Small Mistakes, Big Breaches This Week
Citrix and FortiMail zero-days, a new Spectre v2 variant, and a 16-year-old suspect top this week's threat roundup.
A blank field. A public repo. One reply to an email. A box left exposed. None of it sounds dramatic, which is part of the problem. According to a weekly threat recap published by The Hacker News, this week's attacks repeatedly found leverage in small things that were easy to overlook.
The recap, written by Ravie Lakshmanan and dated Oct 05, 2026, catalogs actively exploited bugs, cleaner intrusion paths, smarter automation, and a long patch list waiting behind them. Some attacks are getting more capable. Others still succeed because the basics gave way first.
Citrix Patches an Exploited Flaw
Citrix released security updates for a high-severity flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targeted zero-day attacks, the recap reported. The vulnerability is tracked as CVE-2026-88779 and carries a CVSS score of 8.7 out of 10.0.
Successful exploitation requires NetScaler ADC or NetScaler Gateway to be configured either as a SAML service provider (SP) or SAML identity provider (IdP), according to the company. The condition narrows the pool of exposed systems but, for those that meet it, the flaw is already in use.
"CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific deployment conditions," Citrix said. "The issue affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met."
— Citrix
FortiMail Zero-Day Draws CISA Warning
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned of active exploitation of a critical flaw in Fortinet FortiMail, according to the recap. The bug, CVE-2026-104286, holds a CVSS score of 9.8 and allows unauthenticated attackers to write arbitrary files on the underlying system.
"may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests."
— Fortinet
The recap notes that Fortinet described the vulnerability as potentially allowing an unauthenticated attacker to write arbitrary files via crafted HTTP or HTTPS requests. CISA's warning indicates the flaw is being used in real-world intrusions, though the advisory did not specify the scale of the attacks.
Two ShinyHunters Suspects Arrested
Law enforcement agencies have arrested two members associated with the ShinyHunters digital extortion group, per the recap. One is a 24-year-old Amsterdam man believed to be Pepijn van der Stap. The second individual is Saif al-Din Khader, who is said to have been detained by Jordanian authorities last week.
ShinyHunters has drawn attention in recent weeks for hijacking the darknet website of Cl0p and for its hack of the FBI's "apply.fbijobs[.]gov" portal, according to the recap.
KillSec Takedown Follows a 16-Year-Old
Police in Spain apprehended a 16-year-old suspected to be the leader of the KillSec ransomware operation, the recap reported. According to Europol, authorities took control of KillSec's leak site on September 30, 2026, securing no less than 110 terabytes of data.
As part of Operation KillSwitch, a total of three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain, and the U.K. One accused member, Fouad Eltibrizi, was arrested in the U.K. and is awaiting extradition to the U.S.
"The group exploited software vulnerabilities and poorly secured access points, particularly to cloud storage, to gain access to organizations' systems," Europol said. "Its members then copied sensitive internal data to infrastructure under their control. Victims were named on the group's dark web leak site and threatened with publication of their data unless paid."
— Europol
Since emerging in 2024, the group is estimated to have launched around 1,000 attacks, at least half of which were successful, according to the recap. Group-IB identified 274 publicly claimed victims, most of them U.S., Indian, and Brazilian organizations.
"The group also sold stolen data outright, with asking prices ranging from USD 5,000 for a single company's records to USD 500,000 for the data it claimed to have taken from the global insurer, making KillSec as much a data broker as a ransomware operator," Group-IB said.
— Group-IB
Spectre v2 Variant Recovers Root Hashes
A new Spectre v2 attack variant called Branch Target Reuse (BTR) can recover root password hashes from Intel computers running Linux in just a few minutes, the recap reported. The attack exploits stale information in a processor's branch predictor after a just-in-time (JIT) engine reuses memory for new code. By tampering with that information, an attacker can trick the processor into temporarily executing wrong instructions and potentially expose sensitive data.
