LIVE · cybersecurity feed
Live wire
CVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-DayClingSTUN Malware Turns IoT Devices Into Proxy NodesCVE-2026-61500 · Rejetto HFS servers now actively scanned for critical RCE flawCVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

patch news

306 stories · page 1 of 7
patch

Wiretapping change sparks big privacy fight in the Golden State

California Governor Gavin Newsom has signed a bipartisan update to the state's wiretapping law, the California Invasion of Privacy Act (CIPA), which will eliminate the ability for private citizens to sue over certain internet-based surveillance. The amendment, known as SB 690, specifically targets the private right to sue websites and mobile applications for unauthorized use of "pen registers"…

patch

ClickFix Attack Hides VBScript Payload in Browser Cache

A new "ClickFix" social engineering campaign has been identified that leverages browser caches to conceal malicious VBScript payloads. The technique, detailed by Microsoft Threat Intelligence on October 3, involves compromised websites pre-fetching a script disguised as an image into a visitor's browser cache. This allows the payload to be present on the victim's device before they are tricked…

CVE-2026-86360critical

Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root Access

Dell has issued an urgent advisory to customers, recommending they patch a critical vulnerability in its System Update (DSU) tool that could allow attackers to gain root access on affected PowerEdge servers. The flaw, identified as CVE-2026-86360, carries a CVSS score of 9.6, indicating its severe potential impact.

breach

FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

The U.S. Federal Bureau of Investigation (FBI) has reportedly removed an Accenture contractor following an alleged security failure that contributed to a data breach attributed to the ShinyHunters threat group. This incident is said to have resulted in the theft of personal details belonging to thousands of FBI employees. The reported cause of the breach was a patch failure.

malware

ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure

Fortinet's FortiGuard Labs has detailed a new Linux backdoor, dubbed ClingSTUN, which leverages legitimate public Session Traversal Utilities for NAT (STUN) infrastructure to mask its command and control (C2) communications. The malware primarily targets unpatched Internet of Things (IoT) devices, functioning as a back-connect proxy that turns compromised systems into remotely controlled nodes.

patch

Three questions a hospital CISO should ask a healthcare fintech vendor

A cybersecurity expert has outlined key questions hospital CISOs should pose to healthcare fintech vendors to assess their security posture, particularly concerning patient data and financial transactions. Drew McCombs, who holds both CTO and CISO roles at Cylerity, emphasizes that security should be an integral part of development processes, not an afterthought, especially when patient data…

CVE-2026-88779

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix has confirmed the active exploitation of a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler appliances. This new flaw reportedly emerged and was exploited just days after the company released patches for two other previously exploited vulnerabilities in the same product line.

CVE-2026-88779

Citrix patches NetScaler SAML zero-day exploited in attacks

Citrix has issued urgent security updates for a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler ADC and NetScaler Gateway appliances. The flaw, described as a memory buffer issue, has been actively exploited in targeted attacks, primarily leading to denial-of-service conditions.

patch

Weekly Update 524: Live From Copenhagen

This week saw reports of two arrests linked to the ShinyHunters cybercrime group. The individuals, identified as Pepijn and Saif, were reportedly apprehended in the Netherlands. The arrests mark a significant development in the ongoing efforts to disrupt the activities of the ShinyHunters group, which has been associated with numerous high-profile data breaches and cyberattacks.

vulnerability

YARA-X 1.21.0 Release, (Sat, Oct 3rd)

The YARA-X project has announced the release of version 1.21.0, which includes five new improvements and four bug fixes. The update was made available on Saturday, October 3rd.

vulnerabilitycritical

Fortra Patches Critical Vulnerabilities in BoKS

Fortra has released patches addressing critical vulnerabilities within its BoKS product line. The reported flaws collectively present a significant security risk, potentially enabling attackers to bypass authentication mechanisms, execute arbitrary shell commands, and trigger memory corruption issues. These vulnerabilities underscore the ongoing challenges in securing privileged access…

CVE-2026-90970critical

CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed

GitLab has released patches for a critical vulnerability in its AI Gateway, identified as CVE-2026-90970, which could enable an authenticated user to execute arbitrary commands on self-hosted gateway instances. The flaw, which carries a CVSS score of 9.9, was publicly disclosed by GitLab on October 2, 2026.

vulnerabilitycritical

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

GitLab has issued a patch for a critical vulnerability in its AI Gateway, which could allow a logged-in user to execute arbitrary commands on self-hosted gateway instances. The flaw, rated 9.9 on the CVSS scale, specifically affects organizations that host their own AI Gateway and have configured it to use Duo Agent Platform access.

