← Latest brief

Security news.

·Afternoon Brief

Active zero-day exploitation takes center stage today as CISA and Citrix issue urgent warnings for a high-severity flaw impacting NetScaler appliances. Meanwhile, critical vulnerabilities in Microsoft Exchange, Dell deployment tools, and Rejetto HFS are facing active targeting or emergency patching. Elsewhere, massive data leaks hit Denmark and Italian health records, alongside notable international law enforcement arrests targeting major cybercrime syndicates.

THNZERO-DAY
1d agoREAD

Citrix NetScaler Zero-Day Under Active Attack

Citrix has issued emergency updates and CISA added CVE-2026-88779 (CVSS 8.7) to its KEV catalog following targeted exploitation of a memory overflow bug that disrupts SAML deployments.

THNPATCH
1d agoREAD

Out-of-Band Microsoft Exchange Patch Fixes Privilege Escalation

Microsoft released emergency fixes for CVE-2026-96940 (CVSS 8.8), an authorization flaw that enables authenticated attackers to elevate privileges and access unauthorized user mailboxes.

THNRCE
1d agoREAD

Rejetto HFS Flaw Exploited for Session Forgery and RCE

Attackers are actively targeting CVE-2026-61500 (CVSS 9.3) in Rejetto HTTP File Server, where weak pseudo-random number generation allows adversaries to predict session keys and execute remote code.

BLEEPINGVULN
1d agoREAD

Dell Warns of Root Privilege Escalation Flaw in System Update

Dell has urged administrators to immediately patch a critical vulnerability in its System Update (DSU) command-line interface tool that allows attackers to obtain root privileges.

BLEEPINGBREACH
1d agoREAD

Danish Population Registry Breach Exposes 8.8 Million Records

Denmark’s Central Population Register suffered a severe security incident exposing personal data belonging to approximately 8.8 million registered citizens.

SECURITYWEEK
1d agoREAD

Key ShinyHunters Extortion Group Member Detained in Jordan

An alleged core operative known as "Rey" has been arrested in Jordan and is reportedly cooperating with the FBI to identify other members of the data extortion syndicate.

BLEEPINGMALWARE
1d agoREAD

Alleged Ploutus ATM Malware Developer Arrested in the US

The U.S. Department of Justice announced the arrest and court appearance of the suspected developer behind the prolific Ploutus jackpotting malware family.

BLEEPINGAI
1d agoREAD

Google Suspends Open-Source Bug Bounty Over AI-Generated Spam

Google temporarily paused vulnerability intake for its Open Source Software Vulnerability Reward Program (OSS VRP) following a massive deluge of invalid, automated submissions.

Generated twice daily from public security RSS feeds. Informational only.