# Archive
Browse past daily curated stories
Monday, October 05, 2026
-
1BleepingComputer generalCitrix patches NetScaler SAML zero-day exploited in attacks
Citrix released emergency patches for CVE-2026-88779, a zero-day denial-of-service vulnerability in NetScaler's SAML implementation that is actively being exploited in attacks. Researchers are investigating whether the flaw can also be leveraged for remote code execution, elevating its potential severity. NetScaler is widely deployed in enterprise environments, making this a high-priority patch for network and security teams.
-
2The Hacker News generalShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members
Saif al-Din Khader, known online as 'Rey' and suspected of membership in the ShinyHunters digital extortion group, was reportedly detained in Jordan on September 29, 2026. Rey is said to be cooperating with the FBI and helping investigators identify other members of the group responsible for numerous high-profile data breaches. The development represents a significant law enforcement action against one of the most prolific cybercriminal collectives in recent years.
-
3The Hacker News generalChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
China-nexus threat actor TA419 has been conducting adversary-in-the-middle (AitM) phishing campaigns against U.S. AI policy experts at think tanks, universities, and law firms, impersonating economists, AI policymakers, and at least one Anthropic employee to harvest credentials. The targeting of AI sector personnel and policy influencers reflects a strategic intelligence collection priority aligned with China's state interests. Security teams supporting organizations in the AI policy space should treat spear-phishing lures mimicking prominent industry figures as a high-risk vector.
-
4The Hacker News generalMI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics
MI5 issued a formal 'Security Service Espionage Alert' on September 30, 2026, warning that over 100 UK-linked academics have been recruited or funded by the China General Technology Research Institute (CGTRI), a front organization for China's Ministry of State Security (MSS), to advance Beijing's intelligence gathering. The alert signals active academic espionage operations targeting UK research institutions. Organizations and universities involved in sensitive research should review relationships with CGTRI-affiliated entities.
-
5Graham Cluley generalN0n ransomware: what you need to know
N0n is a newly identified ransomware and cyber extortion group that emerged in mid-September 2026 and rapidly listed approximately a dozen victims on its dark web leak site within days of surfacing. The group's fast ramp-up mirrors the operational cadence of established ransomware-as-a-service operations. Threat intelligence teams should begin tracking N0n's TTPs and victim profiles to assess sector-specific targeting patterns.
-
6SecurityWeek generalFortra Patches Critical Vulnerabilities in BoKS
Fortra patched multiple critical vulnerabilities in its BoKS privileged access management product, with flaws enabling authentication bypass, shell command execution, and memory corruption. BoKS is used in enterprise environments to control privileged account access, meaning exploitation could grant attackers elevated system control. Organizations running BoKS should apply the patches immediately given the severity and the sensitivity of the product's role in access control architecture.
-
7SecurityWeek generalTrump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force
National Intelligence Director Jay Clayton has been appointed to lead a new federal AI Task Force, announced shortly after President Trump hosted major AI company executives at the White House. The task force signals growing executive-branch focus on AI governance intersecting with national security and intelligence oversight. Security practitioners working in government or regulated industries should monitor the task force's output for potential compliance and policy implications.
-
8SecurityWeek generaldoxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures
Startup doxx.net raised $38 million to launch its Agentic Defense Network (ADN), a platform designed to prevent AI agents operating on behalf of users from taking unauthorized or harmful actions on the internet. As agentic AI systems gain enterprise adoption, their attack surface and misuse potential expand significantly. The funding reflects growing investor and industry recognition that AI agent security is an emerging discipline requiring dedicated tooling.
-
9BleepingComputer generalGoogle Gemini could soon get full access to your Mac’s files, apps and the web
Google is reportedly developing capabilities for its Gemini AI assistant on macOS that would grant it persistent access to local files, installed applications, and the web without requiring per-action permission prompts. Such broad, ambient system access raises significant data exposure and privilege escalation concerns, particularly on enterprise-managed endpoints. Security teams should evaluate macOS MDM policies and data loss prevention controls ahead of any Gemini feature rollout.
-
10The Hacker News generalThe State of Cybersecurity in 2026: Key Segments, Insights, and Innovations
The Hacker News published a 2026 cybersecurity state-of-the-industry report examining how cloud infrastructure expansion, AI integration, distributed systems, and identity sprawl are reshaping enterprise security postures. The report frames the strategic shift toward continuous visibility and at-scale risk response as the defining operational model for modern security programs. Practitioners can use the report as a benchmark for evaluating maturity gaps across identity, cloud, and internet-facing asset management.