Security News Third Exploited NetScaler Zero-Day in a Week: CVE-2026-88779 Crashes SAML-Configured Appliances — Including Boxes Patched Days Earlier — CISA Deadline October 7 Third Exploited NetScaler Zero-Day in a Week: CVE-2026-88779 Crashes
Security News ShinyHunters Operator "Rey" Has Been Detained in Jordan Since September 29 — and Is Reportedly Helping the FBI Identify Other Members ShinyHunters Operator "Rey" Has Been Detained in Jordan Since September
Security News Microsoft Ships Out-of-Band Exchange Server Updates for CVE-2026-96940: Authenticated Attackers Can Read Other Users' Mailboxes — Patch Every Server and Management Tools Box Microsoft Ships Out-of-Band Exchange Server Updates for CVE-2026-96940:
Security News GitLab Patches Critical AI Gateway Flaw CVE-2026-90970: Crafted Duo Agent Platform Flows Could Escape the Prompt Template Sandbox and Run Commands GitLab Patches Critical AI Gateway Flaw CVE-2026-90970: Crafted Duo Agent
Security News Actively Exploited FortiMail Zero-Day CVE-2026-104286 Lets Unauthenticated Attackers Write Arbitrary Files — Fixed Builds Are Not Out Yet Actively Exploited FortiMail Zero-Day CVE-2026-104286 Lets Unauthenticated Attackers Write
Security News Critical Dell System Update Flaw CVE-2026-86360 Lets Unauthenticated Attackers Run Code as Root on PowerEdge Fleets — Upgrade DSU to 2.3.0.0 Critical Dell System Update Flaw CVE-2026-86360 Lets Unauthenticated Attackers Run
Security News Over 16,000 Supabase Databases Expose PII, Passwords and Auth Tokens: UpGuard Points to Missing Row-Level Security in AI-Built Apps Over 16,000 Supabase Databases Expose PII, Passwords and Auth Tokens: UpGuard
Security News Pentagon Personnel Agency Breach Exposed Nearly 3 Million People: DMDC File-Sharing Server Was Accessible to Unauthorized Users for Nine Months Pentagon Personnel Agency Breach Exposed Nearly 3 Million People: DMDC File-Sharing
Security News Apple Patches CoreGraphics Zero-Day CVE-2026-86950 After Meta Reports 'Extremely Sophisticated Attack' Against Targeted Individuals Apple Patches CoreGraphics Zero-Day CVE-2026-86950 After Meta Reports '
Security News Citrix NetScaler Zero-Days CVE-2026-88771 and CVE-2026-88772 Under Active Exploitation: CISA Gives Federal Agencies Until September 30 Citrix NetScaler Zero-Days CVE-2026-88771 and CVE-2026-88772 Under
Security News One URL-Encoded Character Bypasses WAF Rules: ShinyHunters-Linked UNC6240 Expands Oracle PeopleSoft Attacks and Deploys Web Shells One URL-Encoded Character Bypasses WAF Rules: ShinyHunters-Linked UNC6240 Expands Oracle
WAF Security Free Online Security Tools: Browser-Based Checks Every Web Admin Should Run Free Online Security Tools: Browser-Based Checks Every Web Admin Should Run