
October 2, 2026
Security Roundup, October 1: Cisco SD-WAN Zero-Day and Bitget Theft
Cisco patches a critical SD-WAN flaw already under attack, Bitget confirms a $387.5M theft, and Google reports AI finds the flaws attackers want.

October 2, 2026
Security Roundup, September 30: Citrix NetScaler Exploit and Unsloth Studio Flaw
September 30 security roundup: Citrix NetScaler pre-auth exploit, Unsloth Studio code execution flaw, Spectre v2 BTR leaks, and more.

September 30, 2026
CISA orders federal agencies to patch exploited Citrix NetScaler flaws by September 30
CISA has added two actively exploited Citrix NetScaler flaws to its KEV catalog and ordered U.S. federal agencies to secure appliances by September 30.

September 30, 2026
Weekly Recap: $387M Crypto Hack, Citrix NetScaler Exploits, and AI Agents Bypassing Websites
A $387M Bitget crypto heist, actively exploited Citrix NetScaler flaws, an AI agent bypassing a health site, and a placeholder domain weaponized across 1,700

September 30, 2026
Citrix NetScaler Zero-Days Exploited: What the U.S., U.K. and Dutch Warnings Cover
Two Citrix NetScaler zero-days (CVE-2026-88771 and CVE-2026-88772) are under active exploitation. CISA has set a federal patch deadline of Wednesday.

September 30, 2026
A four-week plan to tackle vendor concentration risk
A four-step mapping exercise reveals how 30 vendors can hide five choke points, with a four-week plan teams can start on Monday.

September 30, 2026
CISA Adds Two Citrix NetScaler Zero-Day Flaws to KEV Catalog
CISA confirmed active exploitation of two critical Citrix NetScaler zero-day flaws and added them to the KEV Catalog, alongside six additional vulnerabilities.

September 30, 2026
Citrix confirms two NetScaler RCE zero-days, patches released
Citrix confirms two critical NetScaler RCE flaws are under attack and has shipped patches. Here is what is affected and what to do next.

September 30, 2026
Agent Memory Holds API Keys in Plain Text: The Audit CISOs Need Now
Coding agents are storing API keys, credentials, and sensitive documents in plain-text memory. A new audit reveals how attackers exploit this exposure.
