The Signal
The day’s priority is immediate exploitation alongside high-consequence identity and research-security cases. Those concerns are distinct: exploit response, protection of identity data, and research-governance decisions call for different decisions, while AI-control and SOC stories remain operational context rather than substitutes for them. [1][2][3][4][5]
Must Know
Exploitation · The Hacker News
What happened
VulnCheck reports active exploitation attempts against a critical Rejetto HTTP File Server (HFS) flaw, CVE-2026-61500, rated CVSS 9.3. [1]
The flaw involves session forgery caused by a weak pseudo-random number generator that can produce a predictable key for unauthorized access. [1]
Why it matters
Active exploitation moves this from a theoretical flaw to a concrete exposure-management priority for organizations running the affected software. [1]
Identity · Securityaffairs
What happened
Hackers accessed names, addresses and CPR numbers in Denmark’s national population register through a third-party company with legal registry access. [2]
The registry covers 8.8 million people and contains around 11 million records, including people who have died or moved abroad. [2]
Why it matters
Because CPR numbers support banking, healthcare and tax services, combining them with names and addresses could create a serious identity-fraud risk. [2]
Vulnerability · The Hacker News
What happened
Threat actors have been observed attempting to exploit a now-patched critical security flaw affecting the Realtek Jungle software development kit to deploy the Cling botnet malware. [6]
Nozomi Networks said Cling repurposes ordinary STUN behavior as a practical command-and-control channel rather than introducing a new propagation technique. [6]
Why it matters
This account distinguishes initial access from later operator communications, a useful boundary when assessing the reported activity. [6]
Research · Securityaffairs
What happened
MI5 warned UK universities that more than 100 UK-linked academics contributed to research funded through CGTRI, an institute MI5 assessed as having very strong ties to China’s Ministry of State Security; some academics may not have known CGTRI was involved. [3]
The alert identified research areas including artificial intelligence, cybersecurity, covert communications systems and steganography. [3]
Why it matters
MI5 said continuing work on CGTRI-funded projects could create legal risk under National Security Act 2023 provisions concerning assistance to a foreign intelligence service and obtaining material benefit from one. [3]
Identity · Securityaffairs
What happened
Montenegro approved extraditing dual Turkish-Iranian citizen Amir Barati to the United States after his arrest in Kotor on an FBI warrant; he faces charges including conspiracy, computer fraud, hacking and identity theft. [7]
US prosecutors allege Barati was directly involved in an Iranian Mabna Institute operation targeting universities and research institutions between 2013 and 2017. [7]
Why it matters
US officials estimate the alleged damage at $3.4 billion, while affected universities reportedly spent about $20 million investigating and repairing the attacks. [7]
Also Worth Knowing
AI & Agents · The Hacker News
What happened
Apple announced steps to tighten controls around macOS Full Disk Access because of security risks posed by artificial intelligence agents. [4]
The issue is a permission boundary, not an assertion that every agent use is harmful. [4]
AI & Agents · Helpnetsecurity
What happened
Stellar Cyber announced Stellar Cyber 7.0 as a release intended to advance its Human-Augmented Autonomous SOC concept into a practical operating model for security operations. [5]
Cloud · Helpnetsecurity
What happened
Keyorix is an open-source secrets manager that runs entirely on a company’s own servers. [8]