CYBER THREAT INTEL
DAILY BRIEFING · 2026-10-09 12:15 UTC · REPORT BRIEF-20261009-121554
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Ars Technica Security, BBC Technology, BleepingComputer, BleepingComputer (Google News), Cyber Risk & Security, Cyber Threat Intelligence
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
19
Stories Featured
53
Sources
10
Active KEV CVEs
28
IOC Indicators
Top Stories
01
Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
The flaws, CVE-2026-105133 and CVE-2026-105134, allow attackers to bypass authentication and inject OS commands.
The post Unpatched AhsayCBS Vulnerabilities Exploited in the Wild appeared first on SecurityWeek.
SRC: SecurityWeek
Fri, 09 Oct 2026 10:23:42 +0000
https://www.securityweek.com/unpatched-ahsaycbs-vulnerabilities-exploited-in-the-wild/
02
CVE-2026-107406: Citrix Fixes Critical NetScaler ADC and Gateway Vulnerability
Citrix patched CVE-2026-107406, a critical NetScaler ADC and Gateway flaw that could allow remote code execution or denial-of-service attacks. Citrix has released security updates to fix CVE-2026-107406 (CVSS score of 9.5), a critical flaw affecting NetScaler ADC and NetScaler Gateway that could all
SRC: Security Affairs
Fri, 09 Oct 2026 10:04:43 +0000
https://securityaffairs.com/200670/security/cve-2026-107406-citrix-fixes-critical-netscaler-adc-and-gateway-vulnerability.html
03
Citrix warns admins to patch new NetScaler RCE flaw immediately
Citrix has warned IT administrators to patch systems immediately against a new critical vulnerability affecting NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions. […]
SRC: BleepingComputer
Fri, 09 Oct 2026 04:27:42 -0400
https://www.bleepingcomputer.com/news/security/citrix-warns-admins-to-patch-new-netscaler-rce-flaw-immediately/
04
Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own
Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched. The contest pays researchers to show working exploits and passes the flaws to the vendors. One of the three Pixel exploits earned Ikotas
SRC: The Hacker News
Fri, 09 Oct 2026 13:56:17 +0530
https://thehackernews.com/2026/10/three-teams-demonstrate-remote-hacks-of.html
05
The AI Velocity Paradox: Why Security Is Decades Behind AI Ambition
As enterprises race to deploy autonomous AI agents to accelerate business, a new report reveals they are tethered to security architectures built for a different era. The "Horizons of Identity Security" report from SailPoint highlights a critical “velocity paradox,” in which organizations invest in
SRC: The Hacker News
Fri, 09 Oct 2026 17:00:00 +0530
https://thehackernews.com/2026/10/the-ai-velocity-paradox-why-security-is.html
06
Ransomware attack disrupts Japan's IDCF Cloud used by govt clients
IDC Frontier, a major Japanese cloud and digital infrastructure company, disclosed that its IDCF Cloud service was targeted in a ransomware attack that caused an outage at a data center cluster serving the eastern part of the country. […]
SRC: BleepingComputer
Thu, 08 Oct 2026 16:09:45 -0400
https://www.bleepingcomputer.com/news/security/ransomware-attack-disrupts-japans-idcf-cloud-used-by-govt-clients/
07
Ransomware recovery CEO indicted after allegedly paying hackers and pocketing millions
Zohar Pinhasi allegedly deceived ransomware recovery clients into a payment scheme disguised as a specialized service that helped victims avoid paying cybercriminals.
The post Ransomware recovery CEO indicted after allegedly paying hackers and pocketing millions appeared first on CyberScoop.
SRC: CyberScoop
Thu, 08 Oct 2026 19:44:29 +0000
https://cyberscoop.com/monstercloud-zohar-pinhasi-ransomware-recovery-scheme/
08
ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories
The crooks have trust problems of their own. One ransomware affiliate decided to keep the profits for himself. Elsewhere, an attacker left a server exposed, complete with tools and traces of an intrusion. Apparently, keeping things secure is a problem on both sides of the fence.
The rest of the wee
SRC: The Hacker News
Thu, 08 Oct 2026 23:28:02 +0530
https://thehackernews.com/2026/10/threatsday-ransomware-affiliate.html
09
Man admits to running network of 15,000 money mules for cybercriminals
A Ukrainian-Russian dual citizen has pleaded guilty to running a massive money laundering operation that laundered millions for cybercriminals worldwide. […]
SRC: BleepingComputer
Fri, 09 Oct 2026 07:14:28 -0400
https://www.bleepingcomputer.com/news/security/ukrainian-russian-dual-citizen-admits-to-laundering-millions-for-cybercriminals/
10
US Disrupts China-Linked Integrity Tech ‘s Cyber Espionage Tools
DOJ and FBI seized China-linked hacking tools Microscan and FishHub, linked to Integrity Tech and attacks on critical infrastructure worldwide. The Justice Department and FBI took down two hacking tools this week, Microscan and FishHub, both built and run by a Beijing-based company with direct gover
SRC: Security Affairs
Fri, 09 Oct 2026 10:49:22 +0000
https://securityaffairs.com/200673/security/us-disrupts-china-linked-integrity-tech-cyber-espionage-tools.html
11
US Disrupts Chinese State-Sponsored Hacking Tools
Flax Typhoon and other APTs used MicroScan and FishHub to scan and hack US and foreign critical infrastructure.
