Weekly review

ThreatNoir Afternoon Brief — October 5

2026-10-05Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — October 5, 2026

The cybersecurity landscape continues to shift rapidly as critical vulnerabilities emerge across multiple platforms and threat actors expand their operational reach. Today's briefing covers urgent threats affecting open-source infrastructure, enterprise authentication systems, and macOS deployments, alongside an expanding phishing campaign from a Russian-linked threat group.

Exploitation Hits Rejetto HFS Vulnerability Discovered by AI

A critical vulnerability in Rejetto HFS has come under active exploitation following its discovery through artificial intelligence analysis. Tracked as CVE-2026-61500, this flaw permits attackers to recover the session-cookie signing key, thereby obtaining administrative access and achieving remote code execution on affected systems. The vulnerability represents a significant risk to organizations deploying this file server software, particularly given the accessibility of exploit code in the wild. Source: SecurityWeek

New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

Citrix has released security updates addressing a high-severity zero-day vulnerability actively exploited in targeted attacks against NetScaler ADC and Citrix NetScaler Gateway deployments. CVE-2026-88779, a memory overflow vulnerability assigned a CVSS score of 8.7, poses particular risk to organizations relying on SAML-based authentication infrastructure. The vulnerability has been weaponized by threat actors in real-world campaigns, making immediate patching a critical priority for affected enterprises. Additional related vulnerabilities CVE-2026-88771 and CVE-2026-88772 have also been identified. Source: The Hacker News

Star Blizzard Targets 100+ Organizations with Phishing and RedFlick Technique

Russian-linked threat group Star Blizzard has expanded its phishing campaign operations to target more than one hundred organizations, introducing a new malware delivery technique dubbed RedFlick. The campaign leverages scheduled tasks to deliver the CosmicPulse backdoor payload, enabling persistent access to compromised systems. This expansion demonstrates the group's continued investment in social engineering tactics combined with increasingly sophisticated delivery mechanisms. Source: Hackread

Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access

Apple has announced plans to implement stricter controls governing the Full Disk Access setting in macOS, responding to security risks posed by artificial intelligence agents. Developers have been observed leveraging Full Disk Access in ways that expose sensitive user data including files, email, messages, and browsing history without adequate user awareness or consent. The tightening of these controls reflects growing concerns about how AI-powered applications may access and potentially exfiltrate personal information from user systems. Source: The Hacker News

Today's threat landscape underscores the importance of rapid vulnerability assessment and patching, particularly for infrastructure components serving authentication and file access functions. Organizations should prioritize updates for NetScaler systems while remaining vigilant against phishing campaigns employing novel delivery techniques.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).