📡 Tech & Security Digest — 2026-10-10
Curated from Hacker News, security blogs, and tech publications.
Ars Technica
- Trump Mobile hack and apparent lack of FCC authorization raise security alarms — After hack and data breach, senator asks why Trump Mobile lacks some FCC filings. …
BleepingComputer
- Max severity SonicWall SMA1000 flaw now exploited in attacks — Attackers are exploiting a maximum-severity vulnerability in SonicWall SMA1000 appliances (CVE-2026-102255) that was patched on Tuesday, three days ag…
- Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto — Threat actors are exploiting one critical and one medium-severity vulnerability still unpatched in the AhsayCBS backup management platform to deploy w…
- Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland — The Pwn2Own Ireland 2026 hacking contest has concluded, with hackers collecting $1,262,000 in rewards after exploiting 98 zero-day flaws. […]…
- Citrix warns admins to patch new NetScaler RCE flaw immediately — Citrix has warned IT administrators to patch systems immediately against a new critical vulnerability affecting NetScaler ADC networking appliances an…
- FBI disrupts Chinese hacking tools used to breach critical infrastructure — The FBI has seized seven domains used by Chinese state-sponsored hackers known as Flax Typhoon to operate two hacking tools, MicroScan and FishHub, us…
- Cisco warns of critical flaws allowing Nexus switch takeover — Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run …
Hacker News
- `123456’ password used in Danish CPR data breach (107 pts)
- Telegram Desktop vulnerability allowed any user’s file to be stolen (202 pts)
- OpenAI fires three safety researchers for “mishandling research information” (340 pts)
- OpenAI, the Partition Principle, and Mathematics (203 pts)
Krebs on Security
- FBI Arrests Founder of Ransomware Negotiation Firm — Agents with the Federal Bureau of Investigation (FBI) on Thursday arrested the co-founder of a Canadian cybersecurity firm in connection with an inves…
- ShinyHunters Extorted Boeing Spin-off Prior to Arrests — A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group ShinyHunters has been detained and is reportedly cooper…
- Two Alleged ‘TeamPCP’ Hackers Arrested in Australia — Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrati…
- Microsoft Plugs Nearly 400 Security Holes — Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including on…
The Hacker News
- Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments — Citrix has released patches for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code exec…
- Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes — Cybersecurity researchers have disclosed details of a “human-operated phishing platform” that impersonates advertising products for artificial intelli…
- Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2 — Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK…
- Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer — Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote acces…
- Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details — Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensi…
- Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access — Security researchers have published a full working exploit for a pre-authentication remote code execution flaw in AnyDesk Linux that gives a…
- Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) ca…
- Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own — Three research teams broke into Google’s Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fu…
- Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users’ Mailboxes — Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escal…
- Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge — Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deplo…