# Today's Top Stories

October 06, 2026

  1. 1
    0
    CyberScoop general Oct 05
    Citrix discloses third actively exploited NetScaler zero-day in less than a week

    Citrix disclosed a third actively exploited zero-day in NetScaler within a single week, marking an unprecedented concentration of critical vulnerabilities in a widely-deployed network appliance. While vendors characterized this latest defect as lower-impact than the prior pair, three zero-days in rapid succession signals systemic risk for organizations running customer-managed NetScaler deployments. Security teams should audit all NetScaler ADC and Gateway appliances immediately and verify patch status against all three CVEs.

  2. 2
    0
    The Hacker News general Oct 05
    New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

    Citrix patched CVE-2026-88779 (CVSS 8.7), a memory overflow vulnerability in NetScaler ADC and Citrix NetScaler Gateway that enables denial-of-service against SAML-based authentication deployments, with confirmed active exploitation in targeted attacks. The flaw emerged days after two other NetScaler zero-days were patched, suggesting attackers are actively researching the codebase for adjacent weaknesses. Organizations using SAML-authenticated NetScaler deployments are at particular risk and should apply the out-of-band patch immediately.

  3. 3
    0
    The Hacker News general Oct 05
    Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

    CVE-2026-61500 (CVSS 9.3) in Rejetto HTTP File Server is under active exploitation, allowing attackers to predict session-cookie signing keys via a weak PRNG, enabling admin session forgery and remote code execution. VulnCheck confirmed active exploitation attempts, and the flaw was notably discovered by an AI-assisted vulnerability research process. Administrators running Rejetto HFS should patch immediately as internet-wide scanning for this vulnerability is now underway.

  4. 4
    0
    The Hacker News general Oct 05
    Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes

    Microsoft issued an out-of-band patch for CVE-2026-96940 (CVSS 8.8), a high-severity weak authorization flaw in Microsoft Exchange Server that allows authenticated attackers to read other users' mailboxes by escalating privileges. The out-of-band release indicates Microsoft assessed the risk as urgent enough not to wait for the next Patch Tuesday cycle. Exchange administrators should prioritize applying this update, particularly in environments where insider threat or compromised account scenarios are a concern.

  5. 5
    0
    BleepingComputer general Oct 05
    Denmark population registry data breach affects 8.8 million people

    Denmark's Central Population Register (CPR) suffered a data breach exposing personal information of approximately 8.8 million registered individuals — effectively the entire Danish population. The breach represents a catastrophic single-point failure of a national identity registry, with implications for identity fraud and downstream authentication systems that rely on CPR data. Incident details are still emerging as Danish authorities investigate unauthorized access to the register.

  6. 6
    0
    SecurityWeek general Oct 05
    Alleged ShinyHunters Leader Arrested in Jordan

    Saif al-Din Khader, known as 'Rey' and alleged leader of the ShinyHunters threat group, was detained in Jordan and is reportedly cooperating with the FBI to identify and locate other group members. ShinyHunters is responsible for numerous high-profile data breaches affecting hundreds of millions of users across platforms including Ticketmaster and Santander. This arrest and active cooperation could significantly disrupt the group's operations and potentially expose its broader criminal network.

  7. 7
    0
    The Hacker News general Oct 05
    Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

    A new botnet malware called Cling (also tracked as ClingSTUN) is being deployed by exploiting a critical flaw in the Realtek Jungle SDK, using legitimate STUN (Session Traversal Utilities for NAT) servers as a covert command-and-control channel to blend malicious traffic with normal WebRTC/VoIP communications. Nozomi Networks identified that Cling exploits 24 known vulnerabilities across IoT devices for self-propagation and establishes back-connect proxy nodes to obscure attacker infrastructure. The abuse of STUN protocol for C2 presents a detection challenge since STUN traffic is typically permitted through firewalls.

  8. 8
    0
    SecurityWeek general Oct 05
    Senate Passes Bipartisan Bill to Strengthen Healthcare Cybersecurity

    The U.S. Senate passed a bipartisan bill to strengthen healthcare cybersecurity, spurred by data showing over 730 cyber breaches affected more than 270 million Americans last year at an average cost of $10 million per breach. The legislation would mandate security improvements across healthcare providers and is expected to move to the House following Senate passage. For security practitioners in healthcare, the bill signals incoming compliance requirements and potential federal funding for defensive improvements.

  9. 9
    0
    The Record threat-intel Oct 05
    Belarusian hacktivists spent two years inside Russian healthcare network, researchers say

    Russian cybersecurity researchers attributed a covert two-year espionage campaign inside a Russian healthcare network to the Belarusian Cyber Partisans, a hacktivist group typically known for loud, disruptive operations against government and infrastructure targets. The campaign demonstrates that the group possesses sophisticated long-term persistence capabilities beyond their public profile, and highlights the risk of prolonged undetected intrusions in healthcare sector networks. Attribution was made by Russian researchers, adding a cross-border intelligence dimension to an already politically sensitive operation.

  10. 10
    0
    BleepingComputer general Oct 05
    Alleged dev of Ploutus ATM malware appears in US court after arrest

    The alleged developer of Ploutus ATM jackpotting malware appeared in U.S. federal court following arrest, as the DOJ announced charges related to the software used to steal millions of dollars from ATMs across the United States. Ploutus, which originated in Latin America, allows attackers with physical or remote access to ATMs to dispense cash on demand and has been used in attacks against multiple U.S. financial institutions. The arrest represents a significant law enforcement action against ATM malware infrastructure targeting the financial sector.