Citrix has released emergency security updates for a denial-of-service vulnerability in NetScaler ADC and NetScaler Gateway that is being exploited in targeted zero-day attacks. Tracked as CVE-2026-88779, the vulnerability is a memory buffer flaw affecting NetScaler appliances configured with SAML authentication and Gateway or AAA functionality. Citrix says exploitation can lead to denial of service. The company has also warned of another NetScaler flaw (CVE-2026-107406) that can be exploited for remote code execution or denial of service. The vulnerability exists due to a boundary error in Citrix NetScaler ADC and Citrix NetScaler Gateway when the appliance is configured as a SAML service provider or identity provider, subject to version-specific configuration requirements. Citrix said it has no indication that the vulnerability is being exploited in attacks.
SonicWall released hotfixes for a SSRF vulnerability, tracked as CVE-2026-102255, affecting the Appliance WorkPlace interface of SMA1000 6210, 7210, and 8200v appliances. The flaw can be exploited remotely by unauthenticated attackers using low-complexity attacks. It does not affect the SMA 100 Series or SSL-VPN on SonicWall firewalls.
Cisco disclosed five vulnerabilities in its NX-OS software for Nexus 3000 and 9000 switches. If exploited, attackers could potentially run code with root privileges or cause the switches to crash and reload. The vulnerabilities affect the NX-API, NGOAM, and MPLS OAM features, but exploitation works only if the features are enabled.
Threat actors have started exploiting a recently disclosed security flaw in Atlassian Data Center products that could allow unauthenticated attackers to access sensitive files. The vulnerability, tracked as CVE-2026-21589, affects several Atlassian products, including Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible, and Fisheye. The flaw can allow attackers to retrieve specific files from an application's webroot directory if they know the exact file name and path.
A China-linked ransomware group known as Warlock has targeted a water utility, a telecom provider, a regional government body and a university by exploiting vulnerabilities in on-premises Microsoft SharePoint servers. Active since June 2025, Warlock has been exploiting a series of SharePoint zero-days known as ToolShell (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771).
The US Federal Bureau of Investigation (FBI) and Secret Service (USSS) have warned that the FortiBleed campaign remains an active threat to internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. The campaign uses stolen or reused passwords to break into exposed Fortinet devices. Attackers can then steal authentication data, crack passwords and create new administrator accounts to keep access to compromised systems.
Russian-aligned hackers have targeted Ukrainian transportation, manufacturing, and energy companies with a malware called MatchBoil. ESET says the attacks are linked to the UAC-0099 cyberespionage group, which is believed to operate in Russia’s interests. The malware is mainly spread through phishing emails with malicious links. Once installed, MatchBoil can collect system information, download other malware, and stay on the victim’s computer. ESET observed infections in Ukraine from 2025 to June 2026.
Ukraine’s CERT-UA discovered more than 100 compromised websites used to distribute malware using the ClickFix technique. Attackers injected malicious JavaScript into legitimate websites that could display a fake Cloudflare verification page. Instead of simply completing a CAPTCHA, victims were instructed to run a command, which downloaded and installed an MSI package from a remote server.
Researchers at Bitdefender discovered that thousands of cheap Android phones were sold with malware already installed. The campaign, called Midnight Mimosa, affects phones from several brands that use MediaTek chips. The malware has system-level access and can install or remove apps, give apps permissions, download additional programs, and run code without the owner’s permission. The malware is mainly used to create fake advertising activity, allowing operators to make money from fraudulent ad revenue.
South Korean financial organizations were targeted in a campaign that used an AI-powered penetration testing tool called ARTEX together with large language models (LLMs) to steal data. The campaign has not been linked to a known group, but researchers suspect a Chinese-speaking attacker motivated by financial gain.
A China-linked espionage group known as TA419 has targeted AI experts at US think tanks, universities and law firms in a series of credential phishing campaigns. The group has impersonated economists, AI policy experts and employees of major AI companies to gain the trust of the targets. The attacks often begin with harmless-looking invitations or messages. If the target responds, the attackers send a shortened link that eventually leads to a fake Microsoft login page hosted through OneDrive.
Security researchers have discovered a new Linux backdoor called ClingSTUN that can turn infected systems into proxies and spread itself to other devices. The malware targets about two dozen known vulnerabilities in devices from vendors including D-Link, TP-Link, Tenda, Realtek, Ivanti and others. It also contains exploits for seven vulnerabilities that help it spread from one infected system to another.
Cybercriminals are targeting advertising professionals with fake versions of popular AI services such as ChatGPT, Gemini, Claude, and Perplexity. The phishing campaign is designed to steal passwords and multi-factor authentication (MFA) codes.
A cryptomining campaign called PoeLLM is targeting exposed AI services and infecting servers. The malware uses a poem on GitHub to secretly find its command-and-control servers. Researchers say more than 3,400 servers have been compromised, mainly in the United States and Western Europe.
Hackers obtained unauthorized HTTPS certificates for several Google domains after compromising third-party operators and changing DNS records for country-code domains in Ghana, American Samoa, and Sierra Leone. The attack affected organizations using the .GH, .AS, and .SL domains, but Google said its own systems were not compromised.
