{"date_iso":"2026-09-30","date_human":"Wednesday, September 30, 2026","generated_utc":"2026-09-30 15:13 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"RATHat Android Malware Uses Gemini AI to Control Phones Outside Normal App Permissions","link":"https://cybersecuritynews.com/rathat-android-malware/","reason":"Android","category":"News","sources":["Bleeping Computer","CISA Alerts & Advisories","CISA ICS Advisories","Cyber Security News","GitHub Security Lab","The Hacker News","The Record"],"coverage":7,"cve_ids":[],"summary":"RATHat Android malware uses Gemini AI to help take control of infected phones beyond normal app permissions. The banking trojan abuses a developer feature to establish a separate command channel that can survive removal\u2026","source":"Cyber Security News","date_rel":"5h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/RATHat-Android-Malware-Uses-Gemini-AI-to-Control-Phones-Outside-Normal-App-Permissions.webp","description":"RATHat Android malware uses Gemini AI to help take control of infected phones beyond normal app permissions. The banking trojan abuses a developer feature to establish a separate command channel that can survive removal of the malicious application until the phone reboots. Attackers distribute it through malicious adverts and phishing text messages targeting Europe, Latin America and Southeast Asia. Fake apps lure victims into granting Accessibility access, extending the risks described in earlier RatHat banking attacks with deeper control over the device. Cleafy researchers identified three\u2026","related":[{"title":"Mobile malware warning from Ukrainian researchers includes iPhone exploit kit","link":"https://therecord.media/ukraine-ssscip-mobile-malware-warning-ios-android","source":"The Record","date_rel":"1h ago"},{"title":"Signal adds encypted local backup support to iOS, desktop apps","link":"https://www.bleepingcomputer.com/news/security/signal-adds-encypted-local-backup-support-to-ios-desktop-apps/","source":"Bleeping Computer","date_rel":"17h ago"},{"title":"Viidure Dashcam Android Application","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-07","source":"CISA Alerts & Advisories","date_rel":"29 Sep"},{"title":"Viidure Dashcam Android Application","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-07","source":"CISA ICS Advisories","date_rel":"29 Sep"},{"title":"How we found 24 Android vulnerabilities using our open source AI security agent","link":"https://github.blog/security/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent/","source":"GitHub Security Lab","date_rel":"28 Sep"},{"title":"RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims","link":"https://thehackernews.com/2026/09/rathat-android-malware-console-uses.html","source":"The Hacker News","date_rel":"28 Sep"}]},{"title":"Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771)","link":"https://labs.watchtowr.com/oh-look-the-foot-gun-went-off-again-citrix-netscaler-preauth-command-injection-cve-2026-88771/","reason":"CVE-2026-88771","category":"Research","sources":["CCCS Alerts & Advisories","Palo Alto Unit 42","Rapid7 Blog","SecurityWeek","Sophos Threat Research","watchTowr Labs"],"coverage":6,"cve_ids":["CVE-2026-88771","CVE-2026-88772"],"summary":"God damn it, we're back in the room again. Yes, that sound in your ears is screaming. The footgun has gone off again, shockingly, and we are yet again dealing with a situation where the entire world apparently knew\u2026","source":"watchTowr Labs","date_rel":"28 Sep","thumbnail":"https://storage.ghost.io/c/a0/dc/a0dcbbe4-0ae7-4d7e-90f7-ebbc3a0f5a84/content/images/2026/09/ohlooooook.png","description":"God damn it, we're back in the room again. Yes, that sound in your ears is screaming. The footgun has gone off again, shockingly, and we are yet again dealing with a situation where the entire world apparently knew about Citrix NetScaler CVEs before Citrix had woken up or bothered to acknowledge