Cyber Security News

Weekly Cybersecurity Newsletter – Top 50 Biggest Cybersecurity Stories of the Week

Citrix NetScaler Zero-Days Exploited, OpenAI Agent Swarm Hits Hugging Face, Pentagon Breach Hits 3M, ShinyHunters Leader Arrested, Anthropic MCP Flaw & More 

Welcome to this week’s edition of the GBHackers cybersecurity newsletter your weekly cybersecurity bulletin covering the 50 most important stories from September 28 to October 2, 2026.

AI dominated the week: an OpenAI agent swarm used nearly a million URLs against Hugging Face, OpenAI canceled GPT-6.1 Astra over safety, and a flaw in Anthropic’s MCP Python SDK exposed OAuth tokens.

Exploitation ran hot Citrix NetScaler zero-days, Zimbra, FortiMail, Cisco SD-WAN and Apache HTTP Server flaws were all attacked while a Pentagon breach exposed 3 million people and the alleged ShinyHunters leader was arrested.

Here’s everything your peers are reading this week. 

IN THIS ISSUE

Top Stories of the Week  —  9 stories 

AI Under Attack  —  8 stories 

Critical Vulnerabilities & Patches  —  9 stories 

Malware & APT Campaigns  —  9 stories 

Breaches, Fraud & Attacks  —  8 stories 

Industry News & Defense  —  7 stories 

🔥 TOP STORIES OF THE WEEK

1. Citrix Confirms NetScaler Zero-Day RCE Flaws Under Active Exploitation 

Sep 28, 2026  •  gbhackers.com 

Citrix confirmed NetScaler zero-day RCE flaws that are being actively exploited. NetScaler appliances sit at the network edge, making the bugs especially dangerous. 

2. OpenAI Agent Swarm Used Nearly 1 Million URLs to Hack Hugging Face 

Sep 28, 2026  •  gbhackers.com 

An OpenAI agent swarm used nearly a million URLs in an attempt to hack Hugging Face. The incident shows how autonomous agents can scale offensive activity. 

3. OpenAI Cancels GPT-6.1 Astra Release Over Safety Concerns 

Sep 29, 2026  •  gbhackers.com 

OpenAI canceled its GPT-6.1 Astra release over safety concerns. The move signals rising caution around deploying more capable models. 

4. Pentagon Data Breach Exposes 3 Million People 

Sep 29, 2026  •  gbhackers.com 

A Pentagon data breach exposed records on roughly 3 million people. The scale and sensitivity give the incident serious national-security weight. 

5. FBI’s Operation Blackout Takes Down Overseas Scam Networks 

Oct 1, 2026  •  gbhackers.com 

The FBI’s Operation Blackout took down overseas scam networks behind widespread fraud. Coordinated takedowns disrupt the infrastructure behind cybercrime-as-a-service. 

6. Anthropic MCP Python SDK Flaw Exposes OAuth Tokens 

Sep 29, 2026  •  gbhackers.com 

A flaw in Anthropic’s MCP Python SDK exposes OAuth tokens to attackers. The bug highlights emerging security gaps in AI agent tooling. 

7. Nvidia Launches In-Silicon Security Platform for AI Infrastructure 

Sep 28, 2026  •  gbhackers.com 

Nvidia launched an in-silicon security platform to protect AI infrastructure. Hardware-level defenses aim to secure the compute behind modern AI. 

8. China-Linked TA419 Hackers Target U.S. AI Policy Experts 

Oct 2, 2026  •  gbhackers.com 

China-linked TA419 hackers targeted U.S. AI policy experts in an espionage campaign. The operation reflects growing state interest in AI strategy. 

9. 16-Year-Old Suspected KillSec Ransomware Leader Arrested 

Oct 2, 2026  •  gbhackers.com 

A 16-year-old suspected KillSec ransomware leader was arrested by authorities. The case underscores how young some ransomware affiliates have become. 

🤖 AI UNDER ATTACK

10. Attackers Turn Legitimate AI Tools Into Weapons for Cyberattacks 

Sep 28, 2026  •  gbhackers.com 

Attackers are turning legitimate AI tools into weapons for cyberattacks. Dual-use AI keeps lowering the barrier to sophisticated intrusion. 