CVE-2026-63688critical

Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

Dell has issued security updates to address several critical vulnerabilities within its Container Storage Modules (CSM) that could be leveraged by malicious actors to compromise affected systems. Among the disclosed flaws is CVE-2026-63688, which has been assigned a CVSS score of 10.0. This particular vulnerability is described as a missing authentication for critical function flaw residing in…

zero-day

Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response

Recent security incidents involving Kiteworks and Citrix have highlighted the significant challenges organizations face in responding to zero-day vulnerabilities, particularly concerning communication and mitigation strategies. The incidents presented contrasting approaches to managing critical security flaws, with one vendor issuing an immediate and drastic mitigation directive while the…

vulnerability

SWIFT Banking & Government Middleware Enables RCE

A recent report indicates that critical vulnerabilities have been identified in SWIFT banking and government middleware, potentially enabling remote code execution (RCE). The findings highlight a significant risk, particularly in environments that rely on hardware-based multi-factor authentication (MFA), suggesting that these systems could be exploited if the underlying middleware remains…

vulnerabilitycritical

GitLab warns of critical RCE vulnerability in AI Gateway service

GitLab has issued an urgent warning to customers regarding a critical remote code execution (RCE) vulnerability, identified as CVE-2026-90970, affecting its AI Gateway service. The flaw could allow attackers to execute arbitrary commands on vulnerable self-hosted instances.

patch

New infosec products of the week: October 2, 2026

Several cybersecurity vendors have unveiled new products and platform updates, with a notable emphasis on integrating artificial intelligence into security operations and access control, as well as enhancing software protection. The releases include Vega II, Genea MCP, BlackFog ADX Vision 2.0, and Thales Sentinel Envelope Plus.

vulnerability

Legit Security extends automated fixes to vulnerable open-source dependencies

Legit Security has announced an expansion of its Agentic Remediation capability to automatically address vulnerabilities found in open-source dependencies. This update allows development teams to move directly from vulnerability detection to a verified fix without requiring manual triage, a process previously limited to first-party code.

CVE-2026-73570

Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

Threat actors are actively exploiting a previously disclosed vulnerability in Zimbra Collaboration Suite (ZCS) to gain unauthorized access and exfiltrate sensitive information, as reported by the Microsoft Security Research team. The attacks involve the deployment of web shells and subsequent harvesting of authentication secrets, indicating a sophisticated post-exploitation strategy aimed at…

phishing

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

Microsoft has issued a warning regarding active phishing campaigns that are leveraging legitimate remote monitoring and management (RMM) software, specifically MSP360, to establish remote access on targeted systems. The campaigns reportedly distribute an installer for MSP360, masquerading it as various lures such as meeting invitations, PDF documents, or software update prompts, to trick users…

vulnerabilitycritical

WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

WatchGuard has released a series of patches addressing multiple vulnerabilities within its Fireware OS. The update targets a total of fifteen distinct security flaws, encompassing critical code injection vulnerabilities, denial-of-service issues, authorization bypasses, and path traversal bugs. This comprehensive patch aims to fortify the security posture of devices running the Fireware…

patch

WSL containers are generally available on Windows

Microsoft has announced the general availability of WSL containers, a feature that enables Linux containers to run on Windows via the Windows Subsystem for Linux. The functionality can be installed through `wsl --update` or downloaded from Microsoft's GitHub releases page.

malware

Custom ChatGPTs push ClickFix attacks to deploy RAT malware

A novel attack campaign is leveraging custom variants of OpenAI's ChatGPT, promoted through sponsored Google search results, to direct users to malicious websites. These sites employ "ClickFix" social engineering tactics to deliver remote access trojan (RAT) malware. The campaign was identified by Huntress, a managed detection and response firm, which noted that dozens of users have been affected.

patch

Researchers escape OpenAI Codex sandbox to run commands on host

Security researchers have identified two distinct sandbox escape vulnerabilities in OpenAI's Codex, a coding agent available as both a command-line interface (CLI) tool and a desktop application. Both flaws, reported to OpenAI on August 12 and subsequently patched within eight days, could allow untrusted code to execute commands on a developer's machine outside the intended sandbox environment.

