NetScaler zero-days: check for compromise before you patch

Two zero-days, already exploited, patch available Citrix NetScaler appliances are under active attack through two critical vulnerabilities that were exploited in the wild before any patch existed. Citrix disclosed eight vulnerabilities on September 27 in bulletin CTX697096. The two headline flaws, CVE-2026-88771 and CVE-2026-88772, both score 9.5 on the CVSS v4 scale and both lead […]

80,000 organizations had AI logins stolen, and session cookies are the real problem

SOCRadar’s AI Identity Exposure Report, covered by BleepingComputer, puts a number on something security teams have been quietly dreading: infostealer logs now contain employee logins for AI platforms at serious scale. More than a million records tied to AI services span over 80,000 corporate domains. The researchers narrowed that set to 482 major enterprises and […]

CISA flags four actively exploited flaws in WSO2, Adobe Commerce, SharePoint and MikroTik

Four more flaws join the exploit catalog The U.S. Cybersecurity and Infrastructure Security Agency added four vulnerabilities to its Known Exploited Vulnerabilities catalog this week, and all four carry evidence of attacks in the wild rather than a mere proof of concept. Two entries landed on September 24: a critical JWT authentication bypass in WSO2 […]

Google ran a mole inside the TeamPCP supply-chain gang

The inside view of the worst supply-chain spree on record Reporting by WIRED’s Andy Greenberg, picked up by Ars Technica on Saturday, lays out something that sounds like a spy thriller but happened in a group chat: Google’s security subsidiary Mandiant had an undercover analyst inside TeamPCP’s inner circle for most of the hacking group’s […]

Revolut breach shows how a convincing government email can pull passports and transaction history

Revolut has disclosed a data breach with an uncomfortable mechanism: the company itself handed customer data to the attacker. Someone emailed Revolut while impersonating a government agency, the request passed the company’s checks, and out went identity documents, selfies, and complete transaction histories for an undisclosed number of customers. The story broke via BleepingComputer on […]

Cisco firewall manager flaws pulled three hacking groups into the same appliances

Cisco Talos published research this week on three separate hacking groups that broke into customers through two flaws in Cisco Secure Firewall Management Center, the central management server for Cisco firewalls. One group dropped ransomware. Another is tied to Sandworm, the hacking unit linked to Russian military intelligence. The third stole credentials through a web […]

A Stuxnet source reconstruction appeared on GitHub: what it is and is not

A GitHub repository called Sadpainy/Stuxnet surfaced this week claiming a reconstructed source code of Stuxnet, the worm that damaged Iranian centrifuges and effectively invented the category of cyber-physical weapon. It is written in C, targets Windows XP and Windows 7 only, and comes with the usual educational-use disclaimer. It has 69 stars and a single […]

MikroTrick: pre-auth MikroTik takeover chain under active attack

If you run a MikroTik router with SSH exposed to the internet, patch it now, then check it for compromise. CERT Polska disclosed six RouterOS vulnerabilities on September 5, and two of them chain into what the agency calls MikroTrick: an unauthenticated, full administrative takeover of any device whose SSH service is reachable from public […]

Two alleged TeamPCP hackers arrested over the Shai-Hulud supply chain worm

Australian Federal Police arrested two men this week accused of operating as members of TeamPCP, the hacking group behind the Shai-Hulud supply-chain worm that has infected more than 1,000 organizations since December. The AFP statement says the men, from the Western Australian towns of Cottesloe and Mandurah, face 14 charges in a joint operation with […]

AnonyMousKIT Phishing Platform Uses Conversational Voice AI to Unlock Stolen iPhones

Automating the Social Engineering of Device Unlocks Security researchers at SOCRadar have uncovered a sophisticated phishing-as-a-service platform dubbed AnonyMousKIT. Designed specifically to bypass Apple Activation Lock on stolen iOS devices, the kit integrates conversational voice AI agents alongside automated multi-channel messaging to deceive device owners into surrendering their screen passcodes. When an iPhone or iPad […]

Unpatched Flaw in Calix Fiber Gateways Lets Attackers Bypass NAT to Expose Internal Devices

Residential gateways and broadband routers form the first and often only line of defense protecting home and small office networks from direct Internet exposure. Security researchers have disclosed an unpatched vulnerability in widely deployed Calix GS7 XGS (GS5239XG) residential gateways that allows unauthenticated remote attackers on the public Internet to bypass Network Address Translation (NAT) […]

ToxicPanda 2.0 Abuses Android VPN Permissions to Blindside Google Play Protect

The Evolution of a Targeted Banking Trojan Security researchers tracking mobile threats have documented a significant architectural update to ToxicPanda, an Android banking trojan that first surfaced in late 2024. The new variant, labeled ToxicPanda 2.0, has expanded its target list to 349 financial and banking applications across Europe, Latin America, and emerging markets. Beyond […]