# Today's Top Stories
October 01, 2026
-
1The Hacker News general Sep 30Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution
CVE-2026-88772 (CVSS 9.5), a memory overflow in NetScaler's DTLS protocol handling, has been detailed by researchers and is under active exploitation targeting government, financial services, and technology organizations in North America and Europe. The pre-auth path to shellcode execution makes this critical for any org running Citrix NetScaler ADC or Gateway. Security teams should treat unpatched appliances as actively compromised given weeks of undetected exploitation reported by Mandiant.
-
2CyberScoop general Sep 29Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected
Mandiant researchers confirmed that dozens of organizations were compromised via a Citrix NetScaler zero-day (CVE-2026-88771/CVE-2026-88772) for at least three weeks before detection, with attacks attributed to advanced and suspected state-sponsored threat groups. Attackers deployed web shells mapped to CSS-like URLs and created superuser accounts for persistent access. Mandiant expects additional exploitation waves as technical details are now public.
-
3BleepingComputer general Sep 30Cisco warns of new SD-WAN zero-day exploited in attacks
Cisco disclosed and patched a critical zero-day in Catalyst SD-WAN Manager tracked as CVE-2026-76504, which allows unauthenticated remote attackers to invoke the Manager's API with admin privileges — with no available workaround. The flaw is already being actively exploited in the wild, and fixed releases were made available on September 30. Organizations running Cisco SD-WAN infrastructure should prioritize immediate patching.
-
4The Hacker News general Sep 30Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
Microsoft Security Research confirmed active exploitation of CVE-2026-73570 (CVSS 8.9), an unauthenticated OS command injection flaw in Zimbra Collaboration Suite, enabling attackers to deploy web shells and harvest mailbox authentication data via a single crafted email. The attack requires no user interaction beyond delivery, making it particularly dangerous for organizations running internet-exposed Zimbra instances. Patches are available and should be applied immediately.
-
5BleepingComputer general Sep 30Bitget hacked via zero-day in third-party security products
Cryptocurrency exchange Bitget disclosed that attackers stole $387.5 million by exploiting a zero-day vulnerability in unspecified third-party security products used in its infrastructure. The breach, revealed on September 30, underscores supply-chain risk in the security tooling layer itself. No CVE or vendor name was disclosed, but the incident is one of the largest crypto exchange hacks of 2026.
-
ADSponsoredProtect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected → -
6The Hacker News general Sep 29New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses
Researchers from VUSec and Scuola Superiore Sant'Anna disclosed Branch Target Reuse (BTR), a new Spectre-v2 variant that bypasses existing mitigations and leaks Linux kernel memory by exploiting JIT engines in web browsers, language runtimes, and the OS kernel across Intel, AMD, and Arm CPUs. Unlike prior Spectre-v2 variants, BTR targets shared branch target buffers in JIT contexts, making it relevant to any environment running modern browsers or interpreted runtimes on Linux. No patch was immediately available at time of disclosure.
-
7The Hacker News general Sep 30Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT
Mandiant and Google GTIG observed threat actors deploying novel post-exploitation payloads dubbed WHIPSHOT and SLAPSHOT after exploiting the Citrix NetScaler pre-auth flaw against government, financial services, technology, education, and legal organizations in North America and Europe throughout September 2026. The attackers also mapped web shells to CSS-like URLs to evade detection and created superuser accounts. The suspected state-sponsored attribution and breadth of targeted sectors make this a high-priority incident for network defenders.
-
8CyberScoop general Sep 29Alleged ShinyHunters leader arrested in the Netherlands
Dutch authorities arrested a 24-year-old alleged ShinyHunters leader in Amsterdam — notably one week before the group subsequently hacked the FBI. ShinyHunters has since publicly stated it never intended to release stolen FBI data, signaling the group remains operationally active despite law enforcement pressure. The case represents a significant but incomplete blow to a threat actor responsible for numerous large-scale data breaches.
-
9SecurityWeek general Sep 30Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks
Russian FSB-linked APT Star Blizzard has adopted a new phishing technique called 'RedFlick' to deploy the CosmicPulse backdoor, replacing its previous ClickFix-style infection chain and expanding targeting to NGOs, think tanks, journalists, and Ukrainian-linked targets in the US and UK. Microsoft observed that the campaign requires only a single victim interaction and relies on sheer volume for success, indicating a shift toward higher-throughput, lower-sophistication lure design. Security teams supporting civil society and government-adjacent organizations should update phishing awareness training accordingly.
-
10BleepingComputer general Sep 30Over 543,000 valid credentials exposed in public GitHub repositories
Over 543,000 credentials exposed in public GitHub repositories were confirmed still valid as of July 2026, despite GitHub's secret-scanning and push-protection measures. The exposure spans API keys, cloud credentials, and service tokens, representing active risk for any organization whose developers push to public repos. Security teams should audit repositories for leaked secrets and enforce automated secret scanning with mandatory block policies on push.