<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="3.10.0">Jekyll</generator><link href="/feed.xml" rel="self" type="application/atom+xml" /><link href="/" rel="alternate" type="text/html" /><updated>2026-10-07T05:24:59+00:00</updated><id>/feed.xml</id><title type="html">The Hot Drop</title><subtitle>Intel // Tradecraft // Reality</subtitle><entry><title type="html">The Hot Drop for 10-05-2026</title><link href="/blog/the-hot-drop-for-10-05-2026/" rel="alternate" type="text/html" title="The Hot Drop for 10-05-2026" /><published>2026-10-05T13:38:26+00:00</published><updated>2026-10-05T13:38:26+00:00</updated><id>/blog/the-hot-drop-for-10-05-2026</id><content type="html" xml:base="/blog/the-hot-drop-for-10-05-2026/"><![CDATA[<p>Citrix zero-days exploited globally for weeks before patch? And an AI agent just chained two Zammad flaws to breach DIVD. Are we safe?</p>

<p><strong>Since the last show:</strong> 8 developing · 100% overlap with the previous show</p>

<h2 id="contents">Contents</h2>

<ol>
  <li>Citrix NetScaler Zero-Days Exploited Globally for Weeks Before Patch Release</li>
  <li>Citrix patches actively exploited SAML zero-day CVE-2026-88779 in NetScaler ADC and Gateway</li>
  <li>AI Agent Chains Zammad Zero-Days to Breach DIVD</li>
  <li>CISA mandates urgent patch for actively exploited FortiMail zero-day</li>
  <li>ShinyHunters member detained in Jordan, cooperating with FBI</li>
  <li>Microsoft Issues Emergency Exchange Update for Elevation of Privilege Flaw</li>
  <li>CISA and Red Hat issue urgent warning for XZ Utils supply chain compromise</li>
  <li>Warlock ransomware hits critical infrastructure in Portuguese and Spanish-speaking regions</li>
</ol>

<hr />

<h2 id="1-citrix-netscaler-zero-days-exploited-globally-for-weeks-before-patch-release-lead">1. Citrix NetScaler Zero-Days Exploited Globally for Weeks Before Patch Release <em>(Lead)</em></h2>

<p><em>Event now covered by 5 outlets (was 4); Blast radius expanded: new product(s): netscaler gateway, netscaler adc; 1 new indicator(s) observed</em></p>

<h3 id="what-changed">What changed</h3>

<p>Citrix NetScaler appliances have been under active attack for weeks, with attackers exploiting two critical zero-days before the public patch dropped on September 27. The vulnerabilities, CVE-2026-88771 and CVE-2026-88772, allow unauthenticated remote code execution on both ADC and Gateway products. GreyNoise spotted exploitation attempts from IP 149[.]104[.]78[.]141 on September 24, but Mandiant and other researchers indicate the campaign targeting government and financial sectors in North America and Europe started much earlier. Five independent outlets, including Rapid7 and Censys, confirm the core facts, though some reports differ on whether specific APT groups are behind the campaign. CISA added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalog, mandating that federal agencies apply mitigations by September 30, 2026. Private sector defenders need to act now. Check your NetScaler versions immediately; you need 14.1-73.37 or later. Advanced persistent threat groups and ransomware affiliates have confirmed exploitation of Citrix NetScaler ADC. They leveraged lightweight installer web shells to assert the setuid bit on the /bin/sh executable for persistent root-level execution. Attackers gained root access on these FreeBSD-based systems by deploying custom malware named WHIPSHOT and SLAPSHOT. The threat actor conducted credential theft on the compromised appliances, a behavior verified alongside the deployment of the custom malware named WHIPSHOT and SLAPSHOT. Look for the specific IOCs, including the attacker infrastructure IPs 45[.]141[.]21[.]130 and 64[.]94[.]85[.]67.</p>

<h3 id="how-it-works">How it works</h3>

<p>Citrix NetScaler ADC versions before 14.1-73.37 fail input validation, allowing attackers to exploit CVE-2026-88771 for arbitrary command execution. The flaw lets unauthenticated remote attackers bypass authentication entirely to run commands on the FreeBSD-based appliance. Malformed input triggers an out-of-bounds read that leaks cryptographic keys and bypasses ASLR protections. This occurs when the product reads past buffer boundaries while handling VPN or RDP proxy traffic. Additionally, the system fails to parse HTTP request smuggling, enabling unauthorized request injection into back-end servers. Attackers can also exploit improper HTTP URL usage to bypass feature policies and access restricted functionality. With prior access, attackers escalate privileges within the NetScaler infrastructure. The Dutch National Cyber Security Center confirmed these vulnerabilities allow active exploitation on NetScaler ADC and Gateway systems. Citrix NetScaler ADC and Gateway appliances before version 14.1-73.41 face a high-severity flaw, CVE-2026-88779, which expands the active threat beyond initial critical flaws. Versions 14.1 through 73.32 and 13.1 through 63.21 remain exposed to CVE-2026-19490 within a broader event of eleven related vulnerabilities. This weakness allows attackers to bypass ASLR protections, enabling arbitrary code execution without network access. Another flaw enables unauthenticated remote code execution, leading to privilege escalation and denial of service on all default NetScaler appliances. A feature policy bypass via improper HTTP URL expression affects versions before 14.1-73.37, allowing attackers to bypass access controls. The load balancer also suffers from secret injection of malicious HTTP requests, a distinct consequence from other CVEs in this set. The corruption targets organizations in North America and Europe, specifically the government, financial services, education, legal, and professional services sectors.</p>

<h3 id="what-to-do">What to do</h3>

<p>Threat actors are actively exploiting CVE-2026-88772 in Citrix NetScaler ADC and Gateway appliances to achieve remote code execution. Unauthenticated remote attackers can execute arbitrary commands on these appliances, a capability that APT and ransomware groups have already weaponized against government and financial targets. The Dutch National Cyber Security Center has formally warned IT suppliers about active exploitation, confirming that the threat extends beyond isolated incidents to a coordinated campaign against critical infrastructure. Patch Citrix NetScaler Gateway and ADC versions prior to 14.1-73.37 immediately to block this specific request smuggling attack vector. Verify NetScaler inventory against affected version ranges to isolate this specific access precondition before exploitation. Apply the input validation mitigation immediately, as fuzzing remains the only current detection method for this specific overread condition. Verify appliance stability after applying the update, as reports indicate NetScaler devices may reboot repeatedly following the 0-day security patch, requiring a restart to complete the remediation.</p>

<h3 id="limits-and-watch">Limits and watch</h3>

<p>Current evidence confirms no patch date exists for these versions, leaving operators with honest uncertainty regarding immediate remediation options. The specific attribution to state-sponsored APT groups remains contested, with some reports differing on the exact actors behind the campaign. The full extent of credential theft and lateral movement is not yet established. Watch for lateral movement after initial compromise, specifically correlating inbound access to remote service ports with near-time service instability or suspicious child process creation on internal systems. Expect continued broad exploitation by various threat actors in the near term, as experts warn that the campaign targeting North American and European organizations will persist despite the recent patches.</p>

<h3 id="vulnerabilities">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-88772</strong> — CVSS 8.1 (High) · CISA KEV · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2025-5777</strong> — CVSS 7.5 (High) · CISA KEV · CWE-125 · NetScaler ADC; NetScaler Gateway. Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server</li>
  <li><strong>CVE-2026-19490</strong> — CVSS 0 (Low) · CISA KEV · NetScaler ADC; NetScaler Gateway. Vulnerability in NetScaler ADC and NetScaler Gateway.</li>
  <li><strong>CVE-2026-88771</strong> — CVSS 0 (Low) · CISA KEV · CWE-20 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88773</strong> — CVSS 0 (Low) · CWE-444 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Inconsistent interpretation of HTTP requests (‘HTTP Request/Response smuggling’) vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88774</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88775</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88776</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88777</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88778</strong> — CVSS 0 (Low) · CWE-342 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li>and 1 more</li>
</ul>

<h3 id="techniques">Techniques</h3>

<ul>
  <li><strong>AML.T0072</strong> Reverse Shell (Command And Control)</li>
  <li><strong>T1021.001</strong> Remote Desktop Protocol (Lateral Movement)</li>
  <li><strong>T1021.007</strong> Cloud Services (Lateral Movement)</li>
  <li><strong>T1087.001</strong> Local Account (Discovery)</li>
  <li><strong>T1102</strong> Web Service (Command And Control)</li>
  <li><strong>T1133</strong> External Remote Services (Persistence)</li>
  <li><strong>T1136.001</strong> Local Account (Persistence)</li>
  <li><strong>T1190</strong> Exploit Public-Facing Application (Initial Access)</li>
  <li><strong>T1202</strong> Indirect Command Execution (Stealth)</li>
  <li><strong>T1203</strong> Exploitation for Client Execution (Execution)</li>
  <li>and 10 more</li>
</ul>

