Cyber Security
Application Security
Rejetto HFS Flaw Lets Hackers Forge Admin Sessions for RCE
Andrew Doyle
October 5, 2026
A critical Rejetto HFS flaw, CVE-2026-61500, lets attackers forge admin session cookies and gain remote code execution; active exploitation began October 1.
Cybersecurity
Citrix Patches New NetScaler Zero-Day Hit by Active Attacks
Gabby Lee
October 5, 2026
Citrix released emergency patches for CVE-2026-88779, a NetScaler SAML zero-day under active attack that can knock enterprise login gateways offline for users.
Cybersecurity
South Korea’s President Orders Probe Into Bank Data Breaches
Mitchell Langley
October 5, 2026
President Lee Jae Myung ordered an investigation after breaches at Shinhan, KB Kookmin, Hana, Woori, and Yegaram Savings Bank exposed over 60,000 records.
Cybersecurity
Alleged ShinyHunters Leader ‘Rey’ Reportedly Held in Jordan
Gabby Lee
October 5, 2026
A suspected ShinyHunters member known online as Rey was reportedly detained in Jordan on September 29 and is said to be cooperating with FBI investigators.
Cybersecurity
Nikkei Discloses M365 Breach, 9,000 Spoofed Emails Sent
Andrew Doyle
October 5, 2026
Nikkei disclosed a Microsoft 365 account breach that sent 9,000 spoofed emails to contacts, plus a separate cloud intrusion exposing data on 1,646 people.
Application Security
Google Pauses Open-Source Bug Bounty Over AI Report Flood
Gabby Lee
October 5, 2026
Google stopped accepting new submissions to its open-source bug bounty program after a flood of low-quality, AI-generated vulnerability reports arrived.
CVE Vulnerability Alerts
Critical FortiMail Zero-Day Exploited With No Patch Yet
Mitchell Langley
October 2, 2026
Fortinet confirmed active exploitation of a critical FortiMail flaw with no fix shipped for most versions, and CISA added it to its exploited list.
Cybersecurity
Police Dismantle KillSec Ransomware Gang, Nab Teen Leader
Gabby Lee
October 2, 2026
A ten-country police operation seized KillSec's servers and leak site, arrested a suspected 16-year-old ringleader, and recovered over 110TB of stolen data.
Application Security
Kiteworks Patches Second Max-Severity Flaw in a Week
Andrew Doyle
October 2, 2026
Kiteworks patched a maximum-severity code injection flaw found through its bug bounty program, marking its second critical disclosure in roughly a week.
Application Security
Self-Healing WordPress Backdoor Defies Standard Removal
Mitchell Langley
October 2, 2026
Sucuri found a WordPress backdoor, SC, that persists across eight file, database, and memory locations and rebuilds itself when any one is deleted.
CVE Vulnerability Alerts
Cisco Patches Actively Exploited Catalyst SD-WAN Flaw
Mitchell Langley
October 1, 2026
Cisco patched a critical authentication bypass in Catalyst SD-WAN Manager, formerly vManage, that attackers are actively exploiting to seize full admin control.
Cybersecurity
MetaMask Discloses Incident, Exits Ethereum Validators
Gabby Lee
October 1, 2026
MetaMask disclosed a security incident affecting its staking infrastructure and is proactively exiting Ethereum validators it runs through the Lido protocol.
CVE Vulnerability Alerts
TeamViewer Patches Critical Access-Control Bypass Flaw
Andrew Doyle
October 1, 2026
TeamViewer patched a critical access-control bypass and four other flaws in its Full Client and Host software, urging all users to update immediately.
CVE Vulnerability Alerts
WatchGuard Patches Critical Root Code Execution Flaw
Gabby Lee
October 1, 2026
WatchGuard patched a critical Fireware OS flaw letting a rogue VPN server run root commands on Firebox appliances, plus 14 other bugs in the same ...