them. https://www.citrix.com/blogs/2026-01/security-by-design-proven-by-action-with-citrix-netscaler On Saturday, we took our role in the industry seriously - by rapidly adding credibility to the rumors via the (inter)national authorities that we've historically worked with, and then broadcasting that\u2026","related":[{"title":"Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks","link":"https://www.securityweek.com/government-finance-orgs-targeted-in-weeks-long-netscaler-zero-day-attacks/","source":"SecurityWeek","date_rel":"2h ago"},{"title":"Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild","link":"https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/","source":"Palo Alto Unit 42","date_rel":"28 Sep"},{"title":"Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772","link":"https://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772","source":"Rapid7 Blog","date_rel":"28 Sep"},{"title":"Citrix NetScaler vulnerabilities (CVE-2026-88771, CVE-2026-88772) in active exploitation","link":"https://www.sophos.com/en-us/blog/citrix-netscaler-cve-2026-88771-cve-2026-88772-in-active-exploitation","source":"Sophos Threat Research","date_rel":"28 Sep"},{"title":"AL26-024 - Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway \u2013 CVE-2026-88771 and CVE-2026-88772","link":"https://cyber.gc.ca/en/alerts-advisories/al26-024-critical-vulnerabilities-affecting-citrix-netscaler-adc-netscaler-gateway-cve-2026-88771-cve-2026-88772","source":"CCCS Alerts & Advisories","date_rel":"27 Sep"}]},{"title":"Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT","link":"https://thehackernews.com/2026/09/attackers-exploit-netscaler-flaw-for.html","reason":"Citrix","category":"News","sources":["CCCS Alerts & Advisories","CyberScoop","Dark Reading","Infosecurity Magazine","NCSC UK","The Hacker News","The Register Security"],"coverage":7,"cve_ids":[],"summary":"Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity, observed by\u2026","source":"The Hacker News","date_rel":"6h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgjeU_A9ijIuOqFirHL74nU4k_HktRhcj5hx3goc6SfQKIeG9XA_GpZaZQVpCdUYbho_gZT4LoB-MjNJO0FZrV3q6MxXoUzg8bdbHmr2r-8rKxP1_XCMUVKq3IntFoR4aFFSdDPyBQI4Z1-jn8uNaWn4c4ohpPflBYx8M0GPFnAVziUo3Mtap0fzBBU9f_/s1600/citrix-shell.jpg","description":"Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has targeted government, financial services, technology, education, and legal and professional","related":[{"title":"Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers","link":"https://www.darkreading.com/vulnerabilities-threats/netscaler-zero-days-chaos-citrix","source":"Dark Reading","date_rel":"29 Sep"},{"title":"Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings","link":"https://cyberscoop.com/citrix-zero-days-delayed-disclosure/","source":"CyberScoop","date_rel":"29 Sep"},{"title":"\u26a1 Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats","link":"https://thehackernews.com/2026/09/weekly-recap-387m-crypto-hack-citrix.html","source":"The Hacker News","date_rel":"28 Sep"},{"title":"Citrix security advisory (AV26-965)","link":"https://cyber.gc.ca/en/alerts-advisories/citrix-security-advisory-av26-965","source":"CCCS Alerts & Advisories","date_rel":"28 Sep"},{"title":"Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway","link":"https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway","source":"NCSC UK","date_rel":"28 Sep"},{"title":"Citrix Patches Critical Zero Days Under Active Exploitation","link":"https://www.infosecurity-magazine.com/news/citrix-patches-critical-zero-days/","source":"Infosecurity Magazine","date_rel":"28 Sep"}]},{"title":"Apple patches CoreGraphics zero-day already exploited in targeted attacks","link":"https://www.theregister.com/security/2026/09/29/apple-patches-coregraphics-zero-day-already-exploited-in-targeted-attacks/5299721","reason":"CVE-2026-86950","category":"News","sources":["CISA Alerts & Advisories","Dark Reading","Infosecurity Magazine","SANS Internet Storm Center","The Hacker News","The Register