<h3 id="indicators">Indicators</h3>

<ul>
  <li>25 indicators on file</li>
</ul>

<h3 id="coverage">Coverage</h3>

<ul>
  <li><a href="https://rapid7.com/db/vulnerabilities/cve-2026-88771">CVE-2026-88771: Citrix NetScaler: Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway</a></li>
  <li><a href="https://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772">Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772</a></li>
  <li><a href="https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778">Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778</a></li>
  <li><a href="https://cybersecuritynews.com/citrix-netscaler-0-day-rce-vulnerabilities-exploited">CISA Warns of Citrix NetScaler 0-Day RCE Vulnerabilities Exploited in Attacks</a></li>
  <li><a href="https://thehackernews.com/2026/09/cisa-says-attackers-are-exploiting-two.html">CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally</a></li>
  <li><a href="https://hkcert.org/security-bulletin/citrix-products-multiple-vulnerabilities_20260928">Citrix Products Multiple Vulnerabilities</a></li>
  <li><a href="https://www.helpnetsecurity.com/2026/09/28/citrix-netscaler-rce-zero-days-exploited-for-weeks-cve-2026-88771-cve-2026-88772/">Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)</a></li>
  <li><a href="https://greynoise.io/chronicle/gntl-20260928-citrix-cve-2026-88771">GreyNoise Timeline: Citrix CVE-2026-88771</a></li>
  <li><a href="https://labs.watchtowr.com/oh-look-the-foot-gun-went-off-again-citrix-netscaler-preauth-command-injection-cve-2026-88771">Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771)</a></li>
  <li><a href="https://x.com/imposecost/status/2104249722991243742">Andrew Thompson (@ImposeCost) on X</a></li>
  <li>
    <table>
      <tbody>
        <tr>
          <td>[Kwetsbaarheden in Citrix NetScaler ADC en NetScaler Gateway: update nu</td>
          <td>NCSC](https://ncsc.nl/alerts/kwetsbaarheden-in-citrix-netscaler-adc-en-netscaler-gateway-update-nu)</td>
        </tr>
      </tbody>
    </table>
  </li>
  <li><a href="https://www.cybersecuritydive.com/news/citrix-upgrades-netscaler-exploitation/831502/">Citrix urges immediate upgrades of NetScaler amid widespread exploitation attempts</a></li>
  <li><a href="https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation">Swarming Against Citrix 0-Day Exploitation</a></li>
  <li><a href="https://therecord.media/us-uk-warn-of-citrix-netscaler-zero-day-bug">US, UK warn of exploited Citrix NetScaler zero-day bugs</a></li>
  <li><a href="https://socfortress.medium.com/citrix-netscaler-zero-day-vulnerabilities-faq-cve-2026-88771-and-cve-2026-88772-bbd3d8771308">Citrix NetScaler Zero-Day Vulnerabilities FAQ: CVE-2026–88771 and CVE-2026–88772</a></li>
  <li><a href="https://fortiguard.fortinet.com/threat-signal-report/6533">Citrix NetScaler RCE zero-day Vulnerabilities</a></li>
  <li><a href="https://cyberscoop.com/citrix-zero-days-delayed-disclosure/">Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings</a></li>
  <li><a href="https://www.cybersecuritydive.com/news/citrix-netscaler-exploitation-days-before-notification/831634/">Citrix NetScaler exploitation began days before public notification</a></li>
  <li><a href="https://www.helpnetsecurity.com/2026/09/29/netscaler-zero-day-exploitation-escalates-into-mass-attacks-cve-2026-88771/">NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)</a></li>
  <li><a href="https://censys.com/advisory/cve-2026-10747-2">Sept 28 Advisory: Citrix NetScaler ADC and NetScaler Gateway Zero-Day Remote Code Execution [CVE-2026-88771, CVE-2026-88772] - Censys</a></li>
  <li><a href="https://cert.europa.eu/blog/taking-execute-logging-a-bit-too-literally-cve-2026-88771">Taking ‘execute logging’ a bit too literally - CVE-2026-88771</a></li>
  <li><a href="https://x.com/Unit42_Intel">Unit 42 (@Unit42_Intel) on X</a></li>
  <li><a href="https://labs.watchtowr.com/here-we-go-again-citrix-netscaler-dtls-preauth-memory-overflow-cve-2026-88772">Here We Go Again (Citrix NetScaler DTLS Preauth Memory Overflow CVE-2026-88772)</a></li>
  <li><a href="https://www.theregister.com/security/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-professional-services/5299867">Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services</a></li>
  <li><a href="https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances">Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances</a></li>
</ul>

<hr />

<h2 id="2-citrix-patches-actively-exploited-saml-zero-day-cve-2026-88779-in-netscaler-adc-and-gateway-segment">2. Citrix patches actively exploited SAML zero-day CVE-2026-88779 in NetScaler ADC and Gateway <em>(Segment)</em></h2>

<p><em>No material change since last show</em></p>

<p>Citrix released emergency updates for CVE-2026-88779, a zero-day memory buffer flaw in NetScaler ADC and Gateway appliances currently exploited to cause denial of service. Citrix confirms the primary impact is service disruption through daemon termination, though researcher Kevin Beaumont reported finding malware on a patched honeypot. CISA added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating that federal civilian executive branch agencies prioritize rapid remediation under Binding Operational Directive 26-04. If you run NetScaler appliances with SAML enabled, verify your version immediately. Citrix provides Global Deny Lists as an interim mitigation if you cannot patch instantly. Citrix confirms a flaw in NetScaler ADC and Gateway versions prior to 14.1-73.41 and 13.1-64.28 is exploitable without authentication or user interaction. The vulnerability carries a CVSS score of 8.7 and affects any deployment configured as a SAML Service Provider or Identity Provider, identifiable by specific ‘add authentication samlAction’ entries in your ns[.]conf file. While Citrix verifies the denial-of-service impact, reports of shell commands and malware on patched systems remain unverified by the vendor. Watch for unexpected daemon terminations or outbound connections to the IP 213[.]209[.]159[.]55, which is linked to attacker infrastructure.</p>

<p>The vulnerability is a memory buffer overflow (CWE-119) in the SAML authentication processing that allows unauthenticated remote attackers to trigger a crash by sending malformed data to the appliance. The flaw stems from improper bounds checking during buffer operations, allowing injected parameters to expand beyond allocated memory limits. Attackers trigger this by injecting malicious content that expands buffer parameters, causing unintended control flow and potential code execution. The vulnerability exploits CWE-119 by allowing parameter expansion that overwrites function pointers to redirect control flow. The weakness allows control flow redirection when the product reads or writes outside its buffer boundaries. Attackers are exploiting CVE-2025-6543 in NetScaler ADC 14.1 to trigger a denial of service via memory overflow. This remote zero-day flaw crashes systems, with researchers investigating if it enables remote code execution. The NetScaler Gateway 14.1 crash stems from a memory overflow that hijacks control flow during VPN or RDP proxy access. Successful exploitation causes complete daemon termination, disrupting critical services like SSL VPNs and SSO portals.</p>

<p>The zero-day exploitation of CVE-2026-88779 exposes NetScaler ADC or Gateway appliances using SAML to immediate denial-of-service risk, as the flaw is reachable over the network without credentials. With a CVSS of 9.8 and no authentication required, this weakness enables immediate remote code execution on affected systems. While the primary observed behavior is daemon termination, malware on patched honeypots suggests researchers are probing for T1021.007, Cloud Services, access via federated identities, or T1190, Exploit Public-Facing Application, to achieve code execution. The uncertainty remains whether the current exploit chain stops at service disruption or if the same buffer overflow can be chained for remote code execution in patched environments. Defenders must prioritize checking outbound connections to the known attacker IP 213[.]209[.]159[.]55 and validating that Global Deny Lists are active, as MFA or sandboxing cannot mitigate the initial unauthenticated crash. Isolate NetScaler Gateway 14.1 instances immediately while waiting for the vendor’s patch. Apply the emergency update before 14.1-73.41 and 13.1-64.28 immediately to stop the denial-of-service attacks while researchers confirm the remote code execution possibility. Isolate affected NetScaler ADC 13.1 and 14.1 systems today and apply the language-level protections specified in mitigation guidance. Upgrade to patched versions or apply the language-level constraints recommended in the CISA catalog entry. Isolate affected NetScaler ADC 13.1 FIPS units immediately as the only viable mitigation until vendors release a patched version.</p>

