Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild.
Tag: EN
Meta AI Shares Seller’s Address: Facebook Marketplace Buyer Shows Up at His Home
Meta’s Muse AI shared a Facebook Marketplace seller’s pickup address and arranged a deal that ended with a buyer showing up unexpectedly.
Internet Society Launches Global Online Trust and Safety Hub as Part of Its Safer Internet Initiative
Washignton, DC, USA, 30th September 2026, CyberNewswire
Irony alert: OpenAI whines that Chinese model stole its special IP that it stole from everybody else
US model makers can train on web data – but distilling theirs is a ‘national security risk’
Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026
This year at Microsoft Ignite, we spotlight our AI-first, end-to-end security platform designed to protect identities, devices, data, applications,…
Green Growth Without Washington: Why US Businesses Are Still Investing in Climate Technology
As federal clean-energy support shifts, US businesses are still investing. What is driving them and can corporate demand sustain the momentum?
Citrix Patches Critical Zero Days Under Active Exploitation
Citrix has confirmed exploitation of two critical zero-day RCE bugs
A week in security (September 21 – September 27)
A list of topics we covered in the week of September 21 to September 27 of 2026
http-terminator – AI-Assisted HTTP Request-Smuggling Discovery
http-terminator is PortSwigger’s AI pipeline for discovering HTTP request-smuggling bugs. Which stages run, its dependencies, and its testing limits.
WatchGuard fixes critical Fireware OS flaw allowing remote code execution
WatchGuard fixes 15 Fireware OS flaws, including a critical RCE bug that could give attackers root access to vulnerable Firebox appliances. WatchGuard has…
MALFEX npm Attack Spreads Windows RAT, Steals Discord and Browser Data
CloudSEK uncovered the MALFEX campaign using malicious npm packages to deploy Overlord RAT, steal Discord and browser data,…
Hackers stole millions of US military personnel records during months-long data breach
The Department of Defense notified millions of current and former U.S. military personnel that their personal information had been stolen in a months-long…
Huawei Smartphone Chip Narrows Performance Gap
Latest flagship Kirin 9050 Pro chip uses architectural changes to boost performance despite manufacturing constraints, says Bernstein
Certainties in life: Death, taxes, and critical Citrix vulns under attack
Sunday NetScaler patch dump fixes trio of critical vulns and five more serious messes
New SharePoint exploit, Australian OpenAI hack developments, Kiteworks urges stoppage
Another Microsoft SharePoint flaw now exploited Details and doubts emerge regarding OpenAI hack of Australian Health portal Kiteworks urges customers to…
Medela – 423,947 breached accounts
In September 2026, Swiss medical device company Medela was the target of a ShinyHunters “pay or leak” extortion campaign . The data allegedly obtained in…
PaperPhone Headless Browser Network Uses 75,000 IPs and Fabricated Mobile Identities Across 43 Countries
PaperPhone is a large headless-browser network built to make automated web requests look like ordinary mobile traffic. It does not rely on a single…
When Productivity Extensions Become Attack Platforms
Our research uncovered a campaign of 32 malicious browser extensions that uses remote configs to spy on 9,800+ users and hijack browsing activity.
AI Coding Agents Leak 13,000+ Internal Screenshots From 300+ Companies on GitHub
AI coding agents exposed more than 13,000 internal screenshots from over 300 organizations by publishing them in publicly accessible GitHub repositories,…
The Silent Container Death: A TCP Dial That Never Times Out
A pod goes into CrashLoopBackOff . You pull the logs expecting a stack trace, a panic, an error string – anything that points you somewhere. Instead, you…
