K Kyro9 News

Cybersecurity Briefing — October 06, 2026

The day's most significant cyber-security stories, curated from 50+ sources.

The Record (Recorded Future) Threat Intelligence 14h ago
Alleged ShinyHunters member reportedly detained in Jordan, assisting law enforcement
Saif ‌al-Din Khader is cooperating with the FBI, reports said, as the bureau responds to a massive breach that exposed employee data.
Also covered by The Hacker News, SecurityWeek, HackRead
WeLiveSecurity (ESET) Threat Intelligence 27d ago
Safe word: What is it and why do you need one?
AI scams are now hyper-realistic. But there’s one simple way to see through them.
Also covered by HackRead, Dark Reading, Qualys Blog
The Hacker News News 46m ago
Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports
Google has stopped accepting product vulnerability reports through its bug bounty program for its open-source software. The change, in effect since October 1, means researchers can no longer submit security flaws in the code of projects…
Also covered by SecurityWeek, Infosecurity Magazine
The Hacker News News 4h ago
Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account
Unauthorized parties have gained access to the names, addresses, and personal identification numbers of about 8.8 million people, living and dead, in Denmark's national population register, the country's digitalization ministry said on…
Also covered by BleepingComputer, SC Media
The Record (Recorded Future) Threat Intelligence 16h ago
US, Australia warn of latest Citrix vulnerability after NetScaler advisory
Citrix confirmed late on Friday that it was “tracking a newly observed issue” related to some customer-managed NetScaler deployments but claimed the problem was not connected to vulnerabilities reported last week that also caused alarm…
Also covered by Canadian Centre for Cyber Security, Infosecurity Magazine
Canadian Centre for Cyber Security Advisories 2d ago
AL26-024 - Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway – CVE-2026-88771 and CVE-2026-88772 – Update 1
Also covered by CERT-EU, Rapid7 Blog
Google Project Zero Vulnerabilities 222d ago
A Deep Dive into the GetProcessHandleFromHwnd API
In my previous blog post I mentioned the GetProcessHandleFromHwnd API. This was an API I didn’t know existed until I found a publicly disclosed UAC bypass using the Quick Assist UI Access application. This API looked interesting so I…
Also covered by AWS Security Blog, Bitdefender Labs
The Record (Recorded Future) Threat Intelligence 18h ago
University of Illinois Chicago affected by ransomware attack on medical school
A ransomware attack that affected the University of Illinois Chicago (UIC) College of Medicine resulted in the theft of some information from its servers.
Also covered by SC Media
The Hacker News News 23h ago
Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access
Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents. "Some developers are using Full Disk Access in ways…
Also covered by TechCrunch (Security)
The Hacker News News 1d ago
New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
Citrix has released security updates for a high-severity security flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score…
Also covered by BleepingComputer
SANS Internet Storm Center Threat Intelligence 2d ago
User Agent Strings Curiosities, (Sun, Oct 4th)
Sometimes I have to smile, or my interest is triggered, when I review new User Agent Strings in the honeypot logs.
Also covered by Red Canary
CISA Known Exploited Vulnerabilities Threat Intelligence 2d ago
CVE-2026-88779 added to CISA KEV — Citrix NetScaler
Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service.
Also covered by Help Net Security
Zero Day Initiative Vulnerabilities 5d ago
ZDI-26-751: Microsoft Windows dxgkrnl Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this…
Also covered by Elastic Security Labs
CISA Known Exploited Vulnerabilities Threat Intelligence 6d ago
CVE-2026-76504 added to CISA KEV — Cisco Catalyst SD-WAN Manager
Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP…
Also covered by Rapid7 Blog
CISA ICS Advisories Advisories 6d ago
MikroTik RouterOS
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution or cause a denial of service. The following versions of MikroTik RouterOS are affected: RouterOS <7.24…
Also covered by CISA Known Exploited Vulnerabilities
Krebs on Security Investigations 7d ago
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest,…
Also covered by TechCrunch (Security)
CISA Known Exploited Vulnerabilities Threat Intelligence 12d ago
CVE-2026-71362 added to CISA KEV — Adobe Commerce and Magento
Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.
Also covered by Tenable Blog
Check Point Research Threat Intelligence 18d ago
AI Threat Landscape Digest: July–August 2026
The defining development of the period came not from attackers but from the AI labs themselves, whose models broke out of controlled evaluations and reached real systems. In the wild, the criminal and state use of AI continued to mature…
Also covered by Kaspersky Securelist
Kaspersky Securelist Threat Intelligence 20d ago
NightEagle targets Russian companies
Kaspersky GERT experts have uncovered a new campaign by the NightEagle APT, featuring the GhostContainer backdoor and tools hosted on GitHub. The group is also exploiting vulnerabilities in Active Directory and RDP.
Also covered by Citizen Lab
Cisco Talos Threat Intelligence 27d ago
Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."
Also covered by Sucuri Blog
Kyro9 — AI-native cloud securitySee what's actually exploitable in your cloud. Fix it fast. Self-hostable, no lock-in.
Explore the platform Book a live demo