
New AWS Controls, Citrix/Dell/Exchange Patches, Denmark CPR Breach
Coverage: 05 Oct 2026 (UTC)
< view all daily briefs >Security teams faced a busy cycle of new controls and urgent fixes. AWS introduced identity and endpoint protections and expanded automated security testing, while administrators contended with critical updates across Citrix NetScaler, Microsoft Exchange, and Dell PowerEdge tooling amid active exploitation against Rejetto HFS and renewed botnet activity against Realtek-based devices. Google paused its open-source bug bounty program due to AI-driven noise, Denmark reported a national registry breach, and platform updates from Cloudflare and AWS continued to reshape data and AI operations.
Identity and Access: Network Guardrails and Device Posture
AWS IAM Identity Center now supports network access controls for the Identity Store and SCIM APIs, allowing administrators to require requests from specific VPC endpoints, source VPCs, or defined IP ranges. Controls are optional and off by default; requests made by AWS services on customers' behalf are exempt. The feature is configured via the Identity Store API using SDKs or the CLI and is available in all Regions where IAM Identity Center operates.
AWS Client VPN added device posture assessment, integrating with providers such as CrowdStrike, Jamf, and JumpCloud. Administrators author Cedar policies to enforce requirements (for example, compliance scores, encryption status, or risk levels) and can validate rules with a built-in Test Policy tool. Posture is continuously evaluated during sessions with options to disconnect noncompliant devices or run in monitoring-only mode. The capability is available in all AWS Regions where Client VPN is offered, requires AWS VPN Client 6.2.0 or later, and has no additional cost.
Automated Security Verification: From CI/CD to Code Repair
AWS Continuum for Penetration Testing now integrates directly with CI/CD pipelines in public preview, running penetration tests at deploy time and surfacing severity, affected endpoints, and remediation steps in pipeline output. Pipelines automatically retest fixes after remediation, and setup is streamlined via an auto-generated snippet with application context bootstrapped on first run. The goal is more frequent, automated security checks with reduced operational overhead for development and security teams.
On end-to-end code security, AWS Continuum reported an 89.0% S3 success rate on the CyberGym-E2E benchmark (819/920 tasks), outperforming the prior public high by 23.1 percentage points and setting records across all S1–S4 stages. The multi-agent system progresses through discovery, validation, and remediation, carrying evidence forward; evaluations were performed under strict network isolation to ensure repairs arose from analysis rather than retrieval. Results rose to 93.7% when allowed to run beyond the 90-minute limit. The benchmark centers on sanitizer-detected memory-safety issues in C/C++ projects, and AWS notes that real-world deployments can incorporate production context—such as exposure and permissions—to prioritize impact.
Patching and Active Exploits: Citrix, Exchange, Dell, HFS, Realtek — and a National Breach
Citrix NetScaler disclosed CVE-2026-88779 (CVSS 8.7), a memory buffer issue exploited in targeted attacks that can cause denial of service in SAML configurations—specifically when appliances are set as a SAML SP using add authentication samlAction or as a SAML IdP using add authentication samlIdPProfile. Customers on NetScaler ADC and Gateway 14.1 prior to 14.1-73.41 and 13.1 prior to 13.1-64.28 should apply updates; interim signatures are available via the Global Deny List. CISA added the CVE to KEV and directed federal agencies to apply mitigations by October 7.
Microsoft released out-of-band updates for Exchange Server to address CVE-2026-96940 (CVSS 8.8), a weak-authorization flaw that lets an authenticated attacker elevate privileges to access other users’ mailboxes in the same organization. Exchange Online received a service-side fix; on-premises deployments—including Subscription Edition RTM and several 2016/2019 CUs—require patching. Microsoft rated exploitation as “More Likely” and credited Jan Mitchell for the report.
Dell issued an urgent advisory for Dell System Update (DSU) on PowerEdge servers, patching CVE-2026-86360, a path traversal vulnerability enabling unauthenticated remote code execution with root privileges. DSU v2.3.0.0 also fixes four additional high-severity issues (two RCEs and two privilege escalations). Dell strongly recommends immediate upgrades, noting longstanding U.S. government guidance condemning path traversal defects and past targeting of Dell flaws by state-backed groups.
The Rejetto HFS project is under active attack via CVE-2026-61500 (CVSS 9.3), where a non-cryptographic PRNG (Math.random) used for session-cookie signing is exposed during SRP login. Attackers can reconstruct the PRNG state, forge admin cookies, and use the server_code configuration to execute arbitrary server-side JavaScript. A patch shipped in July 2026 (HFS 3.2.1), but a late-September proof-of-concept accelerated exploitation observed on October 1; reporting attributes targeting to an unnamed China-based actor focusing on U.S. hosts.
Nozomi Networks observed attempts to exploit a Realtek Jungle SDK RCE (CVE-2021-35394) to deploy the Cling botnet, which abuses STUN behavior and public infrastructure for covert C2. Cling persists by modifying system paths or replacing wget, spreads via multiple historical router/DVR exploits, and embeds commands in STUN transaction IDs while spoofing responses from well-known services—complicating detection and response.
Separately, Denmark’s Central Population Register reported a breach affecting about 8.8 million registered individuals. According to BleepingComputer, attackers abused a private company’s legitimate access and appear to have brute-forced enumeration of valid CPR numbers to harvest records including names, addresses, dates of birth, marital status, and identification numbers. Access was revoked, additional measures implemented, and a police investigation opened; authorities issued guidance and set up a cyber hotline for potentially affected individuals.
Platforms, Models, and Program Shifts
AWS Bedrock added the GLM 5.3 model from Z.ai, a mixture-of-experts architecture with 753B total parameters (about 40B active per token), a 1M-token context window, up to 128K output tokens, and selectable reasoning effort levels. The integration includes explicit prompt caching with cache points to reduce latency and input costs for reused context. Availability is limited to eligible enterprise customers via US and Global cross-Region inference profiles in the console and APIs.
Amazon Redshift can now create and refresh Apache Iceberg materialized views, storing precomputed results as Iceberg tables in Amazon S3 and registering them in the AWS Glue Data Catalog. Results become immediately accessible to Iceberg-compatible engines (e.g., Amazon Athena, Apache Spark on EMR, AWS Glue, and third-party engines like Trino and Snowflake). Manual incremental refresh recomputes only changed data to reduce compute and I/O, supporting simpler pipelines and shared, governed outputs without conversion.
Cloudflare’s Birthday Week delivered 46 announcements across security, developer tooling, AI economics, data, and observability. Highlights from Cloudflare include a new cf CLI and the open-source Forge pipeline, EmDash (serverless CMS), a commitment to become a public certificate authority, a post-quantum plan with Merkle Tree Certificates and CryptoLabe-assisted discovery, and IETF work to harden IPsec downgrades. The company also launched Monetization Gateway and Pay Per Use for agent-driven services, GA’d Basin and AI Search, introduced the K2 durable event stream, added post-quantum Web Crypto and faster KV reads in Workers, consolidated observability with Cloudflare Traces, and enhanced Quick Tunnels and account protections.
Google suspended its Open Source Vulnerability Rewards Program until 2027 amid a surge of automated, largely invalid submissions. As reported by Infosecurity, supply-chain reports and previously submitted findings will continue to be processed; the company plans to reformat the program and share details in Q1 2027. During the hiatus, Google advises routing relevant issues through its Cloud VRP, AI VRP, or Patch Rewards Program.