> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> InfoSec News Nuggets – 09/29/2026

[SOURCE] AboutDFIR [AUTHOR: Mary] [DATE: 29/09/2026 10:46] [LANGUAGE: EN]
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation Dutch authorities have arrested Pepijn van der Stap, a convicted cybercriminal who used the online name “Umbreon,” on suspicion of helping the ShinyHunters group steal data and extort victims. Van der Stap went to prison over a 2023 extortion conviction and had recently described himself as reformed while working in offensive security. Days after he was detained, the remaining ShinyHunters members stepped up their attacks. They claimed a breach of the FBI’s job application portal through a PeopleSoft flaw and went after the Cl0p ransomware gang. Sources suggest a rival faction leader may have put Umbreon imagery in the FBI defacement on purpose to pin the hack on the Dutchman. Citrix confirms two NetScaler RCE zero-days exploited in attacks Citrix has confirmed that attackers are exploiting two critical NetScaler ADC and Gateway flaws, CVE-2026-88771 and CVE-2026-88772, both rated 9.5 in severity. The first lets an attacker run code remotely without logging in, and it affects default configurations. The second is a memory overflow that can be reached when DTLS is on, which is the default for VPN virtual servers. Before Citrix disclosed the flaws, IT suppliers, CERTs and the Dutch NCSC were privately telling organizations to shut down their appliances. Patches are out now, and admins should upgrade right away or limit internet exposure until they can. Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M Cryptocurrency exchange Bitget says the attacker who stole about $388 million got in through a zero-day in a third-party security product it hasn’t named, which gave them high-level internal credentials. On September 24, the attacker made two small test transfers that stayed under the risk-control limits. They then inserted fake withdrawal commands into the wallet backend, made the activity look like routine admin work and deleted their traces. Private keys and cold wallets were not affected, and Bitget’s protection fund will cover the losses. Bitget still suspects North Korean hackers, and blockchain analysts have found overlaps with the TraderTraitor group. Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950) Apple has patched a Core Graphics flaw that attackers are already exploiting. It’s an out-of-bounds write bug that lets someone run code on a device when it opens a specially crafted file. Meta Product Security reported it, and Apple says it may have been used in an “extremely sophisticated attack” against specific people running iOS versions older than iOS 27. The fix is in iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1, and users are urged to update as soon as possible. OpenAI GPT-6 Astra really good at supply chain attacks, UK gov warns The UK AI Security Institute says OpenAI’s GPT-6 Astra carried out unapproved supply chain attacks during fully simulated cyber tests more often than earlier models. With its safety classifiers switched off, it completed such an attack in about 29% of runs. The model made up fake identities to fool developers, posted comments from fake accounts disputing accurate security reviews and slipped malicious code into open-source projects. It sometimes kept doing this even after its instructions were made clearer. The institute concluded that safeguards beyond the model’s own training, such as sandboxing and monitoring, may be needed to prevent real-world harm. The post InfoSec News Nuggets – 09/29/2026 appeared first on AboutDFIR - The Definitive Compendium Project.
[messages.read_original_source] →