[{"title": "Wireshark 4.6.9 Released, (Sun, Sep 27th)", "link": "https://isc.sans.edu/diary/rss/33372", "summary": "Wireshark release 4.6.9 fixes 19 vulnerabilities and 16 bugs.", "source": "sans_isc", "published_date": "2026-09-27T15:04:49"}, {"title": "Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation", "link": "https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html", "summary": "Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr said on September 26.\n\nCitrix has not confirmed the flaws or published a fix. Some administrators say they have taken appliances offline rather than wait for one to be available.\n\nNetScaler ADC and", "source": "hackernews", "published_date": "2026-09-27T13:17:57"}, {"title": "Citrix admins warned to shut down NetScalers over 2 exploited zero-days", "link": "https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/", "summary": "Two unpatched Citrix NetScaler zero-day vulnerabilities are reportedly being exploited in attacks, with cybersecurity agencies, security researchers, and IT providers privately warning organizations about the flaws ahead of patches expected next week. [...]", "source": "bleepingcomputer", "published_date": "2026-09-27T12:02:37"}, {"title": "Cloudflare fixes Containers cross-tenant flaw exposing customer data", "link": "https://www.bleepingcomputer.com/news/security/cloudflare-fixes-containers-cross-tenant-flaw-exposing-customer-data/", "summary": "Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers' containers on the same physical host. [...]", "source": "bleepingcomputer", "published_date": "2026-09-27T10:13:31"}, {"title": "Anthropic turns Claude into an AI marketplace with 2,000+ plugins and connectors", "link": "https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-turns-claude-into-an-ai-marketplace-with-2-000-plus-plugins-and-connectors/", "summary": "Anthropic has just announced a new Claude Marketplace, and it brings all AI-related tools into one place, including plugins, connectors, agents, and more. [...]", "source": "bleepingcomputer", "published_date": "2026-09-27T09:38:40"}, {"title": "Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials", "link": "https://thehackernews.com/2026/09/lunex-stealer-abuses-amd-driver-to.html", "summary": "The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex.\n\nThe new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users.\n\n\"The attack chain begins with a fake CAPTCHA page and", "source": "hackernews", "published_date": "2026-09-26T23:52:52"}, {"title": "Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells", "link": "https://thehackernews.com/2026/09/attackers-bypass-wafs-to-exploit-oracle.html", "summary": "Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally.\n\nThe ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution.\n\nThe vulnerability was first exploited as a zero-day", "source": "hackernews", "published_date": "2026-09-26T17:16:40"}, {"title": "Zero Trust for AI Agents Starts With Fixing Zero Visibility", "link": "https://thehackernews.com/2026/09/zero-trust-for-ai-agents-starts-with.html", "summary": "The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much productivity they could promise, a string of recent incidents, including a widely discussed intrusion at Hugging Face during an evaluation of OpenAI agents, has spurred organizations to", "source": "hackernews", "published_date": "2026-09-26T16:00:00"}, {"title": "Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link", "link": "https://thehackernews.com/2026/09/elementor-csrf-flaw-lets-attackers-take.html", "summary": "Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site.\n\nThe cross-site request forgery (CSRF) vulnerability, which has yet to be assigned a CVE identifier, carries a CVSS score of 8.8 out of 10.0. It only affects versions", "source": "hackernews", "published_date": "2026-09-26T15:25:22"}, {"title": "ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks", "link": "https://www.bleepingcomputer.com/news/security/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks/", "summary": "The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers. [...]", "source": "bleepingcomputer", "published_date": "2026-09-26T15:03:34"}]