International Cyber Digest
βΌοΈBREAKING: An actively exploited unknown critical Citrix NetScaler zero-day has prompted governments and organizations to SHUTDOWN all their devices immediately. We don't know what's exactly going on yet. Stay tuned for more info.
Shellcode (Sh3llc0d3)
Inside the NetScaler Zero-Day Siege: Chained Pre-Auth RCEs Weaponized in the Wild (watchTowr Disclosure) | Shellcode (Sh3llc0d3)
A critical perimeter emergency is unfolding across enterprise infrastructure worldwide as threat intelligence teams confirm the active, in-the-wild exploit...
π₯1
International Cyber Digest
βΌοΈBREAKING: An actively exploited unknown critical Citrix NetScaler zero-day has prompted governments and organizations to SHUTDOWN all their devices immediately. We don't know what's exactly going on yet. Stay tuned for more info.
Citrix Community
Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778
Guidance for customers on newly addressed vulnerabilities and recommended updates As the cybersecurity landscape continues to evolve, organizations across the industry are seeing changes in the pace, scale, and complexity of vulnerability research, discoveryβ¦
π1π₯1
βΌοΈ Hackers breached Arizona's state court system and have copied personal data on many Arizonans, including the confidential addresses of people with current or past protective orders.
The court is now notifying those affected as the FBI investigates, saying it's unclear whether most of the data can be easily read and there's no evidence it has been shared.
The court is now notifying those affected as the FBI investigates, saying it's unclear whether most of the data can be easily read and there's no evidence it has been shared.
π―9π4π±2π€£2π₯°1
βΌοΈ BREAKING: A ShinyHunters suspect known as 'Umbreon', aka Pepijn van der Stap, was arrested a couple of weeks ago, according to Krebs.
He's a 23-year-old convicted Dutch hacker who was on parole and detained again around September 16 on suspicion of aiding ShinyHunters data thefts and extortions.
Days later, ShinyHunters claimed a hack of the FBI's jobs site and left an Umbreon defacement that sources say was likely a rival's attempt to pin it on him.
https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/
He's a 23-year-old convicted Dutch hacker who was on parole and detained again around September 16 on suspicion of aiding ShinyHunters data thefts and extortions.
Days later, ShinyHunters claimed a hack of the FBI's jobs site and left an Umbreon defacement that sources say was likely a rival's attempt to pin it on him.
https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/
π±18π5π3π₯΄3β€1π€ͺ1
International Cyber Digest
βΌοΈ BREAKING: A ShinyHunters suspect known as 'Umbreon', aka Pepijn van der Stap, was arrested a couple of weeks ago, according to Krebs. He's a 23-year-old convicted Dutch hacker who was on parole and detained again around September 16 on suspicion of aidingβ¦
βΌοΈ UPDATE: ShinyHunters denies any link to Pepijn van der Stap, the convicted Dutch hacker that sources identify as the man arrested in the investigation into the gang.
"That individual has no association with us. Frankly, we are laughing," the group told Hackread, calling Dutch police incompetent and attention-seeking.
Dutch police confirmed they arrested a 24-year-old Amsterdam man but have not named him. He faces a closed-door hearing at the Rotterdam court on Tuesday.
"That individual has no association with us. Frankly, we are laughing," the group told Hackread, calling Dutch police incompetent and attention-seeking.
Dutch police confirmed they arrested a 24-year-old Amsterdam man but have not named him. He faces a closed-door hearing at the Rotterdam court on Tuesday.
π14π4π¨2π€ͺ2π€¬1
βοΈ An AI agent broke out of its virtual machine and triggered a use-after-free in Google's heavily hardened hypervisor by tricking KVM into quietly rewriting a memory-mapping entry with a single three-byte instruction.
It then flooded the host with 49,152 memory mappings until KVM followed a pointer into that freed memory, and on its fourth live attempt the host handed over Google's secret flag.
