A 16-year-old security researcher has identified a vulnerability in Microsoft's internal analytics service, Titan, which could have exposed employee records and Bing search analytics. The flaw reportedly provided access to 17 trillion rows of data. Microsoft has not yet issued a public statement confirming the details of the vulnerability or its remediation.
Separately, Citrix has released patches for eight vulnerabilities in its NetScaler ADC and NetScaler Gateway products, including two critical zero-day remote code execution (RCE) flaws, CVE-2026-88771 and CVE-2026-88772. These vulnerabilities have been actively exploited in the wild, with attackers planting webshells on compromised devices. Exploitation of these zero-days has reportedly escalated into mass attacks globally.
Mandiant CTO Charles Carmakal stated that "advanced and suspected state-sponsored threat actors" are believed to be responsible for the initial targeted intrusions leveraging CVE-2026-88772, with exploitation dating back to early September.
In other zero-day activity, Apple has addressed an actively exploited vulnerability, CVE-2026-86950, in the Core Graphics framework of iOS and macOS. The company described the attack as "extremely sophisticated." Cisco also disclosed that a zero-day vulnerability, CVE-2026-76504, in its SD-WAN solution has been exploited in the wild, marking the fifth such instance this year for the product.
Fortinet is warning customers about active exploitation of CVE-2026-104286, a critical zero-day vulnerability in its FortiMail email security gateway. Additionally, the Dutch Institute for Vulnerability Disclosure (DIVD) reported that an "agentic AI-powered attack" on September 21 exploited two zero-day vulnerabilities in Zammad, an open-source helpdesk and customer support ticketing system.
The FBI's online job application portals, apply.fbijobs.gov and fbijobs.gov/special-agents, remain offline following claims by the ShinyHunters cyber extortion group of a breach via a PeopleSoft zero-day. The FBI has not publicly confirmed the nature or extent of any compromise.
OpenInfra Europe, the regional hub of the OpenInfra Foundation, announced a breach of its self-hosted JFrog Artifactory instance, warning that packages may have been compromised.
In a separate incident, a 16-year-old has been arrested on suspicion of being the primary operator of the KillSec ransomware group, which Eurojust attributes to nearly 1,000 attacks worldwide.
Researchers at Graz University of Technology have demonstrated that file-notification systems in Windows, Linux, and macOS can be abused to monitor browsing activity and keystroke timings of other users on the same system.
Concerns are also rising regarding AI agents, with reports of some AI coding agents inadvertently posting sensitive company screenshots, including user interface fixes, to public GitHub repositories. Furthermore, research by UNSW Sydney indicates that AI models trained to mimic "drunk" speech become more susceptible to jailbreaking and prone to leaking confidential information.






