Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Citrix, FortiMail, and Apple Zero-Days Expose Users
October 5, 2026
South Korean President Orders Full Security Checks After Financial Sector Hacks
October 4, 2026
ShinyHunters Member Arrested, Cooperating with FBI in Jordan
October 4, 2026
Home/CyberSecurity News/Critical Citrix, FortiMail, and Apple Zero-Days Expose Users
CyberSecurity News

Critical Citrix, FortiMail, and Apple Zero-Days Expose Users

Key Takeaways Several critical zero-day vulnerabilities in Apple CoreGraphics, Fortinet FortiMail, and Citrix NetScaler are under active exploitation or have been reported as such. A significant data...

Jennifer sherman
Jennifer sherman
October 5, 2026 13 Min Read
3 0

Key Takeaways

  • Several critical zero-day vulnerabilities in Apple CoreGraphics, Fortinet FortiMail, and Citrix NetScaler are under active exploitation or have been reported as such.
  • A significant data breach at the Pentagon’s Defense Manpower Data Center exposed personal information for millions of individuals.
  • A broad range of other security threats emerged, including AI agent-related data leaks, new malware delivery methods, and numerous patches for common software like Apache HTTP Server, OpenSSL, and Chrome.
  • Immediate patching and robust mitigation strategies are crucial across all affected platforms and services.

This week brought a flurry of critical cybersecurity alerts, highlighted by a substantial data breach impacting the Pentagon and the disclosure of multiple actively exploited zero-day vulnerabilities across major platforms. These include flaws in Apple’s CoreGraphics, Fortinet’s FortiMail, and reported remote code execution (RCE) vulnerabilities in Citrix NetScaler that lack official patches.

Table Of Content

  • Key Takeaways
  • Major Security Incidents and Vulnerabilities
  • Pentagon Data Breach Exposes Millions
  • Apple Addresses Actively Exploited CoreGraphics Zero-Day
  • FortiMail Zero-Day Under Active Exploitation
  • Reported Citrix NetScaler RCE Zero-Days Allegedly Exploited
  • Other Noteworthy Security Developments
  • AI Agent Governance and Risks
  • Malware and Threat Campaigns
  • Software Updates and Patches
  • Emerging Evasion Techniques and Discoveries
  • Law Enforcement Action
  • Windows 11 Update Issues
  • What You Should Do

Beyond these high-profile incidents, the security landscape saw a wide array of developments, from new malware campaigns and AI-driven data exposures to crucial updates for cloud identity, remote access, browser security, and infrastructure components.

Major Security Incidents and Vulnerabilities

Pentagon Data Breach Exposes Millions

The Pentagon has confirmed that an unauthorized intrusion into a Defense Manpower Data Center (DMDC) information system led to a significant data exposure. This breach, facilitated by a vulnerability in a file-sharing mechanism, impacted approximately 2.76 million living individuals and an additional 294,000 deceased individuals. The unauthorized access reportedly occurred between October 2025 and July 2026 before the DMDC identified and remediated the flaw on July 16.

Compromised data included unencrypted personal details such as names, Social Security numbers, birth dates, contact information, demographic specifics, and military occupational data. While no evidence of data misuse has been reported, the long-term nature of identity information presents ongoing risks for fraud, phishing, impersonation, and even counterintelligence. Affected individuals are being offered one year of complimentary credit monitoring and identity restoration services.

Apple Addresses Actively Exploited CoreGraphics Zero-Day

Apple has released urgent updates, iOS 26.7.1 and iPadOS 26.7.1, to mitigate a critical zero-day vulnerability, CVE-2026-86950. This out-of-bounds write flaw in CoreGraphics is believed to have been exploited in highly sophisticated, targeted attacks. Maliciously crafted files could trigger memory corruption, potentially leading to arbitrary code execution within the affected process.

The vulnerability impacts a wide range of devices, including iPhone 11 and later models, along with supported versions of iPad Pro, iPad Air, iPad, and iPad mini. Apple credited Meta Product Security for the discovery and resolved the issue by implementing enhanced bounds checking. Users and enterprise administrators are strongly advised to install these updates immediately and verify their deployment through mobile device management (MDM) systems.

FortiMail Zero-Day Under Active Exploitation

Fortinet has issued a warning regarding active exploitation of CVE-2026-104286, a critical FortiMail vulnerability with a CVSS score of 9.8. This unauthenticated flaw combines path traversal with improper NULL byte handling, allowing attackers to write arbitrary files to the system via specially crafted HTTP or HTTPS requests.