CVE-2026-28299high

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

SolarWinds has released a patch for a critical vulnerability in its Access Rights Manager (ARM) software. The flaw, designated CVE-2026-28299, enables unauthenticated remote code execution. This issue stems from the presence of a hard-coded static key within the software. All versions of ARM preceding 2026.2.1 are affected by this vulnerability.

vulnerability

Researchers use AI to find widespread software decoder flaw

Cybersecurity researchers have identified a widespread vulnerability in popular software decoders that could lead to remote code execution and data theft across major internet platforms, enterprise services, and web frameworks. The flaw, dubbed "HEIF Heist," exploits memory corruption errors when processing specially crafted image files, potentially allowing attackers to bypass application…

vulnerability

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

WordPress has released patches addressing a new set of vulnerabilities within its core software. One of these flaws, dubbed "Click2Shell" by the reporting security firm pwn.ai, could enable a logged-in administrator to inadvertently install a theme from the official WordPress.org directory simply by opening a specially crafted web link, without requiring explicit user interaction to confirm…

vulnerability

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

Microsoft has reportedly addressed 18 vulnerabilities spanning its Azure and AI-branded product lines. The majority of these patched flaws were identified as privilege escalation vulnerabilities, indicating a focus on issues that could allow an attacker to gain elevated access within affected systems.

patch

Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE

Amazon Web Services (AWS) has confirmed the permanent loss of customer data in its Middle East (Bahrain) region, designated me-south-1, and in one availability zone of its Middle East (UAE) region, me-central-1. The announcement, made in two updates on September 15, comes six months after Iranian drone strikes impacted AWS infrastructure in the region.

patch

Windows 11 24H2 Home and Pro reach end of support in October

Microsoft has issued a reminder to users that Windows 11 24H2 Home and Pro editions will cease receiving updates next month, specifically on October 13, 2026. After this date, devices running these versions will no longer receive monthly security or non-security preview updates, leaving them vulnerable to new security threats.

vulnerabilityhigh

Cisco warns of max severity ISE zero-day exploited in attacks

Cisco has issued an urgent warning regarding a maximum-severity zero-day vulnerability in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products, which is actively being exploited in the wild. The flaw, identified as CVE-2026-76460, allows remote attackers to bypass authentication by exploiting an API weakness, regardless of the system's configuration.

vulnerability

Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day

Cisco has released an emergency security patch for a zero-day vulnerability affecting its Identity Services Engine (ISE) product, following reports of active exploitation. The flaw allows remote, unauthenticated attackers to bypass authentication mechanisms by sending specially crafted requests to affected ISE instances. This critical update addresses a significant security risk given the…

patch

Windows 11 KB5124008 update breaks domain trust for some users

Microsoft is currently investigating reports that its KB5124008 security update for Windows 11 is causing domain trust relationships to break on some enterprise systems. This issue is preventing users from logging in with valid domain credentials.

CVE-2026-58704high

Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

Google has released a security update addressing a high-severity vulnerability in its Pixel Cellular Modem, acknowledging that the flaw has been exploited in limited, targeted attacks in the wild. The issue, identified as CVE-2026-58704, carries a CVSS score of 8.0, indicating a significant risk.

patch

Mythos has made 2026 patching hell. It might make 2027 a breeze

The year 2026 has seen an unprecedented volume of software patches, creating significant challenges for cybersecurity teams, but this surge in vulnerability disclosures may signal a turning point towards more secure software in 2027. This perspective, presented at Gartner’s IT Symposium in Australia, suggests that AI-powered bug-hunting tools, such as Anthropic’s Mythos, are rapidly…

vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

Apple has released a substantial security update across its operating systems and software, addressing over 260 Common Vulnerabilities and Exposures (CVEs). This marks the largest single patch cycle in the company's history. While no vulnerabilities are currently reported as being under active exploitation, the disclosure of these flaws often prompts attackers to attempt to exploit them.

