Executive Summary
Facts Only
* Google vulnerability disclosures doubled to 10,000 per month in 2026.
* Researchers developed a Spectre v2 variant that leaked a Linux root password hash in minutes via Kernel cBPF exploit.
* Citrix NetScaler ADC and Gateway appliances were actively exploited with zero-days (CVE-2026-88771 and CVE-2026-88772) leading to remote code execution or denial of service.
* A KernelCTF exploit targets CVE-2026-80521, achieving local root on affected kernels via a use-after-free in AFUNIX socket garbage collection.
* DepthFirst released a container escape exploit for CVE-2026-80521 demonstrating shared kernel risks.
* A U.S. Army soldier was sentenced to 70 months in prison for hacking telecommunications companies and stealing metadata.
* The Dutch police arrested a suspect in the ShinyHunters investigation.
* Researchers found file-notification side channels across operating systems revealing activity without revealing file contents.
* Citrix NetScaler zero-days were actively exploited globally for weeks, with CISA adding them to the KEV catalog.
* A coalition of 44 U.S. state attorneys general fined Labcorp $2.3 million for data security failings related to a 2019 breach.
Full Take
From the original · SC Magazine
First up we talk with Threatlocker CTO Michael Jenkins about threat actors use of AI and keeping the bad things out with Zero Trust.Read the full story at scworld.com
Sentinel — Human
The text reads like a compilation of curated deep-dive security research and expert commentary, stitched together around timely exploits and broader trends, indicating a human journalist or analyst synthesizing complex information.
