Daily digest,
ZITADEL Identity Provider Vulnerabilities Expose Critical… (+7 more)
Vulnerabilities
ZITADEL Identity Provider Vulnerabilities Expose Critical Authentication Flaws
Between October 2 and October 5, 2026, a cluster of vulnerabilities affecting the ZITADEL identity provider was disclosed, revealing 15 CVEs, including critical flaws that allow unauthenticated account takeover and bypass of multi-factor authentication (MFA). The most severe vulnerabilities include CVE-2026-105209 (CVSS 9.6), enabling cross-organization passkey enrollment, and CVE-2026-105215 (CVSS 9.1), allowing unauthenticated account pre-hijacking. These vulnerabilities stem from a failure to verify the binding between credentials and claimed identities, exposing systems that rely on ZITADEL for authentication. The 3.x version line reached end-of-life on August 31, 2026, leaving deployments vulnerable. Active exploitation of these vulnerabilities is under investigation, with some reports indicating potential exploitation in the wild. Organizations using ZITADEL for user authentication are urged to assess their deployments and apply patches immediately.
Vulnerability · 2 sources · score 70 · CVE-2026-105206, CVE-2026-105207, CVE-2026-105208, CVE-2026-105209, CVE-2026-105210
Breaches
Data Access Governance Gaps Expose Organizations to Cloud Security Risks
Over 90% of enterprises now run workloads in the cloud, but many lack effective Data Access Governance (DAG) to manage sensitive data access. A recent report indicates that 80% of organizations experienced at least one cloud security incident in the past year, primarily due to governance gaps rather than infrastructure failures. Discovery tools help locate data but do not manage who can access it or how permissions change over time. The Cloud Security Alliance identifies insecure identities and excessive permissions as top risks in cloud security. Regulatory compliance, including GDPR and HIPAA, now requires organizations to demonstrate continuous access governance. Additionally, the rise of generative AI tools introduces further risks as these systems operate with inherited permissions, increasing exposure to sensitive data. Continuous monitoring and enforcement of least-privilege access are essential to mitigate these risks.
Vulnerability · 2 sources · score 55
IQVIA Fined €7 Million for Data Anonymization Failures
Italy's Data Protection Authority has fined IQVIA €7 million ($7.8 million) for inadequate health data anonymization practices that jeopardized the privacy of approximately one million patients. The investigation, initiated in April 2025, revealed that IQVIA had created a database aggregating sensitive health information from 800 general practitioners without proper anonymization, allowing for potential re-identification of individuals. The data included detailed health records, such as diagnoses and prescriptions, and some records contained identifiable information for over 3,300 patients. The company failed to establish legal grounds for processing the data and did not inform patients, violating GDPR regulations. IQVIA has 120 days to comply with the Authority's requirements or face further penalties. The fine reflects the serious nature of the breach and the number of patients affected.
Breach · 3 sources · score 52
Accenture Contractor Removed from FBI After Data Breach Exposes Sensitive Employee Information
On October 5, 2026, the FBI removed an Accenture contractor due to their role in a data breach that exposed sensitive personal details of thousands of bureau employees. The breach was attributed to a failure to apply a security patch for Oracle's PeopleSoft platform, which was exploited by the hacking group ShinyHunters. The FBI's cyber chief, Brett Leatherman, confirmed that the breach resulted from a security failure linked to a third-party organization, identified as Accenture. The exposed data includes sensitive information such as job descriptions, addresses, and medical records of FBI personnel. The breach has raised significant concerns regarding operational security within the FBI and the intelligence community. Accenture has stated its commitment to supporting the FBI but did not address inquiries about the contractor's failure to patch the system. The incident highlights the importance of timely patching in defending against cyber threats.
