Weekly Cybersecurity Newsletter – Top 50 Biggest Cybersecurity Stories of the Week
Citrix NetScaler Zero-Days Exploited, OpenAI Agent Swarm Hits Hugging Face, Pentagon Breach Hits 3M, ShinyHunters Leader Arrested, Anthropic MCP Flaw & More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter your weekly cybersecurity bulletin covering the 50 most important stories from September 28 to October 2, 2026.
AI dominated the week: an OpenAI agent swarm used nearly a million URLs against Hugging Face, OpenAI canceled GPT-6.1 Astra over safety, and a flaw in Anthropic’s MCP Python SDK exposed OAuth tokens.
Exploitation ran hot Citrix NetScaler zero-days, Zimbra, FortiMail, Cisco SD-WAN and Apache HTTP Server flaws were all attacked while a Pentagon breach exposed 3 million people and the alleged ShinyHunters leader was arrested.
Here’s everything your peers are reading this week.
Top Stories of the Week — 9 stories
AI Under Attack — 8 stories
Critical Vulnerabilities & Patches — 9 stories
Malware & APT Campaigns — 9 stories
Breaches, Fraud & Attacks — 8 stories
Industry News & Defense — 7 stories
1. Citrix Confirms NetScaler Zero-Day RCE Flaws Under Active Exploitation
Sep 28, 2026 • gbhackers.com
Citrix confirmed NetScaler zero-day RCE flaws that are being actively exploited. NetScaler appliances sit at the network edge, making the bugs especially dangerous.
2. OpenAI Agent Swarm Used Nearly 1 Million URLs to Hack Hugging Face
Sep 28, 2026 • gbhackers.com
An OpenAI agent swarm used nearly a million URLs in an attempt to hack Hugging Face. The incident shows how autonomous agents can scale offensive activity.
3. OpenAI Cancels GPT-6.1 Astra Release Over Safety Concerns
Sep 29, 2026 • gbhackers.com
OpenAI canceled its GPT-6.1 Astra release over safety concerns. The move signals rising caution around deploying more capable models.
4. Pentagon Data Breach Exposes 3 Million People
Sep 29, 2026 • gbhackers.com
A Pentagon data breach exposed records on roughly 3 million people. The scale and sensitivity give the incident serious national-security weight.
5. FBI’s Operation Blackout Takes Down Overseas Scam Networks
Oct 1, 2026 • gbhackers.com
The FBI’s Operation Blackout took down overseas scam networks behind widespread fraud. Coordinated takedowns disrupt the infrastructure behind cybercrime-as-a-service.
6. Anthropic MCP Python SDK Flaw Exposes OAuth Tokens
Sep 29, 2026 • gbhackers.com
A flaw in Anthropic’s MCP Python SDK exposes OAuth tokens to attackers. The bug highlights emerging security gaps in AI agent tooling.
7. Nvidia Launches In-Silicon Security Platform for AI Infrastructure
Sep 28, 2026 • gbhackers.com
Nvidia launched an in-silicon security platform to protect AI infrastructure. Hardware-level defenses aim to secure the compute behind modern AI.
8. China-Linked TA419 Hackers Target U.S. AI Policy Experts
Oct 2, 2026 • gbhackers.com
China-linked TA419 hackers targeted U.S. AI policy experts in an espionage campaign. The operation reflects growing state interest in AI strategy.
9. 16-Year-Old Suspected KillSec Ransomware Leader Arrested
Oct 2, 2026 • gbhackers.com
A 16-year-old suspected KillSec ransomware leader was arrested by authorities. The case underscores how young some ransomware affiliates have become.
10. Attackers Turn Legitimate AI Tools Into Weapons for Cyberattacks
Sep 28, 2026 • gbhackers.com
Attackers are turning legitimate AI tools into weapons for cyberattacks. Dual-use AI keeps lowering the barrier to sophisticated intrusion.
11. AI Agents Expose 13,000 Private Developer Screenshots
Oct 1, 2026 • gbhackers.com
AI agents exposed roughly 13,000 private developer screenshots containing sensitive data. The leak highlights the risks of unsupervised agent access to workstations.
12. New Gemini-Powered Malware Uses AI to Generate Attack Code
Sep 30, 2026 • gbhackers.com
New Gemini-powered malware uses AI to generate attack code on the fly. AI-driven implants can adapt without operator input.
13. OpenAI Launches Codex Security Cloud to Harden AI-Generated Code
Sep 30, 2026 • gbhackers.com
OpenAI launched Codex Security Cloud to harden AI-generated code against flaws. The move reflects mounting concern over vulnerabilities in machine-written software.
14. FTC Investigates OpenAI and Anthropic Over Data Practices
Oct 2, 2026 • gbhackers.com
The FTC is investigating OpenAI and Anthropic over their data practices. The probe signals intensifying scrutiny of leading AI firms.
15. Best AI Penetration Testing Tools 2026
Sep 29, 2026 • gbhackers.com
GBHackers compares the best AI penetration testing tools for 2026. Machine learning is reshaping how security teams probe their own defenses.
