Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution | Cybersecurity
Ravie LakshmananSep 30, 2026Vulnerability / Network Security Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under…
Read moreFake iPhone Duo preorder scam triggers DarkSword attack | Malware
Apple announced its first foldable iPhone on September 9, and scammers were ready to ‘deliver’ one before anyone could buy it. Most of what we found around the launch of…
Read moreFrench Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks | Cybersecurity
An attacker used stolen passwords of staff at France’s tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July. Neither the tax…
Read moreMeta’s Muse sent a Facebook Marketplace buyer to a seller’s home | Malware
A Facebook Marketplace buyer arrived at a seller’s apartment to collect a keyboard. The seller wasn’t home and didn’t know anyone was coming. Meta’s AI assistant Muse had handled the…
Read moreKiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown | Cybersecurity
Ravie LakshmananSep 29, 2026Vulnerability / Enterprise Security Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during…
Read moreUpdate your iPhone, iPad, or Mac: Flaw could run attackers’ code | Malware
Apple has released updates for iPhones, iPads, and Macs to fix a flaw that could let an attacker run code when a device processes a malicious file. Apple says it…
Read moreDutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation | Cybersecurity
Ravie LakshmananSep 29, 2026United States Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. “It is true that this month a…
Read moreOpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot | Cybersecurity
OpenAI said it has made the decision to pause training of its most powerful models after one of its agents during reinforcement learning (RL) training contacted an external chatbot by…
Read moreFBI agents’ blood tests and doctors’ notes surface after breach | Malware
BBC News reports it has seen samples of stolen FBI agents’ medical examinations. The “fitness-for-work” reports identify FBI agents by name and address, and reveal even more personal details. They…
Read moreHackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks | Cybersecurity
Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in…
Read moreWebinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI | Cybersecurity
The Hacker NewsSep 28, 2026Identity Security / AI Agent Security AI agents are moving into production faster than security teams can govern them. They are connecting to apps, handling data,…
Read moreOpenAI pauses work on top AI models after agent slips past internet controls | Malware
OpenAI’s latest containment failure adds to a pattern that may force the company to make an unpopular decision. The company has paused training, evaluation, and tool-enabled inference for its most…
Read moreCISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally | Cybersecurity
Ravie LakshmananSep 28, 2026Vulnerability / Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited…
Read moreApple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks | Cybersecurity
Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked…
Read moreA week in security (September 21 – September 27) | Malware
Last week on Malwarebytes Labs: LinkedIn adds new checks for fake profiles and work histories Kothamine malware uses Tailscale’s tailcat to evade network detection Criminals turn placeholder domain into ClickFix…
Read moreWarning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation | Cybersecurity
Swati KhandelwalSep 27, 2026Vulnerability / Network Security Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in…
Read moreLunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials | Cybersecurity
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue,…
Read moreAttackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells | Cybersecurity
Ravie LakshmananSep 26, 2026Vulnerability / Web Security Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally….
Read moreThat shipping rebate offer may come with a monthly charge | Malware
Thanks to Malwarebytes research engineer Stefan Dasic for his help with this article. A name like ShipmentsFree suggests a way to save on shipping. The service does offer shipping rebates,…
Read moreElementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link | Cybersecurity
Ravie LakshmananSep 26, 2026Vulnerability / Web Security Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to…
Read moreCriminals turn placeholder domain into ClickFix trap | Malware
A domain that has long appeared in software documentation, code examples, and developer test material is now being used to push a ClickFix attack against Windows users. A placeholder domain…
Read moreKothamine malware uses Tailscale’s tailcat to evade network detection | Malware
We discovered an undocumented remote-access Trojan (RAT) called Kothamine Agent. It supports more than 30 commands and it gives attackers control of an infected Windows computer: they can run commands,…
Read moreCompromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware | Cybersecurity
Ravie LakshmananSep 25, 2026Malware / Supply Chain Attack Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were…
Read moreLinkedIn adds new checks for fake profiles and work histories | Malware
LinkedIn is adding trust and verification features aimed at making fake professional identities, invented work histories, and company impersonation harder to pull off. The company is responding to an environment…
Read moreRoundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild | Cybersecurity
Ravie LakshmananSep 25, 2026Vulnerability / Email Security The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability…
Read moreGoogle’s location data privacy failures draw a €403 million fine | Malware
The Irish Data Protection Commission (DPC) has fined Google €403 million ($459 million) for violating European privacy law. The penalty follows a six-year inquiry into Google’s management of user location…
Read moreWSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV | Cybersecurity
Ravie LakshmananSep 25, 2026Vulnerability / Web Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to…
Read moreNew Browser Guard features add protection before and after you click | Malware
Most of us click on search results without knowing much about the website we’re about to visit. And once we’re there, it’s not always obvious when something isn’t quite right. …
Read moreOpenAI agent breached Australian government site, took months to report it | Malware
An OpenAI agent didn’t take “no” for an answer when it encountered a government website’s access controls. It got through, prompting Australia’s Prime Minister Anthony Albanese to raise his concerns…
Read moreUnpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions | Cybersecurity
Swati KhandelwalSep 24, 2026Vulnerability / Mobile Security A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special…
Read more