"We evaluated the end-to-end exploit on both Raptor Cove and Lion Cove, and leaked the password within 3 and 5 minutes on average, respectively," researchers claimed. "Indirect branch prediction is inherent to modern CPUs, and BTR exploits the desynchronization between the branch predictor and the actual state of the code. No current CPU has a mechanism to keep the two in sync, so until vendors add one, your CPU is vulnerable."
— the researchers
Star Blizzard Shifts to Fake Invites
The Russian state-sponsored group Star Blizzard has employed a new malware delivery technique called RedFlick in attacks targeting Ukrainian individuals and institutions as well as international non-government organizations (NGOs), Western think tanks, governments, and other organizations tied to international policy, according to the recap. The end goal is to deploy a custom backdoor called CosmicPulse by setting up scheduled tasks using RedFlick through phishing emails masquerading as invitations.
Once a victim responds to an initial phishing email, Star Blizzard typically sends a follow-up containing a password-protected archive that triggers the RedFlick chain.
"This technique is a notable departure from the actor's previous use of ClickFix-based infection chains which required victims to complete multiple actions before CosmicPulse could be installed," Microsoft said. "By contrast, the RedFlick infection flow only requires a single user interaction, reducing friction in the compromise process."
— Microsoft
NeedyMantis Maintains Quiet Access
A modular post-compromise malware family called NeedyMantis is being used by threat actors to maintain long-term stealth access and support post-compromise operations, per the recap. It is distributed by a two-stage loader and launched via DLL sideloading, and has been observed in a limited number of targeted operations affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors.
The activity aligns with operations associated with threat actors operating from China, and the malware operation has been active since at least October 2025.
"While NeedyMantis employs techniques commonly used by modern malware, its architecture combines multiple loaders, custom encrypted file archives, a custom executable file format, and modular components that enable operators to evade analysis and extend functionality through additional modules," Microsoft said.
— Microsoft
At least one threat actor has been linked to its use: Storm-3069, which is Microsoft's designation for the DAEMON Tools supply chain attack that took place in May 2026, according to the recap.
RatHat Sorts Victims With Gemini
The Android malware known as RatHat has been observed using Google Gemini to estimate each victim's bank balance and sort the device into high-value and mid-value groups, the recap reported.
"Gemini is used on both sides of the operation: the malware asks an LLM where to tap when its automation fails on an unfamiliar phone, and the panel uses one to estimate victims' bank balances from their SMS," Cleafy said.
— Cleafy
Over the course of the operation, the actors behind RatHat changed its command-and-control (C2) panel entirely, moving from ackCat to Panda Workshop.
"The panel works as a complete malware factory: it builds, signs, and publishes new samples from the console, rebuilds them on a schedule to evade hash-based detection, without the operator touching the hosting infrastructure," Cleafy added. "Account caps and role-gated sections exist to constrain the panel's own users, and pivoting on its frontend artifacts resolves the three generations to nearly 100 separate deployments since April 2026."
— Cleafy
PixelLeak Exposes 13K Screenshots
A new report from Glow Labs found that AI coding agents posted more than 13,000 sensitive screenshots of corporate software projects from 343 companies to public GitHub repositories, according to the recap. The activity has been codenamed PixelLeak. About a third of the exposures came from developers who were using gitshot.
"Each case investigated during our 'PixelLeak' research started with a developer asking an agent to prove that a visual change worked," researchers said. "The software was changed, for example with a fix to the user interface layout, and the reviewers needed to see the before and after. The agents figured out that they could make the image available to the human reviewer by hosting it in an adjacent public repo. They just didn't consider the security implications."
— Glow Labs researchers
The incidents show that AI creates new security risks even without having to facilitate cyber attacks, the recap noted.