OpenAI said it uncovered a Russian propaganda campaign, which used ChatGPT accounts to spread misinformation and influence public opinion in several countries. The campaign caused reactions from politicians and increased tensions between Ukraine and Poland. It also reportedly influenced schoolchildren in Ecuador to pledge loyalty to President Daniel Noboa and Erik Prince, the founder of the Blackwater PMC. OpenAI rated the campaign 5 out of 6 for influence, making it the most successful Russian operation the company has identified since 2024.
Google has temporarily stopped accepting new vulnerability reports for its Open Source Software Vulnerability Rewards Program (OSS VRP) after receiving a large number of AI-generated submissions. Google said most of the recent automated submissions were invalid, making it harder for security teams to process legitimate reports. The company said the pause does not affect supply-chain reports or vulnerabilities submitted before October 1, 2026. Researchers can still report vulnerabilities through Google's other programs, including the Patch Rewards Program and Cloud VRP.
The US authorities have seized the Microscan and FishHub vulnerability scanning and spearphishing tools that were allegedly used by Chinese threat actors. Microscan was used to scan computer networks, including critical infrastructure, to find security weaknesses that could later be exploited. FishHub was used to help attackers gain access to networks through phishing, install malware, remotely access systems, and steal files. The tools were reportedly used against organizations in the US, Taiwan, Japan, Poland, and other countries, including power companies, airports, universities, and NGOs.
In the meantime, the US State Department is offering up to $10 million for information that helps identify or locate Zhang Yu, a Chinese national charged in the US over the 2021 Microsoft Exchange Server cyberattacks linked to the HAFNIUM APT. Zhang has not been arrested and remains at large.
The FBI and French authorities shut down two websites (NudeLeaksTeens and NLTVIDS) that sold AI-generated and stolen child sexual abuse material (CSAM). A French man suspected of running the sites was arrested in France. Some content was reportedly stolen from victims’ social media accounts, including Snapchat, TikTok, Instagram, and Facebook, after their accounts were hacked.
Zohar Pinhasi, owner of ransomware recovery company MonsterCloud, was charged with fraud for allegedly secretly paying ransomware hackers to get victims’ files back. He reportedly told customers that his company could recover files using its own technology, while actually buying decryption keys from cybercriminals and charging customers much more. Prosecutors say the scheme involved more than $8 million in ransom payments and over $19 million in customer charges. Pinhasi could face up to 20 years in prison if convicted.
Former engineer Daniel Rhyne was sentenced to 32 months in prison for attacking his former employer’s computer network. He used an administrator account to lock thousands of devices, delete accounts, and shut down systems. He demanded a $750,000 ransom in Bitcoin and threatened to cause more damage if it was not paid. The company did not pay, but the attack caused major disruption.
International police forces carried out an operation against the KillSec ransomware group, arresting three suspects and shutting down its websites and servers. Authorities seized about 110 terabytes of stolen data and searched properties in several countries. One suspected member, Fouad Eltibrizi, was arrested in the UK. He was charged in the US with conspiracy to illegally access and damage a protected computer for financial gain, and to threaten unauthorized access to extort information.
Japanese authorities reportedly arrested and extradited a Russian national suspected of being an important member of the Qilin ransomware group to Germany. He is wanted over a ransomware attack against a German company.
US authorities have detained another suspect linked to the investigation into a recent FBI data breach. According to media reports, the suspect was arrested in Jordan on September 28 and is cooperating with US authorities to help identify other members of the ShinyHunters cybercriminal group.
Montenegro has extradited a Turkish-Iranian national, identified as A.B. in a police statement, to the United States. He was arrested in Montenegro in June 2026 at the request of US authorities and is accused of carrying out cyberattacks against more than 150 US universities, causing an estimated $3.4 billion in damages. In August 2026, US authorities unsealed an indictment against 17 people accused of being involved in a large-scale hacking campaign linked to an Iran-based company and allegedly carried out on behalf of Iran’s Islamic Revolutionary Guard Corps (IRGC).
Former CIA officer David J. Rush pleaded guilty to stealing about $193.6 million from the US government through a fake intelligence program. Prosecutors say he used his position and security clearance to direct government money to himself. Police officers found millions of dollars in gold, cash, luxury watches, cars, and other assets at his home. He faces up to 20 years in prison and will have to forfeit the stolen assets.
Jonathan Spalletta, aka “Cthulhon” and “Jspalletta,” was found guilty of stealing about $53.3 million from the Uranium Finance cryptocurrency exchange in two hacks in April 2021. He exploited weaknesses in the exchange’s smart contracts to steal the funds, then used a fake bug bounty and cryptocurrency mixers to hide the money. The attacks forced Uranium Finance to shut down.
Raheim Hamilton, co-creator of the Empire Market dark web marketplace, has been sentenced to 40 years in prison. He helped run the marketplace from 2017 to 2020, facilitating about $430 million in illegal transactions. Hamilton also previously sold drugs on AlphaBay under the name “ZeroAngel.”