9 Oct 2026

Week in review

Greetings,

Online fashion retailer ASOS has confirmed that customer information may have been accessed following a cyber incident that saw hackers send unauthorised messages through the company's official mobile app. The retailer said names and contact details may have been exposed, while payment card information and account passwords were not affected.

The incident came to light after customers received push notifications from the ASOS app containing messages from threat actors claiming responsibility for the attack. ASOS is investigating the incident and working with cybersecurity specialists to secure its systems.

Attackers have claimed they stole customer data, although the full scope of the incident remains under investigation and these claims have not been confirmed by the company.

The incident highlights the risks associated with third-party communication platforms and trusted customer channels. Even when financial data is not compromised, exposed personal information can be leveraged in phishing and social engineering attacks.


Citrix discloses third actively exploited NetScaler zero-day in less than a week
Date: 2026-10-05
Author: CyberScoop

[See AUSCERT Bulletin https://portal.auscert.org.au/bulletins/ESB-2026.12056/]
Citrix customers just got through back-to-back weekends filled with varying levels of uncertainty and worry, as yet another actively exploited zero-day vulnerability was discovered in Citrix NetScaler products.
Researchers and security experts said the vulnerability — CVE-2026-88779 — is less concerning because exploitation triggers denial of service and only impacts instances that have SAML (security assertion markup language) enabled.
“This means it doesn’t work out of the box against every NetScaler deployment,” Jake Knott, head of threat intelligence at watchTowr, told CyberScoop. “While this is very inconvenient, it doesn’t have organizations scrambling to trigger incident response.”

Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
Date: 2026-10-05
Author: The Hacker News

Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions.
The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system.
"Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network," Microsoft said in an advisory released on October 2, 2026.

ASOS confirms data breach after “HACKED” in-app notifications
Date: 2026-10-06
Author: Bleeping Computer

UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment.
ASOS is a large UK-based online fashion retailer that sells clothing, footwear, accessories, and beauty products to customers worldwide, including in the United States.

Chrome 155 Update Patches 247 Vulnerabilities
Date: 2026-10-07
Author: Security Week

[See AUSCERT Bulletin https://portal.auscert.org.au/bulletins/ESB-2026.12256]
Four critical-severity use-after-free defects were fixed in Chromecast, Browser, Navigation, and Track.
Google on Tuesday rolled out a Chrome 155 security update that addresses 247 vulnerabilities, including four critical-severity flaws.
All four critical bugs are use-after-free issues. They impact Chrome’s Chromecast, Browser, Navigation, and Track components and are tracked as CVE-2026-106382, CVE-2026-106197, CVE-2026-106358, and CVE-2026-106347.

Hackers exploit critical Atlassian flaw after public PoC release
Date: 2026-10-07
Author: Bleeping Computer

[See AUSCERT Bulletin https://portal.auscert.org.au/bulletins/ESB-2026.12187]
A critical vulnerability (CVE-2026-21589) affecting multiple Atlassian product families, including Jira, Confluence, and Bitbucket, is being exploited in attacks that do not require authentication.
Earlier today, security company Previdian detected the activity on its honeypot network, just hours after a detailed technical report was published.
An unauthenticated attacker can exploit CVE-2026-21589 to access specific files in the application's web root directory if they know the file's exact name and path.


ESB-2026.12162 – GitLab AI Gateway: CVSS (Max): 9.9

Updated versions of GitLab Self-Hosted AI Gateway, that contain a critical security fix, have been released. Gitlab strongly recommends that all GitLab Self-Managed customers with GitLab Self-Hosted AI Gateway installations update to one of these versions immediately.

ESB-2026.12056 – Citrix NetScaler ADC & Citrix NetScaler Gateway: CVSS (Max): 7.5

Software updates have been released to address a vulnerability in Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway).

ESB-2026.12246 – Hitachi Energy SOI: CVSS (Max): 8.8

Hitachi Energy is aware of a RCE (Remote Code Execution) vulnerability in the Apache ActiveMQ component of SOI product versions. Users are advised to apply the patch SOI EP2, which upgrades the ActiveMQ version (JMS message broker) for the SOI Core.

ESB-2026.12323 – Splunk Enterprise: CVSS (Max): 9.8

Splunk have provided upgrades that address multiple vulnerabilities in Splunk Enterprise.

ESB-2026.12333 – Cisco License (Smart Software Manager) On-Prem: CVSS (Max): 10.0

Cisco has released software updates that address vulnerabilities that affect Cisco License On-Prem – regardless of software configuration.


Stay safe, stay patched and have a good weekend!

The AUSCERT team