Daily Recap, major incidents and patching updates dominated todayβs security news: a reported Titan JWT signature flaw enabled access to 17 trillion analytics rows at Microsoft, while Citrix confirmed two NetScaler RCE zero-days were exploited and CISA ordered federal agencies to patch by Wednesday. Meanwhile, Google warned that ShinyHunters is targeting Oracle PeopleSoft environments, and Cloudflare addressed a cross-tenant Containers vulnerability that could expose customer data across accounts.
#Titan #Microsoft #NetScaler #Citrix #CISA #Cloudflare #Containers #ShinyHunters #Oracle #PeopleSoft
#Titan #Microsoft #NetScaler #Citrix #CISA #Cloudflare #Containers #ShinyHunters #Oracle #PeopleSoft
Major Breaches
- A 16-year-old researcher reportedly broke into Microsoft analytics systems and gained access to 17 trillion rows of data by exploiting a Titan JWT signature flaw. β Microsoft Flaw
- Bitget resumed Bitcoin withdrawals after a $387.5 million crypto heist, while the weekly threat roundup also highlighted the broader $387M hack wave. β Bitget Heist, Weekly Recap
- DC Health exposed 400,000 beneficiary records in a data breach affecting sensitive personal information. β DC Health Breach
- A New Mexico jury found Facebook liable for deceiving users about privacy protections. β Facebook Case
Exploits & Patching
- Citrix confirmed two NetScaler RCE zero-days were exploited in attacks, and CISA ordered U.S. federal agencies to patch the flaws by Wednesday. β Citrix Zero-Days, CISA Order
- Cloudflare fixed a Containers cross-tenant vulnerability that could expose customer data across accounts. β Cloudflare Fix
- A browser/file-notification issue can let other users observe browsing activity and time keystrokes through OS file notifications. β File Notification
Threat Actors & Crime
- Google warned that ShinyHunters has launched a fresh campaign targeting Oracle PeopleSoft environments. β PeopleSoft Campaign
- A former US soldier received a 70-month prison sentence for hacking and extorting AT&T, Verizon, and other tech and telecom firms. β Soldier Sentence, Extortion Case
AI Security
- NVIDIA is pushing to enforce AI agent safety in silicon, as research and reports show agent memory and governance remain weak points in enterprise security. β NVIDIA Safety, Agent Memory, AI Governance
- Research found βdrunkβ AI models are poor at keeping secrets, underscoring ongoing jailbreak and data-leak risks. β Drunk AI
Security Industry & Events
- Call for presentations is now open for the 2026 CISO Forum Virtual Summit. β CISO Forum
- Authorizer introduced open-source authentication and authorization tooling for applications. β Authorizer
- The daily threat roundup compiled the latest security developments from 27 Sep 2026. β Weekly Recap