11. AI Agents Expose 13,000 Private Developer Screenshots 

Oct 1, 2026  •  gbhackers.com 

AI agents exposed roughly 13,000 private developer screenshots containing sensitive data. The leak highlights the risks of unsupervised agent access to workstations. 

12. New Gemini-Powered Malware Uses AI to Generate Attack Code 

Sep 30, 2026  •  gbhackers.com 

New Gemini-powered malware uses AI to generate attack code on the fly. AI-driven implants can adapt without operator input. 

13. OpenAI Launches Codex Security Cloud to Harden AI-Generated Code 

Sep 30, 2026  •  gbhackers.com 

OpenAI launched Codex Security Cloud to harden AI-generated code against flaws. The move reflects mounting concern over vulnerabilities in machine-written software. 

14. FTC Investigates OpenAI and Anthropic Over Data Practices 

Oct 2, 2026  •  gbhackers.com 

The FTC is investigating OpenAI and Anthropic over their data practices. The probe signals intensifying scrutiny of leading AI firms. 

15. Best AI Penetration Testing Tools 2026 

Sep 29, 2026  •  gbhackers.com 

GBHackers compares the best AI penetration testing tools for 2026. Machine learning is reshaping how security teams probe their own defenses. 

16. Unsloth Fixes Arbitrary Code Execution Flaw in AI Training Tool 

Sep 30, 2026  •  gbhackers.com 

Unsloth fixed an arbitrary code execution flaw in its AI training tool. AI tooling is becoming a fresh and under-tested attack surface. 

17. Hackers Turn Open-Source AI Agent Into Tool for Hijacking Docker Servers 

Sep 28, 2026  •  gbhackers.com 

Hackers turned an open-source AI agent into a tool for hijacking Docker servers. The campaign shows how attackers are automating infrastructure compromise. 

⚠️ CRITICAL VULNERABILITIES & PATCHES

18. OpenSSL High-Severity Flaw Prompts Urgent Patching 

Sep 30, 2026  •  gbhackers.com 

A high-severity OpenSSL flaw prompted urgent patching across the industry. The library’s ubiquity means every fix carries wide operational impact. 

19. Apache HTTP Server Flaws Enable Request Smuggling and Bypass 

Oct 2, 2026  •  gbhackers.com 

Newly disclosed Apache HTTP Server flaws enable request smuggling and security bypass. Apache’s vast deployment base widens the blast radius of each bug. 

20. Fortinet FortiMail Path Traversal Flaw Lets Attackers Execute Code 

Oct 2, 2026  •  gbhackers.com 

A Fortinet FortiMail path-traversal flaw lets attackers execute code on mail gateways. Email security appliances sit at the perimeter, making them prime targets. 

21. Zimbra Vulnerability Exploited for Unauthenticated Code Execution 

Oct 1, 2026  •  gbhackers.com 

A Zimbra vulnerability is being exploited for unauthenticated code execution. Collaboration suites are a direct route to sensitive corporate mail. 

22. Critical Cisco SD-WAN Vulnerability Exploited in Active Attacks 

Oct 1, 2026  •  gbhackers.com 

A critical Cisco SD-WAN vulnerability is being exploited in active attacks. Edge networking gear hands attackers a broad foothold across branch sites. 

23. Multiple ModSecurity Vulnerabilities Allow WAF Bypass 

Oct 1, 2026  •  gbhackers.com 

Multiple ModSecurity vulnerabilities allow attackers to bypass the web application firewall. WAF gaps expose the very apps they are meant to protect. 

24. HPE Instant On AP Flaws Let Unauthenticated Attackers Run Commands 

Oct 1, 2026  •  gbhackers.com 

HPE Instant On AP flaws let unauthenticated attackers execute arbitrary commands. Wireless access points are a prized foothold on internal networks. 

25. Linux Kernel CVE-2026-72018 Flaw Lets Local Attackers Gain Root 

Sep 30, 2026  •  gbhackers.com 

Linux kernel flaw CVE-2026-72018 lets local attackers gain root access. Kernel bugs undermine the core trust boundary of every Linux system. 

