Cyber Security
Attackers Scan for Rejetto HFS Session-Forgery Flaw CVE-2026-61500
Dell Patches Root-Level Flaw CVE-2026-86360 in System Update Tool
Android October 2026 Update Patches 25 Flaws, Seven Rated Critical
LibreOffice, OpenOffice Flaws Run Code From Spreadsheets Silently
Gentlemen Ransomware Affiliate Used MCP as Command Channel
UIC College of Medicine Hit by Booba Ransomware, 344 GB Claimed
Denmark CPR Breach Exposes Data of 8.8 Million People
Atlassian Fixes Critical CVE-2026-21589 in Eight Data Center Products
FBI Drops Accenture Contractor After ShinyHunters PeopleSoft Breach
Nikkei Discloses Microsoft 365 and Google Workspace Account Breaches
Ex-Engineer Gets 32 Months for Locking 3,000 Employer Devices
Senate Passes Health Care Cybersecurity and Resilience Act
ClickFix Variant Smuggles Payloads Through Browser Cache
ClingSTUN Botnet Abuses STUN Protocol for C2, Exploits Dozens of Flaws
Rejetto HFS Flaw Lets Hackers Forge Admin Sessions for RCE
Citrix Patches New NetScaler Zero-Day Hit by Active Attacks
South Korea’s President Orders Probe Into Bank Data Breaches
Alleged ShinyHunters Leader ‘Rey’ Reportedly Held in Jordan
Nikkei Discloses M365 Breach, 9,000 Spoofed Emails Sent
Google Pauses Open-Source Bug Bounty Over AI Report Flood
Critical FortiMail Zero-Day Exploited With No Patch Yet
Police Dismantle KillSec Ransomware Gang, Nab Teen Leader
Kiteworks Patches Second Max-Severity Flaw in a Week
Self-Healing WordPress Backdoor Defies Standard Removal
Cisco Patches Actively Exploited Catalyst SD-WAN Flaw
MetaMask Discloses Incident, Exits Ethereum Validators
TeamViewer Patches Critical Access-Control Bypass Flaw
WatchGuard Patches Critical Root Code Execution Flaw
CISA Warns of Critical Pre-Auth Flaw in MikroTik Routers
FTC Confirms Probe Into OpenAI, Anthropic AI Agents
ASOS Confirms Breach After Hackers Hijack App Push Notifications
Cybersecurity
ASOS Confirms Breach After Hackers Hijack App Push Notifications
ASOS confirmed a breach after attackers sent a fake push alert claiming a Snowflake hack; names and contact details may be exposed, but not card ...
Application Security
Ninja Forms, WPC Product Bundles XSS Flaws Used to Backdoor Sites
Attackers are exploiting stored XSS flaws in Ninja Forms and WPC Product Bundles to install a fake plugin with four persistence mechanisms on WordPress.
CVE Vulnerability Alerts
Pwn2Own Ireland 2026 Day One: 32 Zero-Days, $388,500 in Payouts
Researchers demonstrated 32 unique zero-day exploits on day one of Pwn2Own Ireland 2026, earning $388,500 against phones, routers, printers and AI platforms.
Application Security
Attackers Scan for Rejetto HFS Session-Forgery Flaw CVE-2026-61500
Scanning has begun for CVE-2026-61500 in Rejetto HFS, a flaw that lets attackers forge admin cookies and reach remote code execution on versions 3.0.0-3.2.0.
CVE Vulnerability Alerts
Dell Patches Root-Level Flaw CVE-2026-86360 in System Update Tool
Dell fixed a critical path traversal, CVE-2026-86360, in its System Update CLI that lets unauthenticated remote attackers run code as root, plus four more bugs.
CVE Vulnerability Alerts
Android October 2026 Update Patches 25 Flaws, Seven Rated Critical
Google's Android security bulletin for patch level 2026-10-01 fixes 25 vulnerabilities, seven of them critical, with no in-the-wild exploitation reported.
Application Security
LibreOffice, OpenOffice Flaws Run Code From Spreadsheets Silently
CVE-2026-63277 in LibreOffice and CVE-2026-59265 in Apache OpenOffice let malicious spreadsheets run code through JDBC drivers with no macro warning shown.
