# Archive
Browse past daily curated stories
Tuesday, September 29, 2026
-
1The Hacker News generalCISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
CISA added two critical Citrix NetScaler ADC and Gateway vulnerabilities — CVE-2026-88771 (CVSS 9.5, improper input validation allowing unauthenticated remote exploitation) and CVE-2026-88772 — to its Known Exploited Vulnerabilities catalog following confirmed active exploitation globally. Security admins were already pulling NetScaler systems offline over the weekend before official advisories from CISA, the UK, and the Netherlands confirmed the threat. Federal agencies face a Wednesday patching deadline under BOD 22-01.
-
2SecurityWeek generalCitrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug
Citrix officially confirmed and released patches for two NetScaler zero-days tracked as CVE-2026-88771 and CVE-2026-88772, which were being actively exploited before patches were available — prompting some administrators to preemptively take systems offline. The delayed official response, with incident responders warning of exploitation on Saturday before Citrix confirmed eight new vulnerabilities, underscores the persistent targeting of NetScaler Gateway products by threat actors.
-
3Krebs on Security threat-intelDutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
Dutch police arrested a 23-year-old convicted cybercriminal in Amsterdam suspected of supporting the ShinyHunters hacking group's data theft and extortion operations. Following the arrest, remaining ShinyHunters members escalated attacks dramatically — breaching the FBI's jobs site and attempting to extort the Russian ransomware group Cl0p — in what analysts describe as a reckless ego-driven campaign rather than financially motivated crime.
-
4The Record threat-intelShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns
Mandiant (Google) warned that ShinyHunters is actively exploiting workarounds for a vulnerability in Oracle PeopleSoft (CVE-2026-35273), with the group modifying its exploit techniques in a fresh campaign. This comes as ShinyHunters simultaneously escalated other attacks following the Dutch arrest of a suspected member, making the group one of the most active and volatile threat actors currently tracked.
-
5The Hacker News generalBitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M
Cryptocurrency exchange Bitget lost approximately $388 million on September 24, 2026, after an attacker exploited a vulnerability in an unnamed third-party security product to obtain high-level internal credentials, which were then used to issue fraudulent withdrawal commands to Bitget's wallet system. The breach represents one of the largest single crypto exchange thefts on record; Bitget has since resumed Bitcoin withdrawals, with North Korean hackers suspected.
-
6The Hacker News generalJADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
Microsoft-tracked threat actor JADEPUFFER (Storm-3168) conducted a destructive Azure attack in early June 2026, using compromised service principals to delete cloud-based storage, applications, and databases over approximately 18 hours. The agentic attack methodology — involving automated reconnaissance, credential theft, and resource destruction — represents an evolution in cloud-targeting TTPs that security teams must account for in Azure IAM and monitoring configurations.
-
7SecurityWeek generalPrison Sentence for Former US Soldier Who Hacked AT&T and Verizon
Former U.S. Army soldier Cameron John Wagenius was sentenced to 70 months (nearly six years) in federal prison for hacking and extorting at least 10 technology and telecommunications companies, including AT&T and Verizon, between April 2023 and December 2024. The case illustrates the insider threat posed by military personnel with technical access and the long-term legal consequences of telecom-sector cybercrime.
-
8Schneier on Security threat-intelNew Attack Against RSA
Bruce Schneier clarified that a newly reported RSA attack is not novel — the underlying research dates to 2007 — and that the new implementation only enables signature forgery against unpadded, unformatted RSA signatures, not private key recovery. Practitioners should note this does not threaten properly implemented RSA with PKCS#1 or PSS padding, but it may affect legacy or non-standard deployments.
-
9The Hacker News generalCarbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent
The Carbonato botnet targets exposed Docker daemons to deploy the open-source Hermes Agent AI framework, overwriting its SOUL.md persona file with a 39-line malicious prompt that executes commands received via Telegram and harvests AI API keys from compromised hosts. ThreatDown researchers identified this novel abuse of an AI agent framework as a threat to cloud-exposed Docker environments, particularly those holding valuable AI service credentials.
-
10The Hacker News generalApple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
Apple patched CVE-2026-86950, an out-of-bounds write vulnerability in the CoreGraphics component affecting older versions of iOS, iPadOS, and macOS, which the company said may have been exploited in targeted attacks. The flaw allows arbitrary code execution when processing a maliciously crafted file, making prompt patching critical for organizations running legacy Apple OS versions.