Security"],"coverage":6,"cve_ids":["CVE-2026-86950"],"summary":"Apple has patched a CoreGraphics zero-day after warning that attackers may already have used the bug to compromise a small number of carefully chosen targets. The vulnerability, tracked as CVE-2026-86950, is an\u2026","source":"The Register Security","date_rel":"29 Sep","thumbnail":"https://image.theregister.com/?imageId=5299734&width=800","description":"Apple has patched a CoreGraphics zero-day after warning that attackers may already have used the bug to compromise a small number of carefully chosen targets. The vulnerability, tracked as CVE-2026-86950, is an out-of-bounds write flaw in CoreGraphics, Apple's framework for handling graphics across its operating systems. According to Apple's advisory, processing a maliciously crafted file could allow an attacker to execute arbitrary code on a vulnerable device. The fruity vendor said it addressed the problem with improved bounds checking, though the bug appears to have made it out into the\u2026","related":[{"title":"Apple Patches CoreGraphics Zero Day Exploited in Attacks","link":"https://www.infosecurity-magazine.com/news/apple-patches-coregraphics-zero/","source":"Infosecurity Magazine","date_rel":"6h ago"},{"title":"Apple Zero-Day Vulnerability Weaponized in Targeted Attacks","link":"https://www.darkreading.com/cyberattacks-data-breaches/apple-zero-day-vulnerability-weaponized-targeted-attacks","source":"Dark Reading","date_rel":"17h ago"},{"title":"CISA Adds One Known Exploited Vulnerability to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/29/cisa-adds-one-known-exploited-vulnerability-catalog","source":"CISA Alerts & Advisories","date_rel":"29 Sep"},{"title":"Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950), (Mon, Sep 28th)","link":"https://isc.sans.edu/diary/rss/33376","source":"SANS Internet Storm Center","date_rel":"28 Sep"},{"title":"Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks","link":"https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html","source":"The Hacker News","date_rel":"28 Sep"}]},{"title":"AI Agent Finds Linux Kernel Bug That Turns a Tiny Memory Write Into Root Access","link":"https://cybersecuritynews.com/ai-agent-finds-linux-kernel-bug/","reason":"Linux","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","Cyber Security News","Elastic Security Labs","The Hacker News"],"coverage":5,"cve_ids":["CVE-2026-72018"],"summary":"Autonomous security research platform XBOW has disclosed CVE-2026-72018, a high-severity Linux kernel vulnerability that converts a tightly constrained out-of-bounds memory write into local root access. The flaw affects\u2026","source":"Cyber Security News","date_rel":"6h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/AI-Agent-Finds-Linux-Kernel-Bug-That-Turns-a-Tiny-Memory-Write-Into-Root-Access.webp","description":"Autonomous security research platform XBOW has disclosed CVE-2026-72018, a high-severity Linux kernel vulnerability that converts a tightly constrained out-of-bounds memory write into local root access. The flaw affects the DIBS loopback implementation used by the SMC-D shared-memory communication path, where a missing bounds check allows attacker-controlled data to be copied beyond an allocated kernel buffer. The vulnerability is notable not only for its impact, but for the weakness of the available exploit primitive. XBOW\u2019s research showed that the bug could reliably produce only 16 zero\u2026","related":[{"title":"Microsoft is rolling out Linux container support to WSL","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-is-rolling-out-linux-container-support-to-wsl/","source":"Bleeping Computer","date_rel":"14h ago"},{"title":"New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses","link":"https://thehackernews.com/2026/09/new-spectre-v2-btr-attack-leaks-linux.html","source":"The Hacker News","date_rel":"21h ago"},{"title":"New Spectre v2 attack variant leaks Linux root password hash in