Saturday, October 10, 2026 · generated · about 5 min read
Morning Brief
Patch today vendors with the most new CVEs today
- WordPress 6 critical 110
- Unknown 21
- Dell 19
- Apache 13
- Microsoft 1 critical 13
- F5 10
- Oracle 9
- Linux 7
- Red Lion Controls 7
- Red Hat 1 critical 5
Ranked by CVE count. Each vendor opens the CVE Feed filtered to that vendor and these dates.
Top developments ranked by cross-source trending
-
Image: The Hacker News Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own
Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched. The contest pays researchers to show working exploits and passes the flaws to the vendors. One of the three Pixel exploits earned Ikotas Labs $300,000, the contest's top prize, and made the team the overall winner. Trend Micro's Zero
Also in Bleeping Computer SecurityWeek SecurityWeek +3
-
Microsoft Teams to Warn Users About Malicious Links Hidden in QR Codes
Microsoft is extending Teams security to detect malicious links hidden inside QR codes and warn users after a message has been delivered. The update adds QR code checks to existing Microsoft Defender for Office 365 protections, giving users clearer warnings and security teams more data to investigate suspicious messages. According to Message Center notice MC1490905 , published on October 7, worldwide rollout begins in early October 2026 and is expected to finish by early November. The feature applies to organizations using Microsoft Teams with Defender for Office 365 and requires no separate…
Also in The Hacker News Bleeping Computer The Hacker News +2
-
Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories
Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories. "Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC," StepSecurity
Also in Cyber Security News Bleeping Computer CCCS Alerts & Advisories
-
One Prompt Could Hijack AWS AI Agents and Steal Cloud Credentials
A single prompt sent to a public-facing AI agent could have exposed every Amazon Bedrock AgentCore agent in the same AWS account and region, according to new research from Zenity Labs. The attack chain, named AgentCorruption, gave the researchers access to private chats, source code, long-term memories, API keys, OAuth tokens, and secrets held in AWS Secrets Manager. Amazon Bedrock AgentCore is a managed service for building and running AI agents. Zenity found that an agent with a tool able to make web requests could be told to contact the local metadata endpoint at 169.254.169.254 . This…
-
$10 million bounty offered for Chinese Hafnium hacker accused of Microsoft Exchange Server mega-attack
The US State Department is offering up to US $10 million for information about the whereabouts of Zhang Yu, a 44-year-old Chinese national who is accused of being a key figure in China's state-sponsored hacking group…
Also in Microsoft Security Tenable Blog
-
Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments
Citrix has released patches for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions. "CVE-2026-107406 is a memory overflow vulnerability that may lead to remote code execution or denial-of-service under specific configuration conditions," Citrix said. The vulnerability
Also in CCCS Alerts & Advisories CCCS Alerts & Advisories Bleeping Computer
-
Low-cost Android phones ship with residential proxy malware
A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies.
Also in SecurityWeek Malwarebytes Labs
-
Recorded Future Introduces AI Infrastructure Indicator Lists, Strengthening AI Governance
Today, Recorded Future is announcing AI Infrastructure Indicator Lists , curated datasets for security teams to identify, monitor, and implement controls for AI-related network traffic. AI Infrastructure Indicator Lists are included for free for Recorded Future customers with a Cyber Operations license. Artificial intelligence has increasingly become enterprise infrastructure and organizations are now confronting unsanctioned tool use (also known as shadow AI), data exposure, and autonomous behavior that their controls cannot always see. Recorded Future's AI Infrastructure Indicator Lists…
-
Why Apple Says Your Mac Is at Risk From AI | Threat Wire
Are AI agents becoming a cybersecurity threat? From fake AI-generated bug bounty submissions overwhelming Google's vulnerability rewards program to Apple's warning about AI agents accessing sensitive Mac data, this week's ThreatWire explores how artificial intelligence is changing cybersecurity — and creating new security risks. Google has temporarily paused its open-source vulnerability rewards program, curl has shut down its bug bounty program, and Debian has announced more than 1,000 kernel CVEs. Meanwhile, Apple is tightening macOS Full Disk Access controls as concerns grow over…
Also in Cisco Talos
-
CastleStealer Malware Uses Browser Protection Bypass and Remote Shell to Expand Attacker Access
