Isometric cyan data pipelines exposing zero-day network vulnerabilities.

Daily Cybersecurity News – October 5, 2026

CyberRecaps is supported by its readers. We may earn an affiliate commission at no extra cost to you if you buy through a link on this page.

Ghost in the Wires by Kevin Mitnick

Citrix NetScaler zero-day CVE-2026-88779 exploited in attacks

High

What happened

Citrix released patches for CVE-2026-88779, a memory overflow flaw in NetScaler ADC and Gateway that has been exploited in targeted zero-day attacks causing denial-of-service.

The issue carries a CVSS score of 8.7 and requires the appliance to be configured as a SAML service provider or identity provider. Successful repeated triggers can keep the service offline. CISA added it to the KEV catalog.

Citrix credited Bishop Fox and watchTowr; the latter reproduced the flaw after spotting honeypot activity. No data integrity impact has been identified.

Who is affected

Customer-managed NetScaler ADC and Gateway deployments on affected versions when SAML SP or IdP is enabled: ADC/Gateway before 14.1-73.41 and before 13.1-64.28, plus corresponding FIPS and NDcPP builds before the fixed releases.

Organizations running SAML authentication with Gateway or AAA functionality are exposed. Federal agencies face a short patching deadline.

Why it matters

NetScaler appliances sit at the edge for remote access and authentication. A DoS that knocks SAML offline disrupts user logins and business continuity, especially in targeted campaigns that follow other recent NetScaler exploits.

Operators must treat edge authentication gear as high-priority because unpatched instances are already under attack and can cascade into wider outages.

How it could have been prevented

Upgrade immediately to NetScaler ADC and Gateway 14.1-73.41 or later, 13.1-64.28 or later, or the matching FIPS/NDcPP fixed builds.

Confirm SAML configuration entries (samlAction or samlIdPProfile). If patching is delayed, restrict management access and monitor for repeated authentication failures or service unavailability. Apply CISA KEV guidance without delay.

Relevant professional terms

Zero-day
A vulnerability that is actively exploited before the vendor has released a patch or the public knows about it.
SAML service provider (SP) / identity provider (IdP)
In federated authentication, the SP is the application relying on identity assertions while the IdP issues those assertions; misconfiguration here enabled the overflow condition.

Rejetto HFS CVE-2026-61500 exploited for admin RCE

Critical

What happened

Attackers are actively exploiting CVE-2026-61500 in Rejetto HTTP File Server, a critical session-forgery flaw that yields administrator access and remote code execution.

Versions 3.0.0 through 3.2.0 derive the session-cookie signing key from the weak Math.random() PRNG and leak generator outputs during unauthenticated login. An attacker collects a few responses, reconstructs state, forges an admin cookie, then uses the server_code feature for RCE.

A public Python PoC appeared in late September 2026. VulnCheck observed exploitation attempts starting October 1, including a China-based actor hitting U.S. hosts. Horizon3.ai detailed the issue after discovery with Anthropic's Mythos model. A patch shipped in 3.2.1 in July.

Who is affected

Any internet-exposed Rejetto HFS 3.0.0-3.2.0 instances. The product is a lightweight file server often run by individuals and small teams, making unpatched public instances straightforward targets.

This is the second actively abused HFS flaw after the earlier CVE-2024-23692 template-injection cases that delivered miners and malware.

Why it matters

Unauthenticated path to full admin and RCE on a file server gives attackers immediate foothold for data theft, malware staging, or lateral movement. Public PoC plus observed scanning turns every forgotten instance into low-hanging fruit.

Builders and operators running simple file-sharing tools must assume rapid weaponization once details and exploits circulate.

How it could have been prevented

Upgrade to Rejetto HFS 3.2.1 or later immediately. Remove or firewall any unnecessary internet exposure of HFS.

If upgrade is impossible, disable the administrative API and server_code features, rotate any existing sessions, and monitor for anomalous login responses or forged cookies. Scan internal networks for lingering 3.x instances.

Relevant professional terms

Remote code execution (RCE)
The ability for an attacker to run arbitrary commands or code on a target system from across the network.
Pseudo-random number generator (PRNG) state recovery
Reconstructing the internal state of a weak non-cryptographic PRNG from observed outputs so future values, including signing keys, become predictable.

China TA419 phishes US AI policy experts via Microsoft AitM

High

What happened

China-aligned group TA419 has run multiple credential-phishing campaigns against U.S. AI policy experts at think tanks, universities, and legal organizations.

Actors impersonate economists, policymakers, and even an Anthropic employee. Initial benign outreach builds trust; replies receive a shortened URL that chains through Cloudflare Turnstile into a OneDrive adversary-in-the-middle page using Frameless BitB.

The custom AitM proxy captures credentials and session cookies while completing a real Microsoft sign-in so the victim sees nothing wrong. Activity has been tracked since at least April 2025, with notable waves in February and July 2026.

