This website uses cookies

Read our Privacy policy and Terms of use for more information.

Summary: Mandiant Consulting and Google Threat Intelligence Group say unknown actors exploited newly patched Citrix NetScaler ADC and Gateway flaws in September 2026 against government, financial services, technology, education, and legal organizations in North America and Europe. Exploitation of CVE-2026-88772 (CVSS 9.5) bypasses authentication and crashes the NetScaler Packet Processing Engine to gain root on the FreeBSD appliance. Operators then drop WHIPSHOT, a PHP web shell that hides Base64 C2 in HTTP headers, and SLAPSHOT, a Python TCP tunneler used for internal recon and credential theft. GreyNoise reported a shift from reconnaissance to mass exploitation beginning September 28.

Key takeaway / Actionable note: Apply Citrix CTX697096 patches, then hunt both HA nodes for WHIPSHOT/.deb/.sig webshells before assuming an upgrade cleaned the box.

Summary: Apple released iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1 to fix CVE-2026-86950, an out-of-bounds write in CoreGraphics reported by Meta Product Security. Apple said it is aware the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27. Processing a maliciously crafted file may lead to arbitrary code execution. The company addressed the bug with improved bounds checking.

Key takeaway / Actionable note: Push iOS/iPadOS 26.7.1 and the matching macOS builds immediately on any device that opens untrusted files or attachments.

Summary: FBI Cyber Division Assistant Director Brett Leatherman said Dutch National Police arrested a 24-year-old Amsterdam man described as an alleged ShinyHunters leader. Dutch police said the September 15 arrest recovered laptop material that included details about two murders to be committed abroad, with indications the suspect gave the order; Rotterdam District Court extended pre-trial detention at least 90 days. The FBI says the group and co-conspirators have compromised more than 140 organizations since last year and collected at least $70 million in extortion payments. The warning follows ShinyHunters’ claim it breached FBI systems via an Oracle PeopleSoft zero-day.

Key takeaway / Actionable note: Treat remaining ShinyHunters SaaS/SSO and PeopleSoft exposure as live extortion risk and rotate vendor-connected identities.

Summary: Reporting on a Defense Manpower Data Center incident says attackers accessed a file-sharing server and exposed personal data for about 3 million living and deceased people tied to Department of Defense records. Coverage describes an unauthorized intrusion that lasted for months and included sensitive personnel data such as Social Security numbers and job details. Officials have not published a full victim-notification timeline in the same reports.

Key takeaway / Actionable note: DoD-affiliated personnel should watch official DMDC/DoD notices and freeze credit if they receive a confirmed notification.

Summary: OpenSSL said on September 29 that CVE-2026-84782, a High-severity DTLS issue, can leak heap memory unencrypted to the other side of a connection or crash the program. The condition can occur when a handshake resend starts while a larger handshake message is still being sent. Fixes shipped in OpenSSL 4.0.3, 3.6.5, 3.5.9, and 3.4.8; older 3.0/1.1.1/1.0.2 branches are limited to premium-support customers. OpenSSL has not reported in-the-wild exploitation.

Key takeaway / Actionable note: Patch DTLS-using stacks (WebRTC, VPN, call setup) to the listed OpenSSL versions even though no attacks are confirmed yet.

Summary: Microsoft reported that Russian state group Star Blizzard has used fake event invitations to trick targets into installing a backdoor on Windows computers. The campaign has been tied to more than 100 organizations. Lures impersonate legitimate events to deliver the implant after the recipient engages the invite.

Key takeaway / Actionable note: Treat unsolicited calendar/event files from new senders as malware delivery and enforce attachment detonation plus DMARC-aligned sender checks.

Summary: ANSSI said an attacker used stolen staff passwords at France’s DGFIP tax administration to take data on a little over 350,000 individuals and a little over 250,000 businesses from the E-Contact messaging tool in June and July. Neither DGFIP nor ANSSI saw the data leave at the time. ANSSI called the intrusion unsophisticated and blamed weak login protection, poorly separated networks, and monitoring gaps. Taxpayers’ own online accounts and passwords were not compromised.

Key takeaway / Actionable note: Privileged staff portals need phishing-resistant MFA, network segmentation, and egress monitoring—password reuse alone was enough here.

Summary: Cryptocurrency exchange Bitget said attackers who stole $387.5 million obtained high-level internal credentials through a vulnerability in a third-party security product, then issued fraudulent withdrawal commands that the wallet system treated as routine. Bitcoin withdrawals were later restarted after the incident. Public reporting ties the theft window to last week’s wallet compromise.

Key takeaway / Actionable note: Treat security-tooling vendors as high-value supply chain; isolate their credentials from hot-wallet signing paths.

Summary: BleepingComputer, citing cybersecurity firms, said attackers used CVE-2026-88772 to deploy custom web shells and tunneling malware, gain root, steal credentials, and move into internal networks. CISA added the twin NetScaler RCEs to KEV and set a Wednesday, September 30 federal remediation deadline, requiring forensic triage on affected appliances.

Key takeaway / Actionable note: Federal and critical-infrastructure operators should treat today as the hard CISA deadline and preserve evidence per BOD guidance while patching.

Summary: Kiteworks lifted a precautionary shutdown advisory issued after a federal-intelligence warning and said it patched a critical vulnerability in Advanced Forms used by less than 1% of customers. Hosted systems were brought back online. The company said it found no evidence of exploitation or compromise.

Key takeaway / Actionable note: Self-managed Kiteworks customers should confirm they are on the patched build before reconnecting file-transfer nodes to the internet.

Also Noted:

Bottom line: Edge appliances remain the cheapest path to root. NetScaler operators should patch CVE-2026-88771/88772 and hunt WHIPSHOT/SLAPSHOT persistence on both HA nodes before CISA’s federal clock runs out today. Pair that with Apple’s CoreGraphics emergency builds and a hard look at SaaS/SSO vendors still in ShinyHunters’ blast radius.

Reply

Avatar

or to participate