Citrix confirmed two critical NetScaler zero-days were exploited before patches were available, with attackers able to remotely execute code. Citrix…
Tag: EN
Citrix Confirms NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attack
Citrix has released emergency security updates for NetScaler ADC and NetScaler Gateway after confirming that attackers are exploiting two critical remote…
Kiteworks Urges 6-Hour Server Shutdown Over Potential Zero-Day Attacks
Secure file-sharing provider Kiteworks issued an urgent advisory urging customers to power down their servers for a six-hour window following credible…
New Windows Process Injection Attack Evades EDR Monitoring Without WriteProcessMemory
A Windows process injection method disclosed by security researcher Two Seven One Three sidesteps two APIs closely associated with remote code injection:…
SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 1
Security Affairs AI-CYBERSECURITY newsletter includes a collection of the best articles and research on AI in the international landscape Artificial…
Six arrests for smuggling migrants via Schengen airports
Europol supported a migrant smuggling investigation involving law enforcement authorities from 17 countries. The criminal network was also engaged in…
Wireshark 4.6.9 Released, (Sun, Sep 27th)
Wireshark release 4.6.9 fixes 19 vulnerabilities and 16 bugs.
x47.c Windows Botnet Uses xAI Grok for Persistence and AI Credit Draining
A new Windows botnet called x47.c is being sold with a range of capabilities, including credential theft, distributed denial-of-service (DDoS) attacks,…
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 116
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter…
Bitget Hack Climbs to $387.5 Million as Exchange Launches Recovery Bounty and Points to North Korea
Crypto exchange Bitget confirmed on September 25 that hackers stole approximately $387.5 million from its hot and warm wallets a day earlier, revising an…
Security Affairs newsletter Round 597 by Pierluigi Paganini – INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email…
Hacking and Extortion Operation Targeting U.S. Official Ends in Conviction
A former U.S. Army soldier, Cameron John Wagenius, has been sentenced to 70 months in prison for participating in a hacking and extortion campaign which…
Rydox Admin Faces 20 Years After Selling Stolen Data and Fraud Tools
Kosovo national Ardit Kutleshi pleaded guilty to running Rydox, a cybercrime marketplace that sold stolen identities and credentials for years. Ardit…
Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28.
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively…
Week in review: Gyazo breach exposes 23.6M user data, TASK#STOMP steals documents
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Know what was tested before your SAP ECC migration goes…
Citrix NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attacks
Citrix NetScaler administrators are confronting reports of two undisclosed remote code execution vulnerabilities allegedly exploited in real-world…
Placeholder Domains Used by 349 AI Agent Skills Found Redirecting to Scams
Manifold Security found placeholder domains cited in 359,000 GitHub files and 349 AI agent skills serving cloaked scam…
Red Hat Enterprise Linux 10 STIG automation now matches DISA STIG V1R2
For the U.S. Department of Defense (DoD) and its contractors, security has to hold up against a published baseline—not a general claim that systems are…
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider…
