📡 Tech & Security Digest — 2026-10-07
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Hackers exploit 32 zero-days on first day of Pwn2Own Ireland — On the first day of the Pwn2Own Ireland 2026 competition, security researchers hacked the Samsung Galaxy S26 twice and earned $388,500 after exploitin…
- Atlassian warns of critical file-access flaw in Jira, Confluence — Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple sel…
- Ninja Forms plugin flaw exploited to hack WordPress sites — Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for W…
- Rejetto HFS servers now actively scanned for critical RCE flaw — Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeov…
- ASOS confirms data breach after “HACKED” in-app notifications — UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to h…
- Nikkei discloses breaches of employees’ Microsoft, Google email accounts — Over the weekend, Japanese publishing giant Nikkei disclosed that unknown attackers recently breached two employee email accounts and used one to send…
Hacker News
- Hackers obtain counterfeit TLS certificates for Google and other large services (100 pts)
- South Korea says AI agents appear to have been used to hack the country’s banks (85 pts)
- Penguin Mail – open-source Rust email client for Linux with AI (208 pts)
Krebs on Security
- Two Alleged ‘TeamPCP’ Hackers Arrested in Australia — Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrati…
- Microsoft Plugs Nearly 400 Security Holes — Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including on…
The Hacker News
- Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes — The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Know…
- New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline — Citrix has released security updates for a high-severity security flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targe…
- Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes — Cybersecurity researchers have disclosed details of a “human-operated phishing platform” that impersonates advertising products for artificial intelli…
- Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes — Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad …
- Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets — Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according …
- Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager — Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks…
- Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2 — Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK…
- Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE — A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck.
The vulnerabili…
- CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-…
- Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details — Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensi…