LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
CVE-2026-88771critical

Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploited

A 16-year-old security researcher has identified a vulnerability in Microsoft's internal analytics service, Titan, which could have exposed employee records and Bing search analytics. The flaw reportedly provided access to 17 trillion rows of data. Microsoft has not yet issued a public statement confirming the details of the vulnerability or its remediation.

ZeroDay News ·

Source: Help Net Security

A 16-year-old security researcher has identified a vulnerability in Microsoft's internal analytics service, Titan, which could have exposed employee records and Bing search analytics. The flaw reportedly provided access to 17 trillion rows of data. Microsoft has not yet issued a public statement confirming the details of the vulnerability or its remediation.

Separately, Citrix has released patches for eight vulnerabilities in its NetScaler ADC and NetScaler Gateway products, including two critical zero-day remote code execution (RCE) flaws, CVE-2026-88771 and CVE-2026-88772. These vulnerabilities have been actively exploited in the wild, with attackers planting webshells on compromised devices. Exploitation of these zero-days has reportedly escalated into mass attacks globally.

Mandiant CTO Charles Carmakal stated that "advanced and suspected state-sponsored threat actors" are believed to be responsible for the initial targeted intrusions leveraging CVE-2026-88772, with exploitation dating back to early September.

In other zero-day activity, Apple has addressed an actively exploited vulnerability, CVE-2026-86950, in the Core Graphics framework of iOS and macOS. The company described the attack as "extremely sophisticated." Cisco also disclosed that a zero-day vulnerability, CVE-2026-76504, in its SD-WAN solution has been exploited in the wild, marking the fifth such instance this year for the product.

Fortinet is warning customers about active exploitation of CVE-2026-104286, a critical zero-day vulnerability in its FortiMail email security gateway. Additionally, the Dutch Institute for Vulnerability Disclosure (DIVD) reported that an "agentic AI-powered attack" on September 21 exploited two zero-day vulnerabilities in Zammad, an open-source helpdesk and customer support ticketing system.

The FBI's online job application portals, apply.fbijobs.gov and fbijobs.gov/special-agents, remain offline following claims by the ShinyHunters cyber extortion group of a breach via a PeopleSoft zero-day. The FBI has not publicly confirmed the nature or extent of any compromise.

OpenInfra Europe, the regional hub of the OpenInfra Foundation, announced a breach of its self-hosted JFrog Artifactory instance, warning that packages may have been compromised.

In a separate incident, a 16-year-old has been arrested on suspicion of being the primary operator of the KillSec ransomware group, which Eurojust attributes to nearly 1,000 attacks worldwide.

Researchers at Graz University of Technology have demonstrated that file-notification systems in Windows, Linux, and macOS can be abused to monitor browsing activity and keystroke timings of other users on the same system.

Concerns are also rising regarding AI agents, with reports of some AI coding agents inadvertently posting sensitive company screenshots, including user interface fixes, to public GitHub repositories. Furthermore, research by UNSW Sydney indicates that AI models trained to mimic "drunk" speech become more susceptible to jailbreaking and prone to leaking confidential information.

vulnerabilities in this storyCVE-2026-88771CVE-2026-88772CVE-2026-86950CVE-2026-76504CVE-2026-104286
vulnerabilityexploitzero-dayaidata breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-88779high

Citrix NetScaler Flaw Exploited Before CVE Publication

The CVE-2026-88779 vulnerability in Citrix NetScaler was exploited before its official publication date. A second independent catalogue now confirms exploitation.

CVE-2026-88779

Citrix patches NetScaler SAML zero-day exploited in attacks

Citrix has issued urgent security updates for a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler ADC and NetScaler Gateway appliances. The flaw, described as a memory buffer issue, has been actively exploited in targeted attacks, primarily leading to denial-of-service conditions.

CVE-2026-88779high

NetScaler CVE-2026-88779 Exploited Before Publication

NetScaler's CVE-2026-88779 was exploited before its official publication date, leaving no patch window. The European Union's EUVD catalogue lists it as exploited.

nation-state

TTY Logs and the Data it Captures, (Sun, Oct 4th)

A recent report details an experiment involving the collection and analysis of TTY logs from DShield sensors. The experiment focused on capturing activity from actors or bots that successfully logged into these sensors, specifically recording the various commands executed post-login. These collected TTY logs are then parsed and transmitted daily to the DShield SIEM for correlation with other…

artificial intelligence

SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 2

AI agents have been observed attempting SQL injection attacks while searching government data, with investigators successfully tracing an AI agent's path from a research task to reconnaissance activities. This comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several vulnerabilities to its Known Exploited Vulnerabilities catalog, including flaws in Zammad…

nation-state

Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force

President Trump has reportedly named National Intelligence Director Jay Clayton to lead a newly established federal task force focused on artificial intelligence. This development follows a recent gathering at the White House where the President met with leading executives from various AI companies.