2026-09-30 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-30 14:45 UTC
Written by: Robin Grunewald, Supriya Mazumdar, Kelli Vanderlee Introduction Google Threat Intelligence Group (GTIG) examines vulnerability disclosure and exploitation statistics to evaluate the impact of artificial intelligence (AI) on the vulnerability threat landscape. We found that AI is measurably changing not just the pace of vulnerability discovery and exploitation, but also the types and typical risk profiles of vulnerabilities that are being discovered. Key findings: Vulnerability discl…
P60
2026-09-30 13:16 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-30 13:30 UTC
WatchGuard has rolled out patches for 15 code execution, DoS, authorization, and path traversal bugs in Fireware OS. The post WatchGuard Patches Critical Fireware OS Code Injection Vulnerability appeared first on SecurityWeek.
P0
2026-09-30 13:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-09-30 13:10 UTC
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to …
P15
2026-09-30 12:48 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-30 12:50 UTC
Several security firms have confirmed seeing exploitation of the NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772. The post Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks appeared first on SecurityWeek.
P30
2026-09-30 11:11 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-30 11:15 UTC
Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. [...]
P25
2026-09-30 08:04 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-30 09:10 UTC
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Apple Multiple Products flaw, tracked as CVE-2026-86950 (CVSS score of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. This week, Apple has released security updates for iOS, iPadOS […]
P35
2026-09-30 07:25 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-30 07:50 UTC
Mandiant and GTIG detail active exploitation of a Citrix NetScaler zero-day, deploying custom web shells WHIPSHOT and SLAPSHOT for root access. Mandiant and Google Threat Intelligence Group caught active exploitation of a zero-day in Citrix NetScaler ADC and Gateway appliances in late September 2026. The bug, tracked as CVE-2026-88772 (CVSS score of 9.5), has been […]
P30
2026-09-30 05:30 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 07:00 UTC
Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that's rooted in the NetScaler
P25
2026-09-30 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-30 21:10 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-18145.
P20
2026-09-30 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-30 21:10 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. An attacker must first obtain the ability to write to the samld session directory on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-13046.
P20
2026-09-29 21:31 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-09-29 21:50 UTC
Attackers are exploiting CVE-2026-86950, an out-of-bounds write flaw, in an extremely sophisticated fashion, according to Apple.
P30
2026-09-29 21:08 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-09-29 21:20 UTC
A patched Unsloth Studio vulnerability allows malicious AI models to execute arbitrary Python code during inspection, via the trust_remote_code setting.
P0
2026-09-29 18:37 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-29 18:50 UTC
Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks. [...]
P30
2026-09-29 17:20 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-29 17:20 UTC
A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in web browsers, language runtimes, and the operating system kernel, across multiple CPU vendors. The new Spectre v2 variant has been codenamed Branch Target Reuse (BTR). "The key insight is that, while modern CPUs
P0
2026-09-29 15:39 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-29 15:50 UTC
The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyberattack that the organization described as "loud and very, very messy." [...]
P0
2026-09-29 15:17 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-29 15:35 UTC
Bulletin ID: 2026-119-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/29/2026 08:00 AM PDT Description: GluonTS is an open source library for deep learning based time series models. We identified CVE-2026-100308 that allows arbitrary command execution upon deserialization of untrusted model artifacts. Deserialization of untrusted data in the model loading component in Amazon GluonTS before 0.17.0 might allow context-dependent attackers to execute arbitrary opera…
P5
2026-09-29 14:19 UTC
Security Journalism
Dark Reading · Rob Wright · indexed 2026-09-29 15:15 UTC
The critical vulnerabilities, which impact default configurations of NetScaler products, essentially give attackers a skeleton key to customers' networks.
P25
2026-09-29 14:13 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-29 15:25 UTC
Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during the scheduled precautionary shutdown. "During the shutdown, this activity led to the discovery of a previously unknown critical vulnerability confined to a capability that is enabled for less than 1% of the customer base," the company
P10
2026-09-29 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-09-29 14:00 UTC
Introduction In late September 2026, Mandiant Consulting and Google Threat Intelligence Group (GTIG) identified active, in-the-wild exploitation of a zero-day vulnerability (CVE-2026-88772) affecting Citrix NetScaler ADC and NetScaler Gateway appliances. We have observed evidence that organizations in North America and Europe in the government, financial services, technology, education, and legal and professional services sectors were likely impacted by this exploitation campaign, which has bee…
P30
2026-09-29 13:28 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-29 13:40 UTC
Apple patched zero-day CVE-2026-86950 in CoreGraphics, exploited in sophisticated targeted attacks against specific iOS users. Apple has released security updates for iOS, iPadOS and macOS to fix a zero-day vulnerability, tracked as CVE-2026-86950, in CoreGraphics that may have been exploited in attacks against specific individuals. The flaw is an out-of-bounds write that can lead to […]
P50
2026-09-29 09:04 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-29 09:10 UTC
American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability. [...]
P10
2026-09-29 07:33 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-29 07:45 UTC
Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices. [...]
P50
2026-09-29 06:18 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-29 06:30 UTC
Apple released iOS and macOS updates to patch a zero-day vulnerability (CVE-2026-86950) reported by Meta’s product security team. The post Apple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’ appeared first on SecurityWeek.
P30
2026-09-28 22:35 UTC
Community
SANS Internet Storm Center · indexed 2026-09-28 22:10 UTC
Apple today released patches for all of its operating systems. However, only patches for older branches include a security fix. The vulnerability being addressed in iOS 26, macOS 26 and macOS 15 is already being exploited. iOS and macOS 27 are not affected. Today's update for the current "27" branch does not address security issues, but fixes some functional issues that got caught after the release two weeks ago. A 27.1 version was also expected to support the new foldable iPhone and w…
P5
2026-09-28 21:13 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-09-28 21:25 UTC
A high-severity vulnerability affects the TDengine time-series database used across industrial, IoT, energy, and automotive environments, and orgs should patch right away.
P0
2026-09-28 19:30 UTC
Security Journalism
The Record · indexed 2026-09-28 19:40 UTC
A vulnerability in a popular line of products from Oracle is being used in a new campaign by the prolific ShinyHunters hacking group, which recently claimed credit for an attack on the FBI’s jobs site.
P0
2026-09-28 19:18 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 20:10 UTC
Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file. The iPhone maker said the
P5
2026-09-28 17:42 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 18:40 UTC
The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system. Exchanges keep most
P0
2026-09-28 16:19 UTC
Security Journalism
The Record · indexed 2026-09-28 16:25 UTC
Incident responders began warning of potential vulnerabilities in NetScaler Gateway products on Saturday before cybersecurity agencies in the Netherlands, U.S. and U.K. released advisories on Sunday confirming vulnerabilities. Citrix itself confirmed eight new vulnerabilities.
P25
2026-09-28 10:56 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-28 11:00 UTC
The extortion group has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273. The post Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign appeared first on SecurityWeek.
P5