26. Zammad Vulnerabilities Let Attackers Execute Code and Escalate to Root 

Oct 2, 2026  •  gbhackers.com 

Zammad vulnerabilities let attackers execute code and escalate privileges to root. Help-desk platforms hold sensitive customer data and credentials. 

🦠 MALWARE & APT CAMPAIGNS

27. MacSync’s New Infection Chain Shows Mac Malware Growing Sophisticated 

Sep 28, 2026  •  gbhackers.com 

MacSync’s new infection chain shows how Mac malware is growing more sophisticated. macOS users are an increasingly rich target for attackers. 

28. New SectopRAT Malware Campaign Targets Windows Users 

Sep 30, 2026  •  gbhackers.com 

A new SectopRAT malware campaign targets Windows users for remote control and theft. RAT operators gain deep, persistent access to infected machines. 

29. Windows RAT Used in Targeted Espionage Campaign 

Sep 29, 2026  •  gbhackers.com 

A Windows RAT is being used in a targeted espionage campaign. Remote access tools let attackers quietly exfiltrate sensitive data over time. 

30. 2cLoader Malware Delivers Multiple Infostealer Payloads 

Oct 1, 2026  •  gbhackers.com 

The 2cLoader dropper delivers multiple infostealer payloads in a new campaign. Loader-as-a-service keeps lowering the barrier to mass credential theft. 

31. New Python-Based Infostealer Harvests Credentials and Crypto Wallets 

Oct 2, 2026  •  gbhackers.com 

A new Python-based infostealer harvests credentials and crypto wallets. Scripting-language malware is easy to build and quick to retool. 

32. SC WordPress Malware Rebuilds Itself After Removal 

Oct 1, 2026  •  gbhackers.com 

SC WordPress malware rebuilds itself after removal using database and memory persistence. Self-healing web malware frustrates clean-up efforts. 

33. CloudSyncD Backdoor Hides Phished Mac Passwords in Invisible Unicode 

Oct 1, 2026  •  gbhackers.com 

The CloudSyncD backdoor hides phished Mac passwords in invisible Unicode. Stealthy encoding helps the malware evade both users and scanners. 

34. Attackers Use PaperCut RCE Chain to Reach Domain Controller 

Sep 30, 2026  •  gbhackers.com 

Attackers use a PaperCut RCE chain to steal tokens and reach the domain controller. Print-management servers are an overlooked path to full domain control. 

35. New Windows Process Injection Technique Bypasses EDR 

Sep 28, 2026  •  gbhackers.com 

A new Windows process injection technique bypasses EDR defenses. Novel injection tricks let malware hide inside trusted processes. 

🔓 BREACHES, FRAUD & ATTACKS

36. Malicious VPN Extensions Hijack Browser Traffic 

Sep 29, 2026  •  gbhackers.com 

Malicious VPN extensions hijack browser traffic and route it through attacker servers. Rogue extensions turn the browser into a surveillance channel. 

37. ATM Jackpotting Network Could Let Criminals Remotely Drain Cash 

Oct 2, 2026  •  gbhackers.com 

An ATM jackpotting network could let criminals remotely drain cash machines. The technique revives a lucrative and highly physical form of fraud. 

38. Researchers Find 543,699 Active Credentials Leaked in Public GitHub Repos 

Oct 1, 2026  •  gbhackers.com 

Researchers found 543,699 active credentials leaked in public GitHub repos. Exposed secrets give attackers instant access to cloud and SaaS accounts. 

39. Storm-3068 Hijacks Azure Cloud Assets in Active Campaign 

Sep 30, 2026  •  gbhackers.com 

Storm-3068 hijacks Azure cloud assets in an active campaign. Cloud identity and resources remain prime targets for well-resourced crews. 

40. OperTraitor Finds Kubernetes Operators With Cluster-Wide Secret Access 

Sep 30, 2026  •  gbhackers.com 

OperTraitor finds Kubernetes operators with cluster-wide secret access and admin paths. Over-privileged operators give attackers sweeping cluster control. 

