ICYMI: 2026-09-30
Latest Headlines
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub
US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access
Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT
OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted
Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution
How Israeli Checkpoints Choke Palestinian Life in the Occupied West Bank
FTC is Investigating OpenAI and Anthropic Over Possible risks to Consumers
Google: AI Is Changing the Pace and Profile of Vulnerability Discovery
WatchGuard Patches Critical Fireware OS Code Injection Vulnerability
Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks
Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit
Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks
ShinyHunters Defiant After FBI Calls on Members to Come Forward
Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development
Cloudflare Builds Post-Quantum CA With Merkle Tree Certificates for Faster Quantum-Safe TLS
Google Releases Chrome Update With 32 Security Fixes for Windows, Mac and Linux
Google Warns of Hackers Actively Exploiting Citrix 0-Day Vulnerabilities to Deploy Web Shells
Russian Hackers Target 100+ Organizations With New RedFlick Phishing Attack
Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster
Supply Chain Attacks Turn Developer Machines Into Gateways for Cloud Breaches
Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs
AI Coding Agents Leak 13,000+ Internal Screenshots From 300+ Companies on GitHub
Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller
Russian state hackers use new RedFlick technique to push malware
Over 543,000 valid credentials exposed in public GitHub repositories
CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS
AI’s Third Wave: Coworkers Break the Security Model That Worked for Agents
Microsoft to block Entra ID script injection attacks starting October
TeamViewer urges users to patch severe flaws “as soon as possible”
– MTZ