Cybersecurity
Gentlemen Ransomware Affiliate Used MCP as Command Channel
CloudSEK found Gentlemen RaaS affiliate Azazel using Model Context Protocol as a command channel in live intrusions that hit 24-plus victims in six countries.
Cybersecurity
UIC College of Medicine Hit by Booba Ransomware, 344 GB Claimed
The University of Illinois Chicago says data was taken from College of Medicine servers; the Booba ransomware gang claims 344 GB stolen from the school.
Cybersecurity
Denmark CPR Breach Exposes Data of 8.8 Million People
Attackers abused a private firm's lawful lookup rights to pull names, addresses and CPR numbers of 8.8 million people from Denmark's Central Person Register.
Application Security
Atlassian Fixes Critical CVE-2026-21589 in Eight Data Center Products
Atlassian disclosed CVE-2026-21589, a CVSS 9.3 path traversal flaw that lets unauthenticated attackers read web-root files in eight Data Center products.
Cybersecurity
FBI Drops Accenture Contractor After ShinyHunters PeopleSoft Breach
The FBI removed an Accenture contractor over an unapplied patch that let ShinyHunters breach FBIJobs.gov, as a suspected group leader was arrested in Jordan.
Cybersecurity
Nikkei Discloses Microsoft 365 and Google Workspace Account Breaches
Nikkei says attackers breached two employee email accounts, exposed data on 1,646 people and sent about 9,000 phishing emails from a Microsoft 365 account.
Cybersecurity
Ex-Engineer Gets 32 Months for Locking 3,000 Employer Devices
Daniel Rhyne, a former core infrastructure engineer, was sentenced to 32 months for locking over 3,000 devices at a New Jersey firm and demanding 20 ...
Cybersecurity
Senate Passes Health Care Cybersecurity and Resilience Act
The US Senate passed the bipartisan Health Care Cybersecurity and Resilience Act by unanimous consent, sending grants and coordination measures to the House.
Cybersecurity
ClickFix Variant Smuggles Payloads Through Browser Cache
Microsoft Threat Intelligence says a new ClickFix variant hides a script in the browser cache as a PNG, sidestepping the Windows Run dialog's character limit.
CVE Vulnerability Alerts
ClingSTUN Botnet Abuses STUN Protocol for C2, Exploits Dozens of Flaws
FortiGuard and Nozomi detail Cling, a Linux botnet that hides command traffic in STUN requests and exploits about two dozen router and IoT vulnerabilities.
Application Security
Rejetto HFS Flaw Lets Hackers Forge Admin Sessions for RCE
A critical Rejetto HFS flaw, CVE-2026-61500, lets attackers forge admin session cookies and gain remote code execution; active exploitation began October 1.
Cybersecurity
Citrix Patches New NetScaler Zero-Day Hit by Active Attacks
Citrix released emergency patches for CVE-2026-88779, a NetScaler SAML zero-day under active attack that can knock enterprise login gateways offline for users.
Cybersecurity
South Korea’s President Orders Probe Into Bank Data Breaches
President Lee Jae Myung ordered an investigation after breaches at Shinhan, KB Kookmin, Hana, Woori, and Yegaram Savings Bank exposed over 60,000 records.
Cybersecurity
Gentlemen Ransomware Affiliate Used MCP as Command Channel
Cybersecurity
UIC College of Medicine Hit by Booba Ransomware, 344 GB Claimed

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

CVE Vulnerability Alerts
Dell Patches Root-Level Flaw CVE-2026-86360 in System Update Tool
CVE Vulnerability Alerts
Android October 2026 Update Patches 25 Flaws, Seven Rated Critical
Cybersecurity
Senate Passes Health Care Cybersecurity and Resilience Act
Cybersecurity
South Korea’s President Orders Probe Into Bank Data Breaches
Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
Attackers Scan for Rejetto HFS Session-Forgery Flaw CVE-2026-61500
Scanning has begun for CVE-2026-61500 in Rejetto HFS, a flaw that lets attackers forge admin cookies and reach remote code execution on versions 3.0.0-3.2.0.