CastleStealer, an emerging C#-based information stealer, has added browser protection bypass and remote shell features that give its operators a wider path into compromised Windows systems. The newer malware samples can collect browser data protected by Chromium’s App-Bound Encryption, run commands on a victim device, download extra payloads, and move stolen information through small encrypted network transmissions rather than one large archive. Flashpoint’s analysis shows that the malware is becoming more capable even though it has not yet reached the broad use seen with major established…
Also in Microsoft Security Microsoft Security Microsoft Security
CVE-2026-62744 ↗CVE-2026-68875 ↗CVE-2026-68878 ↗View on Security Feed
Vulnerability watch what to look at, most urgent first
| Details | CVE | Product | Severity | CVSS | EPSS | KEV | Fix | In the news | |
|---|---|---|---|---|---|---|---|---|---|
| Highest scoring today 10new CVEs, highest CVSS first | |||||||||
| CVE-2026-94503 | ZombifyPX-lab | Critical | 10.0 | — | — | None linked | — | CVSS 10.0No fix linked | |
What it isUnrestricted Upload of File with Dangerous Type vulnerability in PX-lab Zombify zombify allows Upload a Web Shell to a Web Server.This issue affects Zombify: from n/a through 1.7.7. Attack
Exploitation
|
|||||||||
| CVE-2026-108263 | astron-agentiflytek | Critical | 9.9 | — | — | None linked | — | CVSS 9.9No fix linked | |
What it isAstron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow code-node path through /console-api/workflow/code/run and /workflow/v1/run selects LocalExecutor in core/workflow/engine/n… Attack
Exploitation
|
|||||||||
| CVE-2026-85531 | OpenCart Virtual POS ModuleSipay Electronic Money and Payment Services Inc. | Critical | 9.8 | — | — | None linked | — | CVSS 9.8No fix linked | |
What it isImproper verification of cryptographic signature vulnerability in Sipay Electronic Money and Payment Services Inc. OpenCart Virtual POS Module allows Signature Spoofing by Improper Validation. This issue affects OpenCart Virtual POS Module… Attack
Exploitation
|
|||||||||
| CVE-2026-86405 | PrestaShop Virtual POS ModuleSipay Electronic Money and Payment Services Inc. | Critical | 9.8 | — | — | None linked | — | CVSS 9.8No fix linked | |
What it isImproper verification of cryptographic signature vulnerability in Sipay Electronic Money and Payment Services Inc. PrestaShop Virtual POS Module allows Signature Spoofing by Improper Validation. This issue affects PrestaShop Virtual POS Mo… Attack
Exploitation
|
|||||||||
| CVE-2026-100730 | openPDCMicrosoft | Critical | 9.8 | — | — | None linked | — | CVSS 9.8No fix linked | |
What it isA service console interface on openPDC and openHistorian deserializes a client-supplied data structure. On systems using Windows Authentication, an attacker must already be authenticated to reach this function; on systems without Windows Au… Attack
Exploitation
|
|||||||||
| CVE-2026-105278 | openPDC (Docker image)Grid Protection Alliance | Critical | 9.8 | — | — | None linked | — | CVSS 9.8No fix linked | |
What it isThe published Docker image for openPDC includes a fixed administrative credential with no forced change on first use. An attacker with network access to the management interface can authenticate using this credential and gain full administr… Attack
Exploitation
|
|||||||||
| CVE-2026-108107 | phpnuxbillhotspotbilling | Critical | 9.8 | — | — | None linked | — | CVSS 9.8No fix linked | |
What it isPHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.php FreeRADIUS REST endpoint that interpolates request parameters into whereRaw() queries. Attackers can send crafted username, macAddr or na… Attack
Exploitation
|
|||||||||
| CVE-2026-15340 | lwIP SMTP clientSavannah | Critical | 9.8 | — | — | None linked | — | CVSS 9.8No fix linked | |
What it islwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow. Attack
Exploitation
|
|||||||||
| CVE-2026-108474 | ExposedJetBrains | Critical | 9.8 | — | — | None linked | — | CVSS 9.8No fix linked | |
What it isIn JetBrains Exposed before 1.5.1 sQL injection was possible via unescaped string arguments of several SQL functions Attack
Exploitation
|
|||||||||
| CVE-2026-104732 | Advanced IP BlockerWordPress | Critical | 9.8 | — | — | None linked | — | CVSS 9.8No fix linked | |
What it isThe Advanced IP Blocker plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 8.13.13 The vulnerability exists because `handle_login_action()` performs no server-side check — via transient, sessio… Attack
Exploitation
|
|||||||||
Click a row, or press +, to expand it.EPSS is FIRST's estimated chance of exploitation in the next 30 days.Full CVE Feed
Worth reading quieter, still worth your time
-
Scans for Atlassian vulnerablity (CVE-2026-21589), (Wed, Oct 7th)
On October 5th, Atlassian published patches for multiple products to fix an "Arbitrary File Access" vulnerability [CVE-2026-21589]. An attacker can read arbitrary files in the web application's directory, potentially exposing sensitive information such as configuration files.
Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score. No AI writes any of this, and every number traces back to something already published on those two tools.
Top developments come from the Security Feed's cross-source trending detection. Vulnerability watch comes from the CVE Feed's daily NVD and CISA KEV sync.