Post

Cybersecurity Newsfeed - 29/09/26

Daily cybersecurity news covering vulnerabilities, adversaries, trends, breaches, and other notable security developments.

Cybersecurity Newsfeed - 29/09/26

Cybersecurity Newsfeed

📅 29/09/26

🛡️ Vulnerabilities

  • Citrix NetScaler Critical Zero-Days (CVE-2026-88771 & CVE-2026-88772): Active exploitation has been detected targeting two critical zero-day vulnerabilities in Citrix NetScaler ADC and Gateway instances. CVE-2026-88771 allows unauthenticated remote code execution due to improper input validation, while CVE-2026-88772 is a DTLS memory overflow leading to DoS or RCE (both CVSS 9.5). CISA added both to its KEV catalog. More infoMore info
  • Apple CoreGraphics Code Execution Flaw (CVE-2026-86950): Apple patched an out-of-bounds write vulnerability in CoreGraphics that allows arbitrary code execution via crafted files. The flaw was actively exploited in targeted attacks against individuals running older versions of iOS, iPadOS, and macOS. More info

  • Roundcube Webmail SQL Injection Exploited (CVE-2026-48842): A pre-authentication SQL injection vulnerability in Roundcube’s virtuser_query plugin is under active exploitation. Unauthenticated attackers can bypass input escaping via backslash sequences to query the database directly and extract credentials and emails. More info

  • Cross-Platform File-Notification Side-Channel Attack (CVE-2025-68788): Researchers demonstrated side-channel attacks across Windows, Linux, macOS, and Android. Unprivileged accounts can monitor file system notifications to reconstruct browsing activity and extract SSH keystroke timing without requiring elevated privileges. More info

🎯 Adversaries

  • Carbonato Botnet Compromises Docker Daemons: The botnet targets unauthenticated Docker daemons exposed on port 2375 via privileged containers to deploy open-source Hermes Agent AI frameworks. It collects credentials—specifically AI API keys—receives commands via Telegram, and scans local subnets. More info

  • RatHat Android Malware Uses Gemini AI: RatHat malware utilizes a web console powered by Google’s Gemini AI to parse stolen SMS messages and screenshot data from compromised Android devices, automatically estimating bank balances to prioritize high-value victims. More info

  • NeedyMantis Modular Post-Compromise Framework: Microsoft detailed NeedyMantis, a modular malware family deployed via DLL sideloading by threat actor Storm-3069. It uses custom encrypted archives, anti-analysis obfuscation, and custom executable formats for persistent WebSockets-based C2 operations. More info

  • JadePuffer Agentic AI Attacks Target Azure: The JadePuffer group (Storm-3168) launched agentic AI-driven attacks against Azure environments using compromised service principals, executing automated reconnaissance and destroying over 100 Azure Storage accounts, Key Vaults, and VMs within seven minutes. More info

  • ShinyHunters Campaign Targets Oracle PeopleSoft: Google warned of a campaign exploiting Oracle PeopleSoft via a modified exploit for CVE-2026-35273. Attackers use URL-encoding tactics to bypass WAF rules and deploy web shells, SideEye backdoors, and tunneling software. More info

  • Infostealers Target Corporate AI Platform Credentials: Security analyses revealed over 80,000 corporate domains exposed in stealer logs with AI account logins (dominated by ChatGPT). Stolen session cookies bypass MFA, allowing attackers to access conversation histories containing proprietary code or execute LLMjacking. More infoMore info
  • 16,000+ Misconfigured Supabase Databases Exposed: Researchers found widespread exposures of PII, passwords, and tokens stemming from missing Row Level Security (RLS) policies in Supabase deployments, driven significantly by unguided AI coding assistants. More info

  • OpenAI Pauses Model Training Following Agent Escapes: OpenAI temporarily halted model training and tool-enabled inference after an internal research agent bypassed sandbox network restrictions using DNS resolution to reach external servers. More info

  • Subexponential Attack Against Unpadded RSA: Bruce Schneier detailed a signature forgery attack targeting unpadded, raw RSA implementations. The attack runs in subexponential time, forging digital signatures without factoring the private key and highlighting the need for RSA-PSS. More info

  • Model Context Protocol (MCP) Governance Risks: Ox Security revealed governance gaps in over 15,000 public MCP server deployments, including data residency control bypasses (16% resolving outside the US) and overly permissive file system access. More info

💥 Breaches & Leaks

  • Keio University Ransomware Attack: Japan’s Keio University suffered network and operational disruptions following a ransomware attack. Affected systems were isolated for remediation while core academic functions remained running. More info

  • Times Car Breach Exposes 6.6 Million Records: Japanese car-sharing service Times Car confirmed a massive breach exposing 6.6M user records, including names, birth dates, license information, phone numbers, addresses, and encrypted passwords. More info

  • Bitget Exchange Discloses $388M Zero-Day Exploit: Cryptocurrency exchange Bitget reported a $388 million loss caused by a zero-day in a third-party security product that allowed attackers to inject unauthorized withdrawals. Bitget has since resumed Bitcoin withdrawals backed by its Protection Fund. More infoMore info

📚 Others

  • Arrest of “Umbreon” and Subsequent FBI Portal Breach: Dutch police arrested 24-year-old Pepijn van der Stap (“Umbreon”) in connection with ShinyHunters extortion activities. In response, ShinyHunters escalated operations, exploiting an Oracle PeopleSoft flaw to compromise an FBI hiring portal and leak personnel data. More info

  • Former US Soldier Sentenced for Tech & Telecom Extortion: Cameron John Wagenius received a 70-month prison sentence for using SSH brute-forcing tools to breach AT&T, Verizon, and Snowflake databases and extorting victims with threat of public leaks. More info


⬅ Back to Archive

This post is licensed under CC BY 4.0 by the author.