- Critical vulnerability in Rejetto HFS allowing RCE via session cookie forgery
ThreatNoir Afternoon Brief — October 5
Afternoon Review in IT Security — October 5, 2026
The cybersecurity landscape continues to shift rapidly as critical vulnerabilities emerge across multiple platforms and threat actors expand their operational reach. Today's briefing covers urgent threats affecting open-source infrastructure, enterprise authentication systems, and macOS deployments, alongside an expanding phishing campaign from a Russian-linked threat group.
Exploitation Hits Rejetto HFS Vulnerability Discovered by AI
A critical vulnerability in Rejetto HFS has come under active exploitation following its discovery through artificial intelligence analysis. Tracked as CVE-2026-61500, this flaw permits attackers to recover the session-cookie signing key, thereby obtaining administrative access and achieving remote code execution on affected systems. The vulnerability represents a significant risk to organizations deploying this file server software, particularly given the accessibility of exploit code in the wild. Source: SecurityWeek
New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
Citrix has released security updates addressing a high-severity zero-day vulnerability actively exploited in targeted attacks against NetScaler ADC and Citrix NetScaler Gateway deployments. CVE-2026-88779, a memory overflow vulnerability assigned a CVSS score of 8.7, poses particular risk to organizations relying on SAML-based authentication infrastructure. The vulnerability has been weaponized by threat actors in real-world campaigns, making immediate patching a critical priority for affected enterprises. Additional related vulnerabilities CVE-2026-88771 and CVE-2026-88772 have also been identified. Source: The Hacker News
Star Blizzard Targets 100+ Organizations with Phishing and RedFlick Technique
Russian-linked threat group Star Blizzard has expanded its phishing campaign operations to target more than one hundred organizations, introducing a new malware delivery technique dubbed RedFlick. The campaign leverages scheduled tasks to deliver the CosmicPulse backdoor payload, enabling persistent access to compromised systems. This expansion demonstrates the group's continued investment in social engineering tactics combined with increasingly sophisticated delivery mechanisms. Source: Hackread
Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access
Apple has announced plans to implement stricter controls governing the Full Disk Access setting in macOS, responding to security risks posed by artificial intelligence agents. Developers have been observed leveraging Full Disk Access in ways that expose sensitive user data including files, email, messages, and browsing history without adequate user awareness or consent. The tightening of these controls reflects growing concerns about how AI-powered applications may access and potentially exfiltrate personal information from user systems. Source: The Hacker News
Today's threat landscape underscores the importance of rapid vulnerability assessment and patching, particularly for infrastructure components serving authentication and file access functions. Organizations should prioritize updates for NetScaler systems while remaining vigilant against phishing campaigns employing novel delivery techniques.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Previously exploited CVE for planting web shells and tunneling tools.
- Previously exploited CVE for planting web shells and tunneling tools.
- NetScaler ADC and Gateway memory overflow vulnerability exploited in targeted attacks.
- CosmicPulseBackdoor malware delivered via RedFlick technique using scheduled tasks
- RedFlickMalware delivery technique used by Star Blizzard to deploy CosmicPulse
- Vulnerability impacting OpenAI's ChatGPT app for Mac