# Archive

Browse past daily curated stories

Sep 30 Sep 29 Sep 28 Sep 27 Sep 26 Sep 25 Sep 24 Sep 23 Sep 22 Sep 21 Sep 20 Sep 19 Sep 18 Sep 17 Sep 16 Sep 15 Sep 14 Sep 13 Sep 12 Sep 11 Sep 10 Sep 09 Sep 08 Sep 06 Sep 05 Sep 04 Sep 03 Sep 01 Aug 31 Aug 30

Wednesday, September 30, 2026

  1. 1
    0
    BleepingComputer general
    Hackers exploit Citrix NetScaler zero-day to deploy web shells

    Attackers exploited Citrix NetScaler zero-day CVE-2026-88772 to deploy custom web shells and tunneling malware, gaining root access, stealing credentials, and pivoting into internal networks. Mandiant attributed the campaign to advanced, suspected state-sponsored threat actors who operated undetected for at least three weeks across dozens of organizations. US and UK cybersecurity agencies issued joint advisories confirming the exploitation, with Citrix patching eight new vulnerabilities total.

  2. 2
    0
    BleepingComputer general
    Apple patches CoreGraphics zero-day flaw exploited in attacks

    Apple released emergency iOS and macOS security updates patching CVE-2026-86950, an out-of-bounds write flaw in CoreGraphics reported by Meta, being exploited in 'extremely sophisticated' targeted attacks. The zero-day represents an active, weaponized threat against iOS devices requiring immediate patching across enterprise and consumer fleets. Apple's characterization of the attack as extremely sophisticated suggests a high-capability threat actor, potentially a nation-state or commercial spyware vendor.

  3. 3
    0
    BleepingComputer general
    New Spectre v2 attack variant leaks Linux root password hash in minutes

    Researchers from VUSec and Scuola Superiore Sant'Anna disclosed a new Spectre v2 variant called Branch Target Reuse (BTR) that can recover Linux root password hashes on Intel CPUs in 3–5 minutes on average, bypassing existing defenses. The attack targets JIT compilers in web browsers, language runtimes, and the OS kernel, affecting Intel, AMD, and Arm processors. The technique works despite current Spectre v2 mitigations, requiring security teams to evaluate exposure across affected platforms.

  4. 4
    0
    The Hacker News general
    French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks

    An attacker used stolen staff passwords to exfiltrate tax data on hundreds of thousands of French taxpayers and businesses from France's tax administration over a seven-week period in June and July 2026, going completely undetected by both the agency and ANSSI, France's national cybersecurity body. France's ANSSI published a post-incident report characterizing the attack as unsophisticated, attributing success to weak credential controls rather than advanced tradecraft. The incident underscores how basic identity hygiene failures can result in massive data exfiltration even under institutional oversight.

  5. 5
    0
    The Hacker News general
    Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

    Microsoft attributed a campaign using fake event invitations to Russian state actor Star Blizzard, targeting over 100 organizations tied to Ukraine since January 2026, primarily in the US and UK, with at least one confirmed system compromise. The backdoor delivery mechanism relies on victim interaction with phishing lures impersonating legitimate event invites, demonstrating a shift in tactics toward higher-volume, socially engineered operations. The campaign's confirmed victims span government, NGO, and defense-adjacent organizations.

  6. 6
    0
    BleepingComputer general
    FBI tells ShinyHunters members to turn themselves in after recent arrest

    Following Dutch police's arrest of a 24-year-old Amsterdam man identified as an alleged ShinyHunters leader, the FBI publicly warned remaining group members to turn themselves in. The arrest occurred before ShinyHunters reportedly hacked the FBI itself, and the suspect — Pepijn van der Stap, previously convicted in 2023 for hacking and extortion — faces extradition proceedings. The FBI's public call-out is an unusual escalation reflecting the group's increasingly brazen conduct against law enforcement.

  7. 7
    0
    SecurityWeek general
    Pentagon Personnel Agency Data Breach Impacts 3 Million People

    A data breach at the Defense Manpower Data Center (DMDC), the Pentagon agency that maintains personnel records for the entire Department of Defense, has impacted approximately 3 million individuals. The DMDC breach represents a significant national security exposure given the sensitivity of DoD personnel data, which can enable targeted espionage, social engineering, or identification of intelligence personnel. No attribution or breach vector details were publicly disclosed.

  8. 8
    0
    BleepingComputer general
    JadePuffer agentic AI attacks target Azure, destroy cloud resources

    A ransomware operator tracked as JadePuffer is using agentic AI to conduct autonomous attacks against Azure tenants, performing reconnaissance, credential theft, and destructive deletion of cloud storage, applications, and databases in a single campaign. The use of an AI agent framework to drive multi-stage cloud attacks represents an emerging threat pattern where exposed credentials serve as the initial foothold for automated, large-scale cloud resource destruction. Azure administrators should audit service principal permissions and monitor for anomalous bulk-delete API calls.

  9. 9
    0
    The Hacker News general
    Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

    A vulnerability in the official MCP Python SDK allowed malicious MCP servers to intercept OAuth credentials — including client secrets, authorization codes, and PKCE proof keys — by redirecting token exchange requests to an attacker-controlled endpoint. The flaw was patched in MCP Python SDK version 1.30.0 and later, but any application built on earlier versions that connects to untrusted MCP servers may have been exposed. Given the rapid adoption of MCP-based AI tooling in enterprise environments, developers should audit dependencies and upgrade immediately.

  10. 10
    0
    BleepingComputer general
    Misconfigured Supabase apps expose data in over 16,000 databases

    Researchers discovered more than 16,000 misconfigured Supabase database instances exposing publicly readable tables containing PII, plaintext passwords, and authentication tokens. The widespread misconfiguration stems from developers leaving Supabase's row-level security (RLS) disabled or improperly configured, effectively making sensitive backend data accessible without authentication. Organizations using Supabase for application backends should immediately audit RLS policies and restrict public schema access.