This website uses cookies

Read our Privacy policy and Terms of use for more information.

Summary: Citrix released emergency updates for CVE-2026-88779, a memory-overflow flaw (CVSS 8.7) in NetScaler ADC and NetScaler Gateway when the appliance is configured as a SAML service provider or SAML identity provider. Citrix said it has observed targeted attacks on unmitigated deployments that can cause denial of service, and that repeated triggers can keep the service unavailable. Fixed builds are 14.1-73.41 and 13.1-64.28, plus 14.1-73.41 FIPS and 13.1-37.282 for FIPS and NDcPP.

CISA added the bug to the Known Exploited Vulnerabilities catalog on October 4 and gave federal civilian agencies until October 7 to mitigate it. Citrix says its analysis has not identified an impact on customer data integrity. Researchers, including Kevin Beaumont, reported crash sequences and, on at least one patched honeypot, a downloaded malware binary; Citrix has not confirmed remote code execution.

Key takeaway / Actionable note: If SAML is configured (authentication samlAction or authentication samlIdPProfile), upgrade again even if you already installed the builds for CVE-2026-88771 and CVE-2026-88772, then check for unexpected reboots and unexpected binaries.

Summary: VulnCheck says exploitation attempts against CVE-2026-61500 (CVSS 9.3) in Rejetto HTTP File Server were detected on October 1, including an unnamed actor in China targeting vulnerable hosts in the United States. Versions 3.0.0 through 3.2.0 derive the session-cookie signing key from JavaScript Math.random() and expose outputs of the same generator to unauthenticated clients during login.

An attacker who reconstructs the generator state can forge an administrator session cookie and reach remote code execution through the server_code configuration feature. The fix shipped in version 3.2.1 in July 2026; a public proof of concept followed in late September. Horizon3.ai said Anthropic’s Mythos model was used in discovery of the bug.

Key takeaway / Actionable note: Inventory internet-facing HFS instances and move anything below 3.2.1 off the network until it is upgraded.

Summary: SecurityWeek, citing Reuters, reports that Saif al-Din Khader, known as Rey, a teenage cybercriminal from Amman and a known member of Scattered Lapsus$ Hunters, was detained in Jordan and is helping the FBI identify other ShinyHunters members. It is unclear where he is held.

The detention followed the group’s defacement of the FBI jobs site, FBIJobs.gov, and a sample list of about 5,000 FBI employees sent to the media. Last week Dutch police arrested a 24-year-old Amsterdam man in the same FBI investigation; independent reporting has identified him as Pepijn van der Stap. FBI Director Kash Patel posted that more arrests are on the table.

Key takeaway / Actionable note: Treat ShinyHunters extortion as still active, and re-check Oracle PeopleSoft exposure tied to CVE-2026-35273, including WAF rules the group has already bypassed.

Summary: Clover Health Investments and AngMar Management Services are notifying more than 250,000 people after separate thefts of patient information. Clover Health, of Jersey City, told HHS in mid-September that 138,677 people were affected after attackers used social engineering in early July to compromise three non-managerial health-plan employee accounts. Data included names, dates of birth, insurance identifiers, and account identification numbers.

Mansfield, Texas-based AngMar, which supports home health and hospice providers, notified HHS on September 16 that 126,196 people were affected. Stolen data included Social Security numbers, diagnoses, medical history, insurance, prescription details, and dates of service. Interlock listed AngMar on its leak site in August, claiming more than 700 gigabytes.

Key takeaway / Actionable note: Health-plan and home-health vendors should treat help-desk social engineering as the entry point and confirm whether Interlock-related notifications are still outstanding.

Summary: Proofpoint attributes credential-phishing campaigns to TA419, a China-aligned actor it has tracked since at least April 2025 against U.S. and Japan think tanks, defense contractors, universities, and law firms. The campaigns impersonated economists, AI policymakers, and an Anthropic employee.

One February 2026 lure to an AI policy expert at a U.S. think tank used the subject “Request for Feedback on Military Integration of Claude.” Around July 2026 the actor impersonated several people, including a former White House Office of Science and Technology Policy leader.

Harmless invitations establish trust; a reply is followed by a shortened URL, a Cloudflare Turnstile check, and a OneDrive adversary-in-the-middle page using a frameless browser-in-the-browser kit that captures the Microsoft session.

Key takeaway / Actionable note: AI-policy and legal teams should require phishing-resistant passkeys and verify unsolicited subject-matter outreach before opening any follow-up link.

Summary: A Montenegrin court approved sending Amir Barati, 40, a dual Turkish and Iranian citizen, to the United States after his June 25 arrest in Kotor. Montenegro’s police said he is accused of conspiracy to commit computer fraud, computer hacking, and identity theft as an associate of an Iranian entity, with alleged attacks on more than 150 U.S. universities and damage estimated above $3.4 billion.

U.S. prosecutors have named him in a 14-count indictment of 17 people tied to the Mabna Institute and alleged Islamic Revolutionary Guard Corps-backed theft. Prosecutors say the campaign stole at least 31 terabytes and compromised roughly 8,000 professor email accounts between 2013 and 2017.

Key takeaway / Actionable note: Universities should keep faculty mailbox and journal-access logs under review; this case is a prosecution milestone, not a new intrusion wave.

Summary: MI5’s September 30 Security Service Espionage Alert names the China General Technology Research Institute (CGTRI) as an outfit whose primary purpose is to fund research that improves Ministry of State Security technical capability.

The alert says more than 100 UK-linked academics contributed to projects funded by the MSS via CGTRI, and that some may not have known CGTRI was the funder.

Named fields include artificial intelligence, cybersecurity, covert communications, and steganography. MI5 told institutions to review ongoing or planned collaboration and warned that continued work could raise issues under sections 3 and 17 of the National Security Act 2023.

A Chinese embassy spokesperson called the accusations fabricated. The UK China Transparency think tank has previously linked CGTRI staffing to the University of International Relations.

Key takeaway / Actionable note: Research offices should trace ultimate funding on China-linked projects and pause CGTRI collaboration pending legal review.

Summary: Apple told developers it will update Full Disk Access so that level of access is granted only with an explicit user action. It said some developers are using the setting in ways that can expose files, mail, messages, and browsing history without users fully understanding the risk. Timing of the change was not given. The note follows reporting that Meta’s Muse agent read a journalist’s iMessages after Full Disk Access was granted; Meta CTO David Singleton said Messages access also requires the Messages connector to be enabled. Researcher Patrick Wardle has separately demonstrated a now-patched Muse Mac issue and was credited on CVE-2026-100754 in OpenAI’s ChatGPT Mac app.

Key takeaway / Actionable note: Review which Mac apps have Full Disk Access, and do not grant it to agentic tools that also hold mail, messages, or browser connectors.

Also Noted:

Bottom line

The weekend’s highest-priority item is edge gear, not a new ransomware brand. NetScaler appliances configured for SAML were crashing after last week’s patches, Citrix has now shipped CVE-2026-88779 fixes, and CISA’s federal deadline is Wednesday. Pair that upgrade with a sweep for Rejetto HFS below 3.2.1 and for unsolicited AI-policy lures that only turn malicious after a reply.

Reply

Avatar

or to participate