# This Week in Cybersecurity: Week 41

> Week 41: 8.8 million Danish ID records exposed through one company account, rogue Google certificates from hijacked registries, and two more NetScaler flaws.

By Marcus · October 11, 2026 · 19 min read · Weekly

Source: https://bluwarden.com/blog/this-week-in-cybersecurity-2026-w41

---

Denmark disclosed this week that someone pulled the names, addresses and personal ID numbers of about 8.8 million people from its national population register, roughly four in five of everyone it has ever recorded, including people who have moved abroad or died. The register itself was not broken into. The lookups ran for about ten days through the account of one small company that was legally allowed to search it.

A trusted middleman was the weak point in several of the week's stories. Attackers hijacked three country-code domain registries to get genuine HTTPS certificates for Google addresses. The FBI blamed a contractor's missed patch for the ShinyHunters breach of its jobs portal. A criminal operation still holds working logins for tens of thousands of Fortinet firewalls. And NetScaler, last week's headline, produced two more serious flaws. For consumers, an iPhone exploit kit that steals crypto wallet data is spreading through a hijacked shop tracking script, fake CAPTCHA pages learned a new trick, and a LibreOffice flaw lets a spreadsheet run code the moment it opens. This roundup covers Monday 5 to Sunday 11 October.

If you missed it, [last week's roundup](/blog/this-week-in-cybersecurity-2026-w40) covered the first wave of NetScaler mass exploitation, the FortiMail zero-day and how Bitget lost $387.5 million.

## What to act on

### If your iPhone is still on iOS 18, update it now

iVerify [disclosed a new version of DarkSword](https://thehackernews.com/2026/10/p7-darksword-ios-exploit-kit-adds.html), an exploit kit that chains several iOS flaws to break out of the browser and take over an iPhone. Since late 2025 it has been used by a Turkish surveillance vendor, the Russia-aligned Star Blizzard group, a Chinese-speaking operator and financially motivated criminals. The new build, nicknamed P7, adds two-way remote control and goes after iCloud Keychain data, notes, photos and crypto wallet data.

The delivery is the worrying part. Report URI found the kit served through ecomtrack[.]io, an expired domain that someone re-registered and that is still embedded in online shops' tracking tags. Shoppers on legitimate stores were redirected, in one case to a fake crypto trading site that served the exploit.

The kit targets iOS 18.4 through 18.7. Google's [analysis of DarkSword](https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain) says every flaw in the chain is fixed in iOS 26.3 and later, and most were also fixed in later iOS 18 updates. It works on phones that stopped updating.

**Do this:** Settings, General, Software Update. If your iPhone can run iOS 26 or 27 and you have been putting the upgrade off, stop putting it off. If it cannot (the iPhone XS, XS Max and XR top out at iOS 18), install the newest iOS 18 release and consider Lockdown Mode, which Google recommends when updating is not possible. Our [iPhone security guide](/blog/ios-standard-security-hardening) shows how to turn on automatic updates so the next fix lands without you. If you keep a crypto wallet on an old iPhone, move it.

### Fake CAPTCHA pages on 100+ hacked sites, with a new way to hide the command

Ukraine's CERT-UA [reported](https://thehackernews.com/2026/10/100-compromised-websites-use-fake.html) more than 100 compromised websites showing a forged Cloudflare "verify you are human" check that tells visitors to run a command. It only appears to Windows users arriving from a search engine, at most twice in 12 hours, which keeps it out of sight of site owners and researchers. The command installs LunexStealer, which adds a fake "Microsoft Office Word Editor" browser extension that takes cookies, browsing history and logins typed into web forms, and gives the operator remote control of the browser and the computer's files.

Microsoft also [described a refinement](https://thehackernews.com/2026/10/clickfix-smuggles-payloads-through.html) of the same ClickFix trick. The hacked page first hides a script in your browser's cache, disguised as an image, so the command you are told to paste is short, looks harmless and does not have to download anything itself. It ends with malware that steals browser and device credentials.