<p>Reports of malware on patched honeypots lack vendor corroboration, leaving the full scope of post-exploitation activity uncertain.</p>

<h3 id="vulnerabilities-1">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2025-6543</strong> — CVSS 9.8 (Critical) · CISA KEV · CWE-119 · NetScaler ADC; NetScaler Gateway. Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual…</li>
  <li><strong>CVE-2026-88779</strong> — CVSS 0 (Low) · NetScaler ADC; NetScaler Gateway. Vulnerability in NetScaler ADC and NetScaler Gateway.</li>
</ul>

<h3 id="techniques-1">Techniques</h3>

<ul>
  <li><strong>T1021.007</strong> Cloud Services (Lateral Movement)</li>
  <li><strong>T1190</strong> Exploit Public-Facing Application (Initial Access)</li>
  <li><strong>T1212</strong> Exploitation for Credential Access (Credential Access)</li>
</ul>

<h3 id="indicators-1">Indicators</h3>

<ul>
  <li>7 indicators on file</li>
</ul>

<h3 id="coverage-1">Coverage</h3>

<ul>
  <li><a href="https://cybersecuritynews.com/citrix-netscaler-saml-0-day-vulnerability">Citrix NetScaler SAML 0-Day Vulnerability Actively Exploited in Attacks</a></li>
  <li><a href="https://socfortress.medium.com/vulnerability-assessment-report-cve-2026-88779-citrix-netscaler-infrastructure-db3a87282358">Vulnerability Assessment Report: CVE-2026–88779 (Citrix NetScaler Infrastructure)</a></li>
  <li><a href="https://www.bleepingcomputer.com/news/security/citrix-patches-netscaler-saml-zero-day-exploited-in-attacks/">Citrix patches NetScaler SAML zero-day exploited in attacks</a></li>
  <li><a href="https://support.citrix.com/external/article/CTX697174/citrix-netscaler-adc-and-citrix-netscale.html">Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88779</a></li>
  <li><a href="https://www.cisa.gov/news-events/alerts/2026/10/04/cisa-adds-one-known-exploited-vulnerability-catalog">CISA Adds One Known Exploited Vulnerability to Catalog</a></li>
</ul>

<hr />

<h2 id="3-ai-agent-chains-zammad-zero-days-to-breach-divd-segment">3. AI Agent Chains Zammad Zero-Days to Breach DIVD <em>(Segment)</em></h2>

<p><em>Blast radius expanded: new vendor(s): zammad; new product(s): zammad, zammad helpdesk platform, linux; 5 new indicator(s) observed</em></p>

<h3 id="what-changed-1">What changed</h3>

<p>On September 21, an autonomous AI agent breached the Dutch Institute for Vulnerability Disclosure by chaining two zero-day flaws in the Zammad ticketing system. The incident involved the exploitation of CVE-2026-102489 and CVE-2026-102490 to hijack sessions, execute remote code, and escalate privileges to root. Zammad GmbH disputed DIVD’s handling of the incident, arguing they could not verify the second flaw due to missing technical details and claiming it requires prior local access. CISA has added both vulnerabilities to its Known Exploited Vulnerabilities catalog, setting a federal remediation deadline for today, October 5, under Binding Operational Directive 26-04. If you run Zammad, verify you are on version 7.2.0 or higher immediately. Look for unusual shell command executions originating from the Zammad service account, specifically those accompanied by verbose comments or unexpected tool invocations. On September 21, an AI agent exploited CVE-2026-102489 for remote code execution and CVE-2026-102490 for privilege escalation, achieving root access on Linux systems running Zammad versions 6.3.0 through 6.5.4. DIVD confirmed that its internal Zammad helpdesk was compromised by this AI agent using these specific zero-day vulnerabilities. The organization verified that the attack allowed intruders to exfiltrate data before containment efforts were successful.</p>

<h3 id="how-it-works-1">How it works</h3>

<p>The attack chain began with CVE-2026-102489, a session hijacking flaw that enabled remote code execution as the Zammad service account. The agent then leveraged CVE-2026-102490, a local privilege escalation vulnerability, to elevate access from the service account to root. This flaw lets the zammad user escalate privileges to root in Zammad versions 1.5.0 through 7.1.0-alpha. The attacker forces a new session without invalidating old identifiers, leveraging predictable session IDs to assume the zammad user’s identity. Because the application uses predictable session identifiers that do not change on privilege elevation, an attacker can forge valid credentials to usurp access. The flaw allows attackers to forge valid session credentials by inducing clients to use attacker-provided identifiers before authentication, leveraging unchanged session IDs during privilege changes. An attacker forces a new login using a forged session ID, bypassing authentication to assume the user’s identity and execute privileged code. Zammad versions 6.3.0 through 6.5.4 face a session hijack flaw allowing remote code execution as the zammad user. Network segmentation at DIVD prevented further lateral movement, but the initial breach resulted in data exfiltration.</p>

<h3 id="what-to-do-1">What to do</h3>

<p>The compromise of the Dutch Institute for Vulnerability Disclosure shows that Zammad versions 6.3.0 through 6.5.4 face a high-impact chain where remote session hijacking leads directly to root-level access. Because the privilege escalation flaw CVE-2026-102490 was actively exploited in this attack, any unpatched Zammad deployment faces immediate risk of total system compromise rather than just service disruption. Understanding Zammad’s specific root escalation distinguishes its high-impact role because this event includes two related CVEs. Defenders must invalidate existing session identifiers before authorizing new ones to block this privilege escalation path.</p>

<h3 id="limits-and-watch-1">Limits and watch</h3>

<p>Zammad GmbH disputes the severity of the second flaw, arguing that CVE-2026-102490 requires prior local access and could not be verified without technical details, which complicates the assessment of remote exploitability. The exact scope of data exfiltration remains unclear, as the attack was stopped by network segmentation before full lateral movement could be confirmed, leaving the extent of initial compromise uncertain. Watch for a spike in invalid session identifiers in Zammad logs, as this is a potential warning sign of session fixation attempts that precede the exploitation of CVE-2026-102489.</p>

<h3 id="vulnerabilities-2">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-102489</strong> — CVSS 9.8 (Critical) · CISA KEV · CWE-384 · Zammad GmbH Zammad. Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user.</li>
  <li><strong>CVE-2026-102490</strong> — CVSS 9.8 (Critical) · CISA KEV · Zammad GmbH Zammad. All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.</li>
</ul>

<h3 id="techniques-2">Techniques</h3>

<ul>
  <li><strong>AML.T0086</strong> Exfiltration via AI Agent Tool Invocation (Exfiltration)</li>
  <li><strong>AML.T0095.000</strong> Code Repositories (Reconnaissance)</li>
  <li><strong>AML.T0108</strong> AI Agent (Command And Control)</li>
  <li><strong>AML.T0112</strong> Machine Compromise (Impact)</li>
  <li><strong>T1053.005</strong> Scheduled Task (Execution)</li>
  <li><strong>T1068</strong> Exploitation for Privilege Escalation (Privilege Escalation)</li>
  <li><strong>T1110.003</strong> Password Spraying (Credential Access)</li>
  <li><strong>T1203</strong> Exploitation for Client Execution (Execution)</li>
  <li><strong>T1212</strong> Exploitation for Credential Access (Credential Access)</li>
  <li><strong>T1213.003</strong> Code Repositories (Collection)</li>
  <li>and 3 more</li>
</ul>

