📡 Tech & Security Digest — 2026-10-02
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Fortinet warns of critical FortiMail flaw exploited in zero-day attacks — Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks …
- DIVD says Zammad zero-days enabled AI-driven network breach — The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnera…
- Cisco warns of new SD-WAN zero-day exploited in attacks — Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively …
- Microsoft says threat actors are ahead in the early AI race — Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerab…
- Kiteworks patches max severity code injection vulnerability — Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting i…
- Russian state hackers use new RedFlick technique to push malware — The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed “RedFlick” to deploy its signature CosmicPulse backdoor….
Hacker News
Krebs on Security
- Two Alleged ‘TeamPCP’ Hackers Arrested in Australia — Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrati…
- Microsoft Plugs Nearly 400 Security Holes — Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including on…
The Hacker News
- Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes — The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Know…
- Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution — Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has c…
- Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks — Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in tar…
- Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets — Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according …
- Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager — Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks…
- Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells — Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors…
- CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-…
- Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path — Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in …
- Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks — Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a tec…
- Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M — The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security prod…