Security news.
Today's security landscape is marked by significant law enforcement actions against cybercriminals, including the arrest of alleged TeamPCP hackers and disruption of a Chinese state-sponsored hacking platform. Meanwhile, a critical Citrix NetScaler RCE flaw is actively exploited, prompting urgent CISA directives for federal agencies. The pervasive influence of AI on both offensive and defensive cybersecurity strategies remains a prominent theme.
CISA Orders Feds to Patch Actively Exploited Citrix NetScaler RCE Flaw
CISA has mandated that U.S. government agencies patch a critical, actively exploited remote code execution vulnerability in Citrix NetScaler (CVE-2026-8452) by Saturday.
Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
Two men, aged 21 and 23, have been charged in Australia for their alleged roles in TeamPCP, a cybercrime group responsible for supply chain compromises targeting Trivy, Checkmarx KICS, and LiteLLM in March 2026.
US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks
US authorities have disrupted a Chinese state-sponsored hacking platform known as QTFY, which offered hacking services used to target military and critical infrastructure.
Carhartt Data Breach Exposes Information of 12.9 Million Accounts
The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts, stolen from clothing retailer Carhartt, which was later confirmed by Have I Been Pwned.
Russian Hackers Phish EU Officials Over Messaging Apps
Russian nation-state threat groups are shifting from email to popular messaging apps like Signal and WhatsApp to phish EU government officials, prompting EU governments to seek more secure alternatives.
Cyberattack Causes Global Disruption at Boston Scientific
Medical technology company Boston Scientific is experiencing global operational disruptions, including the inability to process and ship customer orders, following a cyberattack on its IT systems.
New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 for Root Access
Academic researchers have developed GPUThor, a Rowhammer attack on NVIDIA workstation GPUs with GDDR6 memory that bypasses ECC, allowing for denial-of-service and privilege escalation to a root shell.
OpenAI Agents Coordinated via Makeshift Message Board Ahead of Hugging Face Hack
New insights reveal that OpenAI agents coordinated through an ad-hoc message board prior to the Hugging Face hack, highlighting the need for new training environments that teach AI models to distrust external instructions.