The affected FortiMail versions include 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, and 7.2.0–7.2.9. Administrators should immediately disable IBE (Identity Based Encryption) support or restrict public access to the management interface. It is also crucial to monitor for fixed releases, preserve system logs, and investigate Fortinet’s published file, account, cron, and network indicators for any signs of prior compromise.

Reported Citrix NetScaler RCE Zero-Days Allegedly Exploited

Security firm watchTowr has reported the discovery of two previously undisclosed remote-code-execution (RCE) vulnerabilities in Citrix NetScaler, identified during forensic investigations. These flaws are allegedly being exploited in real-world attacks. As of the time of publication, Citrix has not released an official advisory, CVE identifiers, details on affected builds, exploitation prerequisites, patches, or indicators of compromise. Therefore, watchTowr’s findings serve as a credible warning rather than a fully confirmed vendor disclosure.

Organizations utilizing NetScaler instances should conduct a thorough inventory, minimize public exposure, restrict management access, and preserve all relevant evidence. This includes scrutinizing authentication events, sessions, configuration changes, files, processes, and outbound network traffic. High-risk organizations unable to effectively mitigate the exposure may need to isolate affected appliances under a pre-approved continuity plan while closely monitoring Citrix’s official bulletin channels for definitive guidance.

Other Noteworthy Security Developments

AI Agent Governance and Risks

Anthropic has introduced the Claude Compliance API, providing security teams with enhanced visibility into Claude Enterprise interactions. This includes monitoring conversations, uploaded files, projects, and session data from Claude Code and Cowork, encompassing prompts, responses, tool calls, and transcript artifacts. This telemetry can be integrated into existing DLP, SIEM, identity, eDiscovery, governance, and incident response workflows.

While Claude Platform customers receive administrative and system activity events, sensitive conversation prompts and model responses are not included. Only the Primary Owner of a Claude Enterprise organization can enable the API and generate access keys. Enterprises retain responsibility for implementing least privilege principles, reviewing connectors, safeguarding keys, managing data retention, and establishing clear AI-use policies.

In related news, OpenClaw launched OpenClaw Enterprise, a free, MIT-licensed platform for managing and governing persistent AI agents. This platform offers multi-tenancy, sandboxing, granular permissions, lifecycle auditing, and model-based reviews to separate trusted services from untrusted agent workloads. While recommended for internal pilots, the project is still under development. Organizations can self-host with Kubernetes and customize its components but must independently validate isolation, permissions, auditing, plugins, and secret handling before integrating with critical systems.

Concerns around AI agent safety were amplified by a user report claiming a Claude Code agent accidentally deleted 48,218 live Windows project files and corrupted a Git repository in 103 seconds during a mirror rebuild. The user-provided verifier report indicated the deletion script mishandled 614 Windows directory junctions, leading to traversal into the live project tree and subsequent content erasure. While not independently confirmed as a Claude Code product defect, this incident underscores the critical need for dry runs, explicit path manifests, reversible operations, least-privilege accounts, filesystem-restricted sandboxes, and human approval for agents performing destructive actions. Bash-based deletions, in particular, may bypass checkpoint-based recovery mechanisms.

Further demonstrating AI-related risks, Glow Labs’ PixelLeak research uncovered over 13,000 internal screenshots from more than 300 organizations across 900+ public GitHub repositories. Coding agents reportedly created public repositories or used public release assets to host images for private pull requests, inadvertently exposing sensitive data like credentials, customer records, internal dashboards, financial interfaces, and unreleased features. A significant factor was that 93% of these exposures originated from repositories under employee usernames rather than corporate organizations, with the gitshot utility contributing to exposures at roughly one-third of affected companies. Defenders should inspect employee public repositories, gists, releases, and _gitshot tags, remove exposed material, rotate visible secrets, disable blanket agent approvals, and use authenticated private upload mechanisms such as GitHub CLI’s --attach option.

Malware and Threat Campaigns

Attackers are leveraging custom ChatGPT GPT pages as the initial stage of a sophisticated ClickFix attack chain. This involves sponsored search results, fake service notices, counterfeit CAPTCHAs, and instructions to paste obfuscated PowerShell commands. Huntress has investigated at least 40 incidents linked to this campaign’s Google Sites infrastructure, including two infections directly traced to malicious Custom GPTs. The attack silently installs an MSI, uses signed Canon or Stardock executables for DLL sideloading, bypasses AMSI, executes .NET code in memory, and establishes persistence for a powerful Remote Access Trojan (RAT). Defenders should look for PowerShell spawning msiexec, signed binaries running from unusual user-profile paths, modified adjacent DLLs, and suspicious scheduled tasks. Users should never paste shell commands provided by a CAPTCHA or AI service page.

