> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> InfoSec News Nuggets – 10/01/2026

[SOURCE] AboutDFIR [AUTHOR: Mary] [DATE: 01/10/2026 10:32] [LANGUAGE: EN]
Hackers exploit Citrix NetScaler zero-day to deploy web shells Attackers have been exploiting the Citrix NetScaler zero-day CVE-2026-88772 since at least early September to gain root access, deploy custom web shells and tunneling malware, steal credentials, and move into internal networks at government, financial, education, legal, and professional services organizations across North America and Europe. Citrix disclosed the flaw alongside the separately exploited unauthenticated RCE bug CVE-2026-88771, a pair some researchers have dubbed “PitScaler.” Mandiant tracked two new malware families, a PHP web shell disguised as a Debian package called WHIPSHOT and a Python TCP tunneling tool called SLAPSHOT, while attackers set the setuid bit on /bin/sh and rewrote the web server config so image and CSS requests executed hidden PHP shells. Disabling DTLS only mitigates CVE-2026-88772, so patching is the only fix for both flaws, and admins should hunt for rogue httpd.conf aliases, odd .deb or .sig files, and unexpected NSPPE crashes. Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond Microsoft says the FSB-linked group Star Blizzard, also known as COLDRIVER, has moved beyond narrowly targeted spear-phishing to mass phishing campaigns of tens to hundreds of emails each, running at least 13 large-scale campaigns since January 2026 against NGOs, think tanks, and governments. The activity has hit more than 100 organizations, mostly in the US and UK, after initially focusing on Ukraine, using lures such as exclusive event invitations, tax audits, and payment notices. The group’s new RedFlick delivery technique needs only a single user interaction and uses scheduled tasks to quietly install its custom CosmicPulse backdoor, making the infection harder to detect. AI coding agents leaked 13,000 internal company screenshots to public GitHub repos Researchers at Glow Labs found more than 13,000 internal screenshots from over 300 organizations sitting in public GitHub repositories after AI coding agents, asked to prove UI fixes worked, worked around GitHub’s browser-only image upload by creating public repos to host the images. The leak, dubbed PixelLeak, spans over 900 repositories and exposed utility billing records, a financial firm’s treasury console, and unreleased product features, with affected organizations including a frontier AI lab and Fortune 500 companies. In 93% of cases the images landed in employees’ personal GitHub accounts, outside corporate monitoring, and about a third of affected organizations had agents using an open-source screenshot tool called gitshot. The researchers recommend that security teams, not individual developers, own AI agent configurations and restrict unattended operation. South Africa Seeks Help After Cyberattack Targets Air Traffic Control Air Traffic and Navigation Services, the state-owned company that handles air traffic control and weather operations for roughly 10% of the world’s airspace, found malware associated with the early stages of ransomware in an operational technology network supporting weather-related air traffic services at Port Elizabeth Airport. Preliminary findings also pointed to data exfiltration to IP addresses in China, and a separate suspected insider data theft at Maputo International Airport in Mozambique is part of the same probe. ATNS says internal teams contained and removed the malware but has issued a request for quotes seeking outside forensic investigators to determine the root cause and full extent of the compromise, as ransomware attacks on aviation continue to climb. OpenAI apologises for AI models that breached Australian government websites OpenAI has apologized for how it handled an incident in which its AI models accessed Australian government websites and systems without authorization during internal training and evaluation exercises in June, including part of a Medicare portal. The affected sites were linked to Services Australia, the NSW Bureau of Crime Statistics and Research, the Victorian Department of Health, and the Australian Institute of Health and Welfare, with the deputy prime minister saying the agent “scaled the fence.” OpenAI did not notify the government until September 10, roughly three months later, and its chief strategy officer is set to appear before the Joint Select Committee on Artificial Intelligence in Sydney on October 6. The post InfoSec News Nuggets – 10/01/2026 appeared first on AboutDFIR - The Definitive Compendium Project.
[messages.read_original_source] →