30 Sep, 2026

Citrix confirms two NetScaler RCE zero-days exploited in attacks

Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws. The vulnerabilities are the same zero-days that cybersecurity researchers, IT providers, and national cybersecurity agencies began privately warning organizations about over the weekend. […]

5 mins read

Arista patches actively exploited VeloCloud Orchestrator zero-day

Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments. VCO is a cloud-based centralized management platform that helps admins configure, monitor, and manage VeloCloud SD-WANs (Software-Defined Wide Area Networks) and associated edge devices. Tracked as CVE-2026-93952, this maximum-severity flaw stems from an […]

2 mins read

ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. The threat actors told GeekFeed the vulnerability allows remote code execution and that they used it Monday night to access FBI systems before moving laterally […]

6 mins read

Check Point warns of Management Server zero-day exploited in attacks

Check Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts. The Security Management Server is a central repository that stores and manages security policies, processes administrator changes, and collects system logs across enterprise networks. Tracked as CVE-2026-93616, this path traversal flaw lets unauthenticated threat […]

3 mins read

New Windows Defender zero-day blocks Microsoft antivirus updates

Over the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates. Naceri named it BigDiskBuster and said it is similar to another Defender zero-day known as UnDefend, which he released in April and that allowed standard users to block definition updates. The security researcher added […]

2 mins read

Cisco warns of max severity ISE zero-day exploited in attacks

Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. Cisco ISE is a centralized policy platform that IT administrators use to manage endpoints, users, and device access to network resources, often while enforcing Zero Trust security models. The security flaw (tracked as CVE-2026-76460) […]

2 mins read

Google fixes actively exploited Android zero-day on Pixel devices

Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks. “There are indications that CVE-2026-58704 may be under limited, targeted exploitation,” the company warned on Wednesday. “All supported Google devices will receive an update to the 2026-09-05 patch level. We […]

2 mins read

Cisco patches Secure Email Gateway zero-day exploited in attacks

Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. “In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability,” the company warned in a Monday security advisory. The security flaw (tracked as CVE-2026-76461) was found in the email parsing […]

2 mins read

Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. The attacks exploited CVE-2026-20079, a maximum-severity authentication bypass flaw, and CVE-2026-20316, a static credential vulnerability that allows attackers to log in using a low-privileged account. According to a new […]

5 mins read

New ‘BlueMoon’ kit exploited Windows and Chrome zero-day flaws

Multiple cyber-espionage groups deployed an exploit kit dubbed “BlueMoon” that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. BlueMoon combines two security issues in Chromium-based browsers that allow remote code execution and sandbox escape with a kernel local privilege escalation in Windows. The kit appears to be a shared modular tool that supports exploit additions […]

3 mins read