<h3 id="indicators-2">Indicators</h3>

<ul>
  <li>6 indicators on file</li>
</ul>

<h3 id="coverage-2">Coverage</h3>

<ul>
  <li><a href="https://www.securityweek.com/zammad-zero-days-exploited-in-ai-powered-divd-hack/">Zammad Zero-Days Exploited in AI-Powered DIVD Hack</a></li>
  <li><a href="https://securityaffairs.com/200126/hacking/ai-agent-chains-zammad-zero-days-to-take-over-divd-systems-in-seconds.html">AI Agent Chains Zammad Zero-Days To Take Over DIVD Systems in Seconds</a></li>
  <li><a href="https://www.bleepingcomputer.com/news/security/divd-says-zammad-zero-days-enabled-ai-driven-network-breach/">DIVD says Zammad zero-days enabled AI-driven network breach</a></li>
  <li><a href="https://www.helpnetsecurity.com/2026/10/01/divd-agentic-ai-attack-breach/">AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit</a></li>
  <li><a href="https://csirt.divd.nl/downloads/DIVD-2026-00015/cve-2026-102489_ioc_check_script_v2.sh">log check script</a></li>
  <li><a href="https://csirt.divd.nl/cases/DIVD-2026-00014">DIVD-2026-00014 - When, not if…</a></li>
  <li><a href="https://csirt.divd.nl/cves/CVE-2026-102490">Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha</a></li>
  <li><a href="https://www.theregister.com/security/2026/10/01/ai-agents-hacked-the-hackers-stealing-email-addresses-from-security-research-org/5300652">AI agents hacked the hackers, stealing email addresses from security research org</a></li>
  <li><a href="https://csirt.divd.nl/cves/CVE-2026-102489">Undisclosed RCE in Zammad v6.3 and higher</a></li>
  <li><a href="https://www.infosecurity-magazine.com/news/zerodays-dutch-institute/">Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Disclosure</a></li>
  <li><a href="https://gbhackers.com/zammad-vulnerabilities/">Zammad Vulnerabilities Let Attackers Execute Code and Escalate Privileges to Root</a></li>
  <li><a href="https://cybersecuritynews.com/zammad-0-day-vulnerabilities-exploited">Zammad 0-Day Vulnerabilities Exploited to Gain Remote Code Execution and Root Access</a></li>
  <li><a href="https://csirt.divd.nl/cases/DIVD-2026-00015">DIVD-2026-00015 - Vulnerabilities in Zammad during investigation of case DIVD-2026-00014</a></li>
  <li><a href="https://community.zammad.org/t/take-care-local-privilege-escalation-cve-2026-102490-is-reported-as-being-actively-exploited/21297">Public reports from Zammad community members</a></li>
  <li><a href="https://gbhackers.com/two-zammad-zero-days/">Autonomous AI Agent Chains Two Zammad Zero-Days in Machine-Speed Cyberattack</a></li>
  <li><a href="https://gbhackers.com/cisa-adds-zammad-vulnerabilities/">CISA Adds Zammad Vulnerabilities to KEV Following Active Exploitation</a></li>
  <li><a href="https://sysdig.com/blog/ai-agent-exploits-zammad-zero-days-in-divd-breach-what-we-know-and-how-to-detect-it">AI agent exploits Zammad zero-days in DIVD breach: What we know and how to detect it</a></li>
  <li><a href="https://cybersecuritynews.com/zammad-divd-vulnerabilities-exploited">CISA Warns of Zammad DIVD Vulnerabilities Actively Exploited in Attacks</a></li>
</ul>

<hr />

<h2 id="4-cisa-mandates-urgent-patch-for-actively-exploited-fortimail-zero-day-segment">4. CISA mandates urgent patch for actively exploited FortiMail zero-day <em>(Segment)</em></h2>

<p><em>Blast radius expanded: new product(s): fortimail</em></p>

<h3 id="what-changed-2">What changed</h3>

<p>CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog, requiring federal civilian agencies to remediate by October 4, 2026. Fortinet disclosed that the group GBHackers is actively exploiting this critical zero-day to compromise email security appliances. This path traversal flaw lets unauthenticated attackers write arbitrary files and execute code on FortiMail appliances via crafted HTTP or HTTPS requests. Fortinet’s internal researcher Gwendal Guégniaud discovered a critical path traversal flaw in FortiMail, rated 9.8 on the CVSS scale. For detection engineering, this is a classic Exploit Public-Facing Application scenario. Investigate unusual file creation events on FortiMail systems or unexpected outbound connections from mail appliances. One attacker infrastructure IP, 45[.]129[.]0[.]192, is associated with this activity. Until patches are deployed, disable Identity-Based Encryption or restrict management interface access to trusted private networks.</p>

<h3 id="how-it-works-2">How it works</h3>

<p>Fortinet FortiMail 8.0.0 through 8.0.1 allows unauthenticated attackers to write arbitrary files via path traversal exploits. The flaw stems from improper pathname sanitization where crafted HTTP requests resolve outside restricted directories to overwrite critical system files. Attackers exploit the vulnerability by sending specially crafted HTTP or HTTPS requests that leverage improper NULL byte handling to bypass path restrictions. This file write capability enables the execution of arbitrary code or commands on the compromised appliance without requiring login credentials. Separately, Fortinet devices like FortiNDR 7.6.0 are vulnerable to a stack-based buffer overflow [CWE-121] where a remote attacker executes code via crafted hash cookies [vulnerability:CVE-2025-32756]. CVE-2025-32756 enables arbitrary command execution on FortiMail and FortiRecorder with a CVSS score of 9.6. This flaw affects FortiMail versions through 7.6.2 and FortiRecorder versions through 7.2.3. A separate CWE-22 weakness allows adversaries to overwrite critical libraries, achieving full system compromise with a CVSS 9.8 score. The affected FortiMail versions include 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.1. Compromised systems face total loss of confidentiality, integrity, and availability as attackers gain unauthorized control over the email security infrastructure.</p>

<h3 id="what-to-do-2">What to do</h3>

<p>Apply the input validation mitigation from evidence three immediately to block file creation on the underlying system. Isolate affected Fortinet appliances immediately until a patch arrives, as this CVE joins CVE-2026-104286 in today’s event. Validate input using an accept-known-good strategy to prevent path resolution outside restricted directories. Validate all input against a strict whitelist of acceptable paths to neutralize the traversal risk before the next update arrives. Disable Identity-Based Encryption on affected FortiMail appliances immediately to block the unauthenticated write vector while awaiting patches.</p>

<h3 id="limits-and-watch-2">Limits and watch</h3>

<p>Static analysis confirms the flaw, but we cannot verify if an exploit exists in the wild without further observation. Patch release dates for affected FortiMail versions are not yet established, leaving a window of exposure for unpatched systems. It remains unclear whether active exploitation of CVE-2026-104286 links to the separate stack-based buffer overflow in CVE-2025-32756 affecting overlapping FortiMail versions. Watch for inbound network access to FortiMail services that leads to daemon crashes or shells spawning from the service context. Look for suspicious URLs containing invalid or denylisted characters after initial decoding, which may indicate attempts to bypass validation logic via URL encoding.</p>

<h3 id="vulnerabilities-3">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-104286</strong> — CVSS 9.8 (Critical) · CISA KEV · CWE-22 · Fortinet FortiMail. An improper limitation of a pathname to a restricted directory (‘path traversal’) vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0…</li>
  <li><strong>CVE-2025-32756</strong> — CVSS 9.6 (Critical) · CISA KEV · CWE-121 · Fortinet FortiNDR; Fortinet FortiCamera; Fortinet FortiRecorder. A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0…</li>
</ul>

<h3 id="techniques-3">Techniques</h3>

<ul>
  <li><strong>T1021.007</strong> Cloud Services (Lateral Movement)</li>
  <li><strong>T1190</strong> Exploit Public-Facing Application (Initial Access)</li>
  <li><strong>T1204.002</strong> Malicious File (Execution)</li>
  <li><strong>T1210</strong> Exploitation of Remote Services (Lateral Movement)</li>
  <li><strong>T1212</strong> Exploitation for Credential Access (Credential Access)</li>
  <li><strong>T1499.004</strong> Application or System Exploitation (Impact)</li>
</ul>

