Here are today’s top cybersecurity stories for Monday, October 5, 2026.
Citrix Patches NetScaler SAML Zero-Day Exploited in Attacks
CVE-2026-88779 is a memory overflow in NetScaler ADC and Gateway with a CVSS score of 8.7. Only appliances configured as a SAML service provider or identity provider are exposed. Citrix confirms targeted attacks leading to denial of service, and researchers observed crafted usernames carrying shell commands. Fixed builds are 14.1-73.41 and 13.1-64.28. CISA added the flaw to its Known Exploited Vulnerabilities catalog with an October 7 deadline. BleepingComputer
Denmark Population Registry Data Breach Affects 8.8 Million People
Attackers misused the legitimate access of a private Danish company to the Central Population Register and enumerated CPR numbers by brute force. Exposed data includes names, addresses, CPR numbers, birth dates, and marital status. Registry administrators discovered the breach on October 2 and announced it on October 5. Police are investigating and the company’s access is blocked. BleepingComputer
Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users’ Mailboxes
CVE-2026-96940 carries a CVSS score of 8.8 and stems from weak authorization. It affects Exchange Server Subscription Edition RTM, Exchange 2016 CU23, and Exchange 2019 CU14 and CU15. Microsoft fixed Exchange Online on the service side and rates exploitation as more likely. No attacks are reported so far. The Hacker News
Attackers Target Rejetto HFS Flaw Enabling Admin Session Forgery and RCE
CVE-2026-61500 scores 9.3 and affects Rejetto HTTP File Server 3.0.0 through 3.2.0. The server signs session cookies with Math.random(), which lets attackers recover the key, forge administrator cookies, and run code. Horizon3.ai found the flaw with an AI model. VulnCheck detected exploitation on October 1 by a Chinese threat actor. Version 3.2.1 fixes the issue. The Hacker News
New Dell System Update Flaw Lets Hackers Gain Root Privileges
CVE-2026-86360 is a path traversal flaw in the Dell System Update command-line tool for PowerEdge servers. An unauthenticated remote attacker reaches the file system and runs code as root. Dell fixed it in DSU 2.3.0.0 along with four high-severity flaws. No exploitation is reported. BleepingComputer
South Korea Probes Bank Breaches Amid Suspected AI-Powered Attacks
The Financial Services Commission held an emergency meeting after breaches at Shinhan Bank, KB Kookmin Bank, and Hana Bank. Shinhan exposed 25,000 customer records and Kookmin leaked credit card data for 119,000 clients. Local media linked an attack server to the ARTEX AI penetration-testing tool, but authorities have not confirmed AI involvement. BleepingComputer
Google Halts Open-Source Bug Bounty Program Amid AI Spam Surge
Google suspended its Open Source Software Vulnerability Rewards Program, citing a significant rise in automated submissions, most of them invalid. Researchers still have the Patch Rewards Program and Cloud VRP. Google expects to share a reformulated program in the first quarter of 2027. BleepingComputer
Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2
Nozomi Networks reports exploitation of CVE-2021-35394, a CVSS 9.8 flaw, starting September 5. The Cling malware hides commands in STUN transaction IDs, which makes command traffic look like normal NAT traversal. It carries exploits for seven more CVEs across Realtek, Eir, MVPower, LB-LINK, FiberHome, TBK, and Linksys devices. The Hacker News
China-Aligned TA419 Targets US AI Policy Experts With Microsoft AitM Phishing
Proofpoint reports the group impersonates economists and AI policymakers and asks targets for feedback on AI policy topics. Victims pass through a Cloudflare Turnstile check to a browser-in-the-browser page spoofing a Microsoft login, where an adversary-in-the-middle proxy captures credentials and session cookies. Targets include think tanks, universities, law firms, and defense contractors. The Hacker News
MI5 Says China’s MSS Funded Research Involving 100+ UK-Linked Academics
MI5 issued an espionage alert on September 30 naming the China General Technology Research Institute as a front company for the Ministry of State Security. The institute funds research in AI, cybersecurity, covert communications, and steganography. MI5 urged UK institutions to review ties and warned of prosecution under the National Security Act 2023. China’s UK embassy rejected the claims. The Hacker News
ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI
Reuters reports Jordanian authorities detained Saif al-Din Khader, known as Rey, on October 1. Two sources say he is cooperating with the FBI to locate other members of the extortion group. He is linked to breaches at Telefónica, Orange, and Jaguar Land Rover. BleepingComputer
Stay tuned for today’s in-depth analysis posts.






