ZeroDay News · Cybersecurity news, CVE tracking and threat intelligence.
About the publication →Wiretapping change sparks big privacy fight in the Golden State
California Governor Gavin Newsom has signed a bipartisan update to the state's wiretapping law, the California Invasion of Privacy Act (CIPA), which will eliminate the ability for private citizens to sue over certain internet-based surveillance. The amendment, known as SB 690, specifically targets the private right to sue websites and mobile applications for unauthorized use of "pen registers"…
Read the brief →
Latest News
view all →
Hackers exploit 32 zero-days on first day of Pwn2Own Ireland
Security researchers collectively uncovered 32 zero-day vulnerabilities on the first day of the Pwn2Own Ireland 2026 competition, earning a total of $388,500. The event, organized by the Zero Day Initiative (ZDI), aims to identify critical flaws in various products before malicious actors can exploit them.

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes
Cybersecurity researchers have uncovered a human-operated phishing platform designed to impersonate advertising portals for popular artificial intelligence (AI) chatbots. The platform specifically targets users by mimicking ad products for services such as Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus. Its primary objective is to capture user credentials and…

Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan
Recent reports indicate the discovery of Linux backdoors actively targeting telecommunications and network appliances within South Korea and Taiwan. These sophisticated backdoors are designed to evade detection by masquerading their malicious traffic as legitimate email services and by impersonating benign system processes. This tactic allows the malware to blend into normal network activity…

Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps
Google has reportedly developed an artificial intelligence agent, named PageBreak, which has identified approximately 500 flaws within Google's own web applications. This development highlights an emerging trend in the cybersecurity industry: the application of AI and deterministic validation methods to automate the discovery of vulnerabilities, assess their exploitability, and provide a…

Former NSA chief Nakasone says agency overhaul is ‘probably needed’
Former National Security Agency Director Paul Nakasone stated that a reported comprehensive reorganization of the agency is likely necessary to address rapidly evolving cyber threats and the competitive landscape in artificial intelligence (AI). Nakasone, who led the NSA and U.S. Cyber Command from 2018 to 2024, made these remarks on Tuesday at VulnCheck's ThreatCon1 conference.

Microsoft extends the Outlook naughty step with two more file types
Microsoft is implementing new security measures for Outlook, adding two file types, .msix and .msixbundle, to its default block list for attachments. These file types are associated with Windows application packages and bundles. The change is set to affect users of the New Outlook for Windows client and Outlook on the Web within Exchange Online.

Mitigate Risks of AI-Generated Apps by Citizen Coders
The increasing use of AI tools by non-technical employees, often referred to as "citizen coders," to develop workplace applications presents significant security and data risks for organizations. While these AI-generated applications can boost productivity and streamline workflows, their rapid creation without proper oversight can lead to "shadow AI" assets with critical vulnerabilities,…

ClickFix Attack Hides VBScript Payload in Browser Cache
A new "ClickFix" social engineering campaign has been identified that leverages browser caches to conceal malicious VBScript payloads. The technique, detailed by Microsoft Threat Intelligence on October 3, involves compromised websites pre-fetching a script disguised as an image into a visitor's browser cache. This allows the payload to be present on the victim's device before they are tricked…

Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root Access
Dell has issued an urgent advisory to customers, recommending they patch a critical vulnerability in its System Update (DSU) tool that could allow attackers to gain root access on affected PowerEdge servers. The flaw, identified as CVE-2026-86360, carries a CVSS score of 9.6, indicating its severe potential impact.
The Briefs
view all →
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure

U.S. Bank CISO says the security role keeps growing and no one can own all of it
Exploited before disclosure
CVE tracker →vulnerabilities were called exploited by a KEV catalogue on or before the day they were published, in the last seven days, across 10 vendors. There was no patch window at all.
- CVE-2026-88779Citrix NetScaler2d before3 of 30.59%
- CVE-2023-54405Unattributedsame day1 of 30.59%
- CVE-2014-125130Unattributedsame day1 of 30.53%
- CVE-2020-37278Unattributedsame day1 of 30.36%
- CVE-2026-104286Fortinet FortiMailsame day3 of 32.2%
- CVE-2024-58388Sharp Corporation Multiple Multifunction Printerssame day1 of 30.81%
- CVE-2026-76504Cisco Catalyst SD-WAN Managersame day3 of 31.8%
- CVE-2026-102489Zammad GmbH Zammadsame day3 of 31.4%
7 more this week in the CVE tracker.
Top Stories
CVE tracker →More Coverage

Citrix NetScaler security snafus get even worse amid more 0-day reports

Rejetto HFS servers now actively scanned for critical RCE flaw

Frontline Education Breach Impacts K-12 School District Staff

Google halts open-source bug bounty program amid AI spam surge

Apple tightens macOS disk access as AI agents become more powerful

doxx.net opens Agentic Defined Networking public beta, raises $38 million

AI slop submissions force Google to freeze its open-source bug bounty

Another OpenAI Safety Expert Quits and Raises New AI Safety Concerns

Three questions a hospital CISO should ask a healthcare fintech vendor

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Keyorix: Open-source secrets management for teams that can’t use SaaS

How RMM abuse gives attackers a way in that looks like business as usual

TTY Logs and the Data it Captures, (Sun, Oct 4th)

Citrix NetScaler Flaw Exploited Before CVE Publication

Citrix patches NetScaler SAML zero-day exploited in attacks

NetScaler CVE-2026-88779 Exploited Before Publication

SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 2

Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 117





