Today on CISO Series…
- Super Cyber Friday:”Hacking Vendor Selection”
- Join us LIVE on YouTube forDepartment of Know
In todays cybersecurity news…
Critical NetScaler vulnerability exploited in attacks
Cybersecurity and Infrastructure Security Agencyis warning that this CVE numbered vulnerability (CVE-2026-19490) which has a CVSS score of 9.3, has been exploited, following an alert posted last week byPrevidianfounder and former WatchTowr head of threat intelligenceRyan Dewhurst. The defect affects all NetScaler ADC and NetScaler Gateway appliances configured as a gateway or an AAA virtual server.Citrixpatched the flaw on August 19.
AdaptHealth data breach impacts 4.1 million people
Following up on a story we covered in July, it turns out the cyberattack on the medical equipment company has resulted in the theft of personal, health, and insurance information belonging to more than 4.1 million individuals. The company, which operates more than 680 facilities across the U.S., suffered the attack through a threat actor gaining access to its “cloud-based applications, including internal systems used for patient management and document storage.” Specifically, “the hacker used social engineering to compromise a user session at a third-party contractor.” The company emphasized that although contact information and health data and health insurance information were stolen, Social Security numbers and financial information were not affected.
MantaxOtax Android malware delivers ransomware and spyware together
A report published byZimperium’s zLabs team, published on Wednesday attributes this malware to Indonesian threat actors. MantaxOtax is an Android malware strain combining ransomware, spyware and device control. After gaining extensive permissions, it can steal messages, credentials, location, contacts, browser history, and screen recordings, while also taking photos and monitoring apps. On older Android versions, it can encrypt files and demand payment; newer versions limit its reach because of Android’s Scoped Storage. Attackers can remotely lock screens, block apps and disrupt devices with intrusive alerts and overlays. The malware appears linked to Indonesian threat actors and uses GitHub to locate changing command-and-control infrastructure.
Gigabud creates Android work profiles to hide from banking app malware checks
In more Android malware news, security firmGroup-IBsaid in a report also published on Wednesday, that the Gigabud banking trojan “now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it.” This hides the trojan from the banking app’s own malware checks. As a remote access trojan, Gigabud gives its operator live control of the phone. “It has been active since 2022 and links to a group it calls GoldFactory, which reaches phones as a fake app posing as a national airline, a tax office, or a government portal, installed from outside the official store.”
Big thanks to our sponsor,ThreatLocker
CISA boss says agency must change quickly to prevent the worst
Cybersecurity and Infrastructure Security Agencyacting director Nick Andersen warned, in an interview at the Billington CyberSecurity Summit in Washington, D.C., of the “significant and possibly devastating cybersecurity vulnerabilities Americans face, blaming past government mistakes, outdated tech and AI as threats.” He told those in attendance, “you all are going to have to go home and look to your family, look to your friends, and explain to them how you knew the worst that could happen and why we didn’t do enough.” Addressing the issue of staffing, Andersen pointed out that regional field workers are also a priority, in addition to hiring for its, cybersecurity division, infrastructure security division and emergency communications division.
Russia’s Wildberries suffers DDoS attack
The Russian e-commerce giant Wildberries is stating that a cyberattack has delayed payments to some sellers, as a result of security measures that were introduced after a DDoS attack targeted the systems used by sellers to track and withdraw their earnings. The company emphasizes that the funds remained safe, just not accessible right now. Wildberries did not offer details of the attacks or attribute them to a specific group, but earlier in August, Ukraine’s military intelligence had said it had “disrupted the company’s operations in a cyberattack carried out alongside a hacker group known as Cyber Corps.”
McKesson breach results in publication of patient data
Following up on a story we covered in August, it appears the cybercrime group ShinyHunters has indeed published sensitive patient data of 6.4 million individuals, following an attack on healthcare company McKesson, which supports 3,300 oncology providers in 29 states. The gang informedThe Registerthat they had “issued a $55.2 million extortion demand to prevent the release of McKesson’s data, a sum that apparently was not paid. In addition to health information, the leaked data includes PII, but no mention was made as to whether Social Security numbers were stolen.
ID verification giant IDScan confirms data breach
The Louisiana-based firm is “used by corporate customers ranging from entertainment venues to cannabis dispensaries to check and verify the identity documents of their customers.” Representatives from the company have confirmed that a data breach resulting from the year-long hack stole PII, driver’s license numbers, and other government-issued documents, such as passports belonging to 150 million people. The breach occurred in the company’s cloud. The breach was first announced byBrian Krebs. Among the files in the stolen data were those of Krebs himself, as well as those of Secretary of Defense Pete Hegseth.
Spotify,Apple Podcasts,YouTube,RSS link,Amazon Music, add as anAlexa Skill, or search “Cybersecurity Headlines” on your favorite podcast app.