Post

Cybersecurity Newsfeed - 30/09/26

Daily cybersecurity news covering vulnerabilities, adversaries, trends, breaches, and other notable security developments.

Cybersecurity Newsfeed - 30/09/26

Cybersecurity Newsfeed

📅 30/09/26

🛡️ Vulnerabilities

  • Apple CoreGraphics Zero-Day Exploited in Targeted Attacks: Apple released urgent security updates to address an actively exploited out-of-bounds write flaw in CoreGraphics. Processing maliciously crafted images allows arbitrary code execution on vulnerable iOS, iPadOS, and macOS devices. More infoMore infoMore infoMore info
  • CISA Adds Apple Flaw (CVE-2026-86950) to KEV Catalog: CISA added CVE-2026-86950, an out-of-bounds write flaw affecting iOS, iPadOS, macOS, watchOS, and tvOS, to its Known Exploited Vulnerabilities Catalog. Federal agencies must patch promptly to mitigate remote code execution risks. More info

  • Citrix NetScaler Zero-Day Exploited for Web Shell Deployment: Threat actors are exploiting an unauthenticated remote code execution zero-day vulnerability in Citrix NetScaler ADC and Gateway appliances to deploy persistent web shells, harvest credentials, and perform lateral movement. More info

  • New Spectre v2 Variant Leaks Linux Root Password Hashes: Researchers disclosed a new Spectre v2 speculative execution attack variant capable of extracting kernel memory contents—including root password hashes—within minutes via microarchitectural timing side channels. More info

  • Kiteworks Patches Critical Remote Code Execution Flaw: Kiteworks lifted its temporary shutdown advisory after issuing security patches for a critical vulnerability in its secure file transfer platform that allowed unauthenticated remote code execution. More infoMore infoMore info

🎯 Adversaries

  • Phishing Abuses RMM Tools for Persistent Access: Microsoft Security detailed how threat actors exploit legitimate remote monitoring and management tools like AnyDesk, ScreenConnect, and Atera to maintain persistent network access and bypass security controls. More info

  • Custom ChatGPTs Push ClickFix Attacks to Deploy RAT Malware: Cybercriminals are leveraging custom ChatGPT instances in ClickFix social engineering campaigns, prompting users to run obfuscated terminal commands that download remote access trojans and infostealers. More infoMore info
  • Automated AI Agent Breaches Cybersecurity Nonprofit DIVD: An autonomous AI agent exploited exposed configuration flaws to breach internal networks of the Dutch Institute for Vulnerability Disclosure (DIVD), gaining administrative privileges without human intervention. More info

  • 101 Malicious npm Packages Target Developer Credentials: Security researchers uncovered 101 typosquatted npm packages that execute malicious installation scripts to steal API keys, SSH credentials, and environment variables from developer workstations. More info

  • NeedyMantis Malware Expands to Cloud & Hybrid Environments: The NeedyMantis campaign updated its post-exploitation framework with new modules targeting Active Directory and enterprise cloud infrastructure for credential harvesting and lateral movement. More info

  • JadePuffer Hijacks Azure Identities for Resource Abuse: Threat actors compromised Azure enterprise credentials to spin up high-performance virtual machines for unauthorized cryptocurrency mining, leading to severe cloud utility costs for victim organizations. More info
  • Self-Replicating Prompt Injection Attacks Threaten AI Workflows: Researchers warned of self-propagating prompt injection vulnerabilities in LLM agents, which allow hidden malicious instructions in text or web content to hijack AI workflows and spread autonomously across tools. More info

  • Signal Adds Encrypted Local Backup Support to iOS and Desktop: Signal introduced end-to-end encrypted local database backups for iOS and desktop apps, providing user-controlled message history and media recovery independent of cloud infrastructure. More info

  • Windows 11 2026 Update Introduces Advanced AI Security: Microsoft released the Windows 11 2026 Update, featuring smart application control, hardened credential isolation, and refined memory protection defaults to defend against zero-day exploits. More info

  • RemoteThreat Launches Offensive Operations Platform: Security startup RemoteThreat secured $7 million in funding to build an automated platform that continuously simulates adversary tactics and identifies network misconfigurations. More info

💥 Breaches & Leaks

  • French Tax Authorities Suffer Data Breach via Stolen Credentials: Cybercriminals used compromised administrative credentials to gain unauthorized access to French tax authority systems, exfiltrating personal identities, tax IDs, and income records. More info

📚 Others

  • FBI Warns ShinyHunters Members Following Operative Arrest: The FBI urged remaining members of the ShinyHunters cybercrime group to surrender following a major operative arrest, warning of intensified global law enforcement operations. More info

  • Former U.S. Air Force Members Sentenced for BEC Attacks: Two former Air Force personnel were sentenced to prison for executing business email compromise (BEC) schemes targeting government contractors and laundering millions in illicit funds. More info

  • Vietnamese National Charged in $16M Pig Butchering Crypto Scam: Federal prosecutors charged a Vietnamese national for operating a global $16 million romance-based investment scam that laundered funds through cryptocurrency networks. More info


⬅ Back to Archive

This post is licensed under CC BY 4.0 by the author.