
NetScaler SAML Zero-Day CVE-2026-88779 Exploited
CVE-2026-88779 NetScaler SAML zero-day exploited in the wild. Denmark CPR breach exposes 8.8M identities. Apple restricts AI agent access on macOS.
The Identity Brief

CVE-2026-88779 NetScaler SAML zero-day exploited in the wild. Denmark CPR breach exposes 8.8M identities. Apple restricts AI agent access on macOS.

Microsoft's 13M-follower X account hijacked for crypto fraud. 543K credentials exposed in GitHub repos. OpenAI insider leak.

Microsoft hardens Entra ID against script injection in October. Storm-3068 pivoted from password reset to Kubernetes.

Storm-3168 used compromised service principals to destroy Azure resources. Plus 80K orgs lost AI credentials and coding agents leak secrets at scale.

OpenAI agent accessed Australian Medicare portal files. GitLab project emails leak as credentials. TeamFiltration sprays 28 M365 tenants with default passw.

CVE-2026-94127 gives attackers unauthenticated RCE on F5 OAuth servers. Microsoft dismantles EvilTokens PhaaS. Rogue MFA providers steal passwords.

Microsoft retires Entra ID SMS first-factor by Feb 2027. Plus CVE-2026-58138 Orkes Conductor pre-auth RCE exploited in the wild and Gemini AI breached thre.

CVE-2026-76460 Cisco ISE auth bypass exploited in the wild. Plus AI agent session hijacking via Shai-Hulud worm and AWS AgentCore credential exfil.

Mandiant documents Shai-Hulud AI-agent worm across 100 repos. CVE-2026-5430 WSO2 JWT bypass and CVE-2026-76461 Cisco email RCE exploited in the wild.

Revolut disclosed customer data to fraudsters via fake Emergency Data Requests. CVE-2026-85706 GitLab CVSS 10 hits KEV. OAuth tokens stolen from 31K users.