View all sources for this day →

The Signal

The day’s priority is immediate exploitation alongside high-consequence identity and research-security cases. Those concerns are distinct: exploit response, protection of identity data, and research-governance decisions call for different decisions, while AI-control and SOC stories remain operational context rather than substitutes for them. [1][2][3][4][5]

Must Know

Exploitation · The Hacker News

Exploitation · Vulnerability

What happened

VulnCheck reports active exploitation attempts against a critical Rejetto HTTP File Server (HFS) flaw, CVE-2026-61500, rated CVSS 9.3. [1]

The flaw involves session forgery caused by a weak pseudo-random number generator that can produce a predictable key for unauthorized access. [1]

Why it matters

Active exploitation moves this from a theoretical flaw to a concrete exposure-management priority for organizations running the affected software. [1]

Identity · Securityaffairs

Identity · Incident

What happened

Hackers accessed names, addresses and CPR numbers in Denmark’s national population register through a third-party company with legal registry access. [2]

The registry covers 8.8 million people and contains around 11 million records, including people who have died or moved abroad. [2]

Why it matters

Because CPR numbers support banking, healthcare and tax services, combining them with names and addresses could create a serious identity-fraud risk. [2]

Vulnerability · The Hacker News

Exploitation · Vulnerability

What happened

Threat actors have been observed attempting to exploit a now-patched critical security flaw affecting the Realtek Jungle software development kit to deploy the Cling botnet malware. [6]

Nozomi Networks said Cling repurposes ordinary STUN behavior as a practical command-and-control channel rather than introducing a new propagation technique. [6]

Why it matters

This account distinguishes initial access from later operator communications, a useful boundary when assessing the reported activity. [6]

Research · Securityaffairs

Research · Policy

What happened

MI5 warned UK universities that more than 100 UK-linked academics contributed to research funded through CGTRI, an institute MI5 assessed as having very strong ties to China’s Ministry of State Security; some academics may not have known CGTRI was involved. [3]

The alert identified research areas including artificial intelligence, cybersecurity, covert communications systems and steganography. [3]

Why it matters

MI5 said continuing work on CGTRI-funded projects could create legal risk under National Security Act 2023 provisions concerning assistance to a foreign intelligence service and obtaining material benefit from one. [3]

Identity · Securityaffairs

Identity · Incident

What happened

Montenegro approved extraditing dual Turkish-Iranian citizen Amir Barati to the United States after his arrest in Kotor on an FBI warrant; he faces charges including conspiracy, computer fraud, hacking and identity theft. [7]

US prosecutors allege Barati was directly involved in an Iranian Mabna Institute operation targeting universities and research institutions between 2013 and 2017. [7]

Why it matters

US officials estimate the alleged damage at $3.4 billion, while affected universities reportedly spent about $20 million investigating and repairing the attacks. [7]

Also Worth Knowing

AI & Agents · The Hacker News

AI & Agents · Security

What happened

Apple announced steps to tighten controls around macOS Full Disk Access because of security risks posed by artificial intelligence agents. [4]

The issue is a permission boundary, not an assertion that every agent use is harmful. [4]

AI & Agents · Helpnetsecurity

AI & Agents · Security

What happened

Stellar Cyber announced Stellar Cyber 7.0 as a release intended to advance its Human-Augmented Autonomous SOC concept into a practical operating model for security operations. [5]

Cloud · Helpnetsecurity

Cloud · Identity

What happened

Keyorix is an open-source secrets manager that runs entirely on a company’s own servers. [8]

Sources (8)
  1. [1] Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

    the hacker news · October 5, 2026

  2. [2] Denmark ’s Population Registry Breached, 8.8 Million Affected

    securityaffairs · October 5, 2026

  3. [3] MI5 Raises Alarm Over Chinese Funding of UK Academic Research

    securityaffairs · October 5, 2026

  4. [4] Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access

    the hacker news · October 5, 2026

  5. [5] Stellar Cyber 7.0 adds measurable workflows for AI-powered SOCs

    helpnetsecurity · October 5, 2026

  6. [6] Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

    the hacker news · October 5, 2026

  7. [7] Iranian hacker accused of draining 31TB from university inboxes extradited to the US

    securityaffairs · October 5, 2026

  8. [8] Keyorix: Open-source secrets management for teams that can’t use SaaS

    helpnetsecurity · October 5, 2026