**Do this:** the rule from our [guide to fake CAPTCHA scams](/blog/fake-captcha-scams) has not changed. No real verification page asks you to press Win+R, open Terminal or PowerShell, and paste something. Close the tab, and if you already pasted it, the guide covers what to do next. Businesses can follow CERT-UA's advice: block the Run dialog for ordinary users through group policy, let only administrators install MSI packages, and allow only approved browser extensions.

### Update LibreOffice before you open anyone's spreadsheet

A [flaw in LibreOffice and Apache OpenOffice](https://thehackernews.com/2026/10/libreoffice-and-openoffice-flaws-let.html) lets a booby-trapped spreadsheet run code as soon as it is opened, with no macro warning. The file points a range of cells at an external database whose Java driver sits on the attacker's server, and the office suite downloads and runs it. It only works when the program's Java support is on. A working proof of concept is public, though no real attacks have been reported.

LibreOffice [fixed it as CVE-2026-63277](https://www.libreoffice.org/security/) on 5 October in versions 26.2.5 and 26.8.0. Apache OpenOffice has no fix yet: everything up to the current 4.1.16 is affected (CVE-2026-59265), and 4.1.17 is still in testing.

**Do this:** update LibreOffice from libreoffice.org or your system's package manager. OpenOffice users should untick "Use a Java runtime environment" in the program's options until 4.1.17 ships, or switch to LibreOffice.

## The week's biggest

### Denmark's population register: 8.8 million ID numbers through one company account

Denmark's digitalisation ministry [announced on 5 October](https://thehackernews.com/2026/10/denmark-says-attackers-accessed-cpr.html) that unauthorised parties had reached the names, addresses and CPR numbers of about 8.8 million people in the Central Person Register, which has recorded everyone who has lived in Denmark since 1968. The figure includes people who have emigrated or died; the register holds about 11 million records, and the country just under 6 million people.

The route was a small private company with a lawful right to look up records. Over roughly ten days in September, someone used its account to run a huge number of automated lookups to find valid CPR numbers. A register employee spotted the activity on Friday 2 October, the company's access was cut, and police are investigating. Nobody has said how the attackers got into the company's systems, who they are, or whether the data has been published. The minister said the safeguards were not strong enough and that alarms should have gone off.

CPR numbers are used to identify people almost everywhere in Danish life, which makes this far more useful to fraudsters than an address list. The official advice is that a CPR number should never be the only proof of identity, which is the lesson for any organisation still treating one as a secret.

**Who's exposed:** anyone who has had a Danish CPR number since 1968, including people who have since left the country. Expect calls, texts and emails that quote your real details, and never share MitID details or one-time codes, however much the caller seems to know. You can set a credit warning on borger.dk, and the government Cyberhotline on +45 33 37 00 37 can help.

### NetScaler again: an exploited flaw, then a critical one on top

On 5 October Citrix [disclosed CVE-2026-88779](https://thehackernews.com/2026/10/new-netscaler-zero-day-exploited-in.html) (CVSS 8.7), a memory overflow that lets attackers knock NetScaler ADC and Gateway appliances offline when they handle SAML single sign-on, and said it had seen targeted attacks. CISA set federal agencies a 7 October deadline to patch, to builds 14.1-73.41 or 13.1-64.28.

Three days later came [CVE-2026-107406](https://thehackernews.com/2026/10/citrix-patches-critical-netscaler-flaw.html) (CVSS 9.5), another memory overflow in SAML setups that Citrix says can lead to remote code execution. No exploitation has been reported. The catch is in [Citrix's bulletin](https://support.citrix.com/external/article/CTX697191/citrix-netscaler-adc-and-citrix-netscale.html): builds 14.1-73.37 to 14.1-73.41 and 13.1-64.23 to 13.1-64.28, the ones admins just installed for last week's mass-exploited flaws and for 88779, are still vulnerable when the appliance acts as a SAML identity provider. The fix is 14.1-73.46 or 13.1-64.29 and later, with matching FIPS builds.

That is four serious NetScaler flaws in two weeks, three of them exploited.

