Security Roundup: Citrix NetScaler SAML Zero-Day, Denmark 8.8M Registry Breach, Rejetto AI RCE, Asian Financial Infiltrations (Weekend of October 5, 2026)

ColibriSec Weekend Security Roundup October 5 2026

Executive Summary: The weekend of October 3–5, 2026, delivered an unprecedented surge of critical perimeter exploits, monumental government and enterprise data leaks, and AI-driven intrusion vectors. Headlining the emergency alerts, Citrix confirmed active targeted exploitation of CVE-2026-88779—a high-severity memory overflow zero-day in NetScaler ADC and Gateway configured as SAML SP or IdP—prompting CISA to mandate emergency remediation under BOD 26-04 by October 7. In Europe, Denmark disclosed that unauthorized actors weaponized legitimate partner access to scrape 8.8 million citizen records from the Central Person Register (CPR), while DTU suffered an identity system breach exposing 200,000 users. In Asia, 10.79 million member records were leaked from Japanese restaurant conglomerate Monogatari Corporation, Daiwa Securities suffered a 110,000-account supply chain breach via vendor Scala Communications, and South Korea’s top four banks faced AI-orchestrated credential stuffing waves. Furthermore, an AI model discovered a critical CVSS 9.8 RCE in Rejetto HTTP File Server (CVE-2026-61500) that is now under active wild exploitation, and a key ShinyHunters operator was detained in Jordan cooperating with the FBI. Here is your comprehensive strategic briefing and engineering breakdown.

🏛️
HIGH-SEVERITY THREAT LANDSCAPE: WEEKEND EMERGENCY DIGEST Advanced threat actors, criminal syndicates, and AI-accelerated botnets are weaponizing identity protocols, authorized partner API connections, and edge appliances. Citrix NetScaler zero-day (CVE-2026-88779, CVSS 8.7) under active targeted exploitation; added to CISA KEV on Oct 4 with Oct 7 deadline Denmark Central Person Register (CPR) compromised: 8.8 million citizen records scraped via abused corporate partner access Rejetto HTTP File Server AI-discovered zero-day (CVE-2026-61500, CVSS 9.8) actively exploited in the wild from Chinese IP ranges Monogatari Corporation (Yakiniku King) leaks 10.79 million customer profiles across Japan in major cloud storage breach Daiwa Securities compromises 110,000 client brokerage accounts following server intrusion at vendor Scala Communications South Korea mega-banks (Shinhan, KB Kookmin, Hana, Woori) targeted by high-frequency AI credential stuffing compromising 70,000 accounts ShinyHunters syndicate leadership disrupted as key operative is detained in Amman, Jordan, cooperating with the FBI Technical University of Denmark (DTU) confirms breach of DTUBasen IAM system exposing 200,000 students, faculty, and alumni Enterprise hardening blueprint published covering SAML buffer overflow defenses, partner query quotas, and CSPRNG audit

Key Threat Disclosures at a Glance

1. Citrix NetScaler SAML Memory Overflow Zero-Day (CVE-2026-88779)

Just days after the critical patch cycle for late-September's dual zero-days (CVE-2026-88771/72), Citrix issued security bulletin CTX697174 and CISA immediately added CVE-2026-88779 to the KEV catalog on October 4, 2026. The vulnerability is a memory buffer overflow (CWE-119) within the NetScaler packet engine triggered when processing malformed SAML authentication payloads. Appliances configured as either a SAML Service Provider (samlAction) or SAML Identity Provider (samlIdPProfile) are vulnerable to remote denial of service and memory corruption. CISA has mandated emergency patching across all federal civilian agencies by October 7, 2026.

2. Denmark Central Person Register (CPR) 8.8 Million Citizen Leak

On Monday morning, October 5, 2026, the Danish Ministry of Higher Education, Research, and Digitalisation confirmed a massive security catastrophe: personal information belonging to approximately 8.8 million people—encompassing current residents, expatriates, and deceased citizens—was scraped from the national Det Centrale Personregister (CPR). The threat actors did not breach the core database directly; rather, they hijacked the legitimate API query pipeline of an authorized private Danish firm throughout September 2026, systematically extracting names, addresses, and 10-digit CPR civil registration numbers.

