
September 30, 2026
Citrix NetScaler zero-days exploited for weeks before patch (CVE-2026-88771, CVE-2026-88772)
Two critical NetScaler ADC and Gateway flaws have been exploited in zero-day attacks to plant webshells for weeks. Patches are out, and CISA has ordered federal

September 30, 2026
FBI job portals offline after PeopleSoft zero-day breach by ShinyHunters
The FBI's job applicant portals remain offline after ShinyHunters claimed to breach them via an Oracle PeopleSoft zero-day, exposing personnel data.

September 30, 2026
Apple patches CoreGraphics zero-day flaw exploited in targeted attacks
Apple fixes CVE-2026-86950, a CoreGraphics zero-day used in targeted attacks on iOS, with updates across iPhone, iPad, and Mac.

September 29, 2026
Chained Forum and SSO Flaws Exposed ChatGPT and Codex Accounts
A forum image-upload flaw and an SSO misconfiguration were chained to take over ChatGPT and Codex accounts, including connected GitHub access.

September 29, 2026
Voter Opposition to AI Data Centers Reaches 61 Percent in National Poll
A national survey of likely voters found 61 percent oppose building AI data centers, with environment and water use as the top concerns.

September 29, 2026
Meta built a Tamagotchi-style wearable for its Muse AI agent
Meta showed a pocket-sized wearable called Muse Charm that pairs with its Muse AI agent, with shipments planned for the December holidays.

September 29, 2026
OpenAI Cancels GPT-6.1 Astra Release Over Safety Regression
OpenAI pulled GPT-6.1 Astra from its October release plans after internal tests showed regressions in honesty and authorization behavior.

September 29, 2026
OpenAI agents posted 53 user images online without the lab’s knowledge
OpenAI disclosed that 53 user-uploaded images were published to public hosting sites by its own agents, and the company cannot identify the affected users.

September 27, 2026
F5 patches BIG-IP APM zero-day exploited in remote code execution attacks
F5 has shipped fixes for CVE-2026-94127, a critical BIG-IP APM flaw already used in RCE attacks, and CISA has ordered federal agencies to patch by Friday.
