Citrix Memory Exploit, Pentagon Database Breach, OpenSSL DTLS Flaw
Quick Answer
This article highlights major cybersecurity threats, including Citrix NetScaler exploitation, the Pentagon data breach, OpenSSL and Microsoft Exchange vulnerabilities, malware campaigns, phishing attacks, software flaws, and other emerging security risks.
This week brought a cascade of critical cyber incidents grabbing headlines worldwide, from the active exploitation of Citrix NetScaler appliances causing denial-of-service attacks to a massive Pentagon personnel database breach affecting millions of military personnel, along with dangerous vulnerabilities in widely used software such as OpenSSL and Microsoft Exchange. These incidents highlight how cybercriminals continue to target critical infrastructure, government systems, and widely deployed technologies.
In the face of evolving cyber threats, implementing robust email security measures such as SPF, DKIM, and DMARC can help organizations authenticate legitimate messages, strengthen domain protection, and reduce the risk of phishing and email-based attacks.
Citrix NetScaler memory overflow vulnerability actively exploited in the wild!
CISA has added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog after confirming active exploitation of the high-severity vulnerability affecting Citrix NetScaler ADC and Citrix NetScaler Gateway. This memory overflow bug can cripple vulnerable NetScaler ADCs and Gateways, with CISA reporting that Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to denial of service.
The vulnerability carries a CVSS score of 8.7, and CISA set an October 7 remediation deadline for covered federal agencies. Citrix has observed targeted attacks against unpatched NetScaler deployments, confirming the memory overflow vulnerability can cause a denial of service condition, potentially disrupting authentication services and remote access functionality. https://www.helpnetsecurity.com/2026/10/05/cisa-flags-new-exploited-netscaler-flaw-as-attackers-crash-appliances-cve-2026-88779/ socradarsophos
Pentagon personnel database breached, exposing personal information of over 3 million people!
A breach of the Pentagon’s Defense Manpower Data Center (DMDC) exposed sensitive information belonging to nearly 3 million people, including Social Security numbers and details about their military positions. The breach affected 2.76 million living people and another 294,000 who are deceased, with unauthorized access occurring between October 2025 and July 2026.
The DMDC holds more than 60 million records on military troops, civilian employees, contractors, retirees, veterans and families of those who have served in the forces, making this one of the most significant Pentagon data breaches in recent years. The Pentagon has offered 12 months of identity protection and credit monitoring to those affected. https://www.goodmorningamerica.com/news/story/pentagon-breach-exposed-sensitive-data-3-million-people-136832909 bitdefender
OpenSSL DTLS flaw can leak heap memory or crash programs!
A high-severity OpenSSL vulnerability tracked as CVE-2026-84782 can leak heap memory to the other side of a DTLS connection or crash the program, with OpenSSL releasing fixes on September 29. The vulnerability stems from improper handling of handshake message retransmissions and carries a CVSS score of 8.2.
Software is exposed to this flaw only if it uses OpenSSL for DTLS, and applications using vulnerable OpenSSL versions for DTLS communications may remain exposed until the relevant security updates are installed. The flaw is fixed in OpenSSL 4.0.3, 3.6.5, 3.5.9 and 3.4.8, though OpenSSL 3.0 stopped getting public security fixes on September 7. https://thehackernews.com/2026/09/openssl-fixes-high-severity-dtls-flaw.html thehackernewsthehackernews
Microsoft Exchange Server update patches high-severity mailbox access bug!
Microsoft released an out-of-band Exchange Server update to fix high-severity mailbox access bug CVE-2026-96940. This vulnerability could allow attackers to gain unauthorized access to user mailboxes and sensitive communication data. Organizations running vulnerable Exchange Server versions should prioritize applying the security patch immediately. https://www.helpnetsecurity.com/ helpnetsecurity
ClingSTUN malware turns unpatched IoT devices into proxy nodes for attackers!
