Sam's News — security — 2026-10-05¶
Security¶
8.5 Denmark's CPR Database Breach Exposes 8.8 Million Citizens' Personal Data¶
Denmark's Central Person Register (CPR) suffered a major breach on October 5 exposing personal data of approximately 8.8 million people—roughly 80% of the 11 million records. Attackers exploited a domestic company's legitimate access credentials to conduct large-scale automated searches identifying valid CPR numbers, compromising names, addresses, and 10-digit identifiers used for healthcare, banking, and government services.
- 8.8 million people affected (~80% of 11M total CPR records)
- Breach occurred in September; detected October 3
- Data exposed: names, addresses, CPR numbers (10-digit identifiers like SSN)
- Attackers exploited legitimate access credentials of Danish company
- Large-scale automated searches to identify valid CPR numbers
- Most significant CPR breach since 2015 (5M+ records on unencrypted CDs)
- Extended security hotline: 8am-midnight
- No suspects identified as of October 5
Sources: The Record AI Web Searched, CyberSecurityNews RSS, Hacker News (front page) RSS
8 Citrix NetScaler Zero-Day Exploited in Targeted SAML Attacks¶
Citrix released patches for CVE-2026-88779, a high-severity memory overflow vulnerability (CVSS 8.7) in NetScaler ADC and NetScaler Gateway being actively exploited in targeted zero-day attacks. Exploitation requires SAML service provider or identity provider configuration and can cause denial-of-service; CISA ordered federal agencies to patch by October 7.
- CVE-2026-88779: memory overflow vulnerability, CVSS score 8.7/10
- Active exploitation in targeted zero-day attacks (discovered by Bishop Fox, watchTowr)
- Requires SAML SP or IdP configuration to exploit
- Affected versions: 14.1 prior to 14.1-73.41; 13.1 prior to 13.1-64.28
- Patches released; CISA deadline for federal agencies: October 7, 2026
- No customer data integrity impact identified; DoS risk under specific conditions
Sources: The Hacker News AI Web Searched, SecurityWeek RSS, BleepingComputer RSS
7.5 Rejetto HFS Vulnerability Exploited in the Wild¶
CVE-2026-61500 is a critical vulnerability (CVSS 9.3) in Rejetto HTTP File Server stemming from weak random number generation using xorshift128+, which is mathematically reversible. Attackers can reconstruct the generator's state, forge administrator session cookies, and achieve remote code execution. Horizon3.ai researchers used Anthropic's Mythos AI model to discover the flaw; Rejetto patched in July 2026, but active exploitation from China Telecom IPs began by October 2.
- CVE-2026-61500: critical vulnerability, CVSS 9.3, affects all versions before 3.2.1
- Weak RNG (xorshift128+) outputs mathematically reversible by attackers
- Enables session cookie forgery and remote code execution via server_code
- Discovered June 2026 using Anthropic's Mythos AI for mathematical analysis
- Rejetto released patch version 3.2.1 on July 13, 2026
- Active exploitation in wild as of October 2, 2026 from China Telecom IPs
- Targeting canaries in Japan and US
Sources: SecurityWeek AI Web Searched, The Hacker News RSS
7.5 Senate Passes Bipartisan Healthcare Cybersecurity Bill¶
The Senate passed a bipartisan bill to strengthen cybersecurity in healthcare, responding to over 730 breaches affecting 270 million Americans in the prior year.
Sources: SecurityWeek RSS
7 Cybersecurity Newsletter: Pentagon Breach, Citrix, FortiMail, Apple Zero-Days¶
A cybersecurity bulletin covers a Pentagon data breach alongside zero-day vulnerabilities in Citrix, FortiMail, and Apple products.
Sources: CyberSecurityNews RSS
7 Cyber attack on police force potentially compromises staff information¶
A cyberattack targeting a police force may have resulted in unauthorized access to personnel records.
Sources: BBC Web Search
6.5 Healthcare Data Breaches Affect 250,000 Patients in New Jersey and Texas¶
Hackers stole patient information from Clover Health Investments and AngMar Management Services in July, impacting 250,000 individuals.
Sources: SecurityWeek RSS
6.5 Apple Tightens macOS Full Disk Access Controls to Mitigate AI Agent Risks¶
Apple is restricting Full Disk Access permissions in macOS to limit data exposure risks posed by AI agents and potentially malicious applications.
Sources: The Hacker News RSS
6 Alleged ShinyHunters leader arrested in Jordan, assisting FBI investigation¶
The suspected leader of the ShinyHunters extortion group, known as Rey, has been arrested in Jordan and is reportedly assisting the FBI to identify other members.
Sources: SecurityWeek RSS Update to: ShinyHunters suspect Rey detained in Jordan, cooperating with FBI
Monetization¶
5.5 OpenAI Tests Visual Ad Format in ChatGPT During Image Generation¶
OpenAI is piloting visual advertisements displayed to users while they generate images in ChatGPT.
Sources: Search Engine Roundtable RSS, BleepingComputer RSS, Unite.AI RSS, Digiday RSS