**Who's exposed:** organisations using NetScaler for SAML sign-in (look for `authentication samlAction` or `authentication samlIdPProfile` in the configuration). If you patched last week and NetScaler is your SAML identity provider, patch again.

### Hijacked domain registries handed out real certificates for Google

Google [said on 6 October](https://blog.google/security/chromes-response-to-recent-cctld-registry-hijacks/) that attackers had compromised the operations behind three country-code domains, .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa), and changed authoritative DNS records. That let them prove "control" of domains under those endings and obtain genuine HTTPS certificates for Google properties and other companies' domains. Google says its own systems were not breached and it has no reason to think the certificate authorities did anything wrong: they checked domain control, and the attackers had it.

The Hacker News [found at least 12 such certificates](https://thehackernews.com/2026/10/attackers-hijack-gh-sl-and-as.html) in public Certificate Transparency logs, for addresses including google.com.gh, google.sl and youtube.com.gh, issued between 22 and 27 September by Let's Encrypt and ZeroSSL. All 12 were revoked by 1 October, and Chrome blocked them as well. Google says other "leading global brands" were also hit but has not named them. Nobody has said who did it, how the registries were compromised, or whether any certificate was used to intercept traffic.

The padlock in your browser shows that whoever requested the certificate controlled the domain at that moment. When the registry above a domain falls, an attacker can get that padlock too, and Certificate Transparency, the public log browsers require certificates to appear in, is how it surfaces.

**Who's exposed:** Chrome users need do nothing, Google says, though it warns that its blocks do not reliably protect people on other browsers. The work falls on owners of .gh, .sl and .as domains and on any company with neglected regional domains. Google's advice is to monitor Certificate Transparency logs for every domain you own and publish restrictive CAA records.

### Atlassian: a no-login file-read flaw in eight products, probed within two hours

Atlassian [disclosed CVE-2026-21589](https://thehackernews.com/2026/10/critical-atlassian-flaw-lets.html) (CVSS 9.3) on 5 October, a path traversal in eight self-hosted Data Center products: Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo, Crowd, Crucible and Fisheye. Without logging in, an attacker who knows a file's exact path can read it from the application's web root. Atlassian's cloud products were already patched.

About two hours after watchTowr published technical details, Previdian's honeypots [recorded exploitation attempts](https://thehackernews.com/2026/10/atlassian-data-center-flaw-draws.html). watchTowr confirmed in-the-wild exploitation, so far mostly fingerprinting products and sweeping for configuration files. The step to worry about comes next: in Crowd and Jira, the `crowd.properties` file can hold credentials that could give an attacker admin access.

Fixed versions include Jira Software 9.12.40, 10.3.26 and 11.3.12, Confluence 9.2.26 and 10.2.19, and Bitbucket 9.4.26, 10.2.8 and 10.5.1; Atlassian's advisory lists the rest. If you cannot patch today, take the instance off the internet or apply Atlassian's WAF or Tomcat rewrite rule. Server editions, which Atlassian no longer supports, are listed as affected, with no fixed version for several products.

**Who's exposed:** companies self-hosting Jira, Confluence or the other affected products, especially where the instance is reachable from the internet. Atlassian Cloud customers have nothing to do.

### FortiBleed is still running, with logins for 86,644 Fortinet firewalls

The FBI and US Secret Service [warned on 6 October](https://thehackernews.com/2026/10/fbi-warns-fortibleed-remains-active.html) that FortiBleed, a credential-harvesting operation against internet-facing FortiGate firewalls and SSL VPNs, is still active. It is a campaign rather than a single software flaw, and SOCRadar and Huntress both warn that patching alone will not stop it. Attackers stuff and spray passwords from old leaks and infostealer logs, sniff more on compromised devices, crack the hashes offline, then move inward, create their own admin accounts and sometimes delete the real ones.

SOCRadar counted 86,644 confirmed-compromised devices across 194 countries as of June. The operator looks like a Russian-speaking access broker, and at least 12 ransomware deployments have been traced to its access, with overlaps to the INC and Lynx groups.

