# Today's Top Stories

October 01, 2026

  1. 1
    0
    The Hacker News general Sep 30
    Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

    CVE-2026-88772 (CVSS 9.5), a memory overflow in NetScaler's DTLS protocol handling, has been detailed by researchers and is under active exploitation targeting government, financial services, and technology organizations in North America and Europe. The pre-auth path to shellcode execution makes this critical for any org running Citrix NetScaler ADC or Gateway. Security teams should treat unpatched appliances as actively compromised given weeks of undetected exploitation reported by Mandiant.

  2. 2
    0
    CyberScoop general Sep 29
    Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected

    Mandiant researchers confirmed that dozens of organizations were compromised via a Citrix NetScaler zero-day (CVE-2026-88771/CVE-2026-88772) for at least three weeks before detection, with attacks attributed to advanced and suspected state-sponsored threat groups. Attackers deployed web shells mapped to CSS-like URLs and created superuser accounts for persistent access. Mandiant expects additional exploitation waves as technical details are now public.

  3. 3
    0
    BleepingComputer general Sep 30
    Cisco warns of new SD-WAN zero-day exploited in attacks

    Cisco disclosed and patched a critical zero-day in Catalyst SD-WAN Manager tracked as CVE-2026-76504, which allows unauthenticated remote attackers to invoke the Manager's API with admin privileges — with no available workaround. The flaw is already being actively exploited in the wild, and fixed releases were made available on September 30. Organizations running Cisco SD-WAN infrastructure should prioritize immediate patching.

  4. 4
    0
    The Hacker News general Sep 30
    Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

    Microsoft Security Research confirmed active exploitation of CVE-2026-73570 (CVSS 8.9), an unauthenticated OS command injection flaw in Zimbra Collaboration Suite, enabling attackers to deploy web shells and harvest mailbox authentication data via a single crafted email. The attack requires no user interaction beyond delivery, making it particularly dangerous for organizations running internet-exposed Zimbra instances. Patches are available and should be applied immediately.

  5. 5
    0
    BleepingComputer general Sep 30
    Bitget hacked via zero-day in third-party security products

    Cryptocurrency exchange Bitget disclosed that attackers stole $387.5 million by exploiting a zero-day vulnerability in unspecified third-party security products used in its infrastructure. The breach, revealed on September 30, underscores supply-chain risk in the security tooling layer itself. No CVE or vendor name was disclosed, but the incident is one of the largest crypto exchange hacks of 2026.

  6. 6
    0
    The Hacker News general Sep 29
    New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses

    Researchers from VUSec and Scuola Superiore Sant'Anna disclosed Branch Target Reuse (BTR), a new Spectre-v2 variant that bypasses existing mitigations and leaks Linux kernel memory by exploiting JIT engines in web browsers, language runtimes, and the OS kernel across Intel, AMD, and Arm CPUs. Unlike prior Spectre-v2 variants, BTR targets shared branch target buffers in JIT contexts, making it relevant to any environment running modern browsers or interpreted runtimes on Linux. No patch was immediately available at time of disclosure.

  7. 7
    0
    The Hacker News general Sep 30
    Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

    Mandiant and Google GTIG observed threat actors deploying novel post-exploitation payloads dubbed WHIPSHOT and SLAPSHOT after exploiting the Citrix NetScaler pre-auth flaw against government, financial services, technology, education, and legal organizations in North America and Europe throughout September 2026. The attackers also mapped web shells to CSS-like URLs to evade detection and created superuser accounts. The suspected state-sponsored attribution and breadth of targeted sectors make this a high-priority incident for network defenders.

  8. 8
    0
    CyberScoop general Sep 29
    Alleged ShinyHunters leader arrested in the Netherlands

    Dutch authorities arrested a 24-year-old alleged ShinyHunters leader in Amsterdam — notably one week before the group subsequently hacked the FBI. ShinyHunters has since publicly stated it never intended to release stolen FBI data, signaling the group remains operationally active despite law enforcement pressure. The case represents a significant but incomplete blow to a threat actor responsible for numerous large-scale data breaches.

  9. 9
    0
    SecurityWeek general Sep 30
    Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks

    Russian FSB-linked APT Star Blizzard has adopted a new phishing technique called 'RedFlick' to deploy the CosmicPulse backdoor, replacing its previous ClickFix-style infection chain and expanding targeting to NGOs, think tanks, journalists, and Ukrainian-linked targets in the US and UK. Microsoft observed that the campaign requires only a single victim interaction and relies on sheer volume for success, indicating a shift toward higher-throughput, lower-sophistication lure design. Security teams supporting civil society and government-adjacent organizations should update phishing awareness training accordingly.

  10. 10
    0
    BleepingComputer general Sep 30
    Over 543,000 valid credentials exposed in public GitHub repositories

    Over 543,000 credentials exposed in public GitHub repositories were confirmed still valid as of July 2026, despite GitHub's secret-scanning and push-protection measures. The exposure spans API keys, cloud credentials, and service tokens, representing active risk for any organization whose developers push to public repos. Security teams should audit repositories for leaked secrets and enforce automated secret scanning with mandatory block policies on push.