Citrix warns admins to patch new NetScaler RCE flaw immediately

Citrix has issued a critical warning to IT administrators, urging them to patch their NetScaler ADC and NetScaler Gateway appliances immediately to prevent remote code execution (RCE) attacks. The vulnerability, tracked as CVE-2026-107406, allows attackers to gain control over targeted devices or trigger denial-of-service (DoS) states that can cause crashes. To be vulnerable, NetScaler appliances … Read more

FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure Intrusions

The FBI has taken a significant step in disrupting a major threat to critical infrastructure by seizing control of seven domains associated with the Flax Typhoon toolset. This move is aimed at preventing hackers from using these tools to infiltrate and compromise sensitive systems, potentially causing widespread damage. Flax Typhoon is a suite of hacking … Read more

Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments

A Critical Flaw in Citrix’s NetScaler Exposes SAML Deployments to Remote Code Execution Citrix has issued a patch for its NetScaler product, addressing a critical vulnerability that could allow attackers to execute malicious code remotely on affected systems. This security flaw affects organizations using NetScaler with Single Sign-On (SSO) capabilities through Security Assertion Markup Language … Read more

Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own

Three Teams of Hackers Successfully Breach Fully Patched Google Pixel 10 Phones at Prestigious Hacking Contest At this year’s Pwn2Own hacking contest, a trio of teams demonstrated astonishingly effective exploits against the supposedly secure Google Pixel 10 smartphones. The devices, boasting the latest software patches and touted as among the most secure on the market, … Read more

GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys

A Critical Flaw in Tor’s Onion Routing System Leaves .onion Addresses Vulnerable to Hijacking A severe security vulnerability has been discovered in the way Tor, a popular anonymizing browser, handles its onion routing system. The flaw, which affects all versions of Tor prior to 2.4.17-rc, allows attackers to hijack .onion addresses and potentially access sensitive … Read more

US Seeks Alleged Chinese Hafnium Hacker With $10 Million Reward

The US Department of State is offering a substantial reward for information leading to the capture of Zhang Yu, a Chinese national accused of being part of a notorious hacking campaign that targeted Microsoft Exchange servers. The Hafnium attacks, which began in 2020, compromised thousands of computers worldwide, including those belonging to a US university … Read more

Google Pixel 10 Exploits Earned Hackers $560,000 at Pwn2Own

The Pwn2Own hacking competition has just wrapped up in Ireland, and it’s been a lucrative year for cybersecurity researchers. The event saw over $1.2 million in rewards paid out to participants who successfully exploited vulnerabilities in various devices, including phones, printers, smart speakers, and cloud databases. At the top of the leaderboard were exploits targeting … Read more

Citrix Urges Immediate Patching of Critical NetScaler Vulnerability

Citrix has issued a critical warning to users of its NetScaler appliances, urging them to patch a severe vulnerability that could allow attackers to execute malicious code or disrupt service. The company’s prompt notification comes on the heels of recent zero-day exploits targeting NetScaler, which have been used in attacks against various organizations. The vulnerability, … Read more

Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland

Cybersecurity Researchers Score Big at Pwn2Own Ireland, Collecting $1.26 Million in Rewards for Identifying Zero-Day Flaws A trio of cybersecurity researchers walked away with a whopping $361,000 and 42.5 Master of Pwn points after dominating this year’s Pwn2Own Ireland hacking contest, which concluded on October 7th. The competition, organized by Trend Micro’s Zero Day Initiative … Read more

FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure Intrusions

The FBI has taken a significant step in disrupting the operations of cyber threat actors, seizing control of seven domains and disabling their tools used in attacks on critical infrastructure. These malicious tools, known as Flax Typhoon, have been linked to a string of high-profile intrusions that compromised sensitive systems and put lives at risk. … Read more