and other sites bait crypto users with rewards votes
HighNew CloudSyncD macOS Backdoor Uses Fake Zoom Installer to Steal Passwords
High16-year-old suspected leader of KillSec ransomware group arrested
HighWordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
HighThe Day-One Hole in Zero Trust Architecture
HighPolice disrupt KillSec ransomware, arrest suspected teenage leader
HighPreparing governments for an era of interconnected cyber risk
HighLosing gamblers pushed to bet more by DraftKings’ AI, report says
HighHallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles
HighMALFEX npm Attack Spreads Windows RAT, Steals Discord and Browser Data
HighScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)
HighShinyHunters suspect arrested, and is now investigated over alleged murder plots
HighMalicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure
HighGoogle says Gemini 4 Argon can find and patch critical software flaws
HighEmployment scam victims tripled at financial firms in 21 countries
HighThe vulnerabilities AI finds are the ones attackers want
HighSome car apps are slipping owners’ data to big tech companies
HighCitrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs
HighOpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates
HighRussian state hackers use new RedFlick technique to push malware
HighMetamask discloses security incident affecting its infrastructure
HighGoogle: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation
HighAutomakers routinely share personally identifiable connected-car data with third parties, report says
HighUS sanctions 10 over ATM malware scheme tied to Tren de Aragua
HighAnthropic Prospectus Reveals Surging Sales, Worsening Losses
HighOpenAI Accuses Moonshot AI of Coordinated Model Distillation
HighYour car’s app could be telling Big Tech who you are and where you go
HighAttackers Abuse ChatGPT Custom GPTs to Deploy a Full-Featured RAT
HighOxygen Forensics, A Russian-run forensics firm spent a decade inside European police departments
HighAmazon Prime Phishing Scam Uses Fake Billing Alert to Steal Logins and Card Details
HighLegit Security launches agentic remediation for open-source dependency vulnerabilities
HighGlobal Group Ransomware Abuses WinMerge to Deploy Encryptor
HighFormer US Air Force members behind million-dollar BEC scheme head to prison
HighUS-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access
HighKnow Your Enemy: Browser-Based Attack Techniques in 2026
HighAttackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
HighAttackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
HighAI's Third Wave: Coworkers Break the Security Model That Worked for Agents
HighOver 543,000 valid credentials exposed in public GitHub repositories
HighRussian FSB-linked hackers scale up phishing attacks against Ukraine supporters
HighMobile malware warning from Ukrainian researchers includes iPhone exploit kit
HighUAE Resists Onslaught of Iranian Cyberattacks
HighChina-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
HighI Want Better Reporting on AI Genie Behavior
HighDutch ShinyHunters Suspect Investigated for Trying to Arrange 2 Murders
HighLLMjacking can run up your business’ AI bill fast – how to stop it
HighMost open critical and high flaws are over 90 days old
HighRussia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor
HighCustom ChatGPTs push ClickFix attacks to deploy RAT malware
HighControversial spyware firm Paragon to go public by end of year
HighGPT-6 Astra Is More Prone to Rogue Supply-Chain Attacks
HighOpenAI Dots Pushes Always-on Agents Into the Enterprise
HighPhishing Abuses RMM Tools for Persistent Access
HighHumans are reviewing Copilot users’ bizarre and abusive image-editing requests
HighFake iPhone Duo preorder scam triggers DarkSword attack
HighGPT-6 Astra and the Supply Chain Attack It Wasn’t Asked to Launch
High24-Year-Old Arrested in Dutch Investigation Into ShinyHunters
HighPhishing Exposure Nears 70% Across Key US Industries. What Should Security Teams Do?
HighHackers Use Hijacked University Emails to Scam Students, Pose as FBI Agent
High'NeedyMantis' Provides Long-Term Access to Compromised Networks
HighSocial Engineering in the Age of Synthetic Media
HighOpenAI’s GPT-6 Astra ran supply chain attacks despite being told not to
HighMalicious Custom GPT on chatgpt.com lures users into installing a RAT
HighDeepfakes become a board priority once an executive falls for one
HighOpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot
HighOpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions
HighDutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation
High101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent
HighVietnamese man charged in $16 million 'pig butchering' crypto scam
HighFormer US Air Force members sent to prison over BEC attacks
HighStar Blizzard refines phishing and malware delivery with the RedFlick technique
High​​Beyond source code: A path to the keys to the kingdom
HighAI Agents Are Becoming Privileged Identities. Is IAM Ready?
HighPro-Russia Hacktivists Increase OT Intrusion Claims Across EU
HighSecuring the keys to the kingdom: Announcing Executive Threat Detection
HighFrom EDU Account Takeover to Job Scam Abuse: West African Fraud Actors Target Universities
HighOperTraitors: How Kubernetes Operators Betray Your Security Posture
HighUsing Device Linking to Eavesdrop on WhatsApp and Signal
HighThe Image That Isn't—Stopping SVG-Borne Attacks
HighStorm-3168, Linked to JADEPUFFER, Abused Stolen Azure Identities
HighAI Accounts Are Becoming the New Target for Infostealers
HighTech Support Scam Kit Uses Google Ads to Deliver Fake Security Alerts
HighFake Email Thread Tricks AI Summarizer Without Hidden Text
HighExclusive: ShinyHunters Says FBI Data Won’t Be Leaked When Ultimatum Ends
HighWeekly Update 523: Live From a Norwegian Fjord
HighChrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions
HighAI Agents Are Privileged Users; Who Is Auditing Their Access?