16. Unsloth Fixes Arbitrary Code Execution Flaw in AI Training Tool
Sep 30, 2026 • gbhackers.com
Unsloth fixed an arbitrary code execution flaw in its AI training tool. AI tooling is becoming a fresh and under-tested attack surface.
17. Hackers Turn Open-Source AI Agent Into Tool for Hijacking Docker Servers
Sep 28, 2026 • gbhackers.com
Hackers turned an open-source AI agent into a tool for hijacking Docker servers. The campaign shows how attackers are automating infrastructure compromise.
18. OpenSSL High-Severity Flaw Prompts Urgent Patching
Sep 30, 2026 • gbhackers.com
A high-severity OpenSSL flaw prompted urgent patching across the industry. The library’s ubiquity means every fix carries wide operational impact.
19. Apache HTTP Server Flaws Enable Request Smuggling and Bypass
Oct 2, 2026 • gbhackers.com
Newly disclosed Apache HTTP Server flaws enable request smuggling and security bypass. Apache’s vast deployment base widens the blast radius of each bug.
20. Fortinet FortiMail Path Traversal Flaw Lets Attackers Execute Code
Oct 2, 2026 • gbhackers.com
A Fortinet FortiMail path-traversal flaw lets attackers execute code on mail gateways. Email security appliances sit at the perimeter, making them prime targets.
21. Zimbra Vulnerability Exploited for Unauthenticated Code Execution
Oct 1, 2026 • gbhackers.com
A Zimbra vulnerability is being exploited for unauthenticated code execution. Collaboration suites are a direct route to sensitive corporate mail.
22. Critical Cisco SD-WAN Vulnerability Exploited in Active Attacks
Oct 1, 2026 • gbhackers.com
A critical Cisco SD-WAN vulnerability is being exploited in active attacks. Edge networking gear hands attackers a broad foothold across branch sites.
23. Multiple ModSecurity Vulnerabilities Allow WAF Bypass
Oct 1, 2026 • gbhackers.com
Multiple ModSecurity vulnerabilities allow attackers to bypass the web application firewall. WAF gaps expose the very apps they are meant to protect.
24. HPE Instant On AP Flaws Let Unauthenticated Attackers Run Commands
Oct 1, 2026 • gbhackers.com
HPE Instant On AP flaws let unauthenticated attackers execute arbitrary commands. Wireless access points are a prized foothold on internal networks.
25. Linux Kernel CVE-2026-72018 Flaw Lets Local Attackers Gain Root
Sep 30, 2026 • gbhackers.com
Linux kernel flaw CVE-2026-72018 lets local attackers gain root access. Kernel bugs undermine the core trust boundary of every Linux system.
26. Zammad Vulnerabilities Let Attackers Execute Code and Escalate to Root
Oct 2, 2026 • gbhackers.com
Zammad vulnerabilities let attackers execute code and escalate privileges to root. Help-desk platforms hold sensitive customer data and credentials.
27. MacSync’s New Infection Chain Shows Mac Malware Growing Sophisticated
Sep 28, 2026 • gbhackers.com
MacSync’s new infection chain shows how Mac malware is growing more sophisticated. macOS users are an increasingly rich target for attackers.
28. New SectopRAT Malware Campaign Targets Windows Users
Sep 30, 2026 • gbhackers.com
A new SectopRAT malware campaign targets Windows users for remote control and theft. RAT operators gain deep, persistent access to infected machines.
29. Windows RAT Used in Targeted Espionage Campaign
Sep 29, 2026 • gbhackers.com
A Windows RAT is being used in a targeted espionage campaign. Remote access tools let attackers quietly exfiltrate sensitive data over time.
30. 2cLoader Malware Delivers Multiple Infostealer Payloads
Oct 1, 2026 • gbhackers.com
The 2cLoader dropper delivers multiple infostealer payloads in a new campaign. Loader-as-a-service keeps lowering the barrier to mass credential theft.
31. New Python-Based Infostealer Harvests Credentials and Crypto Wallets
Oct 2, 2026 • gbhackers.com
A new Python-based infostealer harvests credentials and crypto wallets. Scripting-language malware is easy to build and quick to retool.
32. SC WordPress Malware Rebuilds Itself After Removal
Oct 1, 2026 • gbhackers.com
SC WordPress malware rebuilds itself after removal using database and memory persistence. Self-healing web malware frustrates clean-up efforts.
33. CloudSyncD Backdoor Hides Phished Mac Passwords in Invisible Unicode
Oct 1, 2026 • gbhackers.com
The CloudSyncD backdoor hides phished Mac passwords in invisible Unicode. Stealthy encoding helps the malware evade both users and scanners.
34. Attackers Use PaperCut RCE Chain to Reach Domain Controller
Sep 30, 2026 • gbhackers.com
Attackers use a PaperCut RCE chain to steal tokens and reach the domain controller. Print-management servers are an overlooked path to full domain control.