APT · 2 sources · score 52 · ShinyHunters
Threat actors and malware
2CLoader Malware Loader Distributes Vidar and Remus Infostealers
Zscaler ThreatLabz has identified a new malware loader named 2CLoader, which is used to deliver infostealers Vidar and Remus, as well as XWorm RAT. The loader employs advanced evasion techniques to bypass security measures, including indirect system calls and anti-debugging checks. Organizations are advised to enhance their endpoint security to detect these evasive tactics. Specific indicators of compromise (IOCs) include connections to the domain aware-cr1[.]com. The threat is significant due to its modular nature and ability to adapt to various environments. Security teams should monitor for suspicious scheduled tasks and registry changes associated with 2CLoader. If detected, isolating affected hosts and conducting memory forensic analysis is recommended. The current status indicates ongoing risks as the loader remains active in the wild.
Malware · 2 sources · score 68 · 2CLoader, Remus, Vidar, XWorm, XWorm RAT
ScreenConnect Client Exploited for Unauthorized Remote Access via Phishing
Attackers are leveraging phishing emails to distribute a modified ScreenConnect client, enabling unauthorized remote access to compromised systems. The campaign utilizes a legitimate, digitally signed PE file that has been reconfigured to connect to an attacker-controlled instance. This method exploits the trusted nature of the software to bypass basic security measures. Organizations are advised to monitor for unauthorized use of Remote Monitoring and Management (RMM) tools and enforce strict controls on executable downloads from untrusted sources. The threat actor's approach includes using a custom User-Agent string to evade detection. Immediate isolation of affected endpoints is recommended upon detection of malicious activity. The articles indicate that this campaign is ongoing and poses a significant risk to organizations that utilize RMM tools.
Phishing · 2 sources · score 63
Stealthy Linux Backdoors Target Telecoms in South Korea and Taiwan
Rapid7 has reported new Linux backdoors, specifically BPFDoor and AVERAT, targeting telecom and network-edge appliances in South Korea and Taiwan. These backdoors disguise their malicious traffic as legitimate email using SMTP on TCP port 25, making detection difficult on mail security gateways. The malware can perform various actions, including file transfers and establishing multiple shell sessions. AVERAT connects to hardcoded addresses on compromised devices, which include Synology NAS and Dahua video recorders, potentially forming operational relay box networks. The attack leverages process spoofing by mimicking legitimate software like SpamSniper. Rapid7 recommends investigating unusual outbound connections and restricting access to affected devices. Attribution to state-sponsored actors is ongoing, with no confirmed overlap with known networks.
Malware · 3 sources · score 59 · BPFDoor, BPF Rekoobe, SpamSniper
Phishing Domains Target Key Pakistani Government Agencies
The National Cyber Security Emergency Response Team (NCERT) has identified multiple phishing domains impersonating major Pakistani government institutions, including NADRA, FBR, and PTA. These domains were detected on October 4, 2026, and are designed to deceive citizens into providing sensitive information. The phishing sites mimic official login pages, increasing the risk of credential theft. NCERT has warned that these domains remain active and are being monitored. Citizens are advised to exercise caution when accessing links from unverified sources and to verify the authenticity of websites before entering personal information. Additionally, NCERT has issued guidance on the safe use of Generative AI tools due to associated cybersecurity risks. The agency continues to track these phishing activities and has recommended that organizations implement strict policies regarding the use of AI platforms.
Phishing · 2 sources · score 56
New on leak sites
51 victims listed on ransomware leak sites by 18 groups in the 24 hours before this issue. The most active:
Also moving
- Ransomware groups: KillSec, Black Basta, BlackSuit, Crytox
- Malware: 2CLoader, Anubis, BlockBlasters, BPFDoor, BPF Rekoobe
- Campaigns: AI Swarm Dynamics Hackathon, Cbest
- Vulnerabilities: Buffer overflow, BYOVD
- APT groups: Candiru
- CVEs: CVE-2014-0160, CVE-2014-8361, CVE-2016-10372, CVE-2016-20016, CVE-2021-21551
Get the next one by email
The digest is free and arrives every morning. One click to leave.
A free account turns the digest into a personal watchlist: choose what you want to follow.