HighCarbonato Botnet Puts an AI Agent on Hacked Docker Hosts
HighNew Attack Against RSA
HighDutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
High“Drunk” AI is terrible at keeping secrets
HighCarbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent
High⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats
HighRatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
HighHackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
HighDutch police confirm arrest in ShinyHunters hacking investigation
HighNew Mexico jury finds Meta deceived consumers about data privacy practices
HighThe Developer is the New Perimeter: How Supply Chain Attacks Are Becoming Cloud Breaches 
HighNeedyMantis: Unpacking a post-compromise malware family used in targeted operations
HighOpenAI Pauses Top Models as Rogue Agents Target Agencies
HighOpenAI pauses work on top AI models after agent slips past internet controls
MediumWeekly Update 524: Live From Copenhagen
MediumArmadin Targets Autonomous Remediation With $255.5M Series B
MediumRemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail
MediumFollow the thread: a new dashboard to investigate account abuse
MediumAI Agents Attempt SQL Injection While Searching Government Data
MediumUnidentified Flock Cameras in Florida
MediumDeepKeep’s AI Lens flags coding agent data leaks and routes destructive commands for approval
MediumSentinel Envelope Plus adds software protection without source code changes
MediumArmadin raises $255.5 million to expand AI offensive security platform
MediumGoogle Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version
MediumMost organizations need six months or longer to roll out new security controls
MediumReco Lands $55M to Extend AI Governance Into Agents
MediumScans for Wordfence Protected Websites, (Tue, Sep 29th)
MediumLastPass warns employees before they share sensitive data with AI tools
MediumFrom AI Agents to RCE - Building a Vulnerability Research Workflow
MediumCofense Vision Extends Post-Perimeter Phishing Defense to Google Workspace
MediumBeyond Account-Level Risk: An Evidence-to-Action Pipeline for Detecting Fraud Rings
MediumNVIDIA wants AI agent safety enforced in silicon, not left to the agent
MediumOpenAI is preparing “o,” an always-on ChatGPT assistant that could handle email
MediumNvidia Alliance to Tackle Security Across AI Agent Stack
InformationalTTY Logs and the Data it Captures, (Sun, Oct 4th)
InformationalUser Agent Strings Curiosities, (Sun, Oct 4th)
InformationalISC Stormcast For Friday, October 2nd, 2026 https://isc.sans.edu/podcastdetail/10120, (Fri, Oct 2nd)
InformationalInside Gemini 4 Argon, the model Google is testing on its own infrastructure first
InformationalLegit Security extends automated fixes to vulnerable open-source dependencies
InformationalInsights from the 2026 Microsoft Digital Defense Report 
InformationalBlackFog adds prompt protection and governance for agentic AI
Informational8 Top Red Teaming Service Providers for Enterprise Adversary Emulation
InformationalRecorded Future Debuts Autonomous Defense, Built for Machine-Speed Threats
InformationalISC Stormcast For Wednesday, September 30th, 2026 https://isc.sans.edu/podcastdetail/10116, (Wed, Sep 30th)
InformationalPrivate 5G Moves Into Banking at Hana Financial’s 16-Floor Headquarters
InformationalNvidia Launches AI Agent Safety Platform to Prevent Rogue Activities
InformationalCloudflare Announces Public Certificate Authority for the Post-Quantum Web
InformationalISC Stormcast For Monday, September 28th, 2026 https://isc.sans.edu/podcastdetail/10112, (Mon, Sep 28th)
InformationalISC Stormcast For Tuesday, September 29th, 2026 https://isc.sans.edu/podcastdetail/10114, (Tue, Sep 29th)
InformationalRecorded Future Launches MCP, the Intelligence Layer for Agentic Security Operations
InformationalMITRE ATT&CK v19: What's changed, and how EclecticIQ helps you keep up

Vulnerability (93)

CriticalWeek in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploited
CriticalSecurity Affairs newsletter Round 598 by Pierluigi Paganini – INTERNATIONAL EDITION
CriticalCVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed
CriticalU.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog
CriticalA Vulnerability in Fortinet FortiMail Could Allow for Arbitrary Code Execution
CriticalCritical FortiMail zero-day exploited in the wild (CVE-2026-104286)
CriticalDell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
CriticalGitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
Critical[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE
CriticalA Vulnerability in Kiteworks EPG (Email Security Gateway) Could Allow for Arbitrary Code Execution
CriticalBreach Roundup: Cisco SD-WAN Flaw Under Attack
CriticalPublic PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950
CriticalThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
CriticalKiteworks patches max severity code injection vulnerability
CriticalMonta monta.app
CriticalArmatura LLC Armatura One
CriticalWatchGuard fixes critical Fireware OS flaw allowing remote code execution