Researchers have identified OpenSUpdater, also known as Snackarcin, embedded within modified 7-Zip self-extracting installer code. These malicious packages include a genuine foobar2000 installer as a decoy, while a hidden call within the rebuilt extraction component contacts attacker infrastructure to download DLLs and an encrypted payload. This is not a vulnerability in standard 7-Zip archives but rather deliberate tampering with open-source installer code. Analysts should examine the extraction stub itself, not just its embedded program and configuration, and view nested installers, mismatched publishers, unusual version metadata, and padded certificates as red flags warranting deeper investigation.

Proofpoint has linked a password-spraying campaign, dubbed UNK_CondorFiltration, to the TeamFiltration testing framework. This activity targeted 5,714 accounts across 28 Microsoft 365 tenants, resulting in seven confirmed compromises. All compromised accounts were functional or service identities, not personal employee accounts. These accounts were enabled, unmonitored, apparently lacked MFA, and in six cases were breached within seven minutes, consistent with shared or unchanged default passwords. Organizations must inventory non-human identities, assign owners, rotate inherited secrets, enforce MFA or workload identities, and configure alerts for first-time access and widespread password failures from distributed cloud infrastructure.

Cisco Talos has identified Antino, a Rust-based backdoor that utilizes Microsoft Graph and stores its native command-and-control (C2) workflow within Outlook and OneDrive. The UAT-11587 campaign, assessed by Talos with high confidence to have links to China, targeted government, defense, diplomatic, academic, and policy organizations. Outlook is used for commands and responses, while OneDrive handles registration, heartbeats, stolen data, and additional tools, allowing the malware to blend seamlessly into trusted cloud traffic. Delivery methods included tailored phishing, fake installers, Windows scripting, encrypted JavaScript, unsafe .NET processing, DLL sideloading, and abuse of Windows troubleshooting components for execution and persistence.

Microsoft has uncovered NeedyMantis, a modular post-compromise framework observed in a limited number of targeted intrusions affecting telecommunications, universities, medical nonprofits, intergovernmental bodies, and government contractors. Active since at least October 2025, Microsoft assesses that NeedyMantis is deployed after initial access, rather than via a consistent infection vector. The framework employs DLL sideloading, custom encrypted archives, obfuscated loaders, WebSockets, and modular payload delivery. Defenders should search for traffic to corp.tripswithengine[.]com, unexpected DLL loads alongside Poedit, curl, Vim, or TightVNC components, Impacket activity, and suspicious encoded data in HTTPS cookie headers. Any detection should trigger a broader investigation into lateral movement and credential theft.

Attackers are also exploiting Microsoft Defender exclusions to conceal malicious directories and file types while maintaining a visibly enabled antivirus. Since modifying these settings requires administrative access, this behavior is a post-compromise evasion technique. Exclusions can be configured via PowerShell, WMI, Group Policy, or registry changes, and policies can hide them from standard PowerShell queries. Defenders should monitor underlying exclusion registry locations, investigate broad drive or staging directory exemptions, and correlate new exclusions with concealment policy changes rather than relying on an empty query result as proof of a clean configuration.

ThreatMon investigated an intrusion in a Viva Aerobus environment where attackers leveraged SQL Server’s xp_cmdshell to execute Windows commands and encoded PowerShell. The same database connection was used to exfiltrate files, split into chunks, Base64-encoded, and returned through query results. An exposed attacker server revealed 17 tools for credential harvesting, SQL password testing, file movement, and lateral movement preparation, along with collected source code and configuration material. Defenders should investigate unexpected xp_cmdshell activation, PowerShell or cmd.exe launched by SQL Server service accounts, unusual query output volumes, and any credentials or secrets potentially exposed to the staging server.

Operation Master combined exploitation of CVE-2026-0257, a GlobalProtect authentication bypass, with SQL injection to fuel large-scale invoice fraud. Investigators confirmed unauthorized sessions through seven gateways in four countries and data theft from at least nine database systems, including one reconstructed theft involving 24,558 debtor records. The stolen data was used to personalize fraudulent bills sent via hijacked Microsoft 365 mailboxes, SMS gateways, and WhatsApp templates. Defenders must patch exposed gateways, inspect abnormal VPN sessions, restrict database command execution, monitor anomalous DNS exfiltration and cloud-mail activity, and scrutinize device-code approvals.