The post US Disrupts Chinese State-Sponsored Hacking Tools appeared first on SecurityWeek.
SRC: SecurityWeek
Fri, 09 Oct 2026 08:36:37 +0000
https://www.securityweek.com/us-disrupts-chinese-state-sponsored-hacking-tools/
12
AI-Driven tool ARTEX used in attacks against South Korean Banks
CrowdStrike analyzes open directories left by an attacker who used the ARTEX AI pentest tool and LLMs to breach South Korean financial firms. CrowdStrike published a research on a campaign against South Korean financial organizations that ran from late September to early October 2026 and ended with
SRC: Security Affairs
Fri, 09 Oct 2026 07:53:38 +0000
https://securityaffairs.com/200661/hacking/ai-driven-tool-artex-used-in-attacks-against-south-korean-banks.html
13
Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks
Attackers behind a string of personal data leaks at Japanese organizations have abused APIs for mobile apps and targeted known software flaws, the JPCERT Coordination Center (JPCERT/CC) said.
The Tokyo-based center, which takes incident reports, based its October 8, 2026 alert on those reports and
SRC: The Hacker News
Thu, 08 Oct 2026 21:15:56 +0530
https://thehackernews.com/2026/10/japan-sees-sharp-rise-in-web-data-leaks.html
14
Asos confirms breach of customer data after hackers send rogue app notification
The hackers alerted the fashion giant's customers through a push notification that said they had "fully compromised" the company's cloud storage.
SRC: TechCrunch Security
Thu, 08 Oct 2026 15:01:15 +0000
https://techcrunch.com/2026/10/08/asos-confirms-breach-of-customer-data-after-hackers-send-rogue-app-notification/
15
ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms
Cybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence (AI) pen testing tool named ARTEX to carry out the attacks.
The activity, per CrowdStrike Intelligence, was active from late September to early
SRC: The Hacker News
Thu, 08 Oct 2026 19:42:34 +0530
https://thehackernews.com/2026/10/artex-ai-pentesting-tool-used-in-data.html
16
Google Domains Impacted by Recent ccTLD Hijacks
Hackers hijacked the .gh, .sl, and .as ccTLDs and obtained HTTPS certificates for several Google domains.
The post Google Domains Impacted by Recent ccTLD Hijacks appeared first on SecurityWeek.
SRC: SecurityWeek
Fri, 09 Oct 2026 11:43:14 +0000
https://www.securityweek.com/google-domains-impacted-by-recent-cctld-domain-hijacks/
17
Microsoft: Outdated Windows devices will stop receiving security updates
Microsoft says devices running unsupported versions of Windows will stop receiving security updates after next year's Windows Update certificate rotation. […]
SRC: BleepingComputer
Fri, 09 Oct 2026 06:12:24 -0400
https://www.bleepingcomputer.com/news/microsoft/microsoft-outdated-windows-devices-will-lose-security-protection-next-year/
18
Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries
Midnight Mimosa is the name given to a malware campaign primarily running preinstalled on low-cost Android devices.
The post Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries appeared first on SecurityWeek.
SRC: SecurityWeek
Fri, 09 Oct 2026 09:55:35 +0000
https://www.securityweek.com/pre-baked-firmware-malware-hits-budget-android-devices-in-150-countries/
19
GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys
A bug in GoBalance, a tool many dark-web sites use to stay reachable during attacks, lets anyone work out the secret key that controls a site's .onion address using only public information, and then take that address over.
Searchlight Cyber, which disclosed the flaw on October 8, says an attacker w
SRC: The Hacker News
Fri, 09 Oct 2026 14:33:24 +0530
https://thehackernews.com/2026/10/gobalance-flaw-lets-attackers-hijack.html
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2015-5477 | BIND (ISC) | 2026-10-08 |
| CVE-2016-3081 | Struts (Apache) | 2026-10-08 |
| CVE-2023-22894 | Strapi (Strapi) | 2026-10-08 |
| CVE-2021-3199 | Docs (ONLYOFFICE) | 2026-10-08 |
| CVE-2015-3306 | ProFTPD (ProFTPD) | 2026-10-08 |
| CVE-2026-88779 | NetScaler (Citrix) | 2026-10-04 |
| CVE-2026-102490 | Zammad (Zammad GmbH) | 2026-10-02 |
| CVE-2026-102489 | Zammad (Zammad GmbH) | 2026-10-02 |
| CVE-2026-104286 | FortiMail (Fortinet) | 2026-10-01 |
| CVE-2026-76504 | Catalyst SD-WAN Manager (Cisco) | 2026-09-30 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
