Monday, October 5, 2026 · generated · about 5 min read
Morning Brief
Patch today vendors with the most new CVEs today
- MediaTek, Inc. 31
- kishor-23 11
- zitadel 3 critical 10
- Unknown 8
- itsourcecode 7
- SourceCodester 6
- Red Hat 3
- WordPress 3
Ranked by CVE count. Each vendor opens the CVE Feed filtered to that vendor and these dates.
Top developments ranked by cross-source trending
-
Image: Cyber Security News CISA Warns of Citrix NetScaler Vulnerability Actively Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has added a Citrix NetScaler vulnerability, tracked as CVE-2026-88779 , to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The flaw affects Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway). CVE-2026-88779 is an improper restriction of operations within the bounds of a memory buffer issue, classified under CWE-119. The vulnerability could allow an attacker to trigger a denial-of-service condition on affected NetScaler appliances, potentially disrupting…
Also in SecurityWeek Sophos Threat Research Bleeping Computer +1
-
Google Gemini Will Soon Get Full Access Permission to Use Your Computer
Google’s Gemini Desktop app may soon introduce a “Full Access” permission that would let the AI assistant read files, control applications, access network services, and take action across a user’s Mac. The capability appears to be part of a hidden “Additional sandbox options” setting discovered in a recent version of the Gemini Desktop app . The reported feature would significantly expand Gemini’s computer-use capabilities beyond its existing role as a conversational AI assistant. If enabled, the permissions could let Gemini interact with a user’s local environment in ways normally reserved…
Also in Malwarebytes Labs SecurityWeek Infosecurity Magazine +2
-
Need for Speed: AI-Driven Attacks Are Changing Security Strategies
AI-powered attacks are fast, relentless, and automated. How security teams can keep up is top of mind, according to the latest Dark Reading reader poll.
Also in Wiz Research The Hacker News Dark Reading
-
New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
Citrix has released security updates for a high-severity security flaw in NetScaler ADC and Citrix NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0. "CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to
Also in Infosecurity Magazine CCCS Alerts & Advisories CCCS Alerts & Advisories
-
RemoveMacAI Free Up 12GB of Data by Removing Apple Intelligence Models
RemoveMacAI, an open-source tool on GitHub, lets Mac users disable Apple Intelligence, remove its downloaded models, and block future downloads. The utility can recover roughly 10GB to 12GB of storage, depending on which models are present. Its changes are reversible, and the removal process leaves macOS System Integrity Protection enabled. The tool addresses a storage problem in macOS 27. According to its developer, Apple removed the single switch for turning off Apple Intelligence, while disabling individual features leaves their models on disk. RemoveMacAI combines feature restrictions…
Also in Cyber Security News The Hacker News Ars Technica Security
-
Debian's latest kernel security update has 1,313 reasons to patch
The age of LLM-assisted security vulnerability discovery is really starting to bite. Debian's latest Linux kernel security update comes with a formidable reading list of 1,313 CVE identifiers. The DSA-6528-1 Linux security advisory, published on September 29, covers kernel package version 6.12.111-1 for Debian 13, codenamed Trixie. Debian 13.7 was released on September 12, before upstream kernel 6.12.111 arrived nine days later. The Debian security tracker links to descriptions of the individual issues. We have not examined every entry. If we had, this article would not appear until after…
Also in Infosecurity Magazine SecurityWeek
-
ClickFix Fake CAPTCHA Attack Executes Malware Hidden Inside Browser Cache
A new ClickFix campaign is turning a web safety check into a route for malware. Visitors to compromised websites see a fake CAPTCHA or repair message and are told to open the Windows Run dialog, paste copied text, and press Enter. The instruction looks simple, but it makes the victim run the attacker’s command. The campaign is concerning because its main script is placed on the computer before that step, hiding in the browser cache rather than arriving as an obvious download. Microsoft Threat Intelligence identified the activity in a cluster of compromised websites. Microsoft described in its…
Also in Microsoft Security
-
Data breach at Denmark’s national population register exposes 8.8 million people
Denmark is investigating a data breach affecting approximately 8.8 million people after unauthorized users gained access to its national population register.
Also in Bleeping Computer
-
China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations. The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at a
-
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and
Also in SecurityWeek
Vulnerability watch what to look at, most urgent first
| Details | CVE | Product | Severity | CVSS | EPSS | KEV | Fix | In the news | |
|---|---|---|---|---|---|---|---|---|---|
| Highest scoring today 10new CVEs, highest CVSS first | |||||||||
| CVE-2026-105207 | zitadelzitadel | Critical | 9.8 | — | — | None linked | — | CVSS 9.8No fix linked | |
What it isZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the… Attack
Exploitation
|
|||||||||
| CVE-2026-105209 | zitadelzitadel | Critical | 9.6 | — | — | None linked | — | CVSS 9.6No fix linked | |
What it isZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's or… Attack
Exploitation
|
|||||||||
| CVE-2026-103355 | Unlimited Elements For Elementor (Free Widgets, Addons, Templates)Unlimited Elements | Critical | 9.3 | 0.2% | — | None linked | — | EPSS 0.2%CVSS 9.3No fix linked | |
What it isImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL In… Attack
Exploitation
|
|||||||||
| CVE-2026-105215 | zitadelzitadel | Critical | 9.1 | — | — | None linked | — | CVSS 9.1No fix linked | |
What it isZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP c… Attack
Exploitation
|
|||||||||
| CVE-2026-105086 | AVideoWWBN | High | 8.7 | — | — | None linked | — | CVSS 8.7No fix linked | |
What it isWWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding … Attack
Exploitation
|
|||||||||
| CVE-2026-105089 | AVideoWWBN | High | 8.7 | — | — | None linked | — | CVSS 8.7No fix linked | |
What it isWWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates an… Attack
Exploitation
|
|||||||||
| CVE-2026-105210 | zitadelzitadel | High | 8.2 | — | — | None linked | — | CVSS 8.2No fix linked | |
What it isZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted Login V1 UI, whose second-factor enrollment and initialization handlers act on an identify-only session before any primary factor is verifi… Attack
Exploitation
|
|||||||||
| CVE-2026-105213 | zitadelzitadel | High | 8.2 | — | — | None linked | — | CVSS 8.2No fix linked | |
What it isZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold valid credentials, an existing session, or a… Attack
Exploitation
|
|||||||||
| CVE-2026-105211 | zitadelzitadel | High | 8.1 | — | — | None linked | — | CVSS 8.1No fix linked | |
What it isZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victi… Attack
Exploitation
|
|||||||||
| CVE-2026-105293 | LegcordLegcord | High | 8.1 | — | — | None linked | — | CVSS 8.1No fix linked | |
What it isLegcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory via unvalidated theme ids. Attackers running script in the Discord origin, such … Attack
Exploitation
|
|||||||||
Click a row, or press +, to expand it.EPSS is FIRST's estimated chance of exploitation in the next 30 days.Full CVE Feed
Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score. No AI writes any of this, and every number traces back to something already published on those two tools.
Top developments come from the Security Feed's cross-source trending detection. Vulnerability watch comes from the CVE Feed's daily NVD and CISA KEV sync.