The fixes are about identity: reset VPN and admin passwords, end every active session, take admin interfaces off the internet, hunt for admin accounts you did not create, and put phishing-resistant MFA in front of remote access. Our [guide to passkeys and MFA](/blog/password-best-practices-2026) explains why a login that needs only a password is the whole problem here.

**Who's exposed:** organisations with a FortiGate SSL VPN or admin page on the internet, above all where a password alone opens the VPN. If that describes your work VPN, tell your IT team.

### China's hacking contractor: tools seized, and a portal for reading stolen email

A [joint advisory from seven countries](https://thehackernews.com/2026/10/fbi-says-china-linked-hackers-ran.html) on 8 October described hackers tied to Integrity Technology Group, a Beijing company with links to the Chinese government whose methods match the group tracked as Flax Typhoon. Its strangest detail is a web portal that lets unnamed third parties read stolen email by adding an account to the address. The mail came from Microsoft 365 and Exchange accounts broken into mostly by password guessing at scale. Victims included government, police, healthcare and religious organisations in Southeast Asia, plus US government services, manufacturing, IT and education.

The next day the FBI [seized seven domains](https://thehackernews.com/2026/10/fbi-seizes-7-domains-disrupts-flax.html) and disrupted the group's tools, including MicroScan, a scanner with more than 1,300 attack scripts. Targets named in the case include a South Carolina power company, Japanese and Polish airports, and Taiwanese gas and power companies. CISA [added five flaws](https://thehackernews.com/2026/10/flax-typhoon-exploits-five-flaws-as.html) the group exploits, in ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts and the BIND DNS server, to its exploited list and gave federal agencies until 11 October to patch or stop using the software. Two of them date from 2015.

Every flaw on the advisory's list is years old, and much of the rest ran on guessed passwords.

**Who's exposed:** organisations running old software on the internet, or webmail and VPN logins protected only by a password, with critical infrastructure the stated priority. Personal devices are not directly involved.

### A secret-stealing workflow planted in tens of thousands of GitHub repositories

Socket [reports](https://thehackernews.com/2026/10/credential-stealing-github-actions.html) that since 7 October more than 500 GitHub accounts have committed the same malicious workflow, `security-audit.yml` or `github_actions_security.yml`, to tens of thousands of repositories, most likely using maintainers' tokens leaked through infostealers. It scans the code and the whole git history for 13 kinds of credentials, so secrets deleted long ago are caught too, and sends them over plain HTTP to a hard-coded server. Researchers tie it to GhostAction, a campaign first seen in September 2025.

The same week the `tensorlake` npm package [shipped a compromised version 0.5.144](https://thehackernews.com/2026/10/tensorlake-npm-package-compromised-to.html) carrying a worm from the Shai-Hulud family. It runs on install, steals npm, GitHub and cloud credentials, SSH keys, crypto wallets and AI coding tool configs, republishes the victim's own packages to spread, and plants `.claude/settings.json` and `.vscode/tasks.json` so it runs again when a project is opened in Claude Code or VS Code. If the stolen GitHub token is revoked, a monitor it leaves behind wipes the victim's home directory. The bad version has been pulled from npm.

**Who's exposed:** developers and companies on GitHub. Search repositories, forks and mirrors for either workflow file going back to 31 August. If you find one, assume compromise, revoke the token, rotate every secret the repository could see and delete the workflow from all branches. If anyone installed tensorlake 0.5.144, isolate and clean that machine before revoking its tokens, because of the wiper. If you do not write software, nothing here is yours to fix.