41. Hackers Target 5,700 Microsoft 365 Accounts Using Forgotten Service Accounts 

Sep 30, 2026  •  gbhackers.com 

Hackers targeted 5,700 Microsoft 365 accounts using forgotten service accounts with no MFA. Dormant identities remain a soft entry point into the cloud. 

42. Exposed Hacker Server Reveals Toolkit Used in Viva Aerobus-Linked Intrusion 

Oct 2, 2026  •  gbhackers.com 

An exposed hacker server revealed the toolkit used in a Viva Aerobus-linked intrusion. Operational leaks offer rare insight into attacker tradecraft. 

43. Sony PS5 Relapse Jailbreak Chains WebKit and Kernel Exploits 

Oct 2, 2026  •  gbhackers.com 

The PS5 Relapse jailbreak chains JSC memory corruption with a kernel use-after-free. It shows how browser and kernel flaws combine for full device control. 

📊 INDUSTRY NEWS & DEFENSE

44. ShinyHunters Renew Attacks on Oracle PeopleSoft Servers 

Sep 28, 2026  •  gbhackers.com 

ShinyHunters renewed attacks on Oracle PeopleSoft servers to steal enterprise data. HR and ERP systems are rich targets for mass data theft. 

45. Attackers Abuse Microsoft Defender Exclusions to Evade Detection 

Oct 1, 2026  •  gbhackers.com 

Attackers abuse Microsoft Defender exclusions to evade detection. Misused exclusion policies let malware hide inside trusted security tooling. 

46. U.S. Arrests Company Owner Accused of Shipping GPUs to China 

Oct 2, 2026  •  gbhackers.com 

U.S. authorities arrested a company owner accused of illegally shipping GPUs to China. The case reflects tightening enforcement of AI-chip export controls. 

47. 12 Best Azure Security Tools Compared (2026): Features & Pricing 

Sep 28, 2026  •  gbhackers.com 

GBHackers compares the 12 best Azure security tools for 2026. Cloud security tooling is central to defending modern enterprise workloads. 

48. 12 Best AWS Security Tools Compared (2026) 

Sep 28, 2026  •  gbhackers.com 

GBHackers compares the best AWS security tools for 2026. Securing cloud accounts remains a top priority for enterprise defenders. 

49. 10 Best Container Registry Security Tools Compared (2026) 

Oct 2, 2026  •  gbhackers.com 

GBHackers compares the 10 best container registry security tools for 2026. Registry security is key to a trustworthy software supply chain. 

50. 12 Best IAM Solutions Compared (2026): Features & Pricing 

Oct 2, 2026  •  gbhackers.com 

GBHackers compares the 12 best IAM solutions for 2026. Identity remains the primary control plane for enterprise security. 

❓ FREQUENTLY ASKED QUESTIONS

What does this weekly cybersecurity newsletter cover?

Each issue of the GBHackers cybersecurity newsletter rounds up the week’s 50 most important stories critical vulnerabilities, ransomware attacks, data breaches, AI security threats, phishing campaigns, and malware research curated by our editorial team from everything published on gbhackers.com. 

How is a cybersecurity bulletin different from daily security news?

A cybersecurity bulletin condenses hundreds of daily headlines into a single prioritized weekly briefing. Instead of monitoring feeds all day, security teams get the exploited CVEs, active campaigns, and breaches that actually matter with direct links to the full analysis of each story. 

How do I subscribe to the GBHackers weekly cybersecurity newsletter?

Visit gbhackers.com and follow us on LinkedIn or X (@gbhackers_news) to get every weekly issue. The newsletter is free and lands once a week, every week. 

Found this cybersecurity bulletin useful? Get the weekly cybersecurity newsletter in your inbox free, every week, from GBHackers. 

GBHackers News #1 Globally Trusted Cyber Security News Platform 

Read more at gbhackers.com  •  Follow us on LinkedIn and X (@gbhackers_news) 

Kaaviya

Kaaviya is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

24 minutes ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

40 minutes ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

51 minutes ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

2 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

3 hours ago

wolfSSH Patches 5 Security Vulnerabilities, Including Critical SSH Authentication Bypass

wolfSSL has released wolfSSH version 1.6.0, which addresses five security vulnerabilities, including a critical flaw…

3 hours ago