
October 5, 2026
Security Roundup, October 5: NetScaler SAML Zero-Day and Rejetto HFS Flaw Under Active Attack
A Citrix NetScaler SAML zero-day is knocking patched appliances offline, a Rejetto HFS flaw enables remote code execution, and CISA adds a new KEV entry.

October 5, 2026
Security Roundup, October 4: SharePoint Ransomware Flaw and Fortra BoKS Bugs
Daily security roundup: SharePoint flaws used to deploy ransomware, critical Fortra BoKS patches, a Danish university breach, and AI-driven phishing.

October 5, 2026
Security Roundup, October 3: Citrix NetScaler Zero-Days and GitLab AI Gateway RCE
Daily security roundup for October 3, 2026: Citrix NetScaler zero-days under active attack, a critical GitLab AI Gateway RCE, Dell CSM flaws, and more.

October 4, 2026
AI Agents Sent SQL Injection Probes to US and Canadian Government Sites
Researchers found AI agents probed US Department of Education and Library and Archives Canada sites with SQL injection and other attacks while retrieving public

October 4, 2026
The Day-One Gap in Zero Trust: Why Identity Verification Has to Start Before the First Login
Strong MFA and Zero Trust controls leave a window open during onboarding. Here is why Day One identity verification closes the gap before credentials are

October 3, 2026
Exabeam extends AI-assisted security investigations to on-premises data
Exabeam adds agentic SOC capabilities across cloud and on-premises SIEM, including Nova AI triage, AI CLI plugins, and AI activity monitoring.

October 3, 2026
Security Startup Finds 13,000+ Internal Screenshots Leaked to Public GitHub Repos by AI Agents
Glow Security found more than 13,000 internal screenshots from 343 organizations on public GitHub repos, uploaded by AI coding agents using a workaround for

October 2, 2026
AI Agents Keep Access to Company Data After Their Work Is Done
A Delinea 2026 report finds that most organizations lack real-time enforcement of AI agent access, with credentials often remaining active after tasks end.

October 2, 2026
Security Roundup, October 2: FortiMail Zero-Day and Kiteworks Code Injection Flaw
Two max-severity email and file-sharing flaws demand urgent action this week, alongside AI-agent probes against government sites and a new PwC threat survey.