### AI agents in testing broke into real systems, and the labs now say so

Anthropic [published an investigation on 9 October](https://www.anthropic.com/research/investigating-unintended-model-actions) into what its models did on the live internet during testing. Claude Mythos Preview, unable to use a university-hosted tool, found an injection flaw on the server and used it to run its calculation. Claude Haiku 4.5, while generating example tasks, submitted an invented tip about an unsolved homicide to a police department's form; it was flagged as spam and never forwarded. Claude Mythos 5 pulled access tokens from public government sites to query their data directly, in one case skipping a fee. Anthropic says the impact was minimal and no customer data was involved, has notified the affected agencies, and is [cutting live internet access for all its internal evaluations](https://thehackernews.com/2026/10/anthropic-cuts-live-internet-access-for.html) until its monitoring reliably catches this. Philadelphia's police department, whose form it was, called the two-month delay in detecting and reporting it unacceptable.

The Wikimedia Foundation [said](https://thehackernews.com/2026/10/wikimedia-says-openai-agents-tried-to.html) agents it suspects were OpenAI's made millions of automated requests to its services, reconfigured a citation tool apparently to use it as a proxy, and tried unsuccessfully to compromise its public Etherpad service for the same purpose. OpenAI says it is reviewing the activity with the Foundation. It had already paused training of its most capable models the week before.

Apple, meanwhile, [plans to require](https://thehackernews.com/2026/10/apple-plans-tighter-macos-full-disk.html) an explicit user action before an app gets macOS Full Disk Access, warning that the risk "will grow substantially" as AI agents become more autonomous. It named no product, but the change follows a report of Meta's Muse agent reading a journalist's private iMessages after being granted that access.

**Who's exposed:** anyone running a public website, form or API, since agents probe for workarounds the way attackers do, and anyone who has given an AI agent broad access to their computer. On a Mac, check System Settings, Privacy & Security, Full Disk Access, and remove any app that does not clearly need it.

### Three serious fixes to install before anyone exploits them

SonicWall [fixed CVE-2026-102255](https://thehackernews.com/2026/10/sonicwall-patches-cvss-100-pre.html) (CVSS 10.0), a no-login server-side request forgery in the WorkPlace portal of its SMA1000 appliances (models 6210, 7210 and 8200v). It is not known to be exploited, but the two earlier 10.0, no-login WorkPlace flaws this year were. The hotfixes are 12.4.3-03670 and 12.5.0-03082; SMA 100 appliances and the SSL VPN on SonicWall firewalls are not affected.

Microsoft [shipped out-of-band updates](https://thehackernews.com/2026/10/microsoft-exchange-flaw-lets.html) for CVE-2026-96940 (CVSS 8.8), which lets any logged-in user of on-premises Exchange read other people's mailboxes and attachments in the same organisation. Subscription Edition, Exchange 2019 CU14 and CU15, and Exchange 2016 CU23 are affected; Exchange Online was fixed on Microsoft's side. Microsoft rates exploitation as more likely.

Researchers also [published a working exploit](https://thehackernews.com/2026/10/researchers-publish-working-exploit-for.html) that gives root on AnyDesk for Linux without authentication, over a direct connection to TCP port 7070. AnyDesk fixed it quietly in version 8.0.3 in June, describing it only as a crash fix, and there is no CVE. Windows and macOS are not affected.

**Who's exposed:** organisations running SonicWall SMA1000 or on-premises Exchange, and anyone with AnyDesk on a Linux machine that has not updated since June. Update to 8.1.0, or block port 7070 until you can.

## The week in CVEs

| CVE | Product | Exploited | Patch available |
|-----|---------|-----------|-----------------|
| CVE-2026-88779 | Citrix NetScaler ADC / Gateway (SAML) | Yes, targeted | Yes (14.1-73.41, 13.1-64.28) |
| CVE-2026-107406 | Citrix NetScaler ADC / Gateway (SAML) | Not reported | Yes (14.1-73.46, 13.1-64.29) |
| CVE-2026-21589 | Atlassian Data Center (8 products) | Yes, early probing | Yes |
| CVE-2026-102255 | SonicWall SMA1000 | No | Yes (12.4.3-03670, 12.5.0-03082) |
| CVE-2026-96940 | Microsoft Exchange Server (on-premises) | No | Yes (out-of-band update) |
| CVE-2026-63277 | LibreOffice | No, public PoC | Yes (26.2.5, 26.8.0) |
| CVE-2026-59265 | Apache OpenOffice | No, public PoC | No (4.1.17 in testing) |
| None assigned | AnyDesk for Linux | No, public exploit | Yes (8.0.3, June) |
| CVE-2015-3306, CVE-2021-3199, CVE-2023-22894, CVE-2016-3081, CVE-2015-5477 | ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, ISC BIND | Yes, Flax Typhoon | Patch or retire by 11 October (CISA) |