Software Updates and Patches

Apache HTTP Server 2.4.69 addresses 20 vulnerabilities, including five moderate and 15 low-severity issues that could lead to code execution, crashes, information exposure, request smuggling, and authentication problems. Notable flaws include CVE-2026-63292, a stack overflow triggered by an oversized Host header in specific mod_vhost_alias configurations, and CVE-2026-42356, which could allow an existing file to execute as CGI after certain internal redirects. While code execution paths are configuration-dependent, administrators should upgrade to 2.4.69, prioritizing systems with affected virtual-host settings, CGI redirects, WebDAV, digest authentication, HTTP/2, and proxy modules.

A high-severity out-of-bounds read, CVE-2026-84782, has been identified in OpenSSL’s DTLS handshake retransmission logic. When a handshake write is suspended, stale buffer-position state can cause a retransmission to include adjacent heap data as plaintext or crash the process, potentially exposing secrets or causing denial of service. Fixed releases include OpenSSL 4.0.3, 3.6.5, 3.5.9, and 3.4.8, with supported fixes also available for older branches. Security teams must inventory all applications, appliances, VPNs, and embedded products using DTLS—including statically bundled copies that package managers might miss—and update through the relevant software or operating system vendor.

TeamViewer has patched five high-severity flaws affecting its Full Client, Host, and related components across Windows, Linux, and macOS. These include local path traversal and privilege escalation, a Windows installer race condition, unsafe link resolution, a heap overflow in .tvs recording playback, and CVE-2026-92370, an access-control flaw that could allow an authenticated remote attacker to bypass session restrictions and potentially execute code. TeamViewer has reported no known public exploitation and recommends upgrading to version 15.82 or the latest supported maintenance release. Administrators should also review remote-access policies and watch for unusual installer activity, malicious recording files, or unexpected modification of protected files.

Wireshark 4.6.9 and 4.4.19 address 19 documented vulnerabilities across dissectors, capture parsers, Sharkd, and configuration profiles. The most critical issue, CVE-2026-96419, could crash Wireshark or potentially execute code if a victim imports a crafted profile. Other flaws can trigger loops, leaks, crashes, and resource exhaustion through malformed traffic or files. While no known exploitation has been reported, analyst workstations routinely handle untrusted evidence. Teams should update immediately, including forensic workstations and automated capture pipelines, and use sandboxes or disposable virtual machines for unknown profiles and packet captures until patching is complete.

XBOW has disclosed CVE-2026-72018, a high-severity out-of-bounds write in the Linux kernel’s DIBS loopback implementation for SMC-D. Although exploitation yielded only a constrained 16-byte zero write, researchers leveraged it to overwrite fields in the kernel credential structure and achieve local root privileges without a separate information leak. The demonstrated path requires CAP_NET_ADMIN and manipulates SMC-D handshake traffic through NFQUEUE; the proof of concept succeeded on 22 of 100 boots in a mitigation-disabled test environment. Administrators should deploy kernel updates containing the bounds check, reboot affected systems, and review containers and workloads granted CAP_NET_ADMIN.

Google has released Chrome 154.0.8037.92/.93 for Windows and macOS, and 154.0.8037.92 for Linux, incorporating 32 security fixes. The most severe, CVE-2026-102331, is a critical ANGLE buffer overflow. High-severity fixes address V8 type confusion and buffer overflows, WebUI cross-site scripting, use-after-free conditions, authorization weaknesses, and UI misrepresentation. Technical details for several bugs remain restricted while the update reaches users. Organizations should accelerate browser patching, verify that managed devices relaunch into the corrected build, and include long-running browser sessions and shared endpoints in compliance checks.

Emerging Evasion Techniques and Discoveries

A new proof-of-concept technique, termed console named-pipe injection, bypasses common EDR signals that typically rely on VirtualAllocEx and WriteProcessMemory. This method launches a console child process, such as nslookup.exe or netsh.exe, sends payload bytes through redirected standard input, locates the resulting buffer, modifies its protection with VirtualProtectEx, and redirects a thread to execute it. While this method avoids specific API calls, it does not eliminate all telemetry. Memory scanning, executable permission changes, redirected handles, and thread-context manipulation remain observable. Detection engineering should correlate unusual console-process creation, binary-like stdin activity, remote memory-protection changes, and SetThreadContext behavior rather than depending on a single high-signal API call.

A 16-year-old researcher known as Faav discovered a critical authentication flaw in Microsoft’s internal Titan analytics service. The service accepted manipulated JSON Web Tokens without cryptographically validating their signatures. An unsigned token with the user value admin mapped to a privileged local account, allowing unauthorized SQL queries without Microsoft credentials. The researcher estimated connected analytics systems held approximately 17.3 trillion rows, clarifying this was a storage estimate including historical, duplicated, and derived data, not unique individuals or confirmed leaked records. Microsoft restricted the endpoint four days after disclosure, awarded a $5,000 bounty, and found no reported evidence of malicious exploitation.

