Daily Briefing

Cybersecurity & Geopolitics Briefing — Tuesday, September 29, 2026

Geopolitical cyber intelligence in 5 minutes
Tuesday, September 29, 2026 · 20 stories

This briefing covers 20 cybersecurity and geopolitics stories published around Tuesday, September 29, 2026, and 6 disclosed vulnerabilities (CVE-2026-101860, CVE-2026-102240, CVE-2026-102247, CVE-2026-86950 and others). Each entry links to the original reporting.

Share this digest:

CVE-2026-88772 Zero-Day Hits Citrix NetScaler in Active Government, Finance Campaign (3 minute read)

Mandiant and Google GTIG identified active exploitation of Citrix NetScaler ADC and Gateway zero-day CVE-2026-88772 targeting government, financial services, education, and legal sectors across North America and Europe.

Google Threat Intelligence · 8h ago · Read full article →

Microsoft: NeedyMantis Backdoor Grants Persistent Access Across Telecoms, IGOs (1 minute read)

Microsoft identified NeedyMantis malware sustaining long-term access inside telecoms, universities, medical nonprofits, intergovernmental organizations, and government contractors across a small number of targeted intrusions dating to at least an unspecified prior date.

The Hacker News · 19h ago · Read full article →

Russia's Managed Election Forecloses Last Legal Outlet for Public Dissent (1 minute read)

Foreign Policy analysis argues Russia's latest electoral process has been so thoroughly controlled that even the pressure-valve function of rigged elections no longer operates.

Foreign Policy · 3h ago · Read full article →

Xi Leverages Trump's Taiwan Ambiguity to Fuel Chinese Disinformation Campaigns (1 minute read)

The Diplomat argues U.S. presidential statements on Taiwan are being actively exploited by Beijing to amplify disinformation narratives about American commitment to the island.

The Diplomat · 20h ago · Read full article →

Nuclear AI Analogies Distort Policy, Researchers Warn (3 minute read)

War on the Rocks argues the dominant nuclear-weapons analogy for AI is shaping government policy in misleading ways, overstating existential risk and misaligning regulatory frameworks.

War on the Rocks · 6h ago · Read full article →

Dutch Police Arrest ShinyHunters Suspect; Group Retaliates With FBI Data Theft (1 minute read)

Netherlands authorities arrested a 23-year-old linked to ShinyHunters data theft and extortion operations; surviving members immediately retaliated by stealing sensitive FBI data and extorting ransomware group Cl0p.

Krebs on Security · 22h ago · Read full article →

Dodo Pizza Confirms Cyberattack Exposing Customer Data Across 1,500 Locations (1 minute read)

Russian pizza chain Dodo Pizza confirmed a cyberattack potentially compromising names, addresses, emails, phone numbers, dates of birth, and order details for customers across its 1,500-location network.

The Record · 1h ago · Read full article →

Apple Patches CVE-2026-86950 Zero-Day Flagged by Meta as Extremely Sophisticated (1 minute read)

Apple issued iOS and macOS updates to close CVE-2026-86950, a zero-day reported by Meta's product security team and described as linked to an extremely sophisticated attack.

SecurityWeek · 7h ago · Read full article →

CVE-2026-102247: FastAdmin Privilege Escalation Exploit Publicly Released (2 minute read)

A publicly disclosed exploit for CVE-2026-102247 allows remote attackers to execute code with unnecessary privileges via FastAdmin 1.6.1–1.6.5's database.php component, scoring 8.3 HIGH.

CVE Feed (High Severity) · 9h ago · Read full article →

CVE-2026-102240: Netcore NAP930 OS Command Injection Exploit Goes Public, Vendor Silent (2 minute read)

A publicly released exploit for CVE-2026-102240 enables remote OS command injection via the eval function in Netcore NAP930 firmware 0.1.241010.141410's Network Tools CGI component; the vendor did not respond to disclosure.

CVE Feed (High Severity) · 11h ago · Read full article →

CVE-2026-101860 - RaspAP raspap-webgui sudo Configuration PluginInstaller.php ad (2 minute read)

CVE ID : CVE-2026-101860 Published : Sept. 29, 2026, 2:16 a.m.

CVE Feed (High Severity) · 11h ago · Read full article →

NeedyMantis: Unpacking a post-compromise malware family used in targeted operati (1 minute read)

Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware framework used in targeted intrusions that combines custom ...

Microsoft Threat Intelligence · 22h ago · Read full article →

Times Car confirms data breach affecting 6.6 million user accounts (1 minute read)

Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late ...

BleepingComputer · 17h ago · Read full article →

Pentagon Personnel Agency Data Breach Impacts 3 Million People (1 minute read)

The data breach affects the Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense. The post Pentagon...

SecurityWeek · 1h ago · Read full article →

Using Device Linking to Eavesdrop on WhatsApp and Signal (3 minute read)

Modern messaging apps allow users to link their phone accounts to their computer desktop. Eavesdroppers are taking advantage of this capability: Ap...

Schneier on Security · 2h ago · Read full article →

US, UK warn of exploited Citrix NetScaler zero-day bugs (1 minute read)

Incident responders began warning of potential vulnerabilities in NetScaler Gateway products on Saturday before cybersecurity agencies in the Nethe...

The Record · 21h ago · Read full article →

Apple patches CoreGraphics zero-day flaw exploited in attacks (1 minute read)

Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices. [...]

BleepingComputer · 6h ago · Read full article →

Russia’s Sahel Intervention Is Riskier Than It Looks (1 minute read)

No one—not least in postcolonial West Africa—loves an army of occupation.

Foreign Policy · 2h ago · Read full article →

What Xi Actually Thinks of Trump (1 minute read)

China’s president has likely concluded that the U.S. under Trump has lost its way.

Foreign Policy · 17h ago · Read full article →

The U.S. and China Agree to Slash Tariffs (1 minute read)

The cuts are on $60 billion worth of goods—but, crucially, soybeans aren’t included.

Foreign Policy · 17h ago · Read full article →

Get this in your inbox

Free daily briefing. No spam. Unsubscribe anytime.

Subscribe Now