CriticalAI Agent Chains Zammad Zero-Days To Take Over DIVD Systems in Seconds
CriticalU.S. CISA adds Cisco Catalyst SD-WAN Manager flaw to its Known Exploited Vulnerabilities catalog
CriticalCISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
CriticalWHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaign
CriticalCitrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution
CriticalAttackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT
CriticalCisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
CriticalCISA warns of critical pre-auth RCE flaw in MikroTik RouterOS
CriticalUnsloth Studio Flaw Turns Routine Model Inspection Into Code Execution
CriticalApple Zero-Day Vulnerability Weaponized in Targeted Attacks
CriticalHackers exploit Citrix NetScaler zero-day to deploy web shells
CriticalUpdate your iPhone, iPad, or Mac: Flaw could run attackers’ code
CriticalApple Patches CoreGraphics Zero-Day Linked to Sophisticated Targeted Attacks
CriticalDual NetScaler Zero-Days Trigger Chaos for Citrix Customers
CriticalNetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)
CriticalNew Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses
CriticalKiteworks patches critical flaw, brings customer systems online
CriticalToptech TMS7 and TopHAT
CriticalViidure Dashcam Android Application
CriticalMikroTik RouterOS
CriticalU.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
CriticalExploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway
CriticalMultiple Vulnerabilities in NetScaler ADC and NetScaler Gateway Could Allow for Remote Code Execution
CriticalThreat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild
CriticalCitrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)
CriticalCISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
CriticalCISA orders feds to patch exploited Citrix flaws by Wednesday
CriticalUS, UK warn of exploited Citrix NetScaler zero-day bugs
CriticalHackers Hit NetScaler Zero-Days Before Citrix Patched
CriticalA week in security (September 21 – September 27)
HighCISA Adds One Known Exploited Vulnerability to Catalog
HighCitrix patches NetScaler SAML zero-day exploited in attacks
High[webapps] POMS oretnom23v1.0 - SQLi vulnerabilities
High[webapps] InvoicePlane 1.7.1 - RCE
High[webapps] SuiteCRM 8.10.1 - Authenticated SSRF
High[webapps] Krayin CRM 2.2.4 - IDOR
High[webapps] Food-Ordering 1.0 - LFI
High[webapps] WordPress 7.0.2 - Path Travesal
High[webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write
High[remote] Teltonika_RutOS 00.07.06.21 - command injection
HighZDI-26-751: Microsoft Windows dxgkrnl Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability
HighA Vulnerability in WordPress Could Allow for Remote Code Execution
HighCISA Adds One Known Exploited Vulnerability to Catalog
HighA Vulnerability in Apple Products Could Allow for Arbitrary Code Execution
HighA Vulnerability in Cisco Catalyst SD-WAN Manager Could Allow for Authentication Bypass
HighCato VPN Client: Split-Tunnel and Privilege Escalation (CVE-2026-10739)
HighCISA Malcolm
HighMeari IoT Cloud Platform OpenAPI Service
High[remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE
HighZDI-26-749: WatchGuard FireWare OS samld SAMLSession Deserialization of Untrusted Data Remote Code Execution Vulnerability
HighZDI-26-750: WatchGuard FireWare OS spamd statushdlr Stack-based Buffer Overflow Remote Code Execution Vulnerability
HighNew Cisco SD-WAN zero-day exploited in-the-wild (CVE-2026-76504)
HighApple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
HighCISA Adds One Known Exploited Vulnerability to Catalog  
HighiPhone Security Warning: Apple Says iOS 26 Flaw May Have Been Exploited
HighU.S. CISA adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog
HighOpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted
HighAttackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
HighTeamViewer urges users to patch severe flaws “as soon as possible”
HighUnauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570
HighCISA Adds One Known Exploited Vulnerability to Catalog
HighTeen Hacker Finds Auth Flaw in Microsoft System With 17.3 Trillion Data Rows
HighOfficial MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
HighApple patches CoreGraphics zero-day flaw exploited in attacks
HighNew Spectre v2 attack variant leaks Linux root password hash in minutes
HighLantronix G520 Series Cellular Gateway
HighVIVOTEK Camera Firmware
HighBaicells Nova 430H
HighRoundcube SQL injection CVE-2026-48842 is now being exploited in the wild
HighApple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950), (Mon, Sep 28th)
HighOne Packet Can Crash OT Servers in Industrial Sectors
HighOther users can watch your browsing and time your keystrokes through OS file notifications
HighShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns
MediumJohnson Controls EasyIO Neo Series EC and CW Controllers
MediumABB Protection and Control IED Manager PCM600
MediumJohnson Controls EasyIO Neo Series EC and CW Controllers

Daily breach, advisory, and vulnerability briefs publish every weekday.

View Live Breach Feed ← All Weekly Digests