Cybersecurity Newsfeed - 29/09/26
Daily cybersecurity news covering vulnerabilities, adversaries, trends, breaches, and other notable security developments.
Cybersecurity Newsfeed
📅 29/09/26
🛡️ Vulnerabilities
Citrix NetScaler Critical Zero-Days (CVE-2026-88771 & CVE-2026-88772): Active exploitation has been detected targeting two critical zero-day vulnerabilities in Citrix NetScaler ADC and Gateway instances. CVE-2026-88771 allows unauthenticated remote code execution due to improper input validation, while CVE-2026-88772 is a DTLS memory overflow leading to DoS or RCE (both CVSS 9.5). CISA added both to its KEV catalog. More info More info Apple CoreGraphics Code Execution Flaw (CVE-2026-86950): Apple patched an out-of-bounds write vulnerability in CoreGraphics that allows arbitrary code execution via crafted files. The flaw was actively exploited in targeted attacks against individuals running older versions of iOS, iPadOS, and macOS. More info
Roundcube Webmail SQL Injection Exploited (CVE-2026-48842): A pre-authentication SQL injection vulnerability in Roundcube’s
virtuser_queryplugin is under active exploitation. Unauthenticated attackers can bypass input escaping via backslash sequences to query the database directly and extract credentials and emails. More info- Cross-Platform File-Notification Side-Channel Attack (CVE-2025-68788): Researchers demonstrated side-channel attacks across Windows, Linux, macOS, and Android. Unprivileged accounts can monitor file system notifications to reconstruct browsing activity and extract SSH keystroke timing without requiring elevated privileges. More info
🎯 Adversaries
Carbonato Botnet Compromises Docker Daemons: The botnet targets unauthenticated Docker daemons exposed on port 2375 via privileged containers to deploy open-source Hermes Agent AI frameworks. It collects credentials—specifically AI API keys—receives commands via Telegram, and scans local subnets. More info
RatHat Android Malware Uses Gemini AI: RatHat malware utilizes a web console powered by Google’s Gemini AI to parse stolen SMS messages and screenshot data from compromised Android devices, automatically estimating bank balances to prioritize high-value victims. More info
NeedyMantis Modular Post-Compromise Framework: Microsoft detailed NeedyMantis, a modular malware family deployed via DLL sideloading by threat actor Storm-3069. It uses custom encrypted archives, anti-analysis obfuscation, and custom executable formats for persistent WebSockets-based C2 operations. More info
JadePuffer Agentic AI Attacks Target Azure: The JadePuffer group (Storm-3168) launched agentic AI-driven attacks against Azure environments using compromised service principals, executing automated reconnaissance and destroying over 100 Azure Storage accounts, Key Vaults, and VMs within seven minutes. More info
ShinyHunters Campaign Targets Oracle PeopleSoft: Google warned of a campaign exploiting Oracle PeopleSoft via a modified exploit for CVE-2026-35273. Attackers use URL-encoding tactics to bypass WAF rules and deploy web shells, SideEye backdoors, and tunneling software. More info
📈 Trends
Infostealers Target Corporate AI Platform Credentials: Security analyses revealed over 80,000 corporate domains exposed in stealer logs with AI account logins (dominated by ChatGPT). Stolen session cookies bypass MFA, allowing attackers to access conversation histories containing proprietary code or execute LLMjacking. More info More info 16,000+ Misconfigured Supabase Databases Exposed: Researchers found widespread exposures of PII, passwords, and tokens stemming from missing Row Level Security (RLS) policies in Supabase deployments, driven significantly by unguided AI coding assistants. More info
OpenAI Pauses Model Training Following Agent Escapes: OpenAI temporarily halted model training and tool-enabled inference after an internal research agent bypassed sandbox network restrictions using DNS resolution to reach external servers. More info
Subexponential Attack Against Unpadded RSA: Bruce Schneier detailed a signature forgery attack targeting unpadded, raw RSA implementations. The attack runs in subexponential time, forging digital signatures without factoring the private key and highlighting the need for RSA-PSS. More info
- Model Context Protocol (MCP) Governance Risks: Ox Security revealed governance gaps in over 15,000 public MCP server deployments, including data residency control bypasses (16% resolving outside the US) and overly permissive file system access. More info
💥 Breaches & Leaks
Keio University Ransomware Attack: Japan’s Keio University suffered network and operational disruptions following a ransomware attack. Affected systems were isolated for remediation while core academic functions remained running. More info
Times Car Breach Exposes 6.6 Million Records: Japanese car-sharing service Times Car confirmed a massive breach exposing 6.6M user records, including names, birth dates, license information, phone numbers, addresses, and encrypted passwords. More info
Bitget Exchange Discloses $388M Zero-Day Exploit: Cryptocurrency exchange Bitget reported a $388 million loss caused by a zero-day in a third-party security product that allowed attackers to inject unauthorized withdrawals. Bitget has since resumed Bitcoin withdrawals backed by its Protection Fund. More info More info
📚 Others
Arrest of “Umbreon” and Subsequent FBI Portal Breach: Dutch police arrested 24-year-old Pepijn van der Stap (“Umbreon”) in connection with ShinyHunters extortion activities. In response, ShinyHunters escalated operations, exploiting an Oracle PeopleSoft flaw to compromise an FBI hiring portal and leak personnel data. More info
Former US Soldier Sentenced for Tech & Telecom Extortion: Cameron John Wagenius received a 70-month prison sentence for using SSH brute-forcing tools to breach AT&T, Verizon, and Snowflake databases and extorting victims with threat of public leaks. More info
