> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> Security Affairs newsletter Round 598 by Pierluigi Paganini – INTERNATIONAL EDITION

[SOURCE] Security Affairs [AUTHOR: Pierluigi Paganini] [DATE: 04/10/2026 07:58] [LANGUAGE: EN]
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Fake Zoom installer hides macOS backdoor CloudSyncDCVE-2026-90970: Critical GitLab AI Gateway Flaw FixedAntino Backdoor Lets China-Linked UAT-11587 Turn Microsoft 365 Into a C2 ChannelU.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalogAI Agents Attempt SQL Injection While Searching Government DataInvestigators trace an AI agent ‘s path from research task to reconnaissanceU.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalogOperation KillSwitch: Police Dismantle KillSec Ransomware GroupInside Gemini 4 Argon, the model Google is testing on its own infrastructure firstPublic PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950U.S. CISA adds Cisco Catalyst SD-WAN Manager flaw to its Known Exploited Vulnerabilities catalogAI Agent Chains Zammad Zero-Days To Take Over DIVD Systems in SecondsWatchGuard fixes critical Fireware OS flaw allowing remote code executionOxygen Forensics, A Russian-run forensics firm spent a decade inside European police departmentsAttackers Abuse ChatGPT Custom GPTs to Deploy a Full-Featured RATU.S. CISA adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalogWHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaignJapanese railway operators Keio Corporation and Tokyo Metro disclose security breachesThree Million Affected in Pentagon Personnel Agency Data BreachApple Patches CoreGraphics Zero-Day Linked to Sophisticated Targeted Attacks24-Year-Old Arrested in Dutch Investigation Into ShinyHuntersGPT-6 Astra and the Supply Chain Attack It Wasn’t Asked to LaunchAI Accounts Are Becoming the New Target for InfostealersNearly 400,000 Medicaid Beneficiaries Caught in Medicaid and DC Healthcare Alliance Data ExposureStorm-3168, Linked to JADEPUFFER, Abused Stolen Azure IdentitiesU.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalogRoundcube SQL injection CVE-2026-48842 is now being exploited in the wildCitrix Confirmed Two New NetScaler Flaws Exploited as Zero-DayRydox Admin Faces 20 Years After Selling Stolen Data and Fraud Tools International Press – Newsletter Cybercrime Storm-3168: Agentic-driven cloud attacks using compromised service principals   Former U.S. Soldier Sentenced for Hacking and Extortion Scheme That Exposed Sensitive Data of U.S. Government Official   Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation   Pentagon data breach of military personnel raises national security concerns   Japanese Railway Operators Hit with Weekend Cyber Attacks  Vietnamese National Charged for Role in Massive “Pig Butchering” Cryptocurrency Scam FBI to ShinyHunters: ‘We know how to find you Delaware Men Sentenced for Cyber Intrusion Scheme Targeting Victims in the Southern District of Iowa   Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft Teenager suspected of leading KillSec ransomware group as law enforcement seizes servers and leak site   Malware Lunex Unmasked: A New Information Stealer Deployed Through BYOVD   Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties   PhantomSub: Malicious npm Campaign Secretly Adds Users to WhatsApp Spam Channels   CloudSyncD: a two-stage macOS backdoor that hides a phished password in zero-width Unicode Hacking Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild Defeating Satellite Spoofing With Galileo’s Encryption   GPT-6 Astra performs unsanctioned supply-chain attacks in simulations Apple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’   Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances   Branch Target Reuse   Vulnerability Discovery and Exploitation Trends in the AI Era CVE-2026-86950: The Great Glyph Grift   Rogue Agents Investigation AI Agents Targeted U.S. and Canadian Government Websites The EDR blind spot: 3 ways browser attacks evade endpoint telemetry Intelligence and Information Warfare   Star Blizzard refines phishing and malware delivery with the RedFlick technique   DARPA Selects Xint to Use AI in Securing Military Messaging Apps Russian tech surveillance company infiltrated Europe’s law enforcement agencies   Warlock Ransomware Attackers Hit Water and Telecom Operators Tech CEO, Russian National Arrested on Complaint Alleging They Hid Russian Ownership and Development of Software Sold to U.S. Government  How Jared Kushner’s firm’s investment in an Israeli company could be a major conflict of interest  China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor   MI5 warns UK academics their research may have helped Chinese spies Cybersecurity NVIDIA Launches Open Agent Safety Platform to Secure Agents From Testing to Deployment Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability SecondSight Threat Hunting Report   High-Risk ICT Vendors and Critical Infrastructure: European Approaches   Trump, AI CEOs sign voluntary safety pact, back data center expansion   Microsoft to block Entra ID script injection attacks starting October More than half of UK businesses lack confidence in basic cyber skills Judge dismisses spyware case brought by Salvadoran journalists targeted with Pegasus PixelLeak: How AI Agents Exposed Developer Screenshots from Leading Tech Companies   Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, newsletter)
[messages.read_original_source] →