minutes","link":"https://www.bleepingcomputer.com/news/security/new-spectre-v2-attack-variant-leaks-linux-root-password-hash-in-minutes/","source":"Bleeping Computer","date_rel":"22h ago"},{"title":"SUSE Linux security advisory (AV26-974)","link":"https://cyber.gc.ca/en/alerts-advisories/suse-linux-security-advisory-av26-974","source":"CCCS Alerts & Advisories","date_rel":"29 Sep"},{"title":"No MDM for Linux? A 68-line Elastic workflow keeps every endpoint's config current","link":"https://www.elastic.co/security-labs/blog/linux-endpoint-management-elastic-workflows","source":"Elastic Security Labs","date_rel":"29 Sep"},{"title":"Linux security advisory (AV26-970)","link":"https://cyber.gc.ca/en/alerts-advisories/linux-security-advisory-av26-970","source":"CCCS Alerts & Advisories","date_rel":"28 Sep"}]},{"title":"US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access","link":"https://thehackernews.com/2026/09/us-focused-csuite-phishing-steals.html","reason":"Microsoft","category":"News","sources":["404 Media","Bleeping Computer","Dark Reading","Infosecurity Magazine","The Hacker News"],"coverage":5,"cve_ids":[],"summary":"ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations\u2026","source":"The Hacker News","date_rel":"4h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5fq_zpvT8d0bG8IIotVRgIHIXCNOTPBhfIBUIWxLlg1X4bDmzf0PRgt_0UaHhvTIznPU4nOCCuLJ6JbJ3Tx22FPY2Ox93L_HNhA7XjQEvOcsXfw3NIixeGcy9DywlAx_SuEhCM6DRjgP3NBQrdHnJrFOCEFHFR8bFyF4YFWYtYEuPbG7kvWrgAsotLWI/s1600/rmm.jpg","description":"ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud","related":[{"title":"Microsoft to block Entra ID script injection attacks starting October","link":"https://www.bleepingcomputer.com/news/security/microsoft-to-block-entra-id-script-injection-attacks-starting-october/","source":"Bleeping Computer","date_rel":"1h ago"},{"title":"Windows 11 2026 Update released, here's everything you need to know","link":"https://www.bleepingcomputer.com/news/microsoft/windows-11-2026-update-released-heres-everything-you-need-to-know/","source":"Bleeping Computer","date_rel":"21h ago"},{"title":"Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor","link":"https://thehackernews.com/2026/09/russias-star-blizzard-targets-100.html","source":"The Hacker News","date_rel":"21h ago"},{"title":"'NeedyMantis' Provides Long-Term Access to Compromised Networks","link":"https://www.darkreading.com/threat-intelligence/needymantis-long-term-access-compromised-networks","source":"Dark Reading","date_rel":"23h ago"},{"title":"Microsoft Warns NeedyMantis Malware Enables Persistent Network Access","link":"https://www.infosecurity-magazine.com/news/microsoft-needymantis-malware/","source":"Infosecurity Magazine","date_rel":"29 Sep"},{"title":"Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks","link":"https://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.html","source":"The Hacker News","date_rel":"28 Sep"}]},{"title":"Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution","link":"https://thehackernews.com/2026/09/citrix-netscaler-cve-2026-88772-exploit.html","reason":"CVE-2026-88772","category":"News","sources":["Bleeping Computer","CyberScoop","The Hacker News","The Register Security","watchTowr Labs"],"coverage":5,"cve_ids":["CVE-2026-88772"],"summary":"Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild. The vulnerability, tracked\u2026","source":"The Hacker News","date_rel":"9h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjcFl1djJdJQkamdMtV0xibSpzc4ahUKNoVKtVoDSeKFJAYUkH2SnmxalYIJpaVZ9cywBJqyUflBrXWbhTIzpwL51iIyfINyH7z7YUHqDl3IbAJJmpCANlw8YvFFtmLa3T2es4rdE70Jd9tEUYAbuWFuXVBsx6Ar2radG2ZhgkqjBA5ZErCm0xVhNPv6d3F/s1600/watch-exploit.jpg","description":"Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that's rooted in the NetScaler","related":[{"title":"Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected","link":"https://cyberscoop.com/citrix-netscaler-zero-day-attacks-three-weeks-undetected/","source":"CyberScoop","date_rel":"17h