Cybersecurity News | Daily Recap [28 Sep 2026]

Cybersecurity News | Daily Recap [28 Sep 2026]
Daily Recap, major incidents and patching updates dominated today’s security news: a reported Titan JWT signature flaw enabled access to 17 trillion analytics rows at Microsoft, while Citrix confirmed two NetScaler RCE zero-days were exploited and CISA ordered federal agencies to patch by Wednesday. Meanwhile, Google warned that ShinyHunters is targeting Oracle PeopleSoft environments, and Cloudflare addressed a cross-tenant Containers vulnerability that could expose customer data across accounts.
#Titan #Microsoft #NetScaler #Citrix #CISA #Cloudflare #Containers #ShinyHunters #Oracle #PeopleSoft

Major Breaches

  • A 16-year-old researcher reportedly broke into Microsoft analytics systems and gained access to 17 trillion rows of data by exploiting a Titan JWT signature flaw. – Microsoft Flaw
  • Bitget resumed Bitcoin withdrawals after a $387.5 million crypto heist, while the weekly threat roundup also highlighted the broader $387M hack wave. – Bitget Heist, Weekly Recap
  • DC Health exposed 400,000 beneficiary records in a data breach affecting sensitive personal information. – DC Health Breach
  • A New Mexico jury found Facebook liable for deceiving users about privacy protections. – Facebook Case

Exploits & Patching

  • Citrix confirmed two NetScaler RCE zero-days were exploited in attacks, and CISA ordered U.S. federal agencies to patch the flaws by Wednesday. – Citrix Zero-Days, CISA Order
  • Cloudflare fixed a Containers cross-tenant vulnerability that could expose customer data across accounts. – Cloudflare Fix
  • A browser/file-notification issue can let other users observe browsing activity and time keystrokes through OS file notifications. – File Notification

Threat Actors & Crime

  • Google warned that ShinyHunters has launched a fresh campaign targeting Oracle PeopleSoft environments. – PeopleSoft Campaign
  • A former US soldier received a 70-month prison sentence for hacking and extorting AT&T, Verizon, and other tech and telecom firms. – Soldier Sentence, Extortion Case

AI Security

  • NVIDIA is pushing to enforce AI agent safety in silicon, as research and reports show agent memory and governance remain weak points in enterprise security. – NVIDIA Safety, Agent Memory, AI Governance
  • Research found β€œdrunk” AI models are poor at keeping secrets, underscoring ongoing jailbreak and data-leak risks. – Drunk AI

Security Industry & Events

  • Call for presentations is now open for the 2026 CISO Forum Virtual Summit. – CISO Forum
  • Authorizer introduced open-source authentication and authorization tooling for applications. – Authorizer
  • The daily threat roundup compiled the latest security developments from 27 Sep 2026. – Weekly Recap

Cybersecurity News | Daily Recap – hendryadrian.com