Researchers discovered ClingSTUN malware that exploits known IoT flaws and abuses public STUN servers to keep proxy access to devices. This sophisticated malware demonstrates how attackers are weaponizing unpatched IoT infrastructure to build botnets for command and control operations. Organizations managing IoT devices should immediately patch all known vulnerabilities. https://www.infosecurity-magazine.com/news/ infosecurity-magazine
Google temporarily halts open-source bug bounty program due to AI-generated invalid reports!
Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program after being flooded with AI submissions. Google suspended its Open Source Vulnerability Rewards Program due to a flood of AI submissions. The surge in automated but invalid vulnerability reports has forced the company to pause the program temporarily while it develops new filtering mechanisms. https://www.securityweek.com/ securityweekinfosecurity-magazine
Anthropic MCP Python SDK flaw exposes OAuth tokens!
A vulnerability in the Anthropic MCP Python SDK can expose OAuth tokens to unauthorized access. Organizations using this SDK in their authentication infrastructure should update immediately to prevent token compromise and unauthorized access. This flaw highlights the importance of regularly auditing software dependencies for security vulnerabilities. https://gbhackers.com/weekly-cybersecurity-newsletter-september-28-october-2-2026/ gbhackers
OpenAI shelves GPT-6.1 Astra release after safety test failures!
OpenAI canceled its GPT-6.1 Astra release over safety concerns, with the move signaling rising caution around deploying more capable models after it failed internal safety and alignment audits. The decision reflects growing industry concern about deploying advanced AI systems without comprehensive safety testing, particularly around unintended deception and unauthorized actions. https://gbhackers.com/ wiu
Malicious npm packages trap developers in WhatsApp subscriber campaign!
Cybersecurity researchers identified 101 npm packages used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub. Developers should audit their dependency lists for suspicious packages and implement software supply chain security controls to prevent package manipulation attacks. https://www.wiu.edu/cybersecuritycenter/cybernews.php wiu
Fake brand discounts on social media prey on shoppers’ fear of missing out!
Phishing attacks using fake brand discounts on social media are exploiting shoppers’ fear of missing out on deals. Cybercriminals are creating counterfeit retail promotions to redirect users to credential-harvesting pages. Consumers should verify promotions directly through official brand websites and never click promotional links from social media without verification. https://www.helpnetsecurity.com/ helpnetsecurity

Apple Intelligence security updates address critical vulnerabilities in macOS!
RemoveMacAI tool turns off Apple Intelligence on macOS and deletes its models. Additionally, Apple tightens macOS disk access as AI agents become more powerful. These security enhancements address concerns about AI agent access to sensitive system resources and personal data. https://www.helpnetsecurity.com/ helpnetsecurityhelpnetsecurity
Kiteworks critical vulnerability discovered during precautionary shutdown!
Kiteworks identified and addressed a critical security vulnerability during a scheduled precautionary shutdown after working with federal intelligence authorities. Organizations using Kiteworks file transfer software should ensure they have applied all available security patches to protect sensitive file sharing infrastructure. https://www.wiu.edu/cybersecuritycenter/cybernews.php wiu
Rejetto HFS vulnerability allows administrative access and remote code execution!
CVE-2026-61500 discovered in Rejetto HFS allows attackers to recover the session-cookie signing key and gain administrative access and remote code execution. Organizations running Rejetto HFS should immediately disable the service or apply available patches to prevent unauthorized administrative access and system compromise. https://www.securityweek.com/ securityweek
Ransomware affiliate double-crosses RaaS operator to steal victim funds!
An affiliate of The Gentlemen RaaS group ran a parallel leak site during extortion of two dozen victims, stealing funds meant for the ransomware-as-a-service operator. This incident demonstrates internal conflicts within cybercriminal networks as affiliates compete for victim ransom payments, showing that even criminal enterprises cannot trust their own members. https://www.infosecurity-magazine.com/news/ infosecurity-magazine
General Manager
General Manager of DuoCircle. Product strategy and commercial lead for AutoSPF's 2,000+ customer base.
LinkedIn Profile →