Law Enforcement Action

Dutch police, with FBI support, arrested a 24-year-old Amsterdam suspect identified by FBI Director Kash Patel as an alleged leader of the ShinyHunters cyber-extortion group. The operation seized storage devices, and an ongoing international investigation is underway; a Rotterdam court ordered 90 days of pretrial detention. While Dutch authorities did not publicly name the suspect, a private-sector executive identified him as security professional Pepijn van der Stap. ShinyHunters has denied any association with Van der Stap, so descriptions of his precise role remain unproven allegations.

Windows 11 Update Issues

Microsoft has confirmed that Windows 11 updates released from August 27 onwards can prevent Windows Explorer from launching after sign-in, resulting in a black screen for users. This issue primarily affects Azure Virtual Desktop hosts using FSLogix and certain existing user profiles on Windows 11 26H1, 25H2, and 24H2. Users can temporarily restore the shell by opening Task Manager and running explorer.exe. Enterprise administrators should deploy the corresponding Known Issue Rollback policy—KB5124006 for 26H1 or KB5124010 for 25H2 and 24H2—restart affected systems, and retain the rollback until Microsoft delivers a permanent fix.

What You Should Do

  • Patch Immediately: Prioritize installing updates for Apple iOS/iPadOS (26.7.1), FortiMail (specific versions), Apache HTTP Server (2.4.69), OpenSSL (4.0.3, 3.6.5, 3.5.9, 3.4.8), TeamViewer (15.82+), Wireshark (4.6.9, 4.4.19), Linux kernel (for CVE-2026-72018), and Google Chrome (154.0.8037.92/.93).
  • Mitigate Citrix NetScaler Risks: For unpatched NetScaler instances, reduce public exposure, restrict management access, preserve logs, and monitor for anomalies. Consider isolating high-risk appliances.
  • Address Pentagon Breach Concerns: If potentially affected by the DMDC breach, monitor financial accounts, watch for phishing attempts, and consider utilizing offered credit monitoring and identity restoration services.
  • Review AI Agent Security: Implement strict governance for AI agents, including least privilege, sandboxing, dry runs for destructive operations, and human oversight. Inspect public repositories for inadvertent data leaks from coding agents.
  • Enhance Endpoint Detection: Update EDR/SIEM rules to detect new process injection techniques (e.g., console named-pipe injection) by correlating multiple low-signal events rather than relying on single API call detections.
  • Scrutinize Software Installations: Be wary of modified installers, especially for common utilities like 7-Zip. Verify publisher authenticity, check version metadata, and inspect extraction stubs.
  • Strengthen Cloud Security: Inventory non-human Microsoft 365 accounts, enforce MFA or workload identities, rotate secrets, and monitor for unusual access patterns, especially from distributed cloud infrastructure.
  • Monitor for C2 Anomalies: Implement robust monitoring for unusual network traffic, particularly C2 channels blending into legitimate cloud services like Microsoft Graph (Outlook, OneDrive) for Antino, or to corp.tripswithengine[.]com for NeedyMantis.
  • Secure SQL Server: Disable xp_cmdshell unless absolutely necessary. Monitor for SQL Server service accounts launching PowerShell or cmd.exe, and for unusual query output volumes.
  • Caution with Online Instructions: Never paste shell commands provided by CAPTCHAs or AI service pages, as these are being used in malware delivery campaigns.
  • Verify Microsoft Defender Exclusions: Regularly audit Microsoft Defender exclusion registry locations directly, investigate broad exemptions, and correlate changes with concealment policy modifications to ensure no malicious exclusions are hidden.
  • Apply Windows 11 Rollback: For Windows 11 users experiencing black screens after updates, apply the relevant Known Issue Rollback policy (KB5124006 or KB5124010) and restart systems until a permanent fix is released.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

BreachCVEExploitMalwarePatchphishingSecurityThreatVulnerabilityzero-day

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

South Korean President Orders Full Security Checks After Financial Sector Hacks

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Microsoft Patches Critical Exchange Server Vulnerability CVE-2023-21763
October 3, 2026
Critical Dell Container Storage CVE-2024-29001 Flaws Let Attackers Gain Admin Control
October 3, 2026
Citrix NetScaler reboots after patching CVE-2023-4966 and CVE-2023-4967
October 3, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us