IT Security News Roundup: 2026-10-05

IT Security News: today roundup

  1. A new Citrix NetScaler zero-day flaw causes denial-of-service conditions.
  2. Attackers are scanning Rejetto HFS servers for critical RCE flaws.
  3. Fake Zoom installers are deploying the CloudSyncD backdoor on macOS.
  4. AI agents need action-level security controls to prevent data leaks.
  5. Attackers are exploiting a Rejetto HFS flaw discovered by AI.
  6. Complex role-based access control chains complicate database maintenance tasks.
  7. Italy fined IQVIA $7.8 million over poor health data anonymization.
  8. FBI confirmed multiple arrests linked to the ShinyHunters hacking group.
  9. A Microsoft Exchange flaw allows attackers to read user mailboxes.
  10. Technical University of Denmark suffered a breach exposing 200,000 records.
  11. Europol awarded innovation honors to Spanish, Danish, and Dutch police.
  12. Authorities dismantled a human trafficking network exploiting Indian restaurant workers.
  13. Zero-day vulnerabilities in Zammad enabled an AI agent server breach.
  14. A judge dismissed journalists' Pegasus spyware lawsuit against NSO Group.
  15. Chinese threat group TA419 impersonated officials to target AI experts.
  16. Enterprise AI workflows require specialized data governance for unstructured documents.
  17. Timor-Leste authorities arrested 16 suspects running Japanese police phone scams.
  18. MI5 warned UK academics against China-backed intelligence research funding.
  19. Malicious HEIC image uploads can trigger code execution on WordPress.
  20. Hackers targeted US AI policy experts using Microsoft credential phishing.
  21. ZachXBT infiltrated Lazarus Group’s crypto laundering network after Bybit breach.
  22. A data breach exposed personal records of 8.8 million Danes.
  23. Bromcom exposed email addresses through an unmaintained legacy sign-on service.
  24. Hackers exploited 24 IoT vulnerabilities to deploy the ClingSTUN backdoor.
  25. Debian released a kernel update addressing over 1,300 security flaws.
25
articles summarized
10
sources

Sources in this roundup

CySecurity News – Latest Information Security and Hacking Incidents
5 article(s)
Cyber Security News
4 article(s)
www.theregister.com – Articles
4 article(s)
BleepingComputer
3 article(s)
DZone Security Zone
2 article(s)
Hackread – Cybersecurity News, Data Breaches, AI and More
2 article(s)
News
2 article(s)
Security Affairs
1 article(s)
The Hacker News
1 article(s)
darkreading
1 article(s)

Most-mentioned keywords

data
3 mention(s)
security
3 mention(s)
against
2 mention(s)
attackers
2 mention(s)
authenticated
2 mention(s)
backdoor
2 mention(s)
breach
2 mention(s)
china
2 mention(s)

Sources

  1. Citrix NetScaler security snafus get even worse amid more 0-day reports
  2. Rejetto HFS servers now actively scanned for critical RCE flaw
  3. CloudSyncD Backdoor Spread Through Fake Zoom Installer Targeting macOS
  4. Authenticated Doesn’t Mean Safe: Why AI Agents Need Action-Level Security
  5. Anthropic Mythos Found A Bug in Rejetto HFS. Attackers Are Now Exploiting It.
  6. Nobody Designs an RBAC Mess; Everyone Ends Up With One
  7. IQVIA fined $7.8 million for failing to properly anonymize health data
  8. FBI confirms 'multiple' arrests related to ShinyHunters hack
  9. Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
  10. DTU Data Breach Exposes Information of 200,000 People
  11. Spain, Denmark and the Netherlands win Europol 2026 Excellence Awards in Innovation
  12. International investigation identifies over 70 potential victims exploited in Indian restaurants
  13. Zammad Zero-Day Chain Lets AI Agent Hijack Sessions, Execute Code and Escalate to Root
  14. California Court Dismisses El Faro Journalists' Pegasus Spyware Lawsuit Against NSO Group for Second Time
  15. Chinese Hackers Impersonate US Officials for AI Cyber Espionage
  16. Building Enterprise File-Heavy AI Workflows: From Secure Uploads to Governed Document Intelligence
  17. 16 Suspects Detained in Timor-Leste for Japanese Police Impersonation Scam
  18. China's Ministry Allegedly Funded Research Involving 100+ Academics
  19. Malicious HEIC Images Can Trigger Remote Code Execution on WordPress Servers
  20. China-Aligned TA419 Uses Microsoft AitM Phishing Against U.S. AI Policy Experts
  21. Researcher Infiltrates Lazarus Group’s Crypto Laundering Network After $1.5B Bybit Hack
  22. Denmark population registry data breach affects 8.8 million people
  23. Legacy sign-on service comes back to bite school software provider Bromcom
  24. Hackers Exploit 24 IoT Vulnerabilities to Install ClingSTUN Linux Backdoor
  25. Debian's latest kernel security update has 1,313 reasons to patch