<h3 id="indicators-3">Indicators</h3>

<ul>
  <li>15 indicators on file</li>
</ul>

<h3 id="coverage-3">Coverage</h3>

<ul>
  <li><a href="https://cybersecuritynews.com/fortimail-0-day-vulnerability-exploited">Critical Fortinet FortiMail 0-Day Vulnerability Actively Exploited in Attacks</a></li>
  <li><a href="https://www.cisa.gov/news-events/alerts/2026/10/01/cisa-adds-one-known-exploited-vulnerability-catalog">CISA Adds One Known Exploited Vulnerability to Catalog</a></li>
  <li><a href="https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/">Fortinet warns of critical FortiMail flaw exploited in zero-day attacks</a></li>
  <li><a href="https://gbhackers.com/fortinet-fortimail-path-traversal-flaw/">Fortinet FortiMail Path Traversal Flaw Actively Exploited to Compromise Servers</a></li>
  <li><a href="https://www.theregister.com/security/2026/10/02/fortinet-sounds-the-alarm-over-actively-exploited-fortimail-zero-day/5300803">Fortinet sounds the alarm over actively exploited FortiMail zero-day</a></li>
  <li><a href="https://www.securityweek.com/exploited-fortinet-fortimail-zero-day-calls-for-urgent-action/">Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action</a></li>
  <li><a href="https://www.helpnetsecurity.com/2026/10/02/fortinet-fortimail-vulnerability-cve-2026-104286/">Critical FortiMail zero-day exploited in the wild (CVE-2026-104286)</a></li>
  <li><a href="https://www.cybersecuritydive.com/news/fortinet-critical-flaw-fortimail-exploitation/832017/">Fortinet warns that critical flaw in FortiMail is facing exploitation</a></li>
  <li><a href="https://cybersecuritynews.com/fortinet-fortimail-0-day-vulnerability-exploitation">CISA Adds Fortinet FortiMail 0-day Vulnerability to KEV Following Active Exploitation</a></li>
</ul>

<hr />

<h2 id="5-shinyhunters-member-detained-in-jordan-cooperating-with-fbi-segment">5. ShinyHunters member detained in Jordan, cooperating with FBI <em>(Segment)</em></h2>

<p><em>Blast radius expanded: new vendor(s): salesforce; 1 new indicator(s) observed; Now attributed to actor: TeamPCP</em></p>

<p>Saif al-Din Khader, a suspected ShinyHunters operative known as Rey, was detained in Jordan and is reportedly cooperating with the FBI to identify other group members. This detention follows the arrest of Pepijn van der Stap, alias Umbreon, in Amsterdam, where he appeared before Rotterdam District Court on October 5, 2026. The group has breached over 140 organizations, including the FBI, ADT, and the European Commission, and extorted over seventy million dollars since last year. For your SOC, note that Khader’s devices are being seized, which may reveal new infrastructure. A key ShinyHunters operative is behind bars in Jordan and talking to the FBI. Reports agree on the detention and cooperation, though one outlet claims ShinyHunters used an Oracle PeopleSoft zero-day to breach FBI systems before moving into AWS GovCloud. The dossier lists fbijobs[.]gov and apply[.]fbijobs[.]gov as victim assets. Multiple reports confirm that Khader is assisting investigators by providing access to his electronic devices and digital correspondence to help track down the organization. The investigation centers on the group’s alleged breach of sensitive personal and medical records of federal employees, with specific victim assets including fbijobs[.]gov and apply[.]fbijobs[.]gov.</p>

<p>In a separate attack on the European Commission, the group utilized compromised AWS credentials and TruffleHog to breach cloud infrastructure via a Trivy supply chain attack. Specific data exposures include approximately 900,000 contact records from Aura and 340 GB of data from the European Commission, which included personal information and email communications.</p>

<p>TeamPCP’s Rey is detained in Jordan today, and his seized devices likely contain the specific email lists and social engineering scripts used to target apply[.]fbijobs[.]gov and other victim portals. This arrest confirms that the group’s recent Oracle PeopleSoft zero-day breach of the FBI was preceded by a deliberate reconnaissance phase where adversaries gathered email addresses to craft targeted spearphishing voice campaigns. The pattern shifts the investigation focus from generic vulnerability exploitation to verifying whether your organization’s public-facing email infrastructure was probed for valid usernames before the initial access event. The group’s use of account use policy bypasses and audit evasion to access AWS GovCloud means your immediate priority is checking if your own login inactivity timeouts and audit logs are enforcing the same restrictions that prevented Rey’s team from moving laterally. While the 900,000 contact records exposed in the Aura breach confirm that mass data collection is a standard precursor to these attacks, the uncertainty remains whether your specific assets were targeted with voice calls or if the breach relied solely on automated enumeration. You must prioritize correlating recent inbound vishing attempts with your internal user activity logs to determine if the threat actor is still active. The detention of ShinyHunters operative Rey in Jordan exposes the group’s reliance on Oracle PeopleSoft zero-day exploits to breach FBI systems and pivot into AWS GovCloud. This confirmed lateral movement from on-premises PeopleSoft to cloud infrastructure indicates that perimeter controls alone are insufficient to contain ShinyHunters’ data exfiltration campaigns. Implement account use policies that enforce lockout mechanisms and inactivity timeouts to mitigate the risk of brute-force attacks and unauthorized access via external remote services. Deploy network monitoring to detect large, iterative quantities of authentication requests from single sources, which indicate adversaries probing for valid email addresses and usernames.</p>

<p>Technical details for the Oracle PeopleSoft zero-day remain unverified because the claim relies on alleged exploitation rather than confirmed patch data. It is not yet established whether ShinyHunters caused the initial compromise of the European Commission’s infrastructure or only handled the subsequent data extortion. Monitor for new disclosures from the FBI regarding the seized devices of Saif al-Din Khader, which may reveal additional infrastructure used to target apply[.]fbijobs[.]gov. Watch for spikes in authentication request volumes from external sources, as this signal indicates active reconnaissance for email addresses preceding potential phishing or brute-force attempts.</p>

<h3 id="techniques-4">Techniques</h3>

<ul>
  <li><strong>T1003.003</strong> NTDS (Credential Access)</li>
  <li><strong>T1005</strong> Data from Local System (Collection)</li>
  <li><strong>T1006</strong> Direct Volume Access (Stealth)</li>
  <li><strong>T1016</strong> System Network Configuration Discovery (Discovery)</li>
  <li><strong>T1018</strong> Remote System Discovery (Discovery)</li>
  <li><strong>T1021.001</strong> Remote Desktop Protocol (Lateral Movement)</li>
  <li><strong>T1021.004</strong> SSH (Lateral Movement)</li>
  <li><strong>T1021.007</strong> Cloud Services (Lateral Movement)</li>
  <li><strong>T1027.003</strong> Steganography (Stealth)</li>
  <li><strong>T1036.005</strong> Match Legitimate Resource Name or Location (Stealth)</li>
  <li>and 10 more</li>
</ul>

<h3 id="named-actors-and-malware">Named actors and malware</h3>

<ul>
  <li>ShinyHunters (actor)</li>
  <li>Cl0p (malware)</li>
  <li>Scattered Spider (actor)</li>
  <li>TeamPCP (actor)</li>
</ul>

<h3 id="indicators-4">Indicators</h3>

<ul>
  <li>3 indicators on file</li>
</ul>

<h3 id="coverage-4">Coverage</h3>

<ul>
  <li><a href="https://securityaffairs.com/200338/cyber-crime/shinyhunters-suspect-detained-in-jordan-helps-fbi-track-down-the-group.html">ShinyHunters Suspect Detained in Jordan Helps FBI Track Down the Group</a></li>
  <li><a href="https://thehackernews.com/2026/10/shinyhunters-suspect-rey-reportedly.html">ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members</a></li>
  <li><a href="https://www.bleepingcomputer.com/news/security/shinyhunters-hacker-reportedly-detained-in-jordan-aiding-fbi/">ShinyHunters hacker reportedly detained in Jordan, aiding FBI</a></li>
  <li><a href="https://helpnetsecurity.com/2026/03/19/aura-data-breach-900000-records">900,000 contact records exposed in Aura data breach - Help Net Security</a></li>
  <li><a href="https://www.securityweek.com/alleged-shinyhunters-leader-arrested-in-jordan/">Alleged ShinyHunters Leader Arrested in Jordan</a></li>
  <li><a href="https://helpnetsecurity.com/2026/04/13/rockstar-games-data-breach-shinyhunters">Rockstar Games receives “pay or leak” warning after cyberattack - Help Net Security</a></li>
  <li><a href="https://helpnetsecurity.com/2026/04/03/european-commission-cloud-breach">Trivy supply chain attack enabled European Commission cloud breach - Help Net Security</a></li>
  <li><a href="https://www.helpnetsecurity.com/2026/10/05/shinyhunters-member-rey-detained-jordan-fbi/">Detained ShinyHunters hacker reportedly helping FBI track down fellow members</a></li>
  <li><a href="https://helpnetsecurity.com/2026/04/27/adt-systems-data-breach">Hackers claim millions of records stolen in ADT breach - Help Net Security</a></li>
</ul>

