Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Oct 5, 2026·4m

Cyber Security News for October 5 2026 - Daily DefSec Brief

Show notes

1. NetScaler SAML flaw exploited after last fix — CVE-2026-88779 — Fixed: 14.1-73.41 or 13.1-64.28 — federal due 2026-10-07 — Do: Update NetScaler again if it uses SAML — https://support.citrix.com/external/article/CTX697174/citrix-netscaler-adc-and-citrix-netscale.html

2. AI-found Rejetto HFS flaw now exploited — CVE-2026-61500 — Fixed: 3.2.1 — Do: Upgrade Rejetto HFS or take it offline — https://www.cve.org/CVERecord?id=CVE-2026-61500

3. Malicious VS Code themes on official Marketplace — Do: Allowlist the VS Code extensions developers use — https://socket.dev/blog/glassworm-vscode-themes

4. Vercel confirms KVM zero-day, guest escape claimed — Do: Watch for the KVM fix, plan host reboots — https://cybersecuritynews.com/kvm-zero-day-vm-escape/

5. Exchange update reissued for mailbox flaw — CVE-2026-96940 — Do: Install Exchange's September V2 update — https://techcommunity.microsoft.com/blog/exchange/released-september-2026-v2-exchange-server-security-updates/4561718

6. Dell CSM flaws give storage admin, no login — CVE-2026-63688, CVE-2026-63692 — Fixed: 1.18.0 — Do: Upgrade Dell Container Storage Modules — https://www.dell.com/support/kbdoc/en-us/000515771/dsa-2026-448-security-update-for-dell-container-storage-modules-multiple-vulnerabilities

7. GitLab AI Gateway lets Duo users run commands — CVE-2026-90970 — Fixed: 19.2.4, 19.3.2 or 19.4.1 — Do: Upgrade your self-hosted GitLab AI Gateway — https://cyber.gc.ca/en/alerts-advisories/gitlab-security-advisory-av26-994

8. Debian kernel update fixes 1,313 CVEs at once — CVE-2024-52560, CVE-2025-21817, CVE-2026-23137 (+ 1,310 more) — Fixed: 6.12.111-1 — Do: Update Debian 13 kernels and reboot — https://www.debian.org/security/2026/dsa-6528

9. BoKS seeded AD service passwords with the clock — CVE-2026-79901 — Fixed: 9.0.0.7 — Do: Patch and restart BoKS, then rotate passwords — https://www.fortra.com/security/advisories/product-security/fi-2026-012