35. New Windows Process Injection Technique Bypasses EDR
Sep 28, 2026 • gbhackers.com
A new Windows process injection technique bypasses EDR defenses. Novel injection tricks let malware hide inside trusted processes.
36. Malicious VPN Extensions Hijack Browser Traffic
Sep 29, 2026 • gbhackers.com
Malicious VPN extensions hijack browser traffic and route it through attacker servers. Rogue extensions turn the browser into a surveillance channel.
37. ATM Jackpotting Network Could Let Criminals Remotely Drain Cash
Oct 2, 2026 • gbhackers.com
An ATM jackpotting network could let criminals remotely drain cash machines. The technique revives a lucrative and highly physical form of fraud.
38. Researchers Find 543,699 Active Credentials Leaked in Public GitHub Repos
Oct 1, 2026 • gbhackers.com
Researchers found 543,699 active credentials leaked in public GitHub repos. Exposed secrets give attackers instant access to cloud and SaaS accounts.
39. Storm-3068 Hijacks Azure Cloud Assets in Active Campaign
Sep 30, 2026 • gbhackers.com
Storm-3068 hijacks Azure cloud assets in an active campaign. Cloud identity and resources remain prime targets for well-resourced crews.
40. OperTraitor Finds Kubernetes Operators With Cluster-Wide Secret Access
Sep 30, 2026 • gbhackers.com
OperTraitor finds Kubernetes operators with cluster-wide secret access and admin paths. Over-privileged operators give attackers sweeping cluster control.
41. Hackers Target 5,700 Microsoft 365 Accounts Using Forgotten Service Accounts
Sep 30, 2026 • gbhackers.com
Hackers targeted 5,700 Microsoft 365 accounts using forgotten service accounts with no MFA. Dormant identities remain a soft entry point into the cloud.
42. Exposed Hacker Server Reveals Toolkit Used in Viva Aerobus-Linked Intrusion
Oct 2, 2026 • gbhackers.com
An exposed hacker server revealed the toolkit used in a Viva Aerobus-linked intrusion. Operational leaks offer rare insight into attacker tradecraft.
43. Sony PS5 Relapse Jailbreak Chains WebKit and Kernel Exploits
Oct 2, 2026 • gbhackers.com
The PS5 Relapse jailbreak chains JSC memory corruption with a kernel use-after-free. It shows how browser and kernel flaws combine for full device control.
44. ShinyHunters Renew Attacks on Oracle PeopleSoft Servers
Sep 28, 2026 • gbhackers.com
ShinyHunters renewed attacks on Oracle PeopleSoft servers to steal enterprise data. HR and ERP systems are rich targets for mass data theft.
45. Attackers Abuse Microsoft Defender Exclusions to Evade Detection
Oct 1, 2026 • gbhackers.com
Attackers abuse Microsoft Defender exclusions to evade detection. Misused exclusion policies let malware hide inside trusted security tooling.
46. U.S. Arrests Company Owner Accused of Shipping GPUs to China
Oct 2, 2026 • gbhackers.com
U.S. authorities arrested a company owner accused of illegally shipping GPUs to China. The case reflects tightening enforcement of AI-chip export controls.
47. 12 Best Azure Security Tools Compared (2026): Features & Pricing
Sep 28, 2026 • gbhackers.com
GBHackers compares the 12 best Azure security tools for 2026. Cloud security tooling is central to defending modern enterprise workloads.
48. 12 Best AWS Security Tools Compared (2026)
Sep 28, 2026 • gbhackers.com
GBHackers compares the best AWS security tools for 2026. Securing cloud accounts remains a top priority for enterprise defenders.
49. 10 Best Container Registry Security Tools Compared (2026)
Oct 2, 2026 • gbhackers.com
GBHackers compares the 10 best container registry security tools for 2026. Registry security is key to a trustworthy software supply chain.
50. 12 Best IAM Solutions Compared (2026): Features & Pricing
Oct 2, 2026 • gbhackers.com
GBHackers compares the 12 best IAM solutions for 2026. Identity remains the primary control plane for enterprise security.
Each issue of the GBHackers cybersecurity newsletter rounds up the week’s 50 most important stories critical vulnerabilities, ransomware attacks, data breaches, AI security threats, phishing campaigns, and malware research curated by our editorial team from everything published on gbhackers.com.
A cybersecurity bulletin condenses hundreds of daily headlines into a single prioritized weekly briefing. Instead of monitoring feeds all day, security teams get the exploited CVEs, active campaigns, and breaches that actually matter with direct links to the full analysis of each story.
Visit gbhackers.com and follow us on LinkedIn or X (@gbhackers_news) to get every weekly issue. The newsletter is free and lands once a week, every week.
Found this cybersecurity bulletin useful? Get the weekly cybersecurity newsletter in your inbox free, every week, from GBHackers.
GBHackers News #1 Globally Trusted Cyber Security News Platform
Read more at gbhackers.com • Follow us on LinkedIn and X (@gbhackers_news)
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…
wolfSSL has released wolfSSH version 1.6.0, which addresses five security vulnerabilities, including a critical flaw…