<hr />

<h2 id="6-microsoft-issues-emergency-exchange-update-for-elevation-of-privilege-flaw-segment">6. Microsoft Issues Emergency Exchange Update for Elevation of Privilege Flaw <em>(Segment)</em></h2>

<p><em>No material change since last show</em></p>

<p>Microsoft released an out-of-band update in September 2026 for CVE-2026-96940, a high-severity elevation of privilege flaw in Exchange Server. An authenticated attacker can read other users’ mailboxes without user interaction. The bug affects on-premises Exchange 2016, 2019, and Subscription Edition, specifically Exchange 2019 CU 14 and 15, and Exchange 2016 CU 23. Microsoft states the issue was found internally with no known active exploitation, but the CVSS score is 8.8, signaling significant risk to confidentiality, integrity, and availability. Exchange Online customers are protected by a service-side fix, but on-premises administrators must act immediately. The update is available only to organizations enrolled in the Period 2 Extended Security Update program, as the affected server versions are out of standard support. If you run on-prem Exchange, verify your ESU enrollment status today and apply the patch to all affected nodes, including management tools. Reports from Microsoft and independent outlets align on the technical details and the lack of active exploitation. Microsoft confirmed the vulnerability was discovered internally and there is no known active exploitation at release. A related service-side fix has already been deployed to Exchange Online, though Microsoft acknowledged a misstep in the rollout sequence.</p>

<p>Microsoft Exchange Server versions 2016 through 2019 contain CWE-1390 weak authentication flaws that let authenticated attackers elevate privileges. Attackers exploit a capture-replay flaw in Exchange Server 2016 and 2019 to replay captured credentials and gain higher access. On versions 15[.]01[.]0[.]0 and 15[.]02[.]0[.]0, authorized attackers replay captured traffic to bypass authentication entirely. This weakness bypasses identity verification, granting unauthorized access to sensitive application data and enabling privilege escalation. The flaw allows remote exploitation over the network with low complexity, requiring only low-level privileges to access email messages and attachments. This weakness grants high integrity and availability impact over the network, enabling attackers to execute unauthorized commands on affected Exchange servers. Anyone on the network with stolen hash or Kerberos credentials gains full access to domain resources. The system leverages NTLM and Kerberos protocols without proper sequence or cryptographic signing, granting full control over the domain. This allows privilege escalation over the network, granting access to resources otherwise hidden behind strict access controls. An authorized user can escalate privileges by reusing stolen domain hashes or Kerberos tickets without new credentials. Successful exploitation results in a high impact to confidentiality, integrity, and availability, allowing attackers to read sensitive data and potentially execute unauthorized commands within the organization.</p>

<p>This specific CVE targets Exchange Server’s authentication mechanism, offering a high-impact path to data exposure and code execution for networked adversaries. Because the flaw relies on captured hash or Kerberos credentials, defenders gain clarity by isolating systems that lack sequence numbering or cryptographic signing for message integrity. Adversaries exploiting this flaw will use the authenticated session to exfiltrate email data, a behavior that aligns with Remote Email Collection techniques and the exploitation of remote services for lateral movement. The framework mitigation options of disabling unnecessary features and applying application isolation suggest that defenders should isolate the Exchange server from the rest of the network to contain any potential breach. However, uncertainty remains regarding whether the attacker has already used the vulnerability to access credentials, so the watch item is monitoring for unauthorized mailbox access logs and credential harvesting attempts on the affected nodes. Defenders gain distinct clarity by isolating this specific access precondition and version scope from the related CVE-2026-62911 event. Verify that Exchange instances use sequence numbers and cryptographic signing to stop replay attacks. Patch affected Exchange updates immediately while monitoring for authentication attempts from inconsistent IP addresses or suspicious software installation on the domain. Run the Exchange Server Health Checker script to verify that all on-premises nodes have received the update and to identify any remaining unpatched instances.</p>

<p>Without confirmed patching, we cannot guarantee this specific replay vector is blocked on legacy Exchange 2016 systems. The evidence does not confirm whether the weak authentication flaw in CVE-2026-96940 has been actively exploited in the wild, only that it allows privilege elevation over a network. It remains unclear if the capture-replay bypass in CVE-2026-62911 shares the same exploitation path as the weak authorization issue, as both affect the same Exchange Server versions but involve distinct CWE weaknesses. Monitor for authentication attempts using previously used credentials from IP addresses inconsistent with normal user locations, as this indicates potential credential replay exploitation.</p>

<h3 id="vulnerabilities-4">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-96940</strong> — CVSS 8.8 (High) · CWE-1390 · Microsoft Microsoft Exchange Server 2016 Cumulative Update 23; Microsoft Microsoft Exchange Server 2019 Cumulative Update 14; Microsoft Microsoft Exchange Server 2019 Cumulative Update 15. Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.</li>
  <li><strong>CVE-2026-62911</strong> — CVSS 8 (High) · CWE-294 · Microsoft Microsoft Exchange Server 2016 Cumulative Update 23; Microsoft Microsoft Exchange Server 2019 Cumulative Update 14; Microsoft Microsoft Exchange Server 2019 Cumulative Update 15. Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.</li>
</ul>

<h3 id="techniques-5">Techniques</h3>

<ul>
  <li><strong>T1114.002</strong> Remote Email Collection (Collection)</li>
  <li><strong>T1203</strong> Exploitation for Client Execution (Execution)</li>
  <li><strong>T1204.002</strong> Malicious File (Execution)</li>
  <li><strong>T1210</strong> Exploitation of Remote Services (Lateral Movement)</li>
  <li><strong>T1212</strong> Exploitation for Credential Access (Credential Access)</li>
  <li><strong>T1218.002</strong> Control Panel (Stealth)</li>
</ul>

<h3 id="indicators-5">Indicators</h3>

<ul>
  <li>1 indicator on file</li>
</ul>

<h3 id="coverage-5">Coverage</h3>

<ul>
  <li><a href="https://techcommunity.microsoft.com/blog/exchange/released-september-2026-v2-exchange-server-security-updates/4561718">Released: September 2026 V2 Exchange Server Security Updates</a></li>
  <li><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96940">CVE-2026-96940 - Security Update Guide - Microsoft</a></li>
  <li><a href="https://cybersecuritynews.com/microsoft-reissues-exchange-server-update">Microsoft Pushes New Exchange V2 Update After Discovering New Security Flaw</a></li>
  <li><a href="https://www.helpnetsecurity.com/2026/10/05/exchange-server-vulnerability-cve-2026-96940/">Out-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940)</a></li>
</ul>

<hr />

<h2 id="7-cisa-and-red-hat-issue-urgent-warning-for-xz-utils-supply-chain-compromise-segment">7. CISA and Red Hat issue urgent warning for XZ Utils supply chain compromise <em>(Segment)</em></h2>

<p><em>Event first seen in a show</em></p>

<h3 id="what-changed-3">What changed</h3>

<p>CISA issued an urgent advisory identifying a supply chain compromise in the XZ Utils data compression library, affecting versions 5.6.0 and 5.6.1. This newly confirmed threat, designated CVE-2024-3094, represents a critical shift in the security posture of a widely used open-source utility. CISA and Red Hat issued urgent advisories for a supply chain compromise in XZ Utils versions 5.6.0 and 5.6.1, identified as CVE-2024-3094. The malicious code allows threat actors to bypass authentication and gain unauthorized remote access to affected Linux systems. Red Hat verified that while Red Hat Enterprise Linux is unaffected, the compromise actively impacts Fedora Rawhide, Fedora 40 beta, Debian unstable, and several openSUSE distributions. You must immediately halt usage of compromised instances and downgrade to safe versions, specifically the 5.4.x series, such as 5.4.6 Stable.</p>

<h3 id="how-it-works-3">How it works</h3>

<p>The attack chain begins with the liblzma build process extracting a prebuilt object file from a disguised test file within the source code. Complex obfuscations modify specific library functions, embedding a virus into DLL gaps to grant unauthorized code execution. This results in a modified liblzma library that intercepts and modifies data interactions, specifically interfering with SSH authentication processes during the build to facilitate unauthorized access. This compromise grants unauthorized code execution with full confidentiality, integrity, and availability impact. Any software linked against the modified library faces unauthorized code execution, causing a complete loss of confidentiality, integrity, and availability. With a CVSS score of 10, the vulnerability allows network-based attacks with low complexity, requiring no prior privileges or user interaction.</p>

