📡 Tech & Security Digest — 2026-10-05
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Citrix patches NetScaler SAML zero-day exploited in attacks — Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-da…
- Frontline Education breach exposes school district employee data — Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthori…
- Warlock ransomware breach SharePoint in water, telecom operator attacks — The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting Sha…
- GitLab warns of critical RCE vulnerability in AI Gateway service — GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable i…
- Dell asks admins to patch max severity CSM flaws as soon as possible — Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes…
Hacker News
- Denmark Data Breach Exposes 8.8M People’s Personal Data (246 pts)
- Apple and a Hacker’s Future (81 pts)
- Xray-core concealed a certificate verification bypass vulnerability (83 pts)
- Powerless F1 drivers frustrated by Bahrain F1 software glitch (241 pts)
Krebs on Security
- Two Alleged ‘TeamPCP’ Hackers Arrested in Australia — Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrati…
- Microsoft Plugs Nearly 400 Security Holes — Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including on…
The Hacker News
- Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes — The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Know…
- Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution — Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has c…
- Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks — Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in tar…
- New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline — Citrix has released security updates for a high-severity security flaw in NetScaler ADC and Citrix NetScaler Gateway that has been exploited as part o…
- Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes — Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad …
- Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets — Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according …
- Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager — Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks…
- Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE — A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck.
The vulnerabili…
- CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-…
- Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware — The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and ne…