Skip to content
Hacked dAily
4:08 listen

Apple Zero-Day, Supabase Exposures and Citrix NetScaler Attacks

Hacked dAily

Listen now

Stream the full 4:08 briefing here, and it keeps playing as you browse.

In this briefing: 5 stories

Hacked dAily, the first AI-driven cybersecurity podcast from Cytadel Cyber, delivers a concise daily briefing for CISOs, security leaders, and decision-makers. Today’s episode covers five developments with direct implications for enterprise risk, resilience, and security investment.

  1. 01

    Apple patched CVE-2026-86950, a CoreGraphics zero-day enabling arbitrary code execution through specially crafted files, after Meta identified possible exploitation against targeted individuals. The incident highlights the continuing risk of sophisticated, potentially zero-click attacks and the need for rapid patching across Apple fleets.

  2. 02

    Researchers found more than 16,000 misconfigured Supabase databases exposing personal data, passwords, authentication tokens, and possibly payment information. The scale of the exposures underscores how weak access controls and poor cloud configuration can create significant privacy, fraud, and regulatory risks.

  3. 03

    Japan’s Keio confirmed a ransomware attack that disrupted business systems. The incident reinforces the need for tested backups, rapid detection, and practiced response plans to limit downtime, recovery costs, and reputational damage.

  4. 04

    RatHat’s Android banking trojan now uses a web console to rank victims by estimated bank balance, with Gemini AI helping identify valuable targets from stolen messages. Operated as malware-as-a-service, the platform shows how automation is making financial crime more scalable and targeted.

  5. 05

    Citrix NetScaler appliances were exposed to critical pre-auth command injection flaw CVE-2026-88771, which was reportedly exploited in the wild and could provide unauthenticated root access. Because NetScaler often protects remote-access environments, organisations should prioritise patching and verify that internet-facing systems were not compromised.

Newsletter

Subscribe to Our Newsletter

Stay ahead of cyber threats with our weekly insights. Get exclusive access to expert analysis, breaking news, and the latest cybersecurity trends delivered straight to your inbox.

By subscribing you agree to receive the Hacked dAily briefing. Unsubscribe any time: see the privacy notice.