Canadian Cyber Security Journal
SOCIAL:
Filed under: News

Cybersecurity Daily Brief — Friday, October 9, 2026

Here are today’s top cybersecurity stories for Friday, October 9, 2026.

FBI Seizes Seven Domains Tied to Flax Typhoon Hacking Tools
The FBI seized seven domains used to run two tools named MicroScan and FishHub. U.S. authorities say China-based Integrity Technology Group operated the infrastructure for China-linked threat actors. MicroScan is a Python vulnerability scanner with more than 1,300 scripts, and FishHub supports spear-phishing and malware delivery. BleepingComputer

CISA Adds Five Flaws to KEV Catalog After Flax Typhoon Exploitation
CISA added flaws in ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND to its Known Exploited Vulnerabilities catalog. Federal agencies must patch by October 11. The agency says the actors used scanning tools, cross-site scripting, and password spraying against Microsoft Exchange servers to gain access. The Hacker News

FBI Says China-Linked Hackers Ran a Portal Giving Third Parties Access to Stolen Email
A joint advisory from the FBI and agencies in six other countries describes a web application built to give third parties access to stolen email content. The advisory ties the activity to Integrity Technology Group and says intrusions ran since at least mid-January 2021. Victims include government, law enforcement, healthcare, and religious organizations. The Hacker News

Citrix Urges Immediate Patching of Critical NetScaler Flaw CVE-2026-107406
Citrix patched a memory overflow rated 9.5 in CVSS. It affects NetScaler ADC and Gateway appliances configured as a SAML service provider or identity provider and allows remote code execution or denial of service. Citrix knows of no exploitation. Fixes ship in 14.1-73.46 and 13.1-64.29. SecurityWeek

Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge
Huntress reports attackers chained CVE-2026-105133 and CVE-2026-105134 to bypass authentication and run commands on AhsayCBS backup servers. Exploitation began October 7 and affected five organizations by October 8. Huntress says version 10.3.4 remains vulnerable. The Hacker News

Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw
V12 researcher Rick de Jager released an exploit named AnyPwn for a heap overflow in the AnyDesk Linux session protocol. The exploit targets version 8.0.2 over TCP port 7070 and gives root access before a connection is approved. AnyDesk fixed the flaw in version 8.0.3 in June. No in-the-wild exploitation is reported. The Hacker News

P7 Variant of DarkSword iOS Exploit Kit Adds Crypto Wallet Theft and Remote Commands
iVerify describes a DarkSword variant with a smaller on-device footprint. It extracts keychain and crypto-wallet data and polls for commands every 15 seconds. Attacks have hit Saudi Arabia, Turkey, Malaysia, and Ukraine. The Hacker News

Ransomware Attack Disrupts Japan’s IDCF Cloud Used by Government Clients
IDC Frontier, a SoftBank subsidiary, disclosed a ransomware attack on its East Japan Region 1 data center cluster on October 7. The service has 495 corporate and local government customers. The attacker claims to have encrypted 225 databases, and the company has not verified the claims. BleepingComputer

Low-Cost Android Phones Ship With Residential Proxy Malware
Bitdefender found a campaign named Midnight Mimosa embedded in firmware on cheap MediaTek-based Android phones. The malware installs apps silently, drives ad fraud, and includes a proxy component. It reached thousands of devices across more than 150 countries over about two years. BleepingComputer

FakeGit Campaign Returns With 17,610 Malicious GitHub Repositories
Apiiro says the campaign resumed on October 4 and pushed more than 13,000 repositories in 34 hours. The repositories distribute the SmartLoader loader, which delivers the StealC infostealer. At least 700 of the accounts appear to belong to legitimate developers. BleepingComputer

TP-Link Sued by Four More U.S. States Over Router Security and China Ties
Florida, Iowa, Montana, and Nebraska sued TP-Link Systems under consumer-protection laws, joining Texas. TP-Link calls the suits built on false premises. SEC Consult also published details of five flaws in ISP-supplied TP-Link Aginet devices, led by CVE-2025-30237. The Hacker News

Stay tuned for today’s in-depth analysis posts.

Enjoy this article? Don’t forget to share.