📡 Tech & Security Digest — 2026-10-03
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Frontline Education breach exposes school district employee data — Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthori…
- Fortinet warns of critical FortiMail flaw exploited in zero-day attacks — Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks …
- Warlock ransomware breach SharePoint in water, telecom operator attacks — The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting Sha…
- Microsoft says threat actors are ahead in the early AI race — Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerab…
- Kiteworks patches max severity code injection vulnerability — Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting i…
- GitLab warns of critical RCE vulnerability in AI Gateway service — GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable i…
- Dell asks admins to patch max severity CSM flaws as soon as possible — Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes…
Hacker News
Krebs on Security
- Two Alleged ‘TeamPCP’ Hackers Arrested in Australia — Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrati…
- Microsoft Plugs Nearly 400 Security Holes — Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including on…
The Hacker News
- Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes — The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Know…
- Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution — Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has c…
- Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks — Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in tar…
- Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes — Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad …
- Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets — Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according …
- Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager — Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks…
- Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells — Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors…
- CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-…
- Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path — Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in …
- Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks — Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a tec…