Microsoft’s X account breached and more - October 4, 2026

Featured

Microsoft's official X account was breached

The compromised account was used for cryptocurrency pump-and-dump

This Week’s Updates

Breaches

Japanese car-sharing service Times Car confirms roughly 6.6 million user accounts were compromised in a cyberattack

Japan's Keio Corporation confirms a ransomware attack disrupted some of its business systems

Bitget confirms attackers who stole $387.5 million breached its systems by exploiting a zero-day in third-party security products

The Dutch Institute for Vulnerability Disclosure confirms a chain of two Zammad zero-days enabled an AI-driven breach of its own network

MetaMask discloses an ongoing security incident affecting parts of its infrastructure

The Pentagon's Defense Manpower Data Center confirms hackers stole data on nearly 3 million military service members after breaching its HR system

Frontline Education confirms a data breach that stole school district employees' Social Security numbers after attackers exploited a third-party software flaw

The Technical University of Denmark confirms a breach exposed data belonging to up to 200,000 people after hackers accessed its identity and access management system

Vulnerabilities

Cloudflare fixes a Containers and Sandboxes flaw that let Workers Paid customers recover residual data from other customers' containers

Apple patches a CoreGraphics zero-day exploited in sophisticated targeted attacks on iOS devices

Cybersecurity firms confirm attackers exploited the Citrix NetScaler zero-day CVE-2026-88772 to deploy web shells and tunneling malware

TeamViewer urges customers to immediately patch a set of high-severity vulnerabilities in its client and host software

Cisco releases updates for a critical Catalyst SD-WAN Manager zero-day, CVE-2026-76504, actively exploited to gain admin privileges

CISA warns of a critical pre-auth remote code execution flaw in MikroTik RouterOS

Kiteworks patches 126 vulnerabilities, including a max-severity code injection flaw in its Email Protection Gateway

Fortinet warns of a critical FortiMail vulnerability, CVE-2026-104286, being actively exploited in zero-day attacks

Dell patches two maximum-severity Container Storage Modules flaws that gave hackers admin privileges

GitLab urges customers to immediately patch a critical remote code execution vulnerability in its AI Gateway service

Next
Next

BigCommerce breached and more - Sept 27, 2026