# Archive
Browse past daily curated stories
Wednesday, September 30, 2026
-
1BleepingComputer generalHackers exploit Citrix NetScaler zero-day to deploy web shells
Attackers exploited Citrix NetScaler zero-day CVE-2026-88772 to deploy custom web shells and tunneling malware, gaining root access, stealing credentials, and pivoting into internal networks. Mandiant attributed the campaign to advanced, suspected state-sponsored threat actors who operated undetected for at least three weeks across dozens of organizations. US and UK cybersecurity agencies issued joint advisories confirming the exploitation, with Citrix patching eight new vulnerabilities total.
-
2BleepingComputer generalApple patches CoreGraphics zero-day flaw exploited in attacks
Apple released emergency iOS and macOS security updates patching CVE-2026-86950, an out-of-bounds write flaw in CoreGraphics reported by Meta, being exploited in 'extremely sophisticated' targeted attacks. The zero-day represents an active, weaponized threat against iOS devices requiring immediate patching across enterprise and consumer fleets. Apple's characterization of the attack as extremely sophisticated suggests a high-capability threat actor, potentially a nation-state or commercial spyware vendor.
-
3BleepingComputer generalNew Spectre v2 attack variant leaks Linux root password hash in minutes
Researchers from VUSec and Scuola Superiore Sant'Anna disclosed a new Spectre v2 variant called Branch Target Reuse (BTR) that can recover Linux root password hashes on Intel CPUs in 3–5 minutes on average, bypassing existing defenses. The attack targets JIT compilers in web browsers, language runtimes, and the OS kernel, affecting Intel, AMD, and Arm processors. The technique works despite current Spectre v2 mitigations, requiring security teams to evaluate exposure across affected platforms.
-
4The Hacker News generalFrench Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks
An attacker used stolen staff passwords to exfiltrate tax data on hundreds of thousands of French taxpayers and businesses from France's tax administration over a seven-week period in June and July 2026, going completely undetected by both the agency and ANSSI, France's national cybersecurity body. France's ANSSI published a post-incident report characterizing the attack as unsophisticated, attributing success to weak credential controls rather than advanced tradecraft. The incident underscores how basic identity hygiene failures can result in massive data exfiltration even under institutional oversight.
-
5The Hacker News generalRussia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor
Microsoft attributed a campaign using fake event invitations to Russian state actor Star Blizzard, targeting over 100 organizations tied to Ukraine since January 2026, primarily in the US and UK, with at least one confirmed system compromise. The backdoor delivery mechanism relies on victim interaction with phishing lures impersonating legitimate event invites, demonstrating a shift in tactics toward higher-volume, socially engineered operations. The campaign's confirmed victims span government, NGO, and defense-adjacent organizations.
-
6BleepingComputer generalFBI tells ShinyHunters members to turn themselves in after recent arrest
Following Dutch police's arrest of a 24-year-old Amsterdam man identified as an alleged ShinyHunters leader, the FBI publicly warned remaining group members to turn themselves in. The arrest occurred before ShinyHunters reportedly hacked the FBI itself, and the suspect — Pepijn van der Stap, previously convicted in 2023 for hacking and extortion — faces extradition proceedings. The FBI's public call-out is an unusual escalation reflecting the group's increasingly brazen conduct against law enforcement.
-
7SecurityWeek generalPentagon Personnel Agency Data Breach Impacts 3 Million People
A data breach at the Defense Manpower Data Center (DMDC), the Pentagon agency that maintains personnel records for the entire Department of Defense, has impacted approximately 3 million individuals. The DMDC breach represents a significant national security exposure given the sensitivity of DoD personnel data, which can enable targeted espionage, social engineering, or identification of intelligence personnel. No attribution or breach vector details were publicly disclosed.
-
8BleepingComputer generalJadePuffer agentic AI attacks target Azure, destroy cloud resources
A ransomware operator tracked as JadePuffer is using agentic AI to conduct autonomous attacks against Azure tenants, performing reconnaissance, credential theft, and destructive deletion of cloud storage, applications, and databases in a single campaign. The use of an AI agent framework to drive multi-stage cloud attacks represents an emerging threat pattern where exposed credentials serve as the initial foothold for automated, large-scale cloud resource destruction. Azure administrators should audit service principal permissions and monitor for anomalous bulk-delete API calls.
-
9The Hacker News generalOfficial MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
A vulnerability in the official MCP Python SDK allowed malicious MCP servers to intercept OAuth credentials — including client secrets, authorization codes, and PKCE proof keys — by redirecting token exchange requests to an attacker-controlled endpoint. The flaw was patched in MCP Python SDK version 1.30.0 and later, but any application built on earlier versions that connects to untrusted MCP servers may have been exposed. Given the rapid adoption of MCP-based AI tooling in enterprise environments, developers should audit dependencies and upgrade immediately.
-
10BleepingComputer generalMisconfigured Supabase apps expose data in over 16,000 databases
Researchers discovered more than 16,000 misconfigured Supabase database instances exposing publicly readable tables containing PII, plaintext passwords, and authentication tokens. The widespread misconfiguration stems from developers leaving Supabase's row-level security (RLS) disabled or improperly configured, effectively making sensitive backend data accessible without authentication. Organizations using Supabase for application backends should immediately audit RLS policies and restrict public schema access.