ago"},{"title":"Hackers exploit Citrix NetScaler zero-day to deploy web shells","link":"https://www.bleepingcomputer.com/news/security/hackers-exploit-citrix-netscaler-zero-day-to-deploy-web-shells/","source":"Bleeping Computer","date_rel":"20h ago"},{"title":"Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services","link":"https://www.theregister.com/security/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-professional-services/5299867","source":"The Register Security","date_rel":"21h ago"},{"title":"Here We Go Again (Citrix NetScaler DTLS Preauth Memory Overflow CVE-2026-88772)","link":"https://labs.watchtowr.com/here-we-go-again-citrix-netscaler-dtls-preauth-memory-overflow-cve-2026-88772/","source":"watchTowr Labs","date_rel":"29 Sep"}]},{"title":"Custom ChatGPTs push ClickFix attacks to deploy RAT malware","link":"https://www.bleepingcomputer.com/news/security/custom-chatgpts-push-clickfix-attacks-to-deploy-rat-malware/","reason":"Google","category":"News","sources":["Bleeping Computer","Infosecurity Magazine","SecurityWeek"],"coverage":3,"cve_ids":[],"summary":"Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware.","source":"Bleeping Computer","date_rel":"18h ago","thumbnail":"","description":"","related":[{"title":"Google: AI Is Changing the Pace and Profile of Vulnerability Discovery","link":"https://www.securityweek.com/google-ai-is-changing-the-pace-and-profile-of-vulnerability-discovery/","source":"SecurityWeek","date_rel":"1h ago"},{"title":"AI-Found Vulnerabilities More Likely to Enable RCE, Google Says","link":"https://www.infosecurity-magazine.com/news/ai-found-vulnerabilities-rce/","source":"Infosecurity Magazine","date_rel":"1h ago"},{"title":"Attackers Combine ChatGPT Feature Abuse With ClickFix to Deliver Trojan Malware","link":"https://www.infosecurity-magazine.com/news/chatgpt-feature-abuse-to-deliver/","source":"Infosecurity Magazine","date_rel":"3h ago"}]},{"title":"OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted","link":"https://thehackernews.com/2026/09/openssl-fixes-high-severity-dtls-flaw.html","reason":"Openssl","category":"News","sources":["Cyber Security News","SecurityWeek","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-84782"],"summary":"A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a\u2026","source":"The Hacker News","date_rel":"7h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj0Po53IuyRAhsYzbs5KKPp_UBpklONBiOzoLWgXrklvrgDn5xnpjuRjU8UYoyLuImSmiPtOHQK3ExgQk5zhxlqsAcUmTLRFowkQXzan2RD955Gw-sumsvmwzLBTViUBRhyphenhyphenHCnETV23Qbt01RwaovTe1ogMeMYDSGxmF5n84NKZOB3EiWz6VAHUlfDm5YE/s1600/openssl-memory.jpg","description":"A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way","related":[{"title":"High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL","link":"https://www.securityweek.com/high-severity-vulnerabilities-patched-in-openssl-wolfssl/","source":"SecurityWeek","date_rel":"8h ago"},{"title":"OpenSSL Fixes High-Severity Flaw That Can Leak Server Memory in Plaintext","link":"https://cybersecuritynews.com/openssl-leak-server-memory/","source":"Cyber Security News","date_rel":"11h ago"}]},{"title":"Fortinet Uncovers SectopRAT Variant Hidden Inside Tampered Legitimate Windows Software","link":"https://cybersecuritynews.com/fortinet-uncovers-sectoprat/","reason":"Windows","category":"News","sources":["Cyber Security News","Microsoft Security"],"coverage":2,"cve_ids":["CVE-2026-69288","CVE-2026-69504","CVE-2026-69712"],"summary":"A SectopRAT variant has been found hidden inside tampered Windows software, allowing attackers to control an infected computer and steal sensitive information. The intrusion used legitimate application components as\u2026","source":"Cyber Security News","date_rel":"6h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Fortinet-Uncovers-SectopRAT-Variant-Hidden-Inside-Tampered-Legitimate-Windows-Software.webp","description":"A SectopRAT variant has been found hidden inside tampered Windows software, allowing attackers to control