Skip to content
BLACKMESA.CA Brief

Saturday, October 10, 2026 · generated · about 5 min read

Morning Brief

Patch today vendors with the most new CVEs today

Ranked by CVE count. Each vendor opens the CVE Feed filtered to that vendor and these dates.

Top developments ranked by cross-source trending

  1. Image: The Hacker News

    Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own

    News The Hacker News9 Oct8 sources

    Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched. The contest pays researchers to show working exploits and passes the flaws to the vendors. One of the three Pixel exploits earned Ikotas Labs $300,000, the contest's top prize, and made the team the overall winner. Trend Micro's Zero

    Also in Bleeping Computer SecurityWeek SecurityWeek +3

    View on Security Feed

  2. Microsoft Teams to Warn Users About Malicious Links Hidden in QR Codes

    News Cyber Security News7h ago5 sources

    Microsoft is extending Teams security to detect malicious links hidden inside QR codes and warn users after a message has been delivered. The update adds QR code checks to existing Microsoft Defender for Office 365 protections, giving users clearer warnings and security teams more data to investigate suspicious messages. According to Message Center notice MC1490905 , published on October 7, worldwide rollout begins in early October 2026 and is expected to finish by early November. The feature applies to organizations using Microsoft Teams with Defender for Office 365 and requires no separate…

    Also in The Hacker News Bleeping Computer The Hacker News +2

    View on Security Feed

  3. Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

    News The Hacker News17h ago4 sources

    Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories. "Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC," StepSecurity

    Also in Cyber Security News Bleeping Computer CCCS Alerts & Advisories

    View on Security Feed

  4. One Prompt Could Hijack AWS AI Agents and Steal Cloud Credentials

    News Cyber Security News5h ago3 sources

    A single prompt sent to a public-facing AI agent could have exposed every Amazon Bedrock AgentCore agent in the same AWS account and region, according to new research from Zenity Labs. The attack chain, named AgentCorruption, gave the researchers access to private chats, source code, long-term memories, API keys, OAuth tokens, and secrets held in AWS Secrets Manager. Amazon Bedrock AgentCore is a managed service for building and running AI agents. Zenity found that an agent with a tool able to make web requests could be told to contact the local metadata endpoint at 169.254.169.254 . This…

    Also in The Register Security Malwarebytes Labs

    View on Security Feed

  5. $10 million bounty offered for Chinese Hafnium hacker accused of Microsoft Exchange Server mega-attack

    News Graham Cluley22h ago3 sources

    The US State Department is offering up to US $10 million for information about the whereabouts of Zhang Yu, a 44-year-old Chinese national who is accused of being a key figure in China's state-sponsored hacking group…

    Also in Microsoft Security Tenable Blog

    CVE-2026-50696 ↗View on Security Feed

  6. Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments

    News The Hacker News9 Oct3 sources

    Citrix has released patches for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions. "CVE-2026-107406 is a memory overflow vulnerability that may lead to remote code execution or denial-of-service under specific configuration conditions," Citrix said. The vulnerability

    Also in CCCS Alerts & Advisories CCCS Alerts & Advisories Bleeping Computer

    CVE-2026-88771 ↗CVE-2026-88772 ↗View on Security Feed

  7. Low-cost Android phones ship with residential proxy malware

    News Bleeping Computer8 Oct3 sources

    A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies.

    Also in SecurityWeek Malwarebytes Labs

    View on Security Feed

  8. Recorded Future Introduces AI Infrastructure Indicator Lists, Strengthening AI Governance

    Threat Intel Recorded Future Intelligence9 Oct3 sources

    Today, Recorded Future is announcing AI Infrastructure Indicator Lists , curated datasets for security teams to identify, monitor, and implement controls for AI-related network traffic. AI Infrastructure Indicator Lists are included for free for Recorded Future customers with a Cyber Operations license. Artificial intelligence has increasingly become enterprise infrastructure and organizations are now confronting unsanctioned tool use (also known as shadow AI), data exposure, and autonomous behavior that their controls cannot always see. Recorded Future's AI Infrastructure Indicator Lists…

    Also in Cisco Security Advisories Elastic Security Labs

    View on Security Feed

  9. Why Apple Says Your Mac Is at Risk From AI | Threat Wire

    Podcast Hak521h ago2 sources

    Are AI agents becoming a cybersecurity threat? From fake AI-generated bug bounty submissions overwhelming Google's vulnerability rewards program to Apple's warning about AI agents accessing sensitive Mac data, this week's ThreatWire explores how artificial intelligence is changing cybersecurity — and creating new security risks. Google has temporarily paused its open-source vulnerability rewards program, curl has shut down its bug bounty program, and Debian has announced more than 1,000 kernel CVEs. Meanwhile, Apple is tightening macOS Full Disk Access controls as concerns grow over…

    Also in Cisco Talos

    View on Security Feed

  10. CastleStealer Malware Uses Browser Protection Bypass and Remote Shell to Expand Attacker Access

    News Cyber Security News22h ago2 sources

    CastleStealer, an emerging C#-based information stealer, has added browser protection bypass and remote shell features that give its operators a wider path into compromised Windows systems. The newer malware samples can collect browser data protected by Chromium’s App-Bound Encryption, run commands on a victim device, download extra payloads, and move stolen information through small encrypted network transmissions rather than one large archive. Flashpoint’s analysis shows that the malware is becoming more capable even though it has not yet reached the broad use seen with major established…

    Also in Microsoft Security Microsoft Security Microsoft Security

    CVE-2026-62744 ↗CVE-2026-68875 ↗CVE-2026-68878 ↗View on Security Feed

Vulnerability watch what to look at, most urgent first

Details CVEProductSeverity CVSSEPSS KEVFixIn the news
Highest scoring today 10new CVEs, highest CVSS first
CVE-2026-94503 ZombifyPX-lab Critical 10.0 — — None linked — CVSS 10.0No fix linked
CVE-2026-108263 astron-agentiflytek Critical 9.9 — — None linked — CVSS 9.9No fix linked
CVE-2026-85531 OpenCart Virtual POS ModuleSipay Electronic Money and Payment Services Inc. Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-86405 PrestaShop Virtual POS ModuleSipay Electronic Money and Payment Services Inc. Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-100730 openPDCMicrosoft Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-105278 openPDC (Docker image)Grid Protection Alliance Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-108107 phpnuxbillhotspotbilling Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-15340 lwIP SMTP clientSavannah Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-108474 ExposedJetBrains Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-104732 Advanced IP BlockerWordPress Critical 9.8 — — None linked — CVSS 9.8No fix linked

Click a row, or press +, to expand it.EPSS is FIRST's estimated chance of exploitation in the next 30 days.Full CVE Feed

Worth reading quieter, still worth your time

  1. Scans for Atlassian vulnerablity (CVE-2026-21589), (Wed, Oct 7th)

    Research SANS Internet Storm Center7 Oct3 sources

    On October 5th, Atlassian published patches for multiple products to fix an "Arbitrary File Access" vulnerability [CVE-2026-21589]. An attacker can read arbitrary files in the web application's directory, potentially exposing sensitive information such as configuration files.

    Also in Infosecurity Magazine CCCS Alerts & Advisories

    CVE-2026-21589 ↗View on Security Feed

Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score. No AI writes any of this, and every number traces back to something already published on those two tools.

Top developments come from the Security Feed's cross-source trending detection. Vulnerability watch comes from the CVE Feed's daily NVD and CISA KEV sync.