Summaries
Short AI and tech summaries with source links, signal scores, and why each update matters for builders, founders, and Malaysian tech workers.
Showing 1-3 of 3 results
| Date | Provider | Score | Summary |
|---|---|---|---|
| 06 Oct 2026, 7:57 PM | The Hacker News | 6.0 | LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings
Researchers demonstrated that a crafted Calc spreadsheet can make LibreOffice and Apache OpenOffice execute attacker-controlled Java code the moment the file is opened, with no macro-style trust prompt. The chain abuses intended features: a 'database range' in the sheet auto-refreshes from a remote ODB file named by a URL, which in turn names a JDBC driver whose JAR is downloaded and run inside the application. LibreOffice fixed it as CVE-2026-63277 in the October 5 updates (26.2.5 / 26.8.0); Apache OpenOffice has no fix yet for CVE-2026-59265, with every version up to 4.1.16 affected and 4.1.17 still in testing. The attack requires Java support to be enabled, was shown as a proof of concept on Windows and Linux, and has no reported real-world use. Why: Your existing defence — 'never enable macros in an untrusted document' — does not stop this, because no macro is involved. If your team or clients run LibreOffice, the decision is a version check: anything below 26.2.5 or 26.8.0 needs the October 5 update. If anyone is still on Apache OpenOffice, there is no patch available for any release up to 4.1.16, so the only options today are turning Java off in settings or refusing to open spreadsheets from outside your organisation — worth knowing before you accept a supplier's .ods or .xlsx file. This is especially relevant where open-source office suites are chosen to avoid Microsoft licensing, since those installs often sit on shared or lightly managed machines. |
| 05 Oct 2026, 4:09 PM | The Hacker News | 6.0 | Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
CVE-2026-61500 (CVSS 9.3) affects Rejetto HFS 3.0.0 through 3.2.0: the server derived its session-cookie signing key from JavaScript's non-cryptographic Math.random() and leaked outputs of the same V8 PRNG to unauthenticated clients during the SRP login handshake, letting an attacker reconstruct the generator state, recover the signing key, forge an admin cookie, and reach remote code execution through the server_code configuration feature. A patch shipped in July 2026 as version 3.2.1, but a public Python PoC by Alejandro Ramos (aramosf) landed in late September, and VulnCheck's Patrick Garrity says exploitation attempts were detected on October 1, 2026 — one day after Horizon3.ai published more detail. Horizon3.ai researcher Zach Hanley stated that Anthropic's Mythos model was used to discover the flaw. Why: The direct action item is narrow: if you self-host Rejetto HFS, anything in 3.0.0–3.2.0 is exploitable in the wild as of October 1, 2026 and needs to be on 3.2.1. The broader lesson is worth more — session-signing keys and tokens generated with Math.random() (or any non-CSPRNG) are recoverable from observed outputs, and this is exactly the pattern AI coding assistants emit by default when you ask for a session or token helper, so check any JS/Node auth code you or a vibe-coded tool generated. |
| 05 Oct 2026, 10:20 PM | The Hacker News | 3.5 | ⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
The Hacker News weekly recap leads with two actively exploited flaws: CVE-2026-88779 in Citrix NetScaler ADC/Gateway (CVSS 8.7, memory overflow causing denial-of-service, but only when the appliance is configured as a SAML service provider or identity provider), and CVE-2026-104286 in Fortinet FortiMail (CVSS 9.8, unauthenticated arbitrary file write via crafted HTTP/HTTPS requests, flagged by CISA for active exploitation). It also notes the arrest of two alleged ShinyHunters members and teases items on AI coding leaks and Spectre v2, but the provided text cuts off before those sections, so there are no details to summarize on them. The page also embeds a Headspace-sponsored webinar on AI governance, which is promotional rather than news. Why: The two CVEs have very different triage urgency: FortiMail's 9.8 is unauthenticated and remote, so any internet-exposed FortiMail box is the priority patch; NetScaler's 8.7 only bites when the device is configured as a SAML SP or IdP, which narrows who is actually exposed. If you don't run Fortinet or Citrix appliances, nothing here changes your week — the AI coding leak and Spectre v2 items, which would be more relevant to this audience, have no usable detail in the text provided. |