Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (6 October 2026)
Published: Loading…
At a Glance
- Citrix NetScaler ADC and Gateway zero-day CVE-2026-88779 is exploited in targeted attacks to crash SAML authentication, and CISA added it to its KEV catalogue.
- Denmark's national population register breach exposed names, addresses and CPR numbers of about 8.8 million people after a private company's legitimate access was abused.
- Rejetto HFS flaw CVE-2026-61500, a weak signing key enabling session forgery and remote code execution, is being actively scanned and exploited.
- Forty-two malicious RubyGems packages targeting crypto developers open reverse shells or download second-stage payloads, while a compromised SubQuery npm package steals credentials.
- ClingSTUN, a Linux back-connect proxy backdoor, exploits dozens of known IoT flaws and abuses public STUN servers for command-and-control traffic.
- Microsoft released out-of-band Exchange Server updates for CVE-2026-96940, which lets authenticated attackers read other users' mailboxes within the same organisation.
Editorial Analysis
Citrix's third NetScaler problem in under two weeks differs from the earlier ones in what it does to a victim. CVE-2026-88779 is a memory overflow that, according to Citrix, affects availability rather than confidentiality. It only affects appliances configured as a SAML service provider or identity provider, but those appliances sit in front of VPN and single sign-on, so a crashed authentication service can lock out an entire organisation. The condition requires no credentials, and repeated triggering keeps the service down. Severity remains contested: some researchers suggest the overflow could allow remote code execution, which Citrix has not confirmed. CISA's KEV listing, with a 7 October federal deadline, makes this the sixth exploited NetScaler flaw added to the catalogue this year. Citrix initially described the issue as unrelated to the previous week's vulnerabilities, even though it surfaced days after those fixes shipped.
Denmark's CPR breach involved no stolen credentials or software flaw. Attackers abused a private company's lawful search access to the register and retrieved names, addresses and CPR numbers for about 8.8 million people, roughly four-fifths of the 11 million records it holds. Under CPR law, companies may request data on a defined group of people they have already identified individually, making the scale of the retrieval particularly notable. Authorities say irregular behaviour continued through September and was noticed on the evening of 2 October. Bromcom's legacy single sign-on registration service, which exposed email addresses before being withdrawn from production, provides a smaller example of an access path remaining available after its original purpose had ended.
Google's pause on OSS VRP product vulnerability submissions and Debian's 1,313-CVE kernel advisory show the volume of vulnerability reporting putting pressure on the systems that process it. Google says most automated submissions were invalid, while supply-chain reports and earlier submissions are unaffected and a revised programme is promised for Q1 2027. Debian's DSA-6528-1 for kernel 6.12.111-1 lists 1,313 identifiers, although several also affect older kernels, so the figure does not represent bugs introduced in that release. Google follows curl, which ended its HackerOne programme in January, and Intel, which removed rewards from its Intigriti programme in mid-September. Microsoft's record 966-flaw release last month adds to the pressure on intake and triage capacity, even as researchers continue to receive substantial payouts elsewhere: Google paid $17.1 million in 2025.
Highlights of the Day
Citrix NetScaler Zero-Day Exploited to Crash SAML Authentication
Citrix confirmed targeted exploitation of CVE-2026-88779, a memory overflow in the NetScaler nsaaad SAML handler affecting ADC and Gateway appliances. Unauthenticated attackers can send crafted requests to crash the service, locking users out of VPN and single sign-on. CISA added the flaw to its Known Exploited Vulnerabilities catalogue on 4 October, setting a 7 October federal deadline.
Google Pauses Open-Source Bug Bounty Submissions After AI Report Flood
Google has temporarily stopped accepting product vulnerability submissions to its Open Source Software Vulnerability Rewards Program, citing a significant rise in automated reports, most of which are invalid. Supply chain reports and reports submitted before 1 October 2026 are unaffected. Google plans to provide an update on the programme's revised format in the first quarter of 2027.
ClingSTUN Linux Backdoor Hides Traffic in Public STUN Servers
FortiGuard Labs detailed ClingSTUN, a Linux backdoor that turns compromised routers, cameras and other IoT devices into remotely controlled proxy nodes. It spreads by exploiting known, unpatched flaws in devices from vendors including EnGenius, D-Link, TP-Link and Ivanti. The malware contacts legitimate public STUN servers to maintain network address mappings, allowing its traffic to blend with normal VoIP and WebRTC communications.
Danish CPR Breach Exposes Personal Data of 8.8 Million People
Unauthorised actors abused a Danish private company's legitimate access to the Central Person Register, obtaining names, addresses and CPR numbers for about 8.8 million registered individuals. Records of people with name and address protection were not affected, and the company's access has been stopped. Authorities became aware on 2 October 2026, the irregular activity dated from September, and police are investigating.
Microsoft Patches Exchange Flaw Allowing Access to Other Users' Mailboxes
Microsoft disclosed CVE-2026-96940, an Exchange Server weak authentication flaw that lets an authenticated attacker elevate privileges over a network. Successful exploitation allows access to other users' mailboxes within the same organisation, but not across tenant boundaries. The vulnerability is rated Important with a CVSS score of 8.8, and Microsoft reports no public disclosure or exploitation. Security updates cover Exchange Server 2016, 2019 and Subscription Edition, while Exchange Online received a service-side fix.
Gentlemen Ransomware Affiliate Steals Victim Data and Keeps the Proceeds
CloudSEK found that Azazel, a Russian-speaking Gentlemen ransomware affiliate, breached more than two dozen organisations across six countries and held about 6TB of stolen data on exposed servers. He published victims on his own leak site, LEAKNED, bypassing the Gentlemen group and keeping the extortion proceeds. Most intrusions used stolen GitLab CI/CD secrets, while one attack chain used an AI coding assistant's MCP interface to run commands inside a victim environment.
Datadog Finds Dangerous Kubernetes Permissions Granted to Built-In Principals
Datadog Security Labs analysed more than 65,000 clusters from almost 10,000 organisations, identifying about 320,000 role bindings to the anonymous, unauthenticated and authenticated principals. After excluding default and obsolete bindings, researchers found over 3,500 bindings granting at least one dangerous permission. Some were namespace-scoped, and AKS and EKS reject or restrict anonymous access by default.
BigDiskBuster Tool Silently Blocks Microsoft Defender Updates by Filling Disks
LevelBlue SpiderLabs analysed BigDiskBuster, a proof of concept published on GitHub on 19 September 2026 that stops Defender updates by claiming all free space on the C drive. It monitors for update activity, creates a hidden file sized to the available space, and repeats after each failed attempt. Defender's service and real-time protection stay active, while the only visible sign is a generic 0x80070643 error, and no CVE, patch or Microsoft advisory exists.
42 Malicious RubyGems Open Reverse Shells on Developer Machines
On 5 October 2026, the account reqthrottle_3474 published 42 malicious gems, mostly aimed at cryptocurrency developers and including typosquats of real packages. The code runs during installation, skips CI and sandbox environments, then waits 20 to 40 minutes. Eleven gems open a reverse shell to a remote server, while 31 download and run a second-stage script whose function is unknown.
Daily Coverage