Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland

Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland Source: BleepingComputer ​​​On the second day of Pwn2Own Ireland 2026, security researchers collected $232,500 in cash awards after exploiting 45 unique zero-day vulnerabilities. […] Read original

October 8, 2026 Updated: October 8, 2026 1 min

Hackers exploit critical Atlassian flaw after public PoC release

Hackers exploit critical Atlassian flaw after public PoC release Source: BleepingComputer A critical vulnerability (CVE-2026-21589) affecting multiple Atlassian product families, including Jira, Confluence, and Bitbucket, is being exploited in attacks that do not require authentication. […] Read original

Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details

Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details Source: The Hacker News Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Read original

Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details

Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details Source: The Hacker News Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Read original

Hackers exploit 32 zero-days on first day of Pwn2Own Ireland

Hackers exploit 32 zero-days on first day of Pwn2Own Ireland Source: BleepingComputer On the first day of the Pwn2Own Ireland 2026 competition, security researchers hacked the Samsung Galaxy S26 twice and earned $388,500 after exploiting 32 zero-days. […] Read original

October 6, 2026 Updated: October 8, 2026 1 min

Rejetto HFS servers now actively scanned for critical RCE flaw

Rejetto HFS servers now actively scanned for critical RCE flaw Source: BleepingComputer Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeover, and remote code execution (RCE). […] Read original

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2 Source: The Hacker News Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. “Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinar Read original

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2 Source: The Hacker News Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. “Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinar Read original

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2 Source: The Hacker News Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. “Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinar Read original

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE Source: The Hacker News A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) th Read original