an infected computer and steal sensitive information. The intrusion used legitimate application components as cover, with encrypted files concealing the malware until it was loaded into memory. The affected program came from an Italian developer known for a long-running digital audio workstation. Attackers modified its supporting files and arranged automatic execution through a scheduled task. The investigation did not establish how the altered software first reached the victim\u2019s\u2026","related":[{"title":"CVE-2026-69504 Windows NTFS Information Disclosure Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69504","source":"Microsoft Security","date_rel":"1h ago"},{"title":"CVE-2026-69712 Windows Key Distribution Center Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69712","source":"Microsoft Security","date_rel":"1h ago"},{"title":"CVE-2026-69288 Windows GDI+ Information Disclosure Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69288","source":"Microsoft Security","date_rel":"1h ago"}]}],"worth_reading":[{"title":"The Blue Agent POV: Investigating Multi-Platform Data Exfiltration Across AWS and GitHub","link":"https://www.wiz.io/blog/blue-agent-data-exfiltration-investigation","reason":"Aws","category":"Research","sources":["Infosecurity Magazine","Wiz Research"],"coverage":2,"cve_ids":[],"summary":"See how the Blue Agent investigated a multi-platform attack in minutes, following evidence across AWS and GitHub to uncover compromised credentials, stolen source code, and custom data exfiltration tooling","source":"Wiz Research","date_rel":"29 Sep","thumbnail":"https://www.datocms-assets.com/75231/1790604308-artboard-2-copy-3-2x.png","description":"","related":[{"title":"Amazon Bedrock AgentCore Flaws Could Expose AWS Credentials","link":"https://www.infosecurity-magazine.com/news/aws-agentcore-sdk-flaws-ai/","source":"Infosecurity Magazine","date_rel":"29 Sep"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-53988","vendor":"Finsys","product":"dockhand","severity":"CRITICAL","score":10.0,"description":"Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows unauthenticated remote attackers to trigger arbitrary stack redeployments by exploiting a null webhook secret guard condition. A\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/Finsys/dockhand/releases/tag/v1.0.40","https://www.vulncheck.com/advisories/dockhand-unauthenticated-webhook-trigger-via-git-webhook-endpoints"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-53988"},{"id":"CVE-2026-96587","vendor":"Google","product":"Dashcam Android Application","severity":"CRITICAL","score":10.0,"description":"The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational\u2026","cwe":"CWE-798","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-07.json","https://viidure.app/","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-07"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-96587"},{"id":"CVE-2026-71379","vendor":"Toptech Systems","product":"TMS7","severity":"CRITICAL","score":10.0,"description":"The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST request.","cwe":"CWE-552","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02","https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-71379"},{"id":"CVE-2026-84154","vendor":"Dassault Syst\u00e8mes","product":"GEOVIA Geospatial Data Manager","severity":"CRITICAL","score":9.9,"description":"A Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary code on the server.","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":0.0036,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://www.3ds.com/trust-center/security/security-advisories/cve-2026-84154"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-84154"},{"id":"CVE-2026-102911","vendor":"zosmaai","product":"pi-llm-wiki","severity":"CRITICAL","score":9.9,"description":"A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_capture_source MCP tool. Executing a manipulation of the argument url can lead to os command