LIVE · cybersecurity feed
Live wire
CVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-DayClingSTUN Malware Turns IoT Devices Into Proxy NodesCVE-2026-61500 · Rejetto HFS servers now actively scanned for critical RCE flawCVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

ZeroDay News · Cybersecurity news, CVE tracking and threat intelligence.

About the publication →
patch

Wiretapping change sparks big privacy fight in the Golden State

California Governor Gavin Newsom has signed a bipartisan update to the state's wiretapping law, the California Invasion of Privacy Act (CIPA), which will eliminate the ability for private citizens to sue over certain internet-based surveillance. The amendment, known as SB 690, specifically targets the private right to sue websites and mobile applications for unauthorized use of "pen registers"…

Read the brief →

Latest News

view all →
zero-day

Hackers exploit 32 zero-days on first day of Pwn2Own Ireland

Security researchers collectively uncovered 32 zero-day vulnerabilities on the first day of the Pwn2Own Ireland 2026 competition, earning a total of $388,500. The event, organized by the Zero Day Initiative (ZDI), aims to identify critical flaws in various products before malicious actors can exploit them.

phishing

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

Cybersecurity researchers have uncovered a human-operated phishing platform designed to impersonate advertising portals for popular artificial intelligence (AI) chatbots. The platform specifically targets users by mimicking ad products for services such as Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus. Its primary objective is to capture user credentials and…

security

Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan

Recent reports indicate the discovery of Linux backdoors actively targeting telecommunications and network appliances within South Korea and Taiwan. These sophisticated backdoors are designed to evade detection by masquerading their malicious traffic as legitimate email services and by impersonating benign system processes. This tactic allows the malware to blend into normal network activity…

vulnerability

Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps

Google has reportedly developed an artificial intelligence agent, named PageBreak, which has identified approximately 500 flaws within Google's own web applications. This development highlights an emerging trend in the cybersecurity industry: the application of AI and deterministic validation methods to automate the discovery of vulnerabilities, assess their exploitability, and provide a…

ai

Former NSA chief Nakasone says agency overhaul is ‘probably needed’

Former National Security Agency Director Paul Nakasone stated that a reported comprehensive reorganization of the agency is likely necessary to address rapidly evolving cyber threats and the competitive landscape in artificial intelligence (AI). Nakasone, who led the NSA and U.S. Cyber Command from 2018 to 2024, made these remarks on Tuesday at VulnCheck's ThreatCon1 conference.

security

Microsoft extends the Outlook naughty step with two more file types

Microsoft is implementing new security measures for Outlook, adding two file types, .msix and .msixbundle, to its default block list for attachments. These file types are associated with Windows application packages and bundles. The change is set to affect users of the New Outlook for Windows client and Outlook on the Web within Exchange Online.

ai

Mitigate Risks of AI-Generated Apps by Citizen Coders

The increasing use of AI tools by non-technical employees, often referred to as "citizen coders," to develop workplace applications presents significant security and data risks for organizations. While these AI-generated applications can boost productivity and streamline workflows, their rapid creation without proper oversight can lead to "shadow AI" assets with critical vulnerabilities,…

patch

ClickFix Attack Hides VBScript Payload in Browser Cache

A new "ClickFix" social engineering campaign has been identified that leverages browser caches to conceal malicious VBScript payloads. The technique, detailed by Microsoft Threat Intelligence on October 3, involves compromised websites pre-fetching a script disguised as an image into a visitor's browser cache. This allows the payload to be present on the victim's device before they are tricked…

CVE-2026-86360 · ·critical

Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root Access

Dell has issued an urgent advisory to customers, recommending they patch a critical vulnerability in its System Update (DSU) tool that could allow attackers to gain root access on affected PowerEdge servers. The flaw, identified as CVE-2026-86360, carries a CVSS score of 9.6, indicating its severe potential impact.

The Briefs

view all →

Exploited before disclosure

CVE tracker →

7 more this week in the CVE tracker.

Top Stories

CVE tracker →

More Coverage

01
CVE-2026-88779

Citrix NetScaler security snafus get even worse amid more 0-day reports

02
CVE-2026-61500critical

Rejetto HFS servers now actively scanned for critical RCE flaw

03
breach

Frontline Education Breach Impacts K-12 School District Staff

04
vulnerability

Google halts open-source bug bounty program amid AI spam surge

05
ai

Apple tightens macOS disk access as AI agents become more powerful

06
nation-state

doxx.net opens Agentic Defined Networking public beta, raises $38 million

07
vulnerability

AI slop submissions force Google to freeze its open-source bug bounty

08
nation-state

Another OpenAI Safety Expert Quits and Raises New AI Safety Concerns

09
patch

Three questions a hospital CISO should ask a healthcare fintech vendor

10
CVE-2026-88779

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

11
cloud

Keyorix: Open-source secrets management for teams that can’t use SaaS

12
security

How RMM abuse gives attackers a way in that looks like business as usual

13
nation-state

TTY Logs and the Data it Captures, (Sun, Oct 4th)

14
CVE-2026-88779high

Citrix NetScaler Flaw Exploited Before CVE Publication

15
CVE-2026-88779

Citrix patches NetScaler SAML zero-day exploited in attacks

16
CVE-2026-88779high

NetScaler CVE-2026-88779 Exploited Before Publication

17
artificial intelligence

SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 2

18
nation-state

Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force

19
malware

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 117

20
security

ShinyHunters Suspect Detained in Jordan Helps FBI Track Down the Group

Browse the full archive

All published stories →