Dell Patches Root-Level Flaw CVE-2026-86360 in System Update Tool
Dell fixed a critical path traversal, CVE-2026-86360, in its System Update CLI that lets unauthenticated remote attackers run code as root, plus four more bugs.
Android October 2026 Update Patches 25 Flaws, Seven Rated Critical
Google's Android security bulletin for patch level 2026-10-01 fixes 25 vulnerabilities, seven of them critical, with no in-the-wild exploitation reported.
LibreOffice, OpenOffice Flaws Run Code From Spreadsheets Silently
CVE-2026-63277 in LibreOffice and CVE-2026-59265 in Apache OpenOffice let malicious spreadsheets run code through JDBC drivers with no macro warning shown.
Gentlemen Ransomware Affiliate Used MCP as Command Channel
CloudSEK found Gentlemen RaaS affiliate Azazel using Model Context Protocol as a command channel in live intrusions that hit 24-plus victims in six countries.
UIC College of Medicine Hit by Booba Ransomware, 344 GB Claimed
The University of Illinois Chicago says data was taken from College of Medicine servers; the Booba ransomware gang claims 344 GB stolen from the school.
Denmark CPR Breach Exposes Data of 8.8 Million People
Attackers abused a private firm's lawful lookup rights to pull names, addresses and CPR numbers of 8.8 million people from Denmark's Central Person Register.
Atlassian Fixes Critical CVE-2026-21589 in Eight Data Center Products
Atlassian disclosed CVE-2026-21589, a CVSS 9.3 path traversal flaw that lets unauthenticated attackers read web-root files in eight Data Center products.
FBI Drops Accenture Contractor After ShinyHunters PeopleSoft Breach
The FBI removed an Accenture contractor over an unapplied patch that let ShinyHunters breach FBIJobs.gov, as a suspected group leader was arrested in Jordan.
Nikkei Discloses Microsoft 365 and Google Workspace Account Breaches
Nikkei says attackers breached two employee email accounts, exposed data on 1,646 people and sent about 9,000 phishing emails from a Microsoft 365 account.
Ex-Engineer Gets 32 Months for Locking 3,000 Employer Devices
Daniel Rhyne, a former core infrastructure engineer, was sentenced to 32 months for locking over 3,000 devices at a New Jersey firm and demanding 20 ...
Senate Passes Health Care Cybersecurity and Resilience Act
The US Senate passed the bipartisan Health Care Cybersecurity and Resilience Act by unanimous consent, sending grants and coordination measures to the House.
ClickFix Variant Smuggles Payloads Through Browser Cache
Microsoft Threat Intelligence says a new ClickFix variant hides a script in the browser cache as a PNG, sidestepping the Windows Run dialog's character limit.
ClingSTUN Botnet Abuses STUN Protocol for C2, Exploits Dozens of Flaws
FortiGuard and Nozomi detail Cling, a Linux botnet that hides command traffic in STUN requests and exploits about two dozen router and IoT vulnerabilities.
Rejetto HFS Flaw Lets Hackers Forge Admin Sessions for RCE
A critical Rejetto HFS flaw, CVE-2026-61500, lets attackers forge admin session cookies and gain remote code execution; active exploitation began October 1.
Citrix Patches New NetScaler Zero-Day Hit by Active Attacks
Citrix released emergency patches for CVE-2026-88779, a NetScaler SAML zero-day under active attack that can knock enterprise login gateways offline for users.
South Korea’s President Orders Probe Into Bank Data Breaches
President Lee Jae Myung ordered an investigation after breaches at Shinhan, KB Kookmin, Hana, Woori, and Yegaram Savings Bank exposed over 60,000 records.
Alleged ShinyHunters Leader ‘Rey’ Reportedly Held in Jordan
A suspected ShinyHunters member known online as Rey was reportedly detained in Jordan on September 29 and is said to be cooperating with FBI investigators.
Nikkei Discloses M365 Breach, 9,000 Spoofed Emails Sent
Nikkei disclosed a Microsoft 365 account breach that sent 9,000 spoofed emails to contacts, plus a separate cloud intrusion exposing data on 1,646 people.
Google Pauses Open-Source Bug Bounty Over AI Report Flood
Google stopped accepting new submissions to its open-source bug bounty program after a flood of low-quality, AI-generated vulnerability reports arrived.