hacker-news · Crawled Oct 5, 2026

⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests

1 Actors
Read original article ↗

AI Summary

Multiple critical zero-day vulnerabilities were exploited in the wild this week, including CVE-2026-88779 in Citrix NetScaler ADC and Gateway, and CVE-2026-104286 in Fortinet FortiMail, both allowing remote code execution or arbitrary file writes. Russian state-sponsored group Star Blizzard deployed a new malware delivery technique called RedFlick to install the CosmicPulse backdoor via phishing. A Chinese-linked post-compromise malware, NeedyMantis, has been used in targeted operations since October 2025. Additionally, law enforcement disrupted the KillSec ransomware group and arrested members of ShinyHunters. A new Spectre v2 variant, BTR, enables rapid extraction of Linux root password hashes on Intel systems.

AI-extracted · verify before operational use

Extracted Entities 1 found

MITRE ATT&CK TTPs 17 techniques