Security news.
Today's security landscape is dominated by critical zero-day patching across Apple devices and ongoing exploitation of Citrix NetScaler gateways. Meanwhile, massive infrastructure incidents continue to unfold with a multi-million-record Pentagon agency breach and severe supply-chain fallout hitting the cryptocurrency sector. Developers and administrators must also contend with critical flaw disclosures across enterprise tools like Kiteworks and emerging AI infrastructure.
Apple Patches Actively Exploited CoreGraphics Zero-Day
Apple issued emergency security updates for older iOS, iPadOS, and macOS releases to address CVE-2026-86950, an out-of-bounds write flaw in CoreGraphics being exploited in targeted, sophisticated attacks.
CISA Flags Actively Exploited Citrix NetScaler Zero-Days
CISA added two critical NetScaler ADC and Gateway flaws, CVE-2026-88771 and CVE-2026-88772, to its Known Exploited Vulnerabilities catalog following active in-the-wild exploitation.
Pentagon Personnel Agency Breach Impacts 3 Million People
The Defense Manpower Data Center (DMDC), which manages Department of Defense personnel records, suffered a data breach exposing sensitive information for approximately 3 million individuals.
Bitget Heist Traced to Third-Party Security Product Flaw
Cryptocurrency exchange Bitget revealed that a vulnerability in an external security tool allowed attackers to obtain administrative credentials and execute fraudulent withdrawals totaling nearly $388 million.
Kiteworks Resolves Critical Flaw Behind Server Shutdowns
Kiteworks released a patch for a critical vulnerability and lifted emergency guidance that had previously instructed enterprise customers to take their appliances offline.
MCP Python SDK Vulnerability Leaks OAuth Credentials
Maintainers patched a flaw in the official Model Context Protocol (MCP) Python SDK that allowed rogue MCP servers to harvest sensitive OAuth tokens, client secrets, and PKCE keys from client applications.
Over 16,000 Misconfigured Supabase Databases Exposing Secrets
Security researchers uncovered thousands of misconfigured Supabase instances publicly exposing tables containing personally identifiable information, account passwords, and enterprise authentication tokens.
Dutch Authorities Arrest Convicted Hacker in ShinyHunters Probe
Police in the Netherlands detained a 24-year-old hacker in Amsterdam tied to the prolific extortion group ShinyHunters, which recently claimed extensive data compromises against law enforcement personnel.