# Archive
Browse past daily curated stories
Saturday, October 10, 2026
-
1The Hacker News generalFBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure Intrusions
The FBI and DOJ seized 7 domains and disrupted MicroScan and FishHub — hacking tools operated by Beijing-based Integrity Technology Group and used by China-linked Flax Typhoon APT to scan and infiltrate U.S. critical infrastructure. The international coalition action, coordinated with agencies from 6 other countries, also targeted a portal Integrity Tech operated giving third parties access to emails stolen from government, law enforcement, healthcare, and religious organizations in Southeast Asia. Security practitioners should review Flax Typhoon TTPs and the accompanying CISA/FBI/NSA advisory.
-
2The Hacker News generalFlax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies
CISA added five vulnerabilities to its KEV catalog — including CVE-2015-3306 (CVSS 10.0, ProFTPD improper access control) — all actively exploited by China-linked Flax Typhoon, with a federal agency remediation deadline of October 11, 2026. The additions tie directly to the same Integrity Tech / Flax Typhoon campaign disrupted by the FBI and DOJ this week. Federal agencies and critical infrastructure operators must prioritize these five flaws immediately given the tight deadline.
-
3BleepingComputer generalHackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland
Pwn2Own Ireland 2026 concluded with researchers earning $1,262,000 for 98 zero-day exploits across phones, printers, smart speakers, smart home hubs, and AI infrastructure. Google Pixel 10 alone generated $560,000 in payouts, with Ikotas Labs earning the top single prize of $300,000 for a pre-auth remote exploit chain. All vulnerabilities are now being disclosed to vendors, making this a critical window for defenders to anticipate upcoming patches.
-
4BleepingComputer generalMax severity SonicWall SMA1000 flaw now exploited in attacks
Attackers began exploiting CVE-2026-102255, a maximum-severity vulnerability in SonicWall SMA1000 appliances, just three days after SonicWall released a patch on Tuesday. Active exploitation of freshly patched critical flaws in widely-deployed network access appliances demands immediate emergency patching for any organization running SMA1000 in its environment.
-
5The Hacker News generalCitrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments
Citrix patched CVE-2026-107406, a critical memory overflow vulnerability in NetScaler ADC and NetScaler Gateway that can lead to remote code execution or denial-of-service under specific SAML configuration conditions, and is urging administrators to apply the fix immediately. NetScaler appliances are a perennial high-value target for nation-state and ransomware actors, making prompt patching essential for any organization using these products for remote access or load balancing.
-
6The Hacker News generalAttackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge
Threat actors are actively exploiting two unpatched flaws in AhsayCBS backup management software — CVE-2026-105133 (CVSS v4 5.5, improper authentication in checkSysPwd()) and CVE-2026-105134 (OS command injection) — to deploy webshells and XMRig cryptocurrency miners disguised as Microsoft Edge. Backup infrastructure is a high-value target since compromise can undermine disaster recovery capabilities; administrators running AhsayCBS should isolate affected systems pending vendor patches.
-
7BleepingComputer generalFBI arrests another suspected ShinyHunters hacker after agency breach
The FBI arrested a second suspected member of the ShinyHunters extortion group in connection with the breach of FBI systems, with Director Kash Patel announcing the arrest on October 9, 2026. ShinyHunters claimed in September to have breached the FBI's jobs portal and stolen sensitive data on nearly all FBI agents and job applicants, and a separate arrest linked to the group was also announced this week by Krebs on Security involving the co-founder of a Canadian ransomware negotiation firm.
-
8BleepingComputer generalLow-cost Android phones ship with residential proxy malware
The 'Midnight Mimosa' malware campaign has been found pre-installed in the firmware of low-cost Android smartphones sold across 150+ countries, enabling silent app installation, ad fraud, and conversion of devices into residential proxies — all without user interaction and with no ability to uninstall. Bitdefender researchers confirmed the malware is present before the device is first powered on, representing a supply chain compromise targeting consumers who have no viable remediation path short of device replacement.
-
9The Hacker News generalResearchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access
Security researchers published a full working pre-authentication RCE exploit for AnyDesk on Linux that grants root access before any connection is approved by the user; AnyDesk quietly fixed the bug in version 8.0.3 in June 2026, describing it only as 'a bug that could lead to a crash' with no CVE assigned. The combination of a published exploit, no CVE identifier, and a low-profile patch note means many administrators may be running vulnerable versions without awareness, making urgent version verification critical.
-
10Graham Cluley general$10 million bounty offered for Chinese Hafnium hacker accused of Microsoft Exchange Server mega-attack
The U.S. State Department is offering up to $10 million for information on Zhang Yu, a 44-year-old Chinese national accused of being a key figure in the Hafnium APT group responsible for the mass exploitation of Microsoft Exchange Server vulnerabilities. This Rewards for Justice bounty underscores continued U.S. government pressure on Chinese state-sponsored threat actors and may yield new intelligence on Hafnium's current operational infrastructure.