National Cyber Warfare Foundation (NCWF)

Security Affairs newsletter Round 598 by Pierluigi Paganini INTERNATIONAL EDITION


0 user ratings
2026-10-04 08:31:06
milo
Blue Team (CND)
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Fake Zoom installer hides macOS backdoor CloudSyncD CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed Antino Backdoor Lets […


A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.





Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.





Fake Zoom installer hides macOS backdoor CloudSyncD
CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed
Antino Backdoor Lets China-Linked UAT-11587 Turn Microsoft 365 Into a C2 Channel
U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog
AI Agents Attempt SQL Injection While Searching Government Data
Investigators trace an AI agent ‘s path from research task to reconnaissance
U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog
Operation KillSwitch: Police Dismantle KillSec Ransomware Group
Inside Gemini 4 Argon, the model Google is testing on its own infrastructure first
Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950
U.S. CISA adds Cisco Catalyst SD-WAN Manager flaw to its Known Exploited Vulnerabilities catalog
AI Agent Chains Zammad Zero-Days To Take Over DIVD Systems in Seconds
WatchGuard fixes critical Fireware OS flaw allowing remote code execution
Oxygen Forensics, A Russian-run forensics firm spent a decade inside European police departments
Attackers Abuse ChatGPT Custom GPTs to Deploy a Full-Featured RAT
U.S. CISA adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog
WHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaign
Japanese railway operators Keio Corporation and Tokyo Metro disclose security breaches
Three Million Affected in Pentagon Personnel Agency Data Breach
Apple Patches CoreGraphics Zero-Day Linked to Sophisticated Targeted Attacks
24-Year-Old Arrested in Dutch Investigation Into ShinyHunters
GPT-6 Astra and the Supply Chain Attack It Wasn’t Asked to Launch
AI Accounts Are Becoming the New Target for Infostealers
Nearly 400,000 Medicaid Beneficiaries Caught in Medicaid and DC Healthcare Alliance Data Exposure
Storm-3168, Linked to JADEPUFFER, Abused Stolen Azure Identities
U.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild
Citrix Confirmed Two New NetScaler Flaws Exploited as Zero-Day
Rydox Admin Faces 20 Years After Selling Stolen Data and Fraud Tools




International Press – Newsletter





Cybercrime





Storm-3168: Agentic-driven cloud attacks using compromised service principals  





Former U.S. Soldier Sentenced for Hacking and Extortion Scheme That Exposed Sensitive Data of U.S. Government Official  





Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation  





Pentagon data breach of military personnel raises national security concerns  





Japanese Railway Operators Hit with Weekend Cyber Attacks 





Vietnamese National Charged for Role in Massive “Pig Butchering” Cryptocurrency Scam





FBI to ShinyHunters: ‘We know how to find you





Delaware Men Sentenced for Cyber Intrusion Scheme Targeting Victims in the Southern District of Iowa  





Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft





Teenager suspected of leading KillSec ransomware group as law enforcement seizes servers and leak site  





Malware





Lunex Unmasked: A New Information Stealer Deployed Through BYOVD  





Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties  





PhantomSub: Malicious npm Campaign Secretly Adds Users to WhatsApp Spam Channels  





CloudSyncD: a two-stage macOS backdoor that hides a phished password in zero-width Unicode





Hacking





Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation





Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild





Defeating Satellite Spoofing With Galileo’s Encryption  





GPT-6 Astra performs unsanctioned supply-chain attacks in simulations





Apple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’  





Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances  





Branch Target Reuse  





Vulnerability Discovery and Exploitation Trends in the AI Era





CVE-2026-86950: The Great Glyph Grift  





Rogue Agents Investigation





AI Agents Targeted U.S. and Canadian Government Websites





The EDR blind spot: 3 ways browser attacks evade endpoint telemetry





Intelligence and Information Warfare  





Star Blizzard refines phishing and malware delivery with the RedFlick technique  





DARPA Selects Xint to Use AI in Securing Military Messaging Apps





Russian tech surveillance company infiltrated Europe’s law enforcement agencies  





Warlock Ransomware Attackers Hit Water and Telecom Operators





Tech CEO, Russian National Arrested on Complaint Alleging They Hid Russian Ownership and Development of Software Sold to U.S. Government 





How Jared Kushner’s firm’s investment in an Israeli company could be a major conflict of interest 





China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor  





MI5 warns UK academics their research may have helped Chinese spies





Cybersecurity





NVIDIA Launches Open Agent Safety Platform to Secure Agents From Testing to Deployment





Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability





SecondSight Threat Hunting Report  





High-Risk ICT Vendors and Critical Infrastructure: European Approaches  





Trump, AI CEOs sign voluntary safety pact, back data center expansion  





Microsoft to block Entra ID script injection attacks starting October





More than half of UK businesses lack confidence in basic cyber skills





Judge dismisses spyware case brought by Salvadoran journalists targeted with Pegasus





PixelLeak: How AI Agents Exposed Developer Screenshots from Leading Tech Companies  





Follow me on Twitter: @securityaffairs and Facebook and Mastodon





Pierluigi Paganini





(SecurityAffairs – hacking, newsletter)



Source: SecurityAffairs
Source Link: https://securityaffairs.com/200326/breaking-news/security-affairs-newsletter-round-598-by-pierluigi-paganini-international-edition.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.