Pro, VIP and Partner members post into rubrics – every follower of the rubric sees the post.Log in

SecurityWeek reports that Citrix is urging immediate patching of a critical NetScaler vulnerability that could lead to remote code execution or denial of service. The flaw affects NetScaler ADC and NetScaler Gateway appliances in specific SAML configurations, as well as Secure Private Access Hybrid deployments. Citrix says it is not aware of unmitigated exploits, but users should update to the fixed versions as soon as possible.

SecurityWeekCitrix Urges Immediate Patching of Critical NetScaler Vulnerability

Source: securityweek.com

SecurityWeek reports that TP-Link has disclosed five vulnerabilities in its Aginet line of ISP-managed mesh systems, routers and modems. The bugs can let an attacker on the same network take over an affected device, create a super-administrator account, enable SSH access, or recover passwords and Wi-Fi credentials from configuration files. TP-Link says firmware updates are distributed by ISPs, so users should check the device management interface or app for updates and contact their ISP if none are available.

SecurityWeekTP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws

Source: securityweek.com

Help Net Security reports that attackers have already started trying to exploit a critical arbitrary file access flaw in Atlassian’s self-managed Data Center products, including Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible and Fisheye. Atlassian urged customers to upgrade to a fixed version as soon as possible. Those who cannot update quickly should remove vulnerable instances from the internet or block external access, and check access logs for signs of compromise.

Help Net SecurityExploitation attempts against critical Atlassian flaw have begun (CVE-2026-21589)

Source: helpnetsecurity.com

The Register reports that Microsoft is adding .msix and .msixbundle to Outlook’s block list. New Outlook for Windows and Outlook on the Web in Exchange Online will stop users from downloading or opening those attachments by default, because a malicious package could compromise a device. Administrators who need them can allow the file types before the rollout in early to mid-November 2026.

The RegisterMicrosoft extends the Outlook naughty step with two more file types

Source: theregister.com

The Hacker News reports that attackers are trying to exploit a now-patched critical flaw in the Realtek Jungle SDK to deploy the Cling botnet. The malware targets routers and DVRs from multiple vendors, so home users and small offices should make sure their router or device firmware is fully updated and check vendor security advisories for fixes.

The Hacker NewsRealtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

Source: thehackernews.com

The Register reports that exploitation attempts have already been seen against a critical authentication-bypass bug in Rejetto HTTP File Server that can lead to full admin access and remote code execution. If you use Rejetto HFS, update to v3.2.1 or later, which fixes this and other security flaws.

The RegisterAnthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows

Source: theregister.com

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year