<h3 id="what-to-do-3">What to do</h3>

<p>The compromise of XZ Utils versions 5.6.0 and 5.6.1 exposes Fedora Rawhide, Fedora 40 beta, Debian unstable, and openSUSE systems to unauthorized remote access by intercepting SSH authentication data. Because the malicious code is embedded in the liblzma library, any software linked against the compromised version can be manipulated to alter data interactions, creating a broad exposure surface beyond just the compression utility itself. Run a binary or bytecode disassembler on the liblzma library to find and strip the obfuscated malicious code hidden in the source tarballs. Manually analyze the binaries to locate and remove the embedded virus.</p>

<h3 id="limits-and-watch-3">Limits and watch</h3>

<p>Complex obfuscation hides the malicious code, so standard automated scanning may miss the embedded logic. You must perform detailed manual review to confirm complete removal. It remains unclear if the compromised liblzma library reached production environments beyond the identified beta and unstable distributions. This leaves the full scope of exposure uncertain. Watch for package managers installing from non-approved repositories or new ELF binaries appearing in PATH directories. Check for changes to SSH clients or libraries that signal an adversary is establishing persistent access or collecting credentials.</p>

<h3 id="vulnerabilities-5">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2024-3094</strong> — CVSS 10 (Critical) · CWE-506 · Red Hat Red Hat Enterprise Linux 10; Red Hat Red Hat Enterprise Linux 6; Red Hat Red Hat Enterprise Linux 7. Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0.</li>
</ul>

<h3 id="techniques-6">Techniques</h3>

<ul>
  <li><strong>T1195</strong> Supply Chain Compromise (Initial Access)</li>
  <li><strong>T1195.001</strong> Compromise Software Dependencies and Development Tools (Initial Access)</li>
  <li><strong>T1195.003</strong> Compromise Hardware Supply Chain (Initial Access)</li>
  <li><strong>T1554</strong> Compromise Host Software Binary (Persistence)</li>
  <li><strong>T1588.007</strong> Artificial Intelligence (Resource Development)</li>
</ul>

<h3 id="indicators-6">Indicators</h3>

<ul>
  <li>9 indicators on file</li>
</ul>

<h3 id="coverage-6">Coverage</h3>

<ul>
  <li>
    <table>
      <tbody>
        <tr>
          <td>[Reported Supply Chain Compromise Affecting XZ Utils Data Compression Library, CVE-2024-3094</td>
          <td>CISA](https://cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094)</td>
        </tr>
      </tbody>
    </table>
  </li>
  <li><a href="https://cybersecuritynews.com/linux-tool-malware-embedded">Red Hat Warns of Malware Code Embedded in Popular Linux Tool Allow Unauthorized Access to Systems</a></li>
  <li><a href="https://debugactiveprocess.medium.com/reverse-engineering-as-counterintelligence-in-2026-from-malware-artifacts-to-defensive-decisions-3a63c9759bd5">Reverse Engineering as Counterintelligence in 2026: From Malware Artifacts to Defensive Decisions</a></li>
</ul>

<hr />

<h2 id="8-warlock-ransomware-hits-critical-infrastructure-in-portuguese-and-spanish-speaking-regions-segment">8. Warlock ransomware hits critical infrastructure in Portuguese and Spanish-speaking regions <em>(Segment)</em></h2>

<p><em>Event now covered by 3 outlets (was 2); Now attributed to malware: LockBit ransomware</em></p>

<h3 id="what-changed-4">What changed</h3>

<p>Symantec attributes Warlock ransomware deployments to a Chinese threat group targeting critical infrastructure in Portuguese and Spanish-speaking countries. The group actively exploits unpatched Microsoft SharePoint vulnerabilities to compromise water utilities, telecommunications providers, universities, and regional governments. Symantec researchers verified that the attackers are leveraging SharePoint deployments that lack patches for both the 2025 vulnerabilities and the 2026 bugs. This activity persists despite prior warnings issued by Microsoft and CISA regarding these specific SharePoint security flaws. For detection engineering, focus on SharePoint servers with unapplied patches and anomalous administrative traffic. Watch for the domain truemedia[.]org, though its specific role is not yet confirmed. The primary signal to monitor is unpatched SharePoint instances in critical infrastructure sectors within the affected geographic scope.</p>

<h3 id="how-it-works-4">How it works</h3>

<p>The attack chain begins with the exploitation of unpatched SharePoint vulnerabilities to gain initial access to the target network. The Warlock ransomware strain specifically targets critical infrastructure organizations located in Portuguese- and Spanish-speaking countries.</p>

<h3 id="what-to-do-4">What to do</h3>

<p>Standard patching cycles have failed to close the attack surface for water utilities, telecommunications providers, and regional governments across Europe, Africa, and Latin America. Prioritize</p>

<h3 id="limits-and-watch-4">Limits and watch</h3>

<p>The specific role of the domain truemedia[.]org in the attack chain remains unconfirmed, limiting the ability to use it as a definitive indicator of compromise. Current evidence does not establish whether the attackers have successfully disabled security software on all targeted critical infrastructure systems, leaving the scope of active compromise uncertain. Track social media reconnaissance activities targeting staff roles and locations in the affected regions to detect early-stage preparation for phishing or spearphishing campaigns.</p>

<h3 id="techniques-7">Techniques</h3>

<ul>
  <li><strong>T1001.003</strong> Protocol or Service Impersonation (Command And Control)</li>
  <li><strong>T1005</strong> Data from Local System (Collection)</li>
  <li><strong>T1008</strong> Fallback Channels (Command And Control)</li>
  <li><strong>T1010</strong> Application Window Discovery (Discovery)</li>
  <li><strong>T1012</strong> Query Registry (Discovery)</li>
  <li><strong>T1016</strong> System Network Configuration Discovery (Discovery)</li>
  <li><strong>T1021.001</strong> Remote Desktop Protocol (Lateral Movement)</li>
  <li><strong>T1021.002</strong> SMB/Windows Admin Shares (Lateral Movement)</li>
  <li><strong>T1021.004</strong> SSH (Lateral Movement)</li>
  <li><strong>T1027.007</strong> Dynamic API Resolution (Stealth)</li>
  <li>and 10 more</li>
</ul>

<h3 id="named-actors-and-malware-1">Named actors and malware</h3>

<ul>
  <li>LockBit (malware)</li>
  <li>Lazarus group (actor)</li>
  <li>LockBit ransomware (malware)</li>
</ul>

<h3 id="indicators-7">Indicators</h3>

<ul>
  <li>1 indicator on file</li>
</ul>

<h3 id="coverage-7">Coverage</h3>

<ul>
  <li>
    <table>
      <tbody>
        <tr>
          <td>[Threat intelligence REST API</td>
          <td>ThreatCluster](https://threatcluster.io/api)</td>
        </tr>
      </tbody>
    </table>
  </li>
  <li><a href="https://play.prx.org/listen?ge=prx_8376_90132bf3-877e-4b94-8f00-ff2411ab6096&amp;uf=https%3A%2F%2Fpublicfeeds.net%2Ff%2F8376%2Fclickhere">How AI can debunk a conspiracy theory in 8 minutes</a></li>
  <li><a href="https://play.prx.org/listen?ge=prx_8376_6507442c-48e0-48f2-885e-717ea54e9981&amp;uf=https%3A%2F%2Fpublicfeeds.net%2Ff%2F8376%2Fclickhere">How Bellingcat finds the truth in the age of AI</a></li>
  <li><a href="https://therecord.media/warlock-ransomware-used-in-critical-infrastructure-attacks">‘Warlock’ ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries</a></li>
</ul>]]></content><author><name></name></author><summary type="html"><![CDATA[Citrix zero-days exploited globally for weeks before patch? And an AI agent just chained two Zammad flaws to breach DIVD. Are we safe?]]></summary></entry><entry><title type="html">The Hot Drop for 10-02-2026</title><link href="/blog/the-hot-drop-for-10-02-2026/" rel="alternate" type="text/html" title="The Hot Drop for 10-02-2026" /><published>2026-10-02T13:27:59+00:00</published><updated>2026-10-02T13:27:59+00:00</updated><id>/blog/the-hot-drop-for-10-02-2026</id><content type="html" xml:base="/blog/the-hot-drop-for-10-02-2026/"><![CDATA[<p>CISA mandates workarounds by Oct 4 for an actively exploited FortiMail zero-day that lets attackers write files and run code. Meanwhile, Cisco patches a 9.8 CVSS SD-WAN auth bypass, and Microsoft reveals Zimbra SNMP exploitation still</p>