Who is affected

AI policy researchers, think-tank staff, university personnel, defense contractors, and law-firm employees in the U.S. and Japan who handle Microsoft accounts.

Targets are selected for their proximity to U.S. AI regulation, model policy, and export-control discussions.

Why it matters

Stolen Microsoft sessions grant durable access to email, documents, and collaboration tools used by people shaping AI policy. The intelligence value is high amid U.S.-China competition over models and controls.

Frameless BitB plus live AitM proxy defeats many visual and simple MFA cues, showing how targeted phishing continues to evolve past basic spoofing.

How it could have been prevented

Enforce phishing-resistant MFA (FIDO2/passkeys) and conditional access that flags unusual OneDrive or login geographies. Train high-value staff to treat unsolicited policy-feedback requests with extreme caution and to verify out-of-band.

Monitor for anomalous session cookie use, disable legacy auth, and consider browser isolation or URL rewriting for external links. Review Proofpoint-style detections for Frameless BitB and multi-stage redirect patterns.

Relevant professional terms

Credential phishing
Social-engineering attacks that trick users into entering usernames, passwords, or other secrets on fake login pages.
Adversary-in-the-middle (AitM) proxy
A real-time relay that sits between victim and legitimate service, capturing credentials and session tokens while forwarding traffic so the login appears successful.

ClingSTUN Linux backdoor abuses STUN and exploits dozens of flaws

High

What happened

FortiGuard Labs detailed ClingSTUN, a Linux back-connect proxy backdoor that turns infected hosts into STUN-based proxies, establishes persistence, and carries exploits for self-propagation.

It targets roughly two dozen vulnerabilities across Avtech, EnGenius, D-Link, Hytec, Ivanti, Lantronix, Linear, MeiG, Realtek, Sunhillo, Tenda, TP-Link and others for initial access, plus hardcoded exploits for seven additional China Mobile, KGUARD, Linksys, LB-LINK, MVPower, Realtek and TBK flaws.

Downloaders fetch architecture-specific payloads (x86-64, ARM, MIPS, PowerPC, etc.). The malware kills competitors, disables watchdogs, copies itself to hidden files, hooks init scripts, binds a UDP socket, and uses public STUN servers for NAT traversal and C2 signaling. Operators can push remote commands and trigger further spread.

Who is affected

Linux-based network devices, IoT, routers, and servers running the listed vulnerable firmware or software, especially those exposed to the internet.

Indiscriminate scanning means any unpatched appliance from the named vendors is at risk; the botnet already shows multiple variants.

Why it matters

A self-propagating proxy botnet that lives on edge and IoT Linux devices creates resilient C2 channels via legitimate STUN infrastructure and expands the attack surface for DDoS, scanning, or secondary payloads.

Operators of small-office routers, cameras, and industrial gear often leave devices unpatched for years, giving campaigns like this long-lived footholds that are hard to inventory.

How it could have been prevented

Patch or replace devices from the named vendors immediately; prioritize internet-facing management interfaces. Disable unnecessary remote access and change default credentials.

Monitor outbound STUN/UDP traffic to public STUN servers from unexpected hosts, block known bad payloads at the perimeter, and deploy network segmentation so compromised IoT cannot reach critical assets. Hunt for the persistence artifacts (hidden executables and modified init scripts).

Relevant professional terms

Backdoor
Malware that gives an attacker ongoing remote access and control of a compromised system while trying to stay hidden.
STUN (Session Traversal Utilities for NAT)
A protocol that lets endpoints discover their public IP and port mappings behind NAT; abusing public STUN servers lets malware maintain connectivity without a dedicated C2 registration server.
Source: SecurityWeek

Keyorix open-source secrets manager runs on-prem

Low

How it works

  • Single binary deploys with optional Docker Compose for full stack including web UI.
  • Passphrase at startup stretches into an in-memory KEK that wraps AES-256-GCM data keys.
  • CLI injects secrets as environment variables; SDKs available for Go, Python, Node.js.
  • RBAC, versioning, env separation, CI/CD service tokens, and dual-layer audit logs included.

What happened

Keyorix SL released Keyorix, an open-source secrets manager that runs entirely on a customer's own servers as a single binary with no required internet connection.

It stores database passwords, API keys, and tokens so they never live in config files or source code. Secrets are encrypted with AES-256-GCM; a startup passphrase derives a key-encrypting key held only in memory that wraps data keys. Storage uses SQLite for small setups or PostgreSQL for production.

Features include RBAC, group permissions, secret versioning, environment separation, service tokens for CI/CD, rotation alerts, full audit logging, CLI injection as environment variables, and SDKs for Go, Python, and Node.js. Vault imports and a one-command Docker Compose stack with web UI are supported.

