📡 Tech & Security Digest — 2026-10-06
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Citrix patches NetScaler SAML zero-day exploited in attacks — Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-da…
- New Dell System Update flaw lets hackers gain root privileges — Dell warned customers to patch a critical vulnerability in the System Update (DSU) command-line interface (CLI) deployment tool as soon as possible. […
- Rejetto HFS servers now actively scanned for critical RCE flaw — Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeov…
- Nikkei discloses breaches of employees’ Microsoft, Google email accounts — Over the weekend, Japanese publishing giant Nikkei disclosed that unknown attackers recently breached two employee email accounts and used one to send…
Hacker News
- Apple and a hacker’s future (273 pts)
- Denmark data breach exposes 8.8M people’s personal data (484 pts)
- Linux containers in 500 lines of code (2016) (128 pts)
Krebs on Security
- Two Alleged ‘TeamPCP’ Hackers Arrested in Australia — Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrati…
- Microsoft Plugs Nearly 400 Security Holes — Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including on…
The Hacker News
- Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes — The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Know…
- Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution — Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has c…
- New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline — Citrix has released security updates for a high-severity security flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targe…
- Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes — Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad …
- Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets — Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according …
- Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager — Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks…
- Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2 — Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK…
- Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE — A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck.
The vulnerabili…
- CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-…
- Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users’ Mailboxes — Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escal…