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle released its September 2026 Critical Security Patch Update (CSPU) on September 15, addressing 672 unique Common Vulnerabilities and Exposures (CVEs) through 673 security updates across 17 product families. This monthly release cycle, introduced in May 2026, aims to provide a faster cadence for high-severity issues compared to the quarterly Critical Patch Updates (CPUs).

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

A malicious version of the Admin Menu Editor Pro plugin for WordPress was distributed to over 200 customers, affecting at least 1,500 websites, after an attacker compromised the maintainer's website and pushed updates containing a backdoor. The incident, which began on Monday, September 14, involved the distribution of trojanized versions of the premium plugin.

patch

Before You Patch. Why Patch Reliability Matters for Confident Deployment

Microsoft's September 2026 security updates, specifically KB5124008 and KB5124012, have been confirmed by Microsoft to cause issues with USB audio devices on some Windows systems. The problems, which surfaced after the September 8, 2026, updates were installed, primarily affect USB Audio Class 1.0 devices, causing them to fail to start or produce audio.

malware

HBO Max Reddit account compromised to serve ClickFix attacks

The official Reddit account for HBO Max, u/hbomax, was compromised and used to distribute over 100 malicious advertisements, serving ClickFix attacks designed to infect both Windows and macOS devices with information-stealing malware. The incident was part of a broader "massive 48-hour malvertising blitz" that researchers have dubbed PasteSwitch.

patch

Microsoft releases emergency Windows updates to fix RDS failures

Microsoft has released emergency out-of-band updates for various Windows versions to address critical issues, including Remote Desktop Services (RDS) failures, Hyper-V problems, and USB audio malfunctions. These issues were introduced by the security updates deployed earlier in September 2026.

breach

Weekly Update 521: Breach Perception v. Reality

This week's security update highlights a significant disparity between public perception and the reality of cyber threats, particularly concerning the role of artificial intelligence (AI) in offensive operations. The report emphasizes that despite widespread media narratives portraying AI as a primary tool for hackers, its actual involvement in reported breaches is negligible. This challenges…

CVE-2026-85706critical

Critical GitLab Vulnerability Exploited in Internet-Wide Probes

GitLab has released emergency patches for two high-severity vulnerabilities in its software development platform, one of which carries the maximum possible severity score and is already being actively probed by attackers across the internet. The company urged operators of self-managed installations to upgrade immediately, while confirming its own hosted service and single-tenant Dedicated…

vulnerability

More JFrog Artifactory bugs under attack, and all 3 have patches

Multiple attackers are actively exploiting three recently patched vulnerabilities in JFrog Artifactory, gaining administrative control over vulnerable instances and subsequently installing malicious plugins and backdoors. The affected party, JFrog, has not publicly commented on these attacks, but security researchers have confirmed in-the-wild exploitation across various environments.

malware

How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

Threat actors are increasingly exploiting trusted artificial intelligence (AI) platforms by weaponizing their legitimate features to deliver malware and steal sensitive data, according to observations from the Huntress Security Operations Center (SOC). Over the past nine months, Huntress has tracked multiple campaigns that leverage shareable AI content, public mini-applications, and sponsored…

CVE-2025-66516high

Metasploit Wrap Up: This One Goes to Sixteen!

A recent update to the Metasploit framework has introduced sixteen new modules, including ten exploit modules, five of which address vulnerabilities listed on the CISA Known Exploited Vulnerabilities (KEV) catalog. The new exploits target products from Cisco, PaperCut, SonicWall, JetBrains, and Langflow, among others.

vulnerabilityhigh

Ubuntu 24.04.5 LTS release patches security bugs across ten flavors

Canonical has released Ubuntu 24.04.5 LTS, an update to its Noble Numbat long-term support distribution, which integrates security updates and stability fixes directly into new installation media. This point release aims to reduce the number of post-installation updates for new deployments.