|
🇩🇰 Breach exposes 8.8M Danish citizen records
LINK
|
- Denmark has confirmed unauthorized access to its Central Person Register (CPR), exposing personal records for about 8.8 million people, more than the country's population, because the database also holds deceased individuals and former residents who left.
- The national registry itself was not directly compromised; instead, unknown actors abused a Danish company's legitimate, authorized ability to search the CPR system, retrieving names, residential addresses, and CPR numbers, though officials have not disclosed the technical method used.
- Authorities detected irregular activity on October 2 and traced unauthorized searches back to September; the company's access is suspended, and because a CPR number is a central identifier, the data could fuel convincing phishing, vishing, smishing, impersonation, and identity-verification bypass.
|
💧 Hackers breach water utility via SharePoint
LINK
|
- A China-linked group is breaking into critical infrastructure in Portuguese- and Spanish-speaking countries, including a water utility, a telecom provider, a university and a regional government across Europe, Africa and Latin America, by exploiting Microsoft SharePoint flaws to deploy Warlock ransomware.
- According to Symantec, the attacks exploit unpatched SharePoint servers, continuing from the 2025 "ToolShell" bugs into newer 2026 flaws, letting the hackers gain a foothold and, in one case, use a tool to disable security software on dozens of hosts before deploying the ransomware.
- The campaign follows CISA's warning one month ago that six new SharePoint vulnerabilities are being exploited to give attackers wide access, and because SharePoint ties into Microsoft's authentication, a foothold there can let skilled hackers move deeper into victim networks.
|
🔒 Microsoft fixes Exchange mailbox flaw
LINK
|
- Microsoft has shipped a revised V2 security update for on-premises Exchange Server, dated September 2026, adding a fix for a mailbox flaw (CVE-2026-96940) that was missing from the original September package.
- The revised update, published on Thursday, covers Exchange Server Subscription Edition, Exchange Server 2019, and Exchange Server 2016; Exchange Online customers are not affected and need no server-side update.
- Because Exchange 2016 and 2019 are now end of support, only organizations enrolled in Microsoft's Period 2 Extended Security Update program receive the fix, and Microsoft warns hybrid setups that patch only legacy servers can stay exposed even after mailboxes move to the cloud.
|
🎯 AI-found file server bug is now under attack
LINK
|
- Hackers have started exploiting a critical flaw in Rejetto HTTP File Server (HFS) to bypass login and run code on affected servers, security firm VulnCheck warned on Friday.
- The bug (CVE-2026-61500, CVSS 9.3, critical) stems from HFS leaking outputs of its weak session-cookie generator to unauthenticated clients at login, letting an attacker collect a few login responses, rebuild the signing key, and forge valid administrator cookies.
- With forged admin access, an attacker gains remote code execution through the server_code configuration feature; the exploitation so far is small-scale reconnaissance from a China Telecom IP, and version 3.2.1, released on July 13, contains the fix.
|
⚠️ FortiMail zero-day lets hackers write files unauthenticated
LINK
|
- Fortinet is warning that hackers are actively exploiting a zero-day in the FortiMail management interface, letting unauthenticated attackers write arbitrary files on vulnerable devices to run unauthorized code or commands.
- The flaw, CVE-2026-104286, is rated critical (CVSS 9.8) and combines a path-traversal and NULL-byte handling weakness that lets an attacker write files on the underlying system by sending crafted HTTP or HTTPS requests, no login needed.
- Patched versions aren't available yet across the affected FortiMail branches, so Fortinet says admins should disable IBE feature support or block internet access to the management interface, and has published indicators of compromise and log entries to spot compromised appliances.
|
|