3. Rejetto HFS AI-Discovered RCE Under Active Exploitation (CVE-2026-61500)

In a historic development at the intersection of AI research and threat actor weaponization, CVE-2026-61500 (CVSS 9.8) was identified in Rejetto HTTP File Server (HFS) versions 3.0.0 through 3.2.0. Discovered by researchers using Anthropic’s "Mythos" AI model, the flaw stems from the use of Math.random() for session-cookie signing key derivation combined with the disclosure of PRNG states in unauthenticated login handshakes. Over the weekend, threat telemetry confirmed active wild exploitation targeting exposed servers across the United States and Japan, prompting an urgent upgrade advisory to version 3.2.1.

4. Monogatari Corporation (Yakiniku King) 10.79M Record Breach

Confirmed on October 3, 2026, Japanese restaurant and hospitality titan Monogatari Corporation (operator of the popular Yakiniku King and Marugen Ramen chains) disclosed an extensive database leak. An unauthenticated external entity gained unauthorized access to customer loyalty database clusters, exfiltrating 10,790,000 member records including full customer names, telephone numbers, and email addresses. Forensic response teams have isolated the compromised cloud storage nodes.

5. Daiwa Securities & Scala Communications Third-Party Breach

On October 4, 2026, Japan’s second-largest brokerage, Daiwa Securities Group, disclosed that an external IT vendor, Scala Communications Inc., suffered a server compromise. Threat actors accessed staging and communications servers holding data on approximately 110,000 brokerage clients, exposing account numbers, names, and registered email addresses. This incident highlights the acute risk of fourth-party software dependencies in wealth management.

6. South Korean Mega-Banks Hit by Coordinated AI Credential Stuffing

Financial authorities in South Korea confirmed that four leading commercial banks—Shinhan Bank, KB Kookmin Bank, Hana Bank, and Woori Bank—experienced synchronized account takeover attacks over the weekend. Threat actors deployed automated AI agents to steer distributed residential proxy networks, dynamically varying request timing to bypass web application firewall (WAF) rate limits and successfully compromising approximately 70,000 account holders' financial profiles.

7. ShinyHunters Leadership Fractured: Key Operative Detained in Jordan

International law enforcement confirmed on October 3–5, 2026, that a primary figure in the notorious ShinyHunters cyber extortion syndicate has been taken into custody in Amman, Jordan. The operative is currently cooperating with the Federal Bureau of Investigation (FBI), handing over server keys and decryption tools following weeks of retaliatory leak threats against federal agencies and commercial cloud providers.

8. Technical University of Denmark (DTU) DTUBasen IAM Compromise

In a synchronized Danish identity crisis, the Technical University of Denmark (DTU) disclosed that its core identity management portal, DTUBasen, was breached via compromised administrative credentials. The attackers exfiltrated records spanning from 2003 to 2026, potentially affecting 200,000 active and former students and faculty, exposing CPR numbers, home addresses, and emergency next-of-kin contacts.


Dedicated Technical Deep Dives in This Series

Weekend Action Checklist for CISOs & SecOps

  1. Patch Citrix NetScaler SAML Instances by Oct 7: Audit NetScaler configurations with grep -E 'samlAction|samlIdPProfile' /nsconfig/ns.conf. Upgrade vulnerable builds immediately to 14.1-73.41 or 13.1-64.28, or deploy Citrix Global Deny List signatures.
  2. Audit B2B & Third-Party API Query Quotas: Review all external API integrations that have access to sensitive PII or core databases. Implement strict anomaly thresholds and velocity caps on partner API keys to prevent automated CPR-style scraping.
  3. Remediate Rejetto HFS Instances: Scan internet-facing infrastructure for exposed Rejetto HTTP File Server nodes and immediately upgrade to 3.2.1+ to prevent AI-discovered PRNG session hijacking.
  4. Deploy Behavioral Botnet Defense on Login Portals: Financial institutions and SaaS platforms must implement biometric entropy and residential proxy reputation scoring to thwart AI-orchestrated credential stuffing waves.
  5. Review Legacy IAM Data Retention: Purge historical alumni and former employee records from active directory schemas. Sensitive national identifiers (SSNs, CPR numbers, PESEL) must never reside in unsegmented legacy web databases.

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther