Tuesday, October 6, 2026
Follow on LinkedIn

Cyber Security

Citrix NetScaler SAML 0-Day Vulnerability Actively Exploited in Attacks

Citrix has released emergency security updates for a NetScaler SAML zero-day vulnerability that attackers are actively exploiting. Tracked as CVE-2026-88779, the flaw affects customer-managed NetScaler ADC and NetScaler Gateway appliances and can cause denial of service, disrupting access to...

Cybersecurity Newsletter Bulletin – Pentagon Data Breach, Citrix, Fortimail and Apple 0-days and 20+ stories

This week’s security newsletter was dominated by a Pentagon personnel data breach affecting more than three million people, actively exploited zero-days in Apple CoreGraphics and Fortinet FortiMail, and reports of two still-unpatched Citrix NetScaler RCE flaws. The broader bulletin covers...

South Korean President Orders Full Security Checks After Financial Sector Hacks

South Korean President Lee Jae Myung ordered a thorough investigation on October 4, 2026, after a series of financial sector data breaches exposed customer and worker information. The order comes as investigators examine whether AI tools helped attackers break...

Vercel Confirms KVM Zero-Day VM Escape, Awards Researcher $50,000

Vercel has confirmed a KVM zero-day vulnerability after security researcher Paulos Yibelo reported a full virtual machine escape that, he says, allows code inside a guest to gain root access on the host. https://twitter.com/PaulosYibelo/status/2106378929158135903 The discovery came through the Vercel Sandbox...

ShinyHunters Member Detained in Jordan, Reportedly Helping FBI Identify Fellow Hackers

A suspected ShinyHunters member has been detained in Jordan and is reportedly helping the FBI identify other hackers linked to the group. Reuters reported on October 3 that three people familiar with the matter confirmed the detention of Saif...

Microsoft Pushes New Exchange V2 Update After Discovering New Security Flaw

Microsoft has released September 2026 V2 security updates to fix an Exchange Server flaw that lets authenticated attackers access other users’ mailboxes within the same organization. Tracked as CVE-2026-96940, the vulnerability could expose email messages and attachments, making it...

Critical GitLab AI Gateway Vulnerability Enables Remote Code Execution Attacks

GitLab has released urgent security updates for a critical AI Gateway vulnerability that could allow authenticated attackers to execute commands remotely. Tracked as CVE-2026-90970, the flaw carries a CVSS score of 9.9 and affects self-hosted deployments used to support...

Critical Dell Container Storage Flaws Let Unauthenticated Attackers Gain Full Administrative Control

Dell has released security update DSA-2026-448 to address multiple critical vulnerabilities in its Container Storage Modules, including flaws that could allow unauthenticated remote attackers to take full administrative control of affected storage environments. Organizations using vulnerable Dell CSM deployments should...

Citrix NetScaler Keeps Rebooting Following the 0-Day Patch

Citrix NetScaler customers are reporting repeated appliance reboots after installing build 14.1-73.37, the emergency update released for two zero-day flaws under active attack. The failures appear linked to crafted SAML authentication traffic that crashes the nsaaad service. Citrix says its...

Debian has Patched 1,313 Flaws in Massive Update Leading to DoS and Privilege Escalation Attacks

Debian has released a major Linux kernel security update covering 1,313 CVE entries, addressing flaws that could allow privilege escalation, denial of service, and information leaks. The fixes are available for Debian’s stable release, Trixie, in Linux source package...

Latest News

Latest News