2026-10-05 17:22 UTC
Security Journalism
The Record · indexed 2026-10-05 17:30 UTC
Citrix confirmed late on Friday that it was “tracking a newly observed issue” related to some customer-managed NetScaler deployments but claimed the problem was not connected to vulnerabilities reported last week that also caused alarm among cybersecurity experts.
P0
2026-10-05 17:19 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-10-05 17:25 UTC
Italy's Data Protection Authority (GPDP) has fined IQVIA €7 million ($7.8M) over poor data-processing practices that the agency says could have put roughly one million patients at risk of data exposure and de-anonymization. [...]
P0
2026-10-05 17:00 UTC
Security Journalism
The Record · indexed 2026-10-05 17:30 UTC
Ukraine’s largest grocery store chain, ATB, confirmed that it was hit by a cyberattack after hackers posted an extortion demand on its website.
P0
2026-10-05 16:21 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-05 17:30 UTC
Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system. "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a
P5
2026-10-05 15:52 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-10-05 16:15 UTC
An emerging threat group known as TA419 established seemingly legitimate professional relationships with AI policy experts working for US think tanks, universities, and legal organizations.
P0
2026-10-05 15:30 UTC
Security Journalism
The Record · indexed 2026-10-05 16:00 UTC
A ransomware attack that affected the University of Illinois Chicago (UIC) College of Medicine resulted in the theft of some information from its servers.
P15
2026-10-05 15:21 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-10-05 15:25 UTC
Denmark's Central Population Register (CPR) is warning of a data breach that exposed the personal information of approximately 8.8 million registered individuals. [...]
P0
2026-10-05 14:53 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-05 14:55 UTC
Dell warned customers to patch a critical vulnerability in the System Update (DSU) command-line interface (CLI) deployment tool as soon as possible. [...]
P10
2026-10-05 14:26 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-10-05 14:35 UTC
Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP). The post Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports appeared first on SecurityWeek.
P0
2026-10-05 14:22 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-10-05 14:25 UTC
South Korea's Financial Services Commission (FSC) held an emergency meeting following a series of cyberattacks targeting financial institutions in the country. [...]
P0
2026-10-05 14:20 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-05 15:15 UTC
A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats keep finding leverage in small things that were easy to overlook. There are actively exploited bugs in the mix, cleaner intrusion paths, smarter automation, and a long patch list waiting behind them. Some attacks are getting more capable. Others
P40
2026-10-05 14:00 UTC
Security Journalism
Huntress · indexed 2026-10-05 14:50 UTC
ClickFix attacks leave no file to scan or block, which is why most endpoint tools miss it. See how Huntress Attack Disruption kills the chain in under a second.
P0
2026-10-05 13:57 UTC
Other
Check Point Research · urias@checkpoint.com · indexed 2026-10-05 14:15 UTC
For the latest discoveries in cyber research for the week of 5th October, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Arizona’s state court system has suffered a phishing-led cyberattack after an employee clicked a malicious link. Attackers copied backup files containing protective-order records and more than 150,000 Foster Care Review Board reports […] The post 5th October – Threat Intelligence Report appeared first on Check Point Research.
P0
2026-10-05 13:55 UTC
Security Journalism
The Record · indexed 2026-10-05 14:15 UTC
Russian cybersecurity researchers attributed a quiet two-year espionage campaign to the Belarusian Cyber Partisans, a group better known for public attacks against governments and infrastructure.
P0
2026-10-05 13:49 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-05 14:55 UTC
Hackers accessed names, addresses and CPR numbers of 8.8 million people in Denmark through a third-party company with legal registry access. A hacker broke into the database that holds basically every identifying detail on every person connected to Denmark, living, dead, or long since moved away. Denmark’s digital affairs minister announced it Monday and didn’t […]
P0
2026-10-05 13:33 UTC
Security Journalism
BleepingComputer · Sponsored by tenfold Software · indexed 2026-10-05 13:45 UTC
tenfold has added shared content governance and real-time event auditing to its free Community Edition for organizations with under 150 users. The new features help teams manage Microsoft 365 sharing and investigate suspicious identity activity. [...]
P0
2026-10-05 13:15 UTC
Security Journalism
The Record · indexed 2026-10-05 13:30 UTC
The Japanese media giant Nikkei disclosed a cyber incident involving an employee email account that may have compromised journalistic sources.
P0
2026-10-05 13:10 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-05 13:55 UTC
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Citrix NetScaler flaw tracked as CVE-2026-88779 (CVSS score of 8.7), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Gateway […]
P35
2026-10-05 13:01 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-05 13:05 UTC
The U.S. Department of Justice has announced the arrest of the alleged developer of Ploutus malware, used to steal millions of dollars in ATM jackpotting attacks across the United States. [...]
P0
2026-10-05 13:00 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-05 13:15 UTC
ClingSTUN operates as a back-connect proxy backdoor, sets up persistence, and contains exploits for self-propagation. The post Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws appeared first on SecurityWeek.
P0
2026-10-05 13:00 UTC
Security Journalism
Dark Reading · Rob Wright · indexed 2026-10-05 13:00 UTC
AI-powered attacks are fast, relentless, and automated. How security teams can keep up is top of mind, according to the latest Dark Reading reader poll.
P0
2026-10-05 12:35 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-05 12:55 UTC
Hackers stole patient information from Clover Health Investments and AngMar Management Services in July. The post 250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms appeared first on SecurityWeek.
P0
2026-10-05 12:00 UTC
Government
NIST Cybersecurity Insights · Daniel Eliot · indexed 2026-10-05 13:15 UTC
For small businesses who are often confronted with limited resources, knowing how to get started and where to find support with planning, implementing, or evaluating a cybersecurity risk management strategy can be challenging — sometimes making cybersecurity feel like an insurmountable hurdle. However, there is good news. Many non-profit organizations across the United States have created programs for their local small business communities (in addition to local schools, municipal governments, a…
P0
2026-10-05 12:00 UTC
Security Journalism
The Record · indexed 2026-10-05 12:15 UTC
Denmark is investigating a data breach affecting approximately 8.8 million people after unauthorized users gained access to its national population register.
P0
2026-10-05 11:55 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-05 13:20 UTC
Every modern enterprise depends on credentials. This is how humans, systems, and now AI, all connect to data, services, and each other securely. GitGuardian helps secure that credential layer through three connected capabilities: Detect, Remediate, and Prevent. The journey starts with detection, because organizations first need to understand what credentials exist, where they live, and what they
P0
2026-10-05 11:46 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-05 13:20 UTC
Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said in a report
P0
2026-10-05 11:00 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-05 11:00 UTC
CVE-2026-61500 allows attackers to recover the session-cookie signing key and gain administrative access and RCE. The post Exploitation Hits Rejetto HFS Vulnerability Discovered by AI appeared first on SecurityWeek.
P5
2026-10-05 10:42 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-10-05 11:00 UTC
More than 730 cyber breaches affected over 270 million Americans last year, costing an average of $10 million per breach. The post Senate Passes Bipartisan Bill to Strengthen Healthcare Cybersecurity appeared first on SecurityWeek.
P0
2026-10-05 10:38 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-05 11:30 UTC
Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents. "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history – without users' full knowledge
P0
2026-10-05 10:28 UTC
Security Journalism
BleepingComputer · Mayank Parmar · indexed 2026-10-05 10:40 UTC
OpenAI is expanding ads in ChatGPT, and one of the first new formats will show visual ads while you're generating images. [...]
P0