# Today's Top Stories
October 07, 2026
-
1Ars Technica Security general Oct 06Hackers obtain counterfeit TLS certificates for Google and other large services
Attackers compromised three domain registries to obtain counterfeit TLS certificates for Google and other major services, enabling potential man-in-the-middle attacks against encrypted traffic. This represents a fundamental PKI trust failure, as fraudulent certificates issued through legitimate CA infrastructure can bypass standard certificate validation and browser warnings.
-
2SecurityWeek general Oct 05Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier
Citrix confirmed a new zero-day, CVE-2026-88779, was being actively exploited on NetScaler appliances just days after two other actively exploited flaws were patched, suggesting attackers are chaining or rapidly pivoting to new vulnerabilities in the same product line. The US and Australia issued warnings, and security teams managing customer-facing NetScaler deployments should treat this as an emergency patching priority.
-
3The Hacker News general Oct 06Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
A critical unauthenticated file-read vulnerability, CVE-2026-21589 (CVSS 9.3), affects eight Atlassian Data Center products including Confluence, Jira, and Bitbucket, disclosed October 5. Unauthenticated attackers who know a file's exact path can read arbitrary files from the web application root, posing significant risks to self-hosted enterprise deployments that often store sensitive configuration data.
-
4SecurityWeek general Oct 068.8 Million Impacted by Data Breach at Denmark’s Central Person Register
Denmark's Central Person Register (CPR) was breached via a private company's lawful API access, exposing names, addresses, and national ID numbers for all 8.8 million registered citizens — living and dead. The attack vector of abusing legitimate third-party data access rights rather than exploiting a technical flaw makes this particularly difficult to prevent through conventional controls.
-
5CyberScoop general Oct 06Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks
The FBI and Secret Service issued a joint advisory that FortiBleed, a Fortinet vulnerability uncovered earlier this summer, remains an active exploitation campaign capable of locking out users and serving as a ransomware delivery mechanism. Security teams running unpatched Fortinet products should treat this as an ongoing incident-response priority rather than a routine patch cycle item.
-
ADSponsoredPenetration Testing
Comprehensive security assessments by certified professionals. Find vulnerabilities before attackers do.
Learn More → -
6BleepingComputer general Oct 06Hackers exploit 32 zero-days on first day of Pwn2Own Ireland
On day one of Pwn2Own Ireland 2026, security researchers exploited 32 zero-day vulnerabilities and earned $388,500 in prizes, successfully hacking the Samsung Galaxy S26 twice. The breadth of zero-days demonstrated in a single day underscores the attack surface present in modern consumer devices and the value of competitive vulnerability research for improving platform security.
-
7The Hacker News general Oct 06FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach
The FBI terminated its contract with Accenture after an Accenture contractor's failure to apply a security patch allowed the ShinyHunters threat group to breach bureau systems and steal personal data belonging to thousands of FBI employees. A suspected ShinyHunters member, Saif al-Din Khader, has reportedly been detained in Jordan and is cooperating with FBI investigators.
-
8The Hacker News general Oct 06ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits
Microsoft Threat Intelligence documented a new ClickFix variant that pre-fetches malicious JavaScript payloads into the browser cache disguised as PNG files on compromised websites, bypassing Windows execution warnings that typically appear when running remotely-fetched scripts. A related campaign tracked by CERT-UA compromised over 100 Ukrainian websites to deliver the Lunex infostealer via fake Cloudflare verification pages using this technique.
-
9SecurityWeek general Oct 07Personal Information for Over 1 Million People Stolen in a Cyberattack on Arizona’s Court System
Arizona's Supreme Court disclosed a cyberattack that resulted in the theft of personal information for over one million individuals, with records dating back as far as 30 years. The breach of a judicial system represents a high-value target for threat actors seeking sensitive legal records, case histories, and personally identifiable information on a large population.
-
10SecurityWeek general Oct 06FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware
The FBI arrested Canelon Aguirre, alleged developer of the Ploutus ATM jackpotting malware and a leader in Tren de Aragua's ATM fraud operations, who had been on the FBI's Top 10 Most Wanted list since March 2026 — the first cybercriminal ever added to that list. Ploutus is a sophisticated ATM malware family that has been used to steal millions of dollars from financial institutions across Latin America and beyond.