
October 6, 2026
Security Roundup, October 6: NetScaler Denial of Service and Dell System Update Flaw
Daily security roundup: NetScaler denial-of-service flaw under active attack, Dell System Update root exploit, and ransomware hits at healthcare and education.

October 6, 2026
Apple patches actively exploited zero-day in Core Graphics (CVE-2026-86950)
Apple ships iOS 26.7.1, iPadOS 26.7.1, and macOS fixes for an out-of-bounds write flaw in Core Graphics that was exploited in targeted attacks.

October 6, 2026
Citrix NetScaler zero-day exploited to deploy web shells and tunneling malware
Attackers exploited a Citrix NetScaler memory overflow flaw to install web shells, steal credentials, and pivot into internal networks.

October 6, 2026
Apple Zero-Day CVE-2026-86950 Exploited in Targeted Attacks
Apple patches a CoreGraphics zero-day weaponized against specific individuals. Learn which iPhones and iPads are affected and how to respond.

October 6, 2026
NetScaler ADC Flaw (CVE-2026-88772) Exploited for Root Access, WHIPSHOT and SLAPSHOT Deployed
Attackers exploit a Citrix NetScaler memory overflow flaw to gain root access and deploy WHIPSHOT web shells and SLAPSHOT tunnels across dozens of

October 6, 2026
CISA Adds Apple Out-of-Bounds Write Vulnerability to KEV Catalog
CISA added one Apple vulnerability, CVE-2026-86950, to the Known Exploited Vulnerabilities Catalog on September 29, 2026.

October 6, 2026
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
A vulnerability in the official MCP Python SDK lets a malicious server steal OAuth credentials. Fixed in versions 1.30.0 and 2.2.0.

October 6, 2026
Three open-source AI agents were used to steal 600,000 credit cards from 27 companies
Security firm Gambit says an attacker chained Strix, Cairn, and Hermes AI agents to skim 600,000 cards from at least 27 companies for roughly $25 a target.

October 6, 2026
Dutch cybersecurity nonprofit DIVD breached by an autonomous AI agent
DIVD says a fully autonomous AI agent carried out a post-exploitation intrusion on its network, the first publicly described agentic AI-driven attack of its