CVE Vulnerability Alerts
CISA Warns of Critical Pre-Auth Flaw in MikroTik Routers
Gabby Lee
October 1, 2026
CISA warned that a pre-authentication flaw in MikroTik RouterOS lets a single crafted request trigger root code execution or crash the device remotely.
Cybersecurity
FTC Confirms Probe Into OpenAI, Anthropic AI Agents
Gabby Lee
October 1, 2026
The FTC confirmed it is investigating OpenAI, Anthropic, and other AI firms after agents reportedly went beyond instructions to hack external websites.
Cybersecurity
Teen Researcher’s AI Tool Gains Admin on Microsoft Titan
Andrew Doyle
October 1, 2026
A 16-year-old researcher used a self-built AI tool to gain admin access to Microsoft's internal Titan analytics platform, exposing 17.3 trillion rows.
CVE Vulnerability Alerts
OpenSSL Patches High-Severity DTLS Memory Leak Flaw
Gabby Lee
October 1, 2026
OpenSSL patched a high-severity DTLS flaw that can expose unencrypted heap memory or crash affected software running its widely used cryptographic library.
Cybersecurity
CSuite Phishing Campaign Hijacks Microsoft 365 Sessions
Andrew Doyle
October 1, 2026
A phishing campaign dubbed CSuite is hijacking executives' Microsoft 365 sessions and installing ScreenConnect and Action1 for persistent remote access.
Application Security
Chrome, Firefox Patch Over 100 Flaws in Joint Update
Andrew Doyle
October 1, 2026
Chrome and Firefox fixed over 100 vulnerabilities between them, including a critical ANGLE buffer overflow in Chrome rated capable of remote code execution.
Application Security
Rejetto HFS Flaw Lets Hackers Forge Admin Sessions for RCE
Andrew Doyle
October 5, 2026
Cybersecurity
South Korea’s President Orders Probe Into Bank Data Breaches
Mitchell Langley
October 5, 2026
Cybersecurity
Ransomware Attack Disrupts Keio Corporation Business Systems
Mitchell Langley
September 29, 2026
TOP CYBERSECURITY HEADLINES
Cybersecurity
Nikkei Discloses M365 Breach, 9,000 Spoofed Emails Sent
Application Security
Google Pauses Open-Source Bug Bounty Over AI Report Flood
CVE Vulnerability Alerts
Critical FortiMail Zero-Day Exploited With No Patch Yet
This Week’s Security Spotlight
Cybersecurity
South Korea’s President Orders Probe Into Bank Data Breaches
Mitchell Langley
October 5, 2026
Application Security
Google Pauses Open-Source Bug Bounty Over AI Report Flood
Gabby Lee
October 5, 2026
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Featured Videos
Podcasts
Cyber Security News
- All
- Application Security
- Blog
- CVE Vulnerability Alerts
- Cybersecurity
- Cybersecurity Newsletter
- Data Security
- Endpoint Security
- Identity and Access Management
- Information Security
- Network Security
- News
- Phishing
- Podcasts
- Product Reviews
- Ransomware
- Ransomware Victims
- Resources
- Security Spotlight
- Sponsored
- Threat Actors
- Threat Actors
- Threat Detection Tools
Alleged ShinyHunters Leader ‘Rey’ Reportedly Held in Jordan
October 5, 2026
A suspected ShinyHunters member known online as Rey was reportedly detained in Jordan on September 29 and is said to be cooperating with FBI investigators.
Nikkei Discloses M365 Breach, 9,000 Spoofed Emails Sent
October 5, 2026
Nikkei disclosed a Microsoft 365 account breach that sent 9,000 spoofed emails to contacts, plus a separate cloud intrusion exposing data on 1,646 people.
Google Pauses Open-Source Bug Bounty Over AI Report Flood
October 5, 2026
Google stopped accepting new submissions to its open-source bug bounty program after a flood of low-quality, AI-generated vulnerability reports arrived.
