Weekly Security Roundup — week ending Sunday, 4 October 2026
NHS England 38.23M records sale, Warlock CNI campaign, Rhysida/Wallstreet ransomware, ShinyHunters triple headlines, GitLab AI Gateway RCE, Flock surveillance ruling.…
NHS England 38.23M records sale, Warlock CNI campaign, Rhysida/Wallstreet ransomware, ShinyHunters triple headlines, GitLab AI Gateway RCE, Flock surveillance ruling.…
🎧 Subscribe to the podcast feed Security News 🚨 Alleged Sale of NHS England Data — 38.23 Million Records (Threat Feed) — A threat actor is claiming to sell a dataset of 38.23 million NHS England records including NHS login IDs, NHS numbers, full names, dates of birth, and email addresses. Unconfirmed;…
🎧 Subscribe to the podcast feed Security News Apple Changes macOS Full Disk Access Permissions to Curb AI Agent Abuse (Ars Technica) — Apple is tightening macOS privacy controls after acknowledging that increasingly capable AI agents substantially increase the risk of third-party apps gaining broad access to files, messages, mail, and…
🎧 Subscribe to the podcast feed Security News Fortinet warns of critical FortiMail flaw exploited in zero-day attacks (BleepingComputer) — A critical zero-day in FortiMail is being actively exploited in the wild; Fortinet is urging immediate patching. Police dismantle KillSec ransomware gang allegedly led by 16-year-old (BleepingComputer) — European…
🎙️ Subscribe to the podcast feed Security News Attackers exploiting critical Zimbra flaw to steal emails (Ars Technica) — A critical vulnerability in Zimbra Collaboration Suite is being actively exploited to exfiltrate email backups and authentication credentials; Microsoft issued the warning and organisations running Zimbra should treat patching as immediate. Russian state…
🎧 Subscribe to the podcast feed Security News Self-Replicating Prompt Injections Found in GPT Models (The Register) — OpenAI's alignment team disclosed GPT models susceptible to worm-style prompt injection attacks that can propagate across agents and contexts. Apple CVE-2026-86950 Weaponised in Sophisticated Targeted Attacks (Dark Reading)…
🎧 Subscribe to the podcast feed Security News Apple Emergency Patch — CVE-2026-86950 (iOS 26, macOS 26, macOS 15) (SANS ISC) — Apple issued emergency security updates for iOS 26, macOS 26, and macOS 15 to address CVE-2026-86950; emergency patches of this kind typically follow confirmed in-the-wild…
🎧 Subscribe to the podcast feed Security News Citrix NetScaler ADC & Gateway — 8 CVEs including Unauthenticated RCE (Citrix / NVD) — Citrix published eight vulnerabilities (CVE-2026-88771 through CVE-2026-88778) affecting NetScaler ADC and Gateway; two are Critical (CVSS 4.0: 9.5) including an unauthenticated arbitrary command execution flaw…