📡 Tech & Security Digest — 2026-10-09
Curated from Hacker News, security blogs, and tech publications.
Ars Technica
- Trump Mobile hack and apparent lack of FCC authorization raise security alarms — After hack and data breach, senator asks why Trump Mobile lacks some FCC filings. …
BleepingComputer
- Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland — On the second day of Pwn2Own Ireland 2026, security researchers collected $232,500 in cash awards after exploiting 45 unique zero-day vulnerabiliti…
- Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland — The Pwn2Own Ireland 2026 hacking contest has concluded, with hackers collecting $1,262,000 in rewards after exploiting 98 zero-day flaws. […]…
- OAuth grants pile up faster than you can review them. Here’s how to keep up. — OAuth grants create data highways between SaaS apps, AI agents, and other tools. And, they are multiplying faster than any security team can review th…
- ASOS links data breach to social engineering attack, credential theft — ASOS is sending updates to affected customers about the cybersecurity incident it suffered earlier this week, confirming that hackers accessed some pe…
- Citrix warns admins to patch new NetScaler RCE flaw immediately — Citrix has warned IT administrators to patch systems immediately against a new critical vulnerability affecting NetScaler ADC networking appliances an…
- FBI disrupts Chinese hacking tools used to breach critical infrastructure — The FBI has seized seven domains used by Chinese state-sponsored hackers known as Flax Typhoon to operate two hacking tools, MicroScan and FishHub, us…
- Cisco warns of critical flaws allowing Nexus switch takeover — Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run …
Hacker News
- OpenAI withdraws three mathematical results (329 pts)
- OpenAI, the Partition Principle, and Mathematics (138 pts)
- OpenAI annualised revenues $20B less than previously signalled (402 pts)
Krebs on Security
- ShinyHunters Extorted Boeing Spin-off Prior to Arrests — A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group ShinyHunters has been detained and is reportedly cooper…
- Two Alleged ‘TeamPCP’ Hackers Arrested in Australia — Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrati…
- Microsoft Plugs Nearly 400 Security Holes — Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including on…
The Hacker News
- New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline — Citrix has released security updates for a high-severity security flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targe…
- Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments — Citrix has released patches for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code exec…
- Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes — Cybersecurity researchers have disclosed details of a “human-operated phishing platform” that impersonates advertising products for artificial intelli…
- Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2 — Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK…
- Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE — A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck.
The vulnerabili…
- Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer — Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote acces…
- Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details — Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensi…
- Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own — Three research teams broke into Google’s Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fu…
- Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users’ Mailboxes — Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escal…
- Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware — The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and ne…