Critical FortiMail Zero-Day Exploited With No Patch Yet
October 2, 2026
Fortinet confirmed active exploitation of a critical FortiMail flaw with no fix shipped for most versions, and CISA added it to its exploited list.
Police Dismantle KillSec Ransomware Gang, Nab Teen Leader
October 2, 2026
A ten-country police operation seized KillSec's servers and leak site, arrested a suspected 16-year-old ringleader, and recovered over 110TB of stolen data.
Kiteworks Patches Second Max-Severity Flaw in a Week
October 2, 2026
Kiteworks patched a maximum-severity code injection flaw found through its bug bounty program, marking its second critical disclosure in roughly a week.
Self-Healing WordPress Backdoor Defies Standard Removal
October 2, 2026
Sucuri found a WordPress backdoor, SC, that persists across eight file, database, and memory locations and rebuilds itself when any one is deleted.
Cisco Patches Actively Exploited Catalyst SD-WAN Flaw
October 1, 2026
Cisco patched a critical authentication bypass in Catalyst SD-WAN Manager, formerly vManage, that attackers are actively exploiting to seize full admin control.
MetaMask Discloses Incident, Exits Ethereum Validators
October 1, 2026
MetaMask disclosed a security incident affecting its staking infrastructure and is proactively exiting Ethereum validators it runs through the Lido protocol.
TeamViewer Patches Critical Access-Control Bypass Flaw
October 1, 2026
TeamViewer patched a critical access-control bypass and four other flaws in its Full Client and Host software, urging all users to update immediately.
WatchGuard Patches Critical Root Code Execution Flaw
October 1, 2026
WatchGuard patched a critical Fireware OS flaw letting a rogue VPN server run root commands on Firebox appliances, plus 14 other bugs in the same ...
CISA Warns of Critical Pre-Auth Flaw in MikroTik Routers
October 1, 2026
CISA warned that a pre-authentication flaw in MikroTik RouterOS lets a single crafted request trigger root code execution or crash the device remotely.
FTC Confirms Probe Into OpenAI, Anthropic AI Agents
October 1, 2026
The FTC confirmed it is investigating OpenAI, Anthropic, and other AI firms after agents reportedly went beyond instructions to hack external websites.
Teen Researcher’s AI Tool Gains Admin on Microsoft Titan
October 1, 2026
A 16-year-old researcher used a self-built AI tool to gain admin access to Microsoft's internal Titan analytics platform, exposing 17.3 trillion rows.
OpenSSL Patches High-Severity DTLS Memory Leak Flaw
October 1, 2026
OpenSSL patched a high-severity DTLS flaw that can expose unencrypted heap memory or crash affected software running its widely used cryptographic library.
CSuite Phishing Campaign Hijacks Microsoft 365 Sessions
October 1, 2026
A phishing campaign dubbed CSuite is hijacking executives' Microsoft 365 sessions and installing ScreenConnect and Action1 for persistent remote access.
Chrome, Firefox Patch Over 100 Flaws in Joint Update
October 1, 2026
Chrome and Firefox fixed over 100 vulnerabilities between them, including a critical ANGLE buffer overflow in Chrome rated capable of remote code execution.
Pentagon Records Agency Breach Exposes Data on 3 Million
September 30, 2026
A breach of the Pentagon's Defense Manpower Data Center exposed unencrypted personal data on 3 million people, with notice sent months after discovery.
France Tax Agency Breached Seven Weeks via Stolen Passwords
September 30, 2026
An attacker used infostealer-harvested passwords to breach France's DGFIP tax portals for seven weeks, exposing millions of taxpayer and business records.
Citrix NetScaler Zero-Days Deployed WHIPSHOT, SLAPSHOT
September 30, 2026
Attackers exploited two Citrix NetScaler zero-days to plant custom WHIPSHOT and SLAPSHOT malware, hitting government, financial, and legal-sector networks.





















