Cyber Security Week in Review: October 2, 2026
In brief: Cisco, Citrix, Apple patch zero-days in their software; DIVD, Belnet, Bitget breached via zero-day flaws; and more.
In brief: Cisco, Citrix, Apple patch zero-days in their software; DIVD, Belnet, Bitget breached via zero-day flaws; and more.
Separately, Microsoft has warned that threat actors are exploiting a Zimbra vulnerability to remotely execute commands, deploy web shells, and access email and authentication data.
The attackers compromised two security appliances and installed a web shell on one device and deployed malware and a custom withdrawal tool on a production wallet server.
Researchers say the attacks can exploit the NetScaler Packet Processing Engine and result in root-level access on the underlying FreeBSD system.
Microsoft has observed Star Blizzard targeting Ukrainian individuals and institutions, as well as international NGOs, think tanks, governments and financial organizations involved in supporting Ukraine.
Authorities have not released the man's name or other details about the case.
The flaw was exploited in an “extremely sophisticated” attack against specific individuals using versions of iOS before iOS 27.
The attackers performed more than 300 discovery operations before beginning the destructive activity.
Cameron John Wagenius is the third man prosecuted in connection with the 2024 Snowflake data theft campaign.
CVE-2026-35273 allows unauthenticated remote code execution on vulnerable servers.
Showing elements 1 - 10