The Weekly Patch List Grows
The recap's trending CVEs section lists high-severity, widely used, or already-exploited bugs for the week. Citrix NetScaler ADC and NetScaler Gateway tops the list with CVE-2026-88779. Other entries span Wireshark (CVE-2026-95391, CVE-2026-95389), ServiceNow (CVE-2026-86857 through CVE-2026-86860), WordPress (CVE-2026-93485, aka Comment2Shell), HPE Networking Analytics and Location Engine, GitLab (CVE-2026-89078, CVE-2026-93577), Sudo (CVE-2026-96512), Apache Tomcat, IBM Financial Transaction Manager, AWS Connect Salesforce Lambda, NVIDIA, ManageEngine ADSelfService Plus, Red Hat OpenShift, OpenCode, PHP, Authlib, TDengine, ZTE SmartLife, WatchGuard, geoserver/geoserver-cloud, WolfSSL, OpenSSL, Amazon Bedrock AgentCore Python SDK, Cisco Catalyst SD-WAN Manager, MikroTik RouterOS, TeamViewer, Google Chrome, Mozilla Firefox, Kiteworks, Zammad, and Apache HTTP Server, among others.
- CVE-2026-88779 — Citrix NetScaler ADC and NetScaler Gateway, CVSS 8.7, already exploited
- CVE-2026-104286 — Fortinet FortiMail, CVSS 9.8, active exploitation warned by CISA
- 110 TB — data secured from KillSec's leak site on September 30, 2026
- ~1,000 — estimated KillSec attacks since 2024, at least half successful
- 274 — publicly claimed KillSec victims identified by Group-IB
- 13,000+ — sensitive screenshots posted to public GitHub repos across 343 companies
- 3 and 5 minutes — average time to leak a password on Raptor Cove and Lion Cove, respectively
Why It Matters
The common thread running through this week's recap is that none of the successful intrusions required a novel breakthrough. KillSec, per Europol, leaned on software vulnerabilities and poorly secured access points, particularly cloud storage. Star Blizzard's RedFlick chain cut the victim's required effort down to a single interaction. The PixelLeak exposures began with developers asking an agent to show that a visual fix worked.
For organizations, that suggests the highest-return work this week may be unglamorous. The recap's patch list is long and includes at least two flaws already confirmed as exploited in the wild — CVE-2026-88779 and CVE-2026-104286 — which indicates that systems running NetScaler or FortiMail in the affected configurations warrant priority attention. SAML-configured NetScaler deployments, in particular, are the ones Citrix says meet the precondition for exploitation.
The KillSec and ShinyHunters arrests could mean disruption for two groups that have been active, but the sentencing and extradition processes are still in motion, and the recap does not establish that either operation has stopped. It is reasonable to read the arrests as a law-enforcement win without assuming the tactics they used have gone away — the same cloud-storage weaknesses KillSec exploited remain available to whoever comes next.
The RatHat and PixelLeak findings point in a different direction: AI features inside attacker tooling and developer workflows are producing security outcomes their operators did not necessarily intend. RatHat's use of Gemini to rank victims by bank balance suggests targeting decisions formerly made by hand can now be automated. PixelLeak is the inverse case, where an agent solved a visibility problem for its user without weighing the exposure it created. Neither trend has an obvious patch.
What the week does not offer is a single fix. The recap's own framing is that small, overlooked conditions keep providing the leverage. Closing the blank field, tightening the public repo, resisting the one reply, and retiring the exposed box are all mundane tasks, and that may be exactly why they remain open.
Sources
- The Hacker News Original source
Continue Reading
Italy fines IQVIA $7.8M over health data
Italy's privacy regulator fined IQVIA €7M for pseudonymization failures it says risked re-identifying roughly one million patients.
Cling Botnet Hides Commands in STUN Traffic
New botnet abuses common STUN protocol and public servers to blend command-and-control with legitimate NAT-traversal activity.
ClingSTUN Backdoor Turns Linux Hosts Into Proxies
FortiGuard Labs details a Linux backdoor that abuses public STUN servers, exploits two dozen flaws, and self-propagates across routers.