No one gave it an exploit, so the agent spent weeks studying KVM's source code and wrote 14,338 lines of harness code to get there.
https://pwn.ai/blog/kvmescape
It then flooded the host with 49,152 memory mappings until KVM followed a pointer into that freed memory, and on its fourth live attempt the host handed over Google's secret flag.
No one gave it an exploit, so the agent spent weeks studying KVM's source code and wrote 14,338 lines of harness code to get there.
https://pwn.ai/blog/kvmescape
π€£18π¨16π6β€2π1π1
βΌοΈ Anthropic's great steal has gone from content to train its AI to IceSolst's photo, which now appears in the Claude Sonnet 5.5 release promo video, without giving credits or asking permission.
π©19π8π€4π€¬4π₯΄1
βΌοΈ BREAKING: German file-transfer provider FTAPI, used by government agencies and more than 2,000 companies, has confirmed a ransomware attack after The Gentlemen gang listed it on its leak site.
The company says attackers breached a single internal server on September 14 but that its platform and customers' systems and data were not affected.
A countdown on the leak site shows about five days left.
The company says attackers breached a single internal server on September 14 but that its platform and customers' systems and data were not affected.
A countdown on the leak site shows about five days left.
π10π©3β€1
βΌοΈ UPDATE: A Rotterdam court today ordered the ShinyHunters-suspect, 24-year-old convicted hacker Pepijn van der S., held for at least 90 more days.
Dutch police say the suspected ShinyHunters member's laptop held information about two murders planned abroad, with indications that he ordered them.
The suspicion of attempted incitement to murder is separate from the ShinyHunters case, and he was not arrested in the Odido hack investigation, police say.
https://www.politie.nl/nieuws/2026/september/29/11-verdachte-aangehouden-in-onderzoek-naar-hackersgroep-shinyhunters.html
Dutch police say the suspected ShinyHunters member's laptop held information about two murders planned abroad, with indications that he ordered them.
The suspicion of attempted incitement to murder is separate from the ShinyHunters case, and he was not arrested in the Odido hack investigation, police say.
https://www.politie.nl/nieuws/2026/september/29/11-verdachte-aangehouden-in-onderzoek-naar-hackersgroep-shinyhunters.html
π€£17β€2π’2
βΌοΈ BREAKING: A newly released jailbreak cracks every PS5 firmware from 7.00 to 13.60, and early testers say it loads in seconds and works on the PS5 Pro too.
All it takes is visiting a website in the browser.
It chains a WebKit browser bug with a kernel use-after-free race to seize kernel read/write, then loads payloads for homebrew and game backups.
https://github.com/ntfargo/Relapse-Exploit
All it takes is visiting a website in the browser.
It chains a WebKit browser bug with a kernel use-after-free race to seize kernel read/write, then loads payloads for homebrew and game backups.
https://github.com/ntfargo/Relapse-Exploit
β€34π₯9π€―2
βΌοΈ BREAKING: AI agents have leaked more than 13,000 internal screenshots from 343 tech companies onto GitHub, including a frontier AI lab and several Fortune 500 companies.
Unable to attach images to private pull requests, the agents quietly posted them to public repos instead.
https://www.glow.io/blogs/how-ai-agents-exposed-developer-screenshots-from-leading-tech-companies
Unable to attach images to private pull requests, the agents quietly posted them to public repos instead.
https://www.glow.io/blogs/how-ai-agents-exposed-developer-screenshots-from-leading-tech-companies
3π€£36π€3β€2π1π₯΄1
The CIA and West German intelligence secretly bought Swiss encryption maker Crypto AG in 1970, turning the machines governments paid to protect their secrets into a way to read them.
Those governments had no idea the machines were rigged to read their messages.
In the 1980s, Crypto devices accounted for roughly 40% of the foreign government messages the NSA decoded.
The CIA didn't sell the company until 2018 and called the operation "the intelligence coup of the century."
Those governments had no idea the machines were rigged to read their messages.
In the 1980s, Crypto devices accounted for roughly 40% of the foreign government messages the NSA decoded.
The CIA didn't sell the company until 2018 and called the operation "the intelligence coup of the century."
π€£18π₯7π3π€―1π©1