This briefing covers 20 cybersecurity and geopolitics
stories published around Tuesday, September 29, 2026,
and 6 disclosed vulnerabilities
(CVE-2026-101860, CVE-2026-102240, CVE-2026-102247, CVE-2026-86950 and others).
Each entry links to the original reporting.
Mandiant and Google GTIG identified active exploitation of Citrix NetScaler ADC and Gateway zero-day CVE-2026-88772 targeting government, financial services, education, and legal sectors across North America and Europe.
Microsoft identified NeedyMantis malware sustaining long-term access inside telecoms, universities, medical nonprofits, intergovernmental organizations, and government contractors across a small number of targeted intrusions dating to at least an unspecified prior date.
Foreign Policy analysis argues Russia's latest electoral process has been so thoroughly controlled that even the pressure-valve function of rigged elections no longer operates.
The Diplomat argues U.S. presidential statements on Taiwan are being actively exploited by Beijing to amplify disinformation narratives about American commitment to the island.
War on the Rocks argues the dominant nuclear-weapons analogy for AI is shaping government policy in misleading ways, overstating existential risk and misaligning regulatory frameworks.
Netherlands authorities arrested a 23-year-old linked to ShinyHunters data theft and extortion operations; surviving members immediately retaliated by stealing sensitive FBI data and extorting ransomware group Cl0p.
Russian pizza chain Dodo Pizza confirmed a cyberattack potentially compromising names, addresses, emails, phone numbers, dates of birth, and order details for customers across its 1,500-location network.
Apple issued iOS and macOS updates to close CVE-2026-86950, a zero-day reported by Meta's product security team and described as linked to an extremely sophisticated attack.
A publicly disclosed exploit for CVE-2026-102247 allows remote attackers to execute code with unnecessary privileges via FastAdmin 1.6.1–1.6.5's database.php component, scoring 8.3 HIGH.
A publicly released exploit for CVE-2026-102240 enables remote OS command injection via the eval function in Netcore NAP930 firmware 0.1.241010.141410's Network Tools CGI component; the vendor did not respond to disclosure.