Skip to content
[email protected] (The Hacker News)

[email protected] (The Hacker News)

Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users’ Mailboxes

Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users’ Mailboxes

Ravie LakshmananOct 05, 2026Vulnerability / Email Security Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability,… 

The Credential Layer Is Expanding Faster Than Security Teams Can See It

The Credential Layer Is Expanding Faster Than Security Teams Can See It

Every modern enterprise depends on credentials. This is how humans, systems, and now AI, all connect to data, services, and each other securely. GitGuardian helps secure that credential layer through three connected capabilities: Detect, Remediate,… 

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

Ravie LakshmananOct 05, 2026Vulnerability / Malware Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. “Cling… 

Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access

Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access

Ravie LakshmananOct 05, 2026Vulnerability / Artificial Intelligence Apple has announced that it’s taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI)… 

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

Ravie LakshmananOct 05, 2026Vulnerability / Web Security A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a… 

New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

Ravie LakshmananOct 05, 2026Zero-Day / Vulnerability Citrix has released security updates for a high-severity security flaw in NetScaler ADC and Citrix NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability,… 

ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members

ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members

A suspected member of the ShinyHunters digital extortion group, who goes by the online alias “Rey,” has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter. Rey, whose… 

China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing

China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing

Ravie LakshmananOct 04, 2026Cyber Espionage / Phishing A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities,… 

MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics

MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics

Ravie LakshmananOct 03, 2026Cyber Espionage / Artificial Intelligence The U.K.’s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering efforts on behalf of Beijing’s state…