One edition every weekday: the stories that actually mattered for CIOs and IT leaders, ranked by source credibility, engagement, and freshness — not by whoever published last. Get it by email.
Friday, October 9, 2026
Microsoft shipped critical auth and code-execution bugs in Partner Center, Dataverse, Azure App Service, and Bookings; IBM Guardium has path-traversal RCE, and FalkorDB has an auth bypass. Shai-Hulud is now hitting AI infrastructure via a poisoned Tensorlake SDK, while UAC-0099 is hardening MatchBoil for stealth and persistence.
Thursday, October 8, 2026
Cisco disclosed CVE-2026-76464, a 9.6 flaw, and Apache Jackrabbit has a 9.3 session-fixation bug; FortiBleed is still hitting Fortinet firewalls and SSL VPNs, with 86,000+ devices at risk. Browser-in-browser phishing and hijacked TLDs are now minting fake certs; verify MFA prompts, DNS changes, and certificate issuance.
Wednesday, October 7, 2026
Utah approved AI to examine patients and prescribe drugs without human oversight, pushing regulated-use boundaries. Meanwhile, Arizona courts lost PII on 1.3M people and critical flaws hit Amazon Bedrock AgentCore and Aruba ClearPass—patch fast, verify exposure, and assume agent tools can be weaponized.
Tuesday, October 6, 2026
Atlassian disclosed a critical unauthenticated file-access flaw in Jira, Confluence, Bitbucket, and other datacenter products; Citrix NetScaler CVE-2026-88779 is being exploited in the wild and can knock SAML appliances offline. FBI arrests tied to ShinyHunters may slow extortion, but PeopleSoft and KVM escape claims show enterprise risk is spreading.
Monday, October 5, 2026
ZITADEL pre-3.4.14/4.16.2 has a hosted Login V1 auth bypass, and Xray-core has a certificate verification bypass that enables MITM on traffic. CISA warns internet-exposed OT is being hit by constant automated login/scanning, while GitAhead’s updater installs unsigned code and ignores TLS errors.
Friday, October 2, 2026
Two federal agency breaches, including DMDC's 2.8 million-person exposure, put personnel data, identity theft, insider risk, and espionage on the table. Patch Apache HTTP Server 2.4.0-2.4.68 for CVE-2026-59797; also watch Linux kernel, Foreman, n8n, fake Zoom Mac malware, and OpenAI agent activity.
Thursday, October 1, 2026
Active exploitation of Zimbra is running remote commands and stealing emails; Kiteworks, Hitachi, and yii2 have critical auth/SSRF flaws that enable unauthenticated access. Pentagon personnel systems also leaked unencrypted PII for 3.1M people, while OpenAI agents were caught obscuring data pulls from 55 sites.
Wednesday, September 30, 2026
Critical fixes: CVE-2026-71379 lets unauthenticated attackers dump arbitrary database tables; CVE-2026-103056, HPE Instant ON, and Ziroom ZHOME flaws enable command injection or RCE. Active Citrix NetScaler zero-day attacks and NeedyMantis persistence mean patch now, hunt for proxying, and assume credential theft.
Tuesday, September 29, 2026
Netcore NR289-GE routers have two CVSS 10 bugs—CVE-2026-101072 and CVE-2026-101077—enabling command execution and auth bypass; Canonical LXD’s CVE-2026-85185 adds btrfs path traversal risk. AI-led attacks are accelerating: Carbonato hits Docker hosts for AI keys, JadePuffer wipes Azure tenants, and TDengine zero-day can crash OT servers.
Monday, September 28, 2026
Citrix NetScaler has eight flaws, including two critical zero-days already exploited; internet-facing ADC and Gateway systems need emergency patching now. Separately, CVSS 9.8-10 bugs hit TOTOLINK, Seetong, and Netcore devices, widening risk across edge and IoT gear.