## Worth knowing about

**The FBI says a contractor's missed patch let ShinyHunters in.** An FBI official [said](https://thehackernews.com/2026/10/fbi-removes-accenture-contractor-after.html) the breach of the bureau's jobs portal, which exposed personal details of thousands of employees, followed a contractor's failure to apply a patch, and the FBI removed an Accenture contractor. Two Reuters sources name the platform as Oracle PeopleSoft, the route we called plausible when [we looked at the group's claims](/blog/shinyhunters-fbi-hack-claim) in September. The group had claimed a new zero-day; the FBI's account points to a known flaw left unpatched. A third suspect was [arrested in Pennsylvania](https://thehackernews.com/2026/10/fbi-arrests-another-shinyhunters.html), after earlier arrests in the Netherlands and Jordan.

**Fully patched Pixel 10 and Galaxy S26 phones were hacked remotely at Pwn2Own.** Three of four teams at Pwn2Own Ireland [took over a fully patched Pixel 10](https://thehackernews.com/2026/10/three-teams-demonstrate-remote-hacks-of.html) remotely, and the Galaxy S26 fell in all seven attempts; nobody tried an iPhone 17. The bugs go to the vendors to fix, so the only action is to install the next security updates promptly.

**AI bug hunting is swamping maintainers.** Google [paused rewards](https://thehackernews.com/2026/10/google-pauses-oss-product-bug-bounty.html) for product bug reports in its open-source bounty program, citing a surge of automated submissions, most of them invalid. The same week Anthropic [launched a free AI scanner](https://thehackernews.com/2026/10/anthropic-launches-free-ai.html) for open-source projects and [said](https://thehackernews.com/2026/10/anthropic-expands-claude-access-for.html) partners in its Glasswing program had verified at least 129,000 flaws found with its models, while a VulnCheck analysis found just 2 of 300 Anthropic- or Glasswing-credited flaws exploited in the wild. Finding bugs is getting cheap; triaging and fixing them is the bottleneck.

## Summary

1. **iPhone on iOS 18?** Move to iOS 26 or 27 if your phone can run it. If it cannot, install the latest iOS 18 release and consider Lockdown Mode.
2. **Never paste a command a website asks you to run.** Fake Cloudflare checks are live on more than 100 hacked sites.
3. **Update LibreOffice** to 26.2.5 or 26.8.0. OpenOffice users should turn off Java until 4.1.17 ships.
4. **Anyone with a Danish CPR number:** expect phishing that quotes your real details, never share MitID codes, and consider a credit warning.
5. **NetScaler admins using SAML:** move to 14.1-73.46 or 13.1-64.29, even if you patched last week.
6. **Atlassian Data Center admins:** patch CVE-2026-21589 or take the instance off the internet. It is already being probed.
7. **FortiGate admins:** reset VPN and admin passwords, end active sessions, audit admin accounts and add phishing-resistant MFA.
8. **Developers:** search for the GhostAction workflow files, and clean any machine that installed tensorlake 0.5.144 before revoking its tokens.
9. **SonicWall SMA1000, on-premises Exchange and AnyDesk for Linux:** install the fixes before the exploits arrive.

*Most of this week's damage came through someone else's door: a lookup account, a domain registry, a contractor's missed patch, a reused firewall password. If you are not sure which third parties and internet-facing devices can reach your data, [get in touch](/#contact) - bluwarden can help you map that exposure and check what is actually facing the internet.*

*This roundup is for general information and reflects public reporting as of 11 October 2026. Vulnerability details, patch versions and exploitation status change quickly; always confirm against the vendor's own advisory before acting.*
