Skip to content
feed: live
>_0dayNews
$ briefings

Briefings

Periodic SITREPs that compress the week's vulnerability and exploit news into a single readable digest, sourced throughout.

40
editions
230
items covered
37
critical flags
~/briefings/2026-09-29 --latest
Latest edition·September 29, 2026

Sep 29: Citrix KEV Deadline, PeopleSoft Live Campaign

CISA's Citrix patch deadline is September 30. ShinyHunters is running a live Oracle PeopleSoft exploit campaign. Plus: JADEPUFFER on Azure, and a $387M crypto heist closed out.

1h3m
KEV
  • CISA added CVE-2026-88771 and CVE-2026-88772 to the KEV catalog with a federal patch deadline of September 30. Both allow unauthenticated RCE against NetScaler ADC and Gateway.
  • ShinyHunters retooled its CVE-2026-35273 exploit and launched a broader campaign against Oracle PeopleSoft, per a Google Threat Intelligence advisory published September 28.
  • JADEPUFFER-linked operators are using compromised Azure service principals with excessive permissions to delete cloud resources across targeted tenants.
  • Obot AI platform patched three CVEs including an unauthenticated Docker socket exposure. Bitget resumed withdrawals after a $387.5M DPRK-linked theft.
Read full briefing →
$ archive

September 2026

August 2026

July 2026

June 2026

Archive begins June 29, 2026.