> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> InfoSec News Nuggets – 10/05/2026

[SOURCE] AboutDFIR [AUTHOR: Mary] [DATE: 05/10/2026 10:53] [LANGUAGE: EN]
Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier Citrix NetScaler administrators spent the weekend scrambling after attackers began exploiting a new zero-day, CVE-2026-88779, a high-severity memory overflow affecting NetScaler ADC and Gateway appliances configured as a SAML SP or IdP. The attacks surfaced when fully patched systems started rebooting on Friday, only days after admins were warned about two other exploited NetScaler zero-days dubbed PitScaler. Citrix characterizes the flaw as a denial-of-service issue, but researcher Kevin Beaumont observed exploitation attempts against patched honeypots, including one that ran a downloaded malware binary, and admins found shell commands hidden in authentication requests meant to fetch a script that plants web shells. Citrix has released fixed builds 14.1-73.41 and 13.1-64.28, and CISA added the bug to its KEV catalog with an October 7 deadline for federal agencies.   Alleged KillSec Ransomware Mastermind a 16-Year-Old German authorities say a 16-year-old Romanian national arrested in Alicante, Spain, is the alleged administrator of the KillSec ransomware operation, following an international takedown dubbed Operation KillSwitch. The effort, led by Hamburg police with support from Europol, Eurojust, Bitdefender and Group-IB, resulted in three arrests, searches of eight properties across Spain, Greece, Romania and the UK, the seizure of five servers and the group’s leak site, and the securing of at least 110TB of stolen data. Investigators examined roughly 1,000 suspected KillSec attacks, about 500 of them confirmed successful and at least 70 involving government organizations, while US prosecutors separately indicted a Dutch national arrested in the UK for his alleged role in the operation.   Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes CISA has added a critical Fortinet FortiMail flaw, CVE-2026-104286 (CVSS 9.8), to its Known Exploited Vulnerabilities catalog after Fortinet confirmed in-the-wild exploitation. The path traversal and null-byte handling bug lets unauthenticated attackers write arbitrary files to the underlying system via crafted HTTP or HTTPS requests, and it affects FortiMail 7.2 through 8.0.1. Until fixed releases are available for all branches, Fortinet recommends disabling IBE support and restricting management interface access to trusted networks, and it has published IP addresses and file-based indicators of compromise to help defenders hunt for intrusions. Federal agencies were given until October 4 to patch or apply the workarounds.   Warlock ransomware breach SharePoint in water, telecom operator attacks The China-linked Warlock ransomware group has been exploiting on-premises SharePoint vulnerabilities to breach a water utility, a telecom provider, a regional government body, and a university, focusing over the past two months on Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. Symantec and Carbon Black researchers, who track the actor as Longlegs, detailed one intrusion in which the attackers used a vulnerable signed K7 driver to disable security tools on at least 40 hosts in about two hours, then pushed ransomware to at least 33 machines from the domain’s SYSVOL share. The group also abused VS Code’s built-in tunneling for remote access and NetExec for Active Directory enumeration, and researchers warn that ToolShell and other SharePoint flaws remain viable entry points more than a year after Warlock first emerged.   Google Suspends Open-Source Bug Bounty Due to AI Vulnerability Reports Google has paused its Open Source Vulnerability Rewards Program until 2027, citing a significant rise in automated, mostly invalid submissions driven by AI tools. Launched in August 2022, the program paid between $100 and $31,337 for flaws in Google’s open-source projects on GitHub and other platforms, including repository configurations such as GitHub Actions workflows and access control rules. The suspension does not affect supply-chain reports or submissions already in the queue, and Google says it plans to reformat the program with an update expected in the first quarter of 2027, pointing researchers to its other reward programs and the Patch Rewards Program in the meantime. The post InfoSec News Nuggets – 10/05/2026 appeared first on AboutDFIR - The Definitive Compendium Project.
[messages.read_original_source] →