Dagoverzicht
dinsdag 29 september 2026
- 4 direct handelen
- 0 deze week
- 6 reguliere patchcyclus
- 53 nieuws en analyses
Automatisch samengesteld en niet redactioneel beoordeeld. Controleer details altijd bij de bron.
Direct handelen
Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances
- CVE-2026-88772KEV
- CVE-2026-88771KEV
- CVE-2026-88778
Handelingsperspectief: Direct handelen(binnen 48 uur)
- Stel vast of het product bij jullie of bij een leverancier in gebruik is.
- Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan.
- Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.
Gebaseerd op
- CISA KEV: misbruik bevestigd voor CVE-2026-88772 (Citrix NetScaler), toegevoegd 27 sep 2026, CISA-deadline voor Amerikaanse overheidsinstanties 30 sep 2026.
- CISA KEV: misbruik bevestigd voor CVE-2026-88771 (Citrix NetScaler), toegevoegd 27 sep 2026, CISA-deadline voor Amerikaanse overheidsinstanties 30 sep 2026.
Automatisch afgeleid uit brondata volgens vaste regels. Hoe dit werkt
Actief misbruikt: Apple Multiple Products (CVE-2026-86950)
- CVE-2026-86950KEV
Handelingsperspectief: Direct handelen(binnen 48 uur)
- Stel vast of het product bij jullie of bij een leverancier in gebruik is.
- Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan.
- Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.
Gebaseerd op
- CISA KEV: misbruik bevestigd voor CVE-2026-86950 (Apple Multiple Products), toegevoegd 29 sep 2026, CISA-deadline voor Amerikaanse overheidsinstanties 2 okt 2026.
Automatisch afgeleid uit brondata volgens vaste regels. Hoe dit werkt
Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers
Handelingsperspectief: Direct handelen(binnen 48 uur)
- Stel vast of het product bij jullie of bij een leverancier in gebruik is.
- Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan.
- Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.
Gebaseerd op
- De bron meldt actief misbruik of een zero-day.
Automatisch afgeleid uit brondata volgens vaste regels. Hoe dit werkt
Apple patches CoreGraphics zero-day flaw exploited in attacks
Handelingsperspectief: Direct handelen(binnen 48 uur)
- Stel vast of het product bij jullie of bij een leverancier in gebruik is.
- Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan.
- Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.
Gebaseerd op
- De bron meldt actief misbruik of een zero-day.
Automatisch afgeleid uit brondata volgens vaste regels. Hoe dit werkt
Deze week
Geen kwetsbaarheden voor deze week.
Reguliere patchcyclus
Geen aanwijzing voor misbruik of hoge ernst: meenemen in de reguliere patchcyclus.
Stable Channel Update for Desktop
Warning: Two critical vulnerabilities which can lead to Remote Code Execution in WatchGuard, Patch Immediately!
Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution
Hackers exploit SQL injection flaw to steal patient data from Polish medical software provider
Kiteworks patches critical flaw, brings customer systems online
GitHub’s AI agent found 24 Android app vulnerabilities
Nieuws en analyses
Phishing Abuses RMM Tools for Persistent Access
Warning: Critical Cross-site Scripting (XSS) in Rancher - Kubernetes management platform, Patch Immediately!
Beyond source code: A path to the keys to the kingdom
Star Blizzard refines phishing and malware delivery with the RedFlick technique
OperTraitors: How Kubernetes Operators Betray Your Security Posture
Securing the keys to the kingdom: Announcing Executive Threat Detection
US Air Force members given over 6 years in prison for cyber theft of more than $2 million
Custom ChatGPTs push ClickFix attacks to deploy RAT malware
Controversial spyware firm Paragon to go public by end of year
OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference
OpenAI apologizes for agents breaching Australian government websites without authorization
Former US Air Force members sent to prison over BEC attacks
DARPA Selects Xint to Use AI in Securing Military Messaging Apps
Cloudflare Announces Public Certificate Authority for the Post-Quantum Web
New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks
Automated AI agent used to breach cybersecurity nonprofit DIVD
'NeedyMantis' Provides Long-Term Access to Compromised Networks
RemoteThreat Launches With $7 Million for Offensive Operations Platform
Catch threats before they escalate with real-time Identity Telemetry
LastPass warns employees before they share sensitive data with AI tools
Postman adds security controls for AI agents, APIs, and MCP servers
Scans for Wordfence Protected Websites, (Tue, Sep 29th)
Reco Raises $55 Million for Agentic Security
Hackers Use ChatGPT Custom GPTs in ClickFix Attacks
Webinar: Closing the accountability gap in AI-assisted delivery
Meta gives small businesses an AI agent that knows their work
Vega II brings security-trained AI and lasting memory to the SOC
Russian pizza chain with 1,500 locations confirms cyberattack following hacker claims
Arizona Supreme Court says hackers stole residents’ personal data
Pentagon Personnel Agency Data Breach Impacts 3 Million People
Rig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity Risks
Deepfakes become a board priority once an executive falls for one
Malicious Custom GPT on chatgpt.com lures users into installing a RAT
OpenAI’s GPT-6 Astra ran supply chain attacks despite being told not to
Four Cyber Threats Harboring Big Plans for the Future
Onderzoekers melden grootschalig misbruik van kritieke Citrix-lekken
OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training
Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation
Cybersecurity hiring practices leave little room for junior talent
Palo Alto Networks and NVIDIA want tighter control over AI agents
CCB heeft in België nog geen aanvallen door AI-agents gezien
Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft
Cloudflare’s EmDash 1.0 makes sandboxed plugins ask for access first
Claude Sonnet 5.5 gets faster without a price hike
Apple dicht beveiligingslek ingezet bij aanvallen tegen iPhone-gebruikers
A four-week plan to tackle vendor concentration risk
Hottest cybersecurity open-source tools of the month: September 2026
Cybersecurity jobs available right now: September 29, 2026
ISC Stormcast For Tuesday, September 29th, 2026 https://isc.sans.edu/podcastdetail/10114, (Tue, Sep 29th)
Between Two Nerds: The AI crime machine
Nvidia Launches AI Agent Safety Platform to Prevent Rogue Activities
Jonge hacker nu ook verdacht van moordopdrachten: wie is whizzkid Pepijn van der S.?
OpenAI zegt sorry tegen Australië voor hack en ziet af van nieuw AI-model