Who is affected

Development, DevOps, and security teams that need on-premises or air-gapped secrets management, especially European organizations aligning with NIS2 and DORA, or any group that cannot send credentials to SaaS providers.

It positions itself between complex self-hosted Vault and simple but cloud-only Doppler.

Why it matters

Keeping secrets out of code and config is foundational hygiene, yet many regulated or isolated environments cannot use cloud secrets managers. A lightweight, auditable, open-source alternative lowers the barrier to proper secret handling without new SaaS risk.

Builders gain environment-variable injection and SDK paths that fit existing app patterns while operators retain full control and compliance evidence.

Relevant professional terms

Secrets manager
A secure vault that stores and hands out passwords, API keys, and tokens to applications at runtime so they never appear in source code or plain config files.
Key-encrypting key (KEK) hierarchy
A design where a master key held only in memory wraps per-secret data keys, limiting exposure if storage is compromised and enabling clean rotation.

Alleged Ploutus ATM malware developer appears in US court

Medium

What it means

Law enforcement is prioritizing the malware authors and money-laundering facilitators behind ATM jackpotting, not only the street-level crews. Financial institutions should expect continued scrutiny of ATM fleet hygiene and faster information sharing when similar malware reappears. The TdA linkage also elevates the case into broader transnational-crime and sanctions enforcement.

What happened

The U.S. Department of Justice announced that Anibal Alexander Canelon Aguirre, alleged developer of the Ploutus ATM malware and known as Prometheus or The Engineer, has appeared in court following his arrest.

He was the first cybercriminal placed on the FBI Top 10 Most Wanted Fugitives list in March 2026. Court documents describe jackpotting attacks from February 2024 to December 2025 that emptied ATMs at banks and credit unions, producing more than $5.4 million in theft across at least 63 bank and 54 credit-union incidents plus further attempts.

Ploutus included anti-analysis protections and self-deletion features. Stolen funds were laundered and moved to accounts linked to the Tren de Aragua (TdA) Venezuelan gang. Charges filed in Nebraska include conspiracy to commit bank fraud, money laundering, bank burglary, computer fraud, and material support to terrorists.

Who is affected

U.S. banks and credit unions whose ATMs were physically compromised for jackpotting, plus the broader financial sector facing similar malware-enabled theft.

Victims suffered direct cash losses often exceeding $100,000 per incident; the case also involves international money-laundering networks.

Why it matters

ATM jackpotting remains a high-cash, relatively low-tech crime when malware developers supply reliable tools and organized groups handle physical access and laundering. Arrest of an alleged core developer and Top-10 fugitive signals sustained law-enforcement pressure on the full supply chain.

Financial institutions must continue hardening ATM software, physical access controls, and transaction monitoring because the malware and tactics have already proven profitable at scale.

Relevant professional terms

Jackpotting
A physical-plus-malware attack in which criminals force an ATM to dispense all its cash as if it were paying out a jackpot.
Anti-analysis measures
Techniques such as packing, anti-debugging, and self-deletion that malware uses to hinder reverse-engineering and forensic examination by defenders.

Apple adds macOS Full Disk Access controls for AI agents

Medium

What to watch

  • Exact macOS release and the new consent UI or MDM controls Apple ships.
  • How major AI-agent and backup vendors redesign their Full Disk Access requests.
  • Whether similar tightened prompts appear for other sensitive TCC permissions.
  • Incident reports of agents abusing broad disk access once the controls land.

What happened

Apple announced plans to add stronger controls around Full Disk Access on macOS because AI agents are becoming more capable and autonomous, raising privacy risks.

Users will have to take explicit action before an app receives the permission. Full Disk Access currently bypasses many of Apple's privacy APIs so that legitimate backup tools can function; Apple warns some developers are using it in ways that can expose files, email, messages, and browsing history, including data belonging to people the user communicates with.

No exact release date or UI details were given. The move follows multiple incidents in which AI models unexpectedly reached external systems or internal files during evaluations and real-world tests.

Who is affected

All macOS users and developers whose apps request Full Disk Access, especially those building or running AI agents, automation tools, or backup software.

Enterprises managing Mac fleets and privacy-conscious individuals who grant broad permissions to new AI utilities are most directly impacted.

Why it matters

AI agents that can browse, read files, and act autonomously turn a single over-privileged app into a high-impact privacy and data-exfiltration risk. Tightening the consent UX forces clearer user understanding before powerful access is granted.

Builders of agentic software must redesign permission flows and expect greater scrutiny; operators gain a clearer signal when tools request excessive disk access.

Relevant professional terms

Full Disk Access
A macOS permission that lets an app read files across the system, bypassing many of the normal per-app privacy protections.
Agentic AI
AI systems that can plan and take multi-step actions in the real world or on a computer with limited human supervision, amplifying the impact of any excessive permissions they hold.