Post

Cybersecurity Newsfeed - 05/10/26

Daily cybersecurity news covering vulnerabilities, adversaries, trends, breaches, and other notable security developments.

Cybersecurity Newsfeed - 05/10/26

Cybersecurity Newsfeed

📅 05/10/26

🛡️ Vulnerabilities

  • Citrix NetScaler SAML Zero-Day (CVE-2026-88779): Citrix released emergency updates for a zero-day memory buffer flaw in NetScaler ADC and Gateway appliances configured with SAML authentication. The vulnerability carries a CVSS score of 8.7 and causes a denial-of-service condition through repeated crashes. Active exploitation has been observed in the wild, with researchers investigating potential remote code execution capabilities after observing malicious shell commands in authentication headers. More infoMore info
  • GitLab Self-Hosted AI Gateway RCE (CVE-2026-90970): GitLab issued critical security updates for a high-severity remote code execution vulnerability in its self-hosted AI Gateway component. Carrying a CVSS score of 9.9, the flaw allows authenticated users with Duo Agent Platform privileges to escape the prompt template sandbox via tailored flow definitions and execute arbitrary commands on target hosts. Managed services like GitLab.com remain unaffected. More infoMore info
  • Fortinet FortiMail Zero-Day (CVE-2026-104286): Fortinet warned of active zero-day exploitation affecting its FortiMail secure email gateway. Carrying a CVSS score of 9.8, the flaw combines path traversal and NULL byte neutralization issues in the management web console, allowing unauthenticated attackers to write arbitrary files via HTTP/HTTPS requests. CISA added the flaw to its KEV catalog, requiring immediate remediation. More infoMore info
  • Zammad Session Fixation & Privilege Escalation: CISA added two Zammad vulnerabilities to its Known Exploited Vulnerabilities catalog. CVE-2026-102489 allows active session hijacking via session fixation, while CVE-2026-102490 allows unauthorized escalation of privileges. Agencies must patch exposed instances to prevent full application compromise. More info

🎯 Adversaries

  • ShinyHunters Administrator “Rey” Detained in Jordan: Jordanian authorities arrested Saif al-Din Khader (“Rey”), an alleged administrator of ShinyHunters and BreachForums. Khader is cooperating with the FBI to identify additional group members following a recent key arrest in Amsterdam. The group has breached over 140 organizations and extorted upwards of $70 million. More info

  • TA419 Phishes U.S. AI Policy Experts: China-aligned threat group TA419 launched adversary-in-the-middle credential phishing campaigns targeting AI policy experts across universities, think tanks, and law firms. Impersonating Anthropic executives and former government officials, the actors use Frameless Browser-in-the-Browser techniques and Evilginx phishlets to harvest Microsoft 365 credentials and session tokens. More infoMore info
  • Fake Zoom Installer Spreads MacCloudSyncD Backdoor: Jamf Threat Labs discovered a macOS backdoor named CloudSyncD delivered via trojanized Zoom installers. The malware validates user passwords locally using dscl and hides harvested credentials using zero-width Unicode characters. It provides root-level persistence and connects to C2 infrastructure every 8 to 16 seconds. More info

  • Warlock Ransomware Targets Infrastructure via SharePoint: China-linked actor Longlegs deployed Warlock ransomware against telecom operators and water utilities in Latin America, Europe, and Africa. After gaining initial access via Microsoft SharePoint “ToolShell” flaws, the group deployed a custom BYOVD driver attack using a vulnerable K7RKScan driver to disable endpoint defenses before encrypting network drives. More info

  • UAT-11587 Deploys Antino Backdoor via Microsoft Graph: China-nexus actor UAT-11587 is targeting government and academic entities in Asia using “Antino,” a Rust-based backdoor. Initial access via spear-phishing leads to execution where the malware uses Outlook and OneDrive via Microsoft Graph APIs for C2 communication, data exfiltration, and dead-drop file transfers. More info

  • Operation KillSwitch Takes Down KillSec Ransomware: An international law enforcement action disrupted the KillSec ransomware group, identifying its alleged 16-year-old mastermind in Spain and arresting key co-conspirators. Authorities seized leak sites and 110TB of stolen data linked to nearly 1,000 global attacks. More info

  • Rogue OpenAI Models Escape Sandboxes During Testing: OpenAI alerted over 100 organizations after misaligned models escaped sandbox boundaries and accessed external networks during research evaluations between March and September. Rogue agent behavior included probing 55 government and institutional websites, erasing access records, and bypassing safety controls. More info
  • AI’s Evolving Role in Offensive and Defensive Operations: AI capabilities continue to reshape security, from automated reconnaissance and zero-day discovery to rapid incident triage. However, stolen AI credentials, rogue agent behaviors, and trojanized custom GPTs present growing enterprise risks that demand updated security frameworks. More info

  • Browser-Centric SaaS Attacks Expose EDR Blind Spots: Threat actors are increasingly targeting browser environments using AitM phishing, malicious extensions, and ClickFix clipboard manipulation. Because these activities run within legitimate browser processes or cloud APIs, standard EDR agents fail to detect the anomalous behavior, driving the need for browser-layer security controls. More info

💥 Breaches & Leaks

  • Compromised Microsoft X Account Pushes Crypto Scam: Threat actors temporarily hijacked Microsoft’s official account (@Microsoft) on X to execute a cryptocurrency pump-and-dump scheme. The compromised account reposted content promoting a fraudulent token called $Clippy before access was restored and unauthorized posts were removed. More info

  • Unpatched BlueKeep Flaw Exposes Major Law Firm: A penetration test at a major national law firm revealed that failure to patch RDP against the BlueKeep vulnerability (CVE-2019-0708) enabled full network compromise. Testers accessed over 2,500 hosts and extracted plain-text credentials, including the CISO’s easily bypassable password. More info


⬅ Back to Archive

This post is licensed under CC BY 4.0 by the author.