# Today's Top Stories

October 02, 2026

  1. 1
    0
    BleepingComputer general Oct 01
    Hackers stole Pentagon personnel records of over 3 million people

    The Pentagon's Defense Manpower Data Center (DMDC) is notifying over 3 million military service members that their personnel records were stolen following a breach of the Pentagon's human resources management system in October 2025. This is one of the largest known breaches of U.S. military personnel data, with serious implications for national security, counterintelligence exposure, and targeted social engineering against active-duty and veteran populations.

  2. 2
    0
    BleepingComputer general Oct 01
    Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

    Fortinet disclosed CVE-2026-104286, a critical zero-day vulnerability in FortiMail that is being actively exploited to execute unauthorized code or commands on unpatched devices. Security teams running FortiMail should treat this as an urgent patch priority given Fortinet appliances' history of being high-value targets in both nation-state and ransomware campaigns.

  3. 3
    0
    The Hacker News general Oct 01
    CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

    CISA added CVE-2026-76504, a CVSS 9.8 authentication bypass in Cisco Catalyst SD-WAN Manager, to its Known Exploited Vulnerabilities catalog after confirmed active exploitation allowing unauthenticated remote attackers to gain administrative access. Organizations using Cisco SD-WAN Manager must apply patches immediately, as there is no available workaround and the flaw exposes network management plane infrastructure.

  4. 4
    0
    The Hacker News general Oct 01
    Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft

    Cryptocurrency exchange Bitget confirmed attackers stole $387.5 million by exploiting a zero-day vulnerability in unnamed third-party security products, with forensic findings attributed to blockchain security firm SlowMist. The incident underscores the systemic risk of supply-chain dependencies in crypto platform security architectures, where a single third-party flaw can enable nine-figure theft.

  5. 5
    0
    BleepingComputer general Oct 01
    Police dismantle KillSec ransomware gang allegedly led by 16-year-old

    International law enforcement executed 'Operation KillSwitch,' seizing KillSec ransomware's data leak site and servers, arresting three individuals including a 16-year-old alleged administrator in Spain, and securing at least 110 terabytes of stolen victim data. KillSec claimed approximately 500 victims over less than two years, operating as a ransomware-as-a-service group, making this takedown a significant disruption to an active extortion ecosystem.

  6. 6
    0
    The Hacker News general Oct 01
    Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

    Threat actors exploited a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-88771 and CVE-2026-88772) across multiple customer environments, deploying web shells mapped to CSS-like URLs and creating superuser accounts to persist access. LevelBlue's THOR team confirmed the activity targeted government and financial sector organizations over a weeks-long campaign, making unpatched NetScaler appliances an active battleground.

  7. 7
    0
    BleepingComputer general Sep 30
    Russian state hackers use new RedFlick technique to push malware

    Russian state actor Star Blizzard has adopted a new malware delivery technique dubbed 'RedFlick' to deploy its CosmicPulse backdoor against Ukrainian-linked NGOs, think tanks, and journalists, moving away from its previous ClickFix-based approach. The tactic shift indicates active operational security adaptation by the FSB-linked group, requiring defenders to update detections beyond prior RedFlick IOCs.

  8. 8
    0
    The Hacker News general Oct 01
    Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path

    Researchers published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics vulnerability Apple disclosed as potentially used in targeted attacks, triggered by a malicious PDF with a crafted embedded font that causes memory corruption on unpatched iPhones and Macs. WhatsApp PDF handling behavior has been identified as a plausible delivery vector, raising urgency for patching across both Apple devices and messaging platform configurations.

  9. 9
    0
    SecurityWeek general Oct 01
    Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure

    CVE-2026-73570, a zero-day vulnerability in Zimbra, was exploited in the wild prior to public disclosure, allowing attackers to remotely inject OS commands via specially crafted emails without requiring user interaction under certain server configurations. Given Zimbra's widespread deployment in government and enterprise email infrastructure, this pre-patch exploitation window represents significant exposure for unpatched organizations.

  10. 10
    0
    The Hacker News general Oct 01
    OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates

    OpenAI identified and disrupted a coordinated 'distillation attack' beginning in early July 2026 that used a novel encryption bypass technique to illicitly extract protected reasoning outputs from its AI models, with the core activity cluster attributed to individuals associated with Beijing-based Moonshot AI. The incident marks a new category of AI-specific attack targeting model intellectual property, with implications for organizations deploying proprietary AI systems.