Daily Digest

Citrix, Atlassian Patches; Denmark Register Breach; New Botnet & Espionage

October 6, 2026
9 articles (8 new, 1 updated)
27 min read

Summary

Critical Vulnerabilities Under Active Exploitation:

  • Citrix NetScaler Zero-Day Under Active Attack (CVE-2026-88779): Citrix has expanded its list of patched NetScaler versions, now including 13.0-92.21 and later, and 12.1-FIPS/NDcPP 12.1-55.302 and later. Security researchers have confirmed active exploitation, including denial-of-service attacks, with RCE potential still under investigation.
  • Atlassian Jira/Confluence File Access Flaw (CVE-2026-21589): Atlassian has released updates for a critical arbitrary file access vulnerability (CVSS 9.3) affecting multiple Data Center and Server products. Unauthenticated attackers can exploit this to access specific files within the web root, posing a risk of sensitive information exposure.

New Threats and Advisories:

  • Denmark National Population Register Breached: Personal data of 8.8 million individuals was exposed from Denmark's Central Person Register due to misuse of legitimate credentials by a third-party company, not a software vulnerability. Names, addresses, and CPR numbers were compromised, increasing identity theft risks.
  • Georgia Power Data Breach: Approximately 300,000 customer accounts were affected by a breach at Georgia Power and its parent company, Southern Company. Unauthorized access to the online customer portal exposed names, addresses, phone numbers, emails, and partial SSNs.
  • CISA Warns of IoT, EV Charging, and Access Control Flaws: CISA has issued advisories for critical vulnerabilities in IoT platforms (Meari Cloud), EV charging (Monta EV, CVSS 9.4), and access control systems (Armatura One). These flaws could lead to impersonation, arbitrary code execution, and other security risks.
  • Microsoft Exchange Privilege Escalation Flaw (CVE-2026-96940): Microsoft has released an out-of-band update for a high-severity privilege escalation vulnerability (CVSS 8.8) in Exchange Server. An authenticated attacker could gain unauthorized access to other users' mailboxes. Exploitation is considered 'More Likely'.
  • "ClingSTUN" Botnet Exploits IoT Devices: A new botnet, ClingSTUN, is actively compromising IoT devices by exploiting multiple vulnerabilities and using the STUN protocol for command-and-control communications. Infected devices are used for malicious activities, including DoS attacks.
  • Iranian Actor Targets Iraqi Infrastructure with "Blinder Tunnel": A state-aligned Iranian actor is conducting a cyber-espionage campaign against critical infrastructure in Iraq, impersonating Dubai Airports. Attackers use trojanized coding challenges and custom malware, with C2 communications leveraging the GitHub API and advanced evasion techniques.

Industry and Supply Chain Security:

  • IBM & Red Hat's "Lightwell" Fixes 400+ Java Vulnerabilities: The Lightwell initiative has identified and fixed over 400 previously unknown vulnerabilities in open-source Java libraries. The new Lightwell Clearinghouse service offers priority security reviews and backported patches for enterprise customers to secure older software.

Filter by Category

New Articles (8)

Updated Articles (1)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.