Daily digest,
Bitget Suffers $388 Million Hack Linked to North Korean Hackers (+6 more)
Vulnerabilities
Critical NetScaler Vulnerabilities Exploited for Remote Code Execution
Threat actors are exploiting two critical vulnerabilities, CVE-2026-88771 and CVE-2026-88772, in Citrix NetScaler ADC and Gateway appliances, allowing unauthenticated remote code execution. CVE-2026-88771, identified as a pre-authentication RCE flaw, has been since at least September 21, 2026, while CVE-2026-88772, a memory overflow bug, was also weaponized in September 2026. Attackers are deploying PHP web shells and a Go-based command-and-control framework named Platypus to maintain persistence and facilitate further intrusions. The vulnerabilities affect critical sectors including government and finance, with over 50,000 exposed instances of NetScaler appliances globally. Patches have been released, but the rapid weaponization indicates a significant risk for organizations that have not yet updated their systems.
Vulnerability · 2 sources · score 73 · CVE-2026-19490, CVE-2026-88771, CVE-2026-88772, Platypus, Slapshot
Critical Memory Vulnerabilities in Mooncake Transfer Engine Disclosed
On October 1, 2026, multiple critical vulnerabilities were disclosed in the Mooncake transfer engine, particularly CVE-2026-103764 and CVE-2026-103761. CVE-2026-103764, with a CVSS score of 9.3, allows unauthenticated remote attackers to read and write arbitrary memory, potentially leading to code execution. CVE-2026-103761 presents a memory exhaustion vulnerability that can disrupt service by filling memory without limits. Both vulnerabilities affect versions prior to 0.3.13, with patches available for CVE-2026-103764. Attackers can exploit these vulnerabilities via the TCP transport data port and the handshake RPC port, respectively. The urgency of exploitation for CVE-2026-103761 remains uncertain due to the absence of public proof-of-concept or confirmed exploitation. Security professionals are advised to apply patches immediately and restrict network access to vulnerable ports.
Vulnerability · 2 sources · score 72 · CVE-2026-103761, CVE-2026-103764, CVE-2026-103765, CVE-2026-93698
CVE-2026-88789: High-Risk XML Vulnerability in Apache Camel Quarkus
CVE-2026-88789 is a vulnerability in the XSLT support extension of Apache Camel Quarkus, affecting versions from 3.2.0 to 3.40.0. This flaw allows attackers to read local files or access internal network locations by supplying a malicious XML document with external entity declarations. The vulnerability arises from the extension's use of an insecure Xalan-backed TransformerFactory that does not enforce external access restrictions. A proof-of-concept (PoC) for this vulnerability was published on 2026-10-01. The CVSS score for this vulnerability is 8.6, indicating high severity. As of now, active exploitation has not been confirmed, but the potential for exploitation is significant. Users are advised to upgrade to versions 3.33.3 or 3.40.0 or later to mitigate this risk.
Vulnerability · 2 sources · score 58 · CVE-2026-1340, CVE-2026-21643, CVE-2026-23760, CVE-2026-88789
Breaches
Bitget Suffers $388 Million Hack Linked to North Korean Hackers
Bitget, a cryptocurrency exchange, reported a cyberattack resulting in the theft of approximately $388 million. The attack is suspected to be linked to North Korean hackers, as indicated by CEO Gracy Chen. The breach involved unauthorized transfers from the exchange's hot wallets, which are used for active trading. Following the incident, Bitget froze around $1.1 million of the stolen funds and replenished its user protection fund to over $300 million using its own reserves. Chen noted that the recovery of stolen assets is expected to be limited, citing the challenges faced by exchanges in recovering funds after such hacks. The attack exploited vulnerabilities in two third-party security products, allowing attackers to gain privileged access without stealing private keys. Bitget has suspended crypto withdrawals while it investigates the breach. The incident marks the largest known crypto theft of 2026.
Breach · 2 sources · score 73
Microsoft X Account Compromised in Crypto Scam
On October 2, 2026, Microsoft confirmed that its official X account was hijacked by attackers promoting a cryptocurrency token themed around Clippy, the company's virtual assistant. The account, with over 13 million followers, followed and reposted messages from a now-suspended account impersonating Clippy. A second account continued to promote a $Clippy token, falsely claiming a liquidity pool paired with $MSFT stock. Microsoft quickly removed the unauthorized posts and stated it was investigating the breach. The company emphasized that it does not endorse any cryptocurrency or related tokens, and it plans to pursue legal action against the unauthorized use of its intellectual property. The method of account compromise remains unclear, with potential vectors including phishing, SIM swapping, or compromised third-party tools. This incident follows a similar attack on Microsoft's India account in June 2024.
Breach · 4 sources · score 52
$305K Stolen from Ethereum Safe Wallets via Aave V3 Exploit
An attacker exploited a vulnerability in the FlashLoopAdapter of Aave V3's Loop Safe Module, resulting in the theft of approximately $305,000 from two Ethereum Safe wallets. The attacker used a fake Safe contract to bypass access controls, repaid Aave debt with a Morpho flash loan, and withdrew collateral, retaining around 114.09 ETH. The exploit specifically targeted the open() and close() functions of the FlashLoopAdapter, allowing unauthorized access and execution. Despite the breach, Aave's core protocol remained unaffected, and no recovery actions have been reported. AAVE's token price has shown resilience, trading positively despite the incident. The incident underscores the risks associated with third-party modules in DeFi protocols, highlighting the need for improved access controls.
Breach · 3 sources · score 52
Threat actors and malware
Milk Dragon Phishing Kit Targets Social Media Discounts to Steal Payment Data
The Milk Dragon phishing kit, also known as NaiLong, is a phishing-as-a-service operation exploiting social media platforms like Facebook and TikTok to lure victims with fake discounts. Group-IB identified 258 phishing pages linked to this kit since October 2025, affecting victims across 66 countries. The kit utilizes Adversary-in-the-Middle (AiTM) techniques to bypass multi-factor authentication (MFA) protections, employing 36 distinct banking templates. Threat actors promote heavily discounted products through native social media posts, driving traffic to fraudulent websites. The Milk Dragon kit has been actively sold on Telegram, with ongoing support provided to affiliates. Major brands, including LEGO and Calvin Klein, have been impersonated to deceive users. The operation has raised significant concerns among cybersecurity analysts and law enforcement agencies.
Phishing · 3 sources · score 68 · Milk Dragon
New on leak sites
30 victims listed on ransomware leak sites by 13 groups in the 24 hours before this issue. The most active:
Also moving
- CVEs: CVE-2026-1340, CVE-2026-21643, CVE-2026-23760, CVE-2015-7316, CVE-2025-39964
- Malware: Blik, Botany, Chain-24
- Vulnerabilities: Citrix NetScaler
Get the next one by email
The digest is free and arrives every morning. One click to leave.
A free account turns the digest into a personal watchlist: choose what you want to follow.