injection\u2026","cwe":"CWE-77","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/zosmaai/pi-llm-wiki/","https://github.com/zosmaai/pi-llm-wiki/commit/360867034e79175b45c8e04a98e4ca712bbaca35","https://github.com/zosmaai/pi-llm-wiki/issues/185"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-102911"},{"id":"CVE-2023-54400","vendor":"Microsoft","product":"Fumeng Cloud","severity":"CRITICAL","score":9.8,"description":"Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject arbitrary SQL through the Name parameter of the getEmpByname action without any authenticati\u2026","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/emadshanab/goby-poc/blob/main/fumengyun%20%20AjaxMethod.ashx%20SQL%20injection.json","https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/other/fumasoft-sqli.yaml","https://www.vulncheck.com/advisories/fumeng-cloud-sql-injection-via-ajaxmethod-ashx-getempbyname"],"url":"https://cve.blackmesa.ca/?q=CVE-2023-54400"},{"id":"CVE-2026-77177","vendor":"Unknown","product":"","severity":"CRITICAL","score":9.8,"description":"Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt injection (with Jinja2 template syntax) can be used to achieve server-side expression evaluation \u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://gist.github.com/abhi04anon/8ce0b68a5a7dda8a0501cbaf933173eb","https://gist.github.com/abhi04anon/8ce0b68a5a7dda8a0501cbaf933173eb"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-77177"},{"id":"CVE-2026-100291","vendor":"Anjvision","product":"YSSD-RTMP-H5","severity":"CRITICAL","score":9.8,"description":"In Anjvision YSSD\u2011RTMP\u2011H5 firmware version 3.3.2.4, several ONVIF service endpoints process management requests without enforcing required authentication. This could allow an unauthorized attacker to access sensitive device operations.","cwe":"CWE-1188","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-100291"},{"id":"CVE-2026-39117","vendor":"Unknown","product":"","severity":"CRITICAL","score":9.8,"description":"An issue in AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plugin before v.2.0.0 allows a remote attacker to execute arbitrary code via the index.php","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://www.glimmernet.com/security/gt-2026-001-ssrf-66uptime-ping-servers/","https://www.glimmernet.com/security/gt-2026-001-ssrf-66uptime-ping-servers/"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-39117"},{"id":"CVE-2026-76721","vendor":"HP","product":"Instant ON","severity":"CRITICAL","score":9.8,"description":"Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that could allow an unauthenticated remote attacker to run arbitrary code on the underlying host. Successful exploitation could allow an attacker to\u2026","cwe":"","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-76721"}],"vendor_spikes":[{"vendor":"Google","count":144,"critical_count":24},{"vendor":"Mozilla","count":77,"critical_count":9},{"vendor":"WordPress","count":30,"critical_count":0},{"vendor":"Eclipse Foundation","count":23,"critical_count":0},{"vendor":"HP","count":21,"critical_count":5},{"vendor":"Apache","count":19,"critical_count":0},{"vendor":"Unknown","count":19,"critical_count":3},{"vendor":"Wireshark Foundation","count":18,"critical_count":0},{"vendor":"Joomla! Project","count":16,"critical_count":0},{"vendor":"Microsoft","count":15,"critical_count":1}],"epss_risers":[],"developing_map":{},"trending_count":20,"new_cve_count":649,"has_news_data":true,"has_cve_data":true,"news_for_cve":{"CVE-2026-88771":{"anchor":"#dev-2","rank":2,"coverage":6},"CVE-2026-88772":{"anchor":"#dev-2","rank":2,"coverage":6},"CVE-2026-86950":{"anchor":"#dev-4","rank":4,"coverage":6},"CVE-2026-72018":{"anchor":"#dev-5","rank":5,"coverage":5},"CVE-2026-84782":{"anchor":"#dev-9","rank":9,"coverage":3},"CVE-2026-69288":{"anchor":"#dev-10","rank":10,"coverage":2},"CVE-2026-69504":{"anchor":"#dev-10","rank":10,"coverage":2},"CVE-2026-69712":{"anchor":"#dev-10","rank":10,"coverage":2}}}