<p><strong>Since the last show:</strong> 3 new · 6 developing · 1 returning · 4 dropped · 43% overlap with the previous show</p>

<h2 id="contents">Contents</h2>

<ol>
  <li>CISA mandates urgent remediation for actively exploited FortiMail zero-day CVE-2026-104286</li>
  <li>Cisco Patches Actively Exploited Zero-Day in Catalyst SD-WAN Manager; CISA Adds to KEV</li>
  <li>Zimbra SNMP Exploitation Continues</li>
  <li>Citrix NetScaler Zero-Days Exploited Globally for Weeks Before Patch Release</li>
  <li>JadePuffer AI Agent Executes First End-to-End Ransomware Campaign via Langflow Flaw</li>
  <li>AI Agent Chains Zammad Zero-Days to Breach DIVD</li>
  <li>ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach Universities, FBI, and Nissan</li>
  <li>Apple patches CoreGraphics zero-day exploited in targeted attacks</li>
  <li>CISA adds AI-discovered BeyondTrust RCE to KEV as Google reports vulnerability disclosures double</li>
  <li>ThreatCluster Launches Free Threat Intelligence API</li>
</ol>

<hr />

<h2 id="1-cisa-mandates-urgent-remediation-for-actively-exploited-fortimail-zero-day-cve-2026-104286-lead">1. CISA mandates urgent remediation for actively exploited FortiMail zero-day CVE-2026-104286 <em>(Lead)</em></h2>

<p><em>Event first seen in a show</em></p>

<h3 id="what-changed">What changed</h3>

<p>CISA has ordered federal agencies to patch a FortiMail zero-day by October fourth. Fortinet confirmed active exploitation in advisory FG-IR-26-175, issued October 1, 2026. Discovered internally by Gwendal Guégniaud, this path traversal flaw allows unauthenticated attackers to write arbitrary files and execute code on the server. While BleepingComputer and Help Net Security report consistent details, the specific version list comes from a single source, so verify your inventory against Fortinet’s official documentation. Until patches are available, Fortinet recommends disabling Identity-Based Encryption or restricting management interface access. If you run FortiMail, check your logs for unauthorized file creation immediately. Look for unusual file writes to the FortiMail filesystem or unexpected command execution via the management interface. Watch for traffic to the attacker infrastructure IP 45[.]129[.]0[.]192, though other indicators in the dossier are less certain. CVE-2026-104286 is actively exploited in the wild, so this is not a theoretical risk. The flaw is a path traversal vulnerability with a CVSS score of 9.8, discovered internally by Gwendal Guégniaud. Affected versions span 7.2 through 7.2.9, 7.4 through 7.4.8, 7.6 through 7.6.6, and 8.0 through 8.0.1. The MITRE techniques involved are Exploitation of Remote Services and Exploitation for Credential Access. CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog, reinforcing Binding Operational Directive 26-04 for federal agencies.</p>

<h3 id="how-it-works">How it works</h3>

<p>An unauthenticated attacker triggers CVE-2025-32756 by sending crafted HTTP requests with specially designed hash cookies to the FortiCamera service. Fortinet FortiMail versions 8.0.0 through 8.0.1 also face a path traversal flaw where unauthenticated attackers write arbitrary files via crafted HTTP requests. These attackers exploit improper NULL byte handling and path traversal to write arbitrary files on the underlying system using crafted HTTP or HTTPS requests. This file write capability allows the attacker to execute arbitrary code or commands on the server without requiring login credentials. Fortinet devices running FortiCamera versions 2.1.0 through 2.1.3 face a remote stack-based buffer overflow that allows arbitrary code execution. This flaw lets attackers overwrite critical programs or libraries, enabling unauthorized code execution with a CVSS score of 9.8. The group GBHackers has actively exploited this vulnerability to compromise email security appliances, prompting Fortinet to recommend disabling Identity-Based Encryption as an interim mitigation.</p>

<h3 id="what-to-do">What to do</h3>

<p>The flaw grants attackers arbitrary file write capabilities on the underlying system, effectively converting a mail gateway into a foothold for lateral movement into internal networks. Operators must immediately isolate FortiCamera 2.1.0 through 2.1.3 units and apply the vendor patch before the next scheduled maintenance window. Defenders must apply the latest patch immediately and validate all incoming HTTP and HTTPS requests against strict path specifications. Defenders must apply input validation to reject non-conforming paths immediately per mitigation guidance. Defenders must apply the latest patch immediately and implement input validation that rejects any path containing dot-dot-slash sequences.</p>

<h3 id="limits-and-watch">Limits and watch</h3>

<p>Automated static analysis detects the flaw, but confirming the specific impact requires manual white box analysis of the affected FortiMail version. Version ranges for CVE-2026-104286 differ from the broader Fortinet list in CVE-2025-32756, so inventory verification must distinguish the path traversal flaw from the separate stack-based buffer overflow to avoid misapplied patches. Although the path traversal mechanism is confirmed, the extent of lateral movement beyond the initial FortiMail compromise remains unverified, leaving the full scope of internal network exposure uncertain. Monitor for inbound network access to FortiMail management ports that correlates with near-time service instability or abnormal restarts, as this pattern indicates successful exploitation of the remote service.</p>

<h3 id="vulnerabilities">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-104286</strong> — CVSS 9.8 (Critical) · CISA KEV · CWE-22 · Fortinet FortiMail. An improper limitation of a pathname to a restricted directory (‘path traversal’) vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0…</li>
  <li><strong>CVE-2025-32756</strong> — CVSS 9.6 (Critical) · CISA KEV · CWE-121 · Fortinet FortiNDR; Fortinet FortiCamera; Fortinet FortiRecorder. A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0…</li>
</ul>

<h3 id="techniques">Techniques</h3>

<ul>
  <li><strong>T1210</strong> Exploitation of Remote Services (Lateral Movement)</li>
  <li><strong>T1212</strong> Exploitation for Credential Access (Credential Access)</li>
</ul>

<h3 id="indicators">Indicators</h3>

<ul>
  <li>15 indicators on file</li>
</ul>

<h3 id="coverage">Coverage</h3>

<ul>
  <li><a href="https://cybersecuritynews.com/fortimail-0-day-vulnerability-exploited">Critical Fortinet FortiMail 0-Day Vulnerability Actively Exploited in Attacks</a></li>
  <li><a href="https://www.cisa.gov/news-events/alerts/2026/10/01/cisa-adds-one-known-exploited-vulnerability-catalog">CISA Adds One Known Exploited Vulnerability to Catalog</a></li>
  <li><a href="https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/">Fortinet warns of critical FortiMail flaw exploited in zero-day attacks</a></li>
  <li><a href="https://gbhackers.com/fortinet-fortimail-path-traversal-flaw/">Fortinet FortiMail Path Traversal Flaw Actively Exploited to Compromise Servers</a></li>
  <li><a href="https://www.theregister.com/security/2026/10/02/fortinet-sounds-the-alarm-over-actively-exploited-fortimail-zero-day/5300803">Fortinet sounds the alarm over actively exploited FortiMail zero-day</a></li>
  <li><a href="https://www.securityweek.com/exploited-fortinet-fortimail-zero-day-calls-for-urgent-action/">Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action</a></li>
  <li><a href="https://www.helpnetsecurity.com/2026/10/02/fortinet-fortimail-vulnerability-cve-2026-104286/">Critical FortiMail zero-day exploited in the wild (CVE-2026-104286)</a></li>
</ul>

<hr />

<h2 id="2-cisco-patches-actively-exploited-zero-day-in-catalyst-sd-wan-manager-cisa-adds-to-kev-segment">2. Cisco Patches Actively Exploited Zero-Day in Catalyst SD-WAN Manager; CISA Adds to KEV <em>(Segment)</em></h2>

<p><em>CVE-2026-76504 added to CISA KEV catalog; 3 new indicator(s) observed</em></p>

<p>Cisco released urgent patches for CVE-2026-76504, a critical zero-day in Catalyst SD-WAN Manager already under active exploitation. Exploitation began in September 2026, affecting versions 20.9 through 26.2. CISA added the flaw to the Known Exploited Vulnerabilities catalog, requiring federal agencies to remediate by October 3, 2026. This is the eighth Cisco SD-WAN CVE on the KEV list this year, showing persistent targeting of the platform. If you run on-prem Catalyst SD-WAN Manager, verify your version immediately. Cisco confirmed that exploitation of this zero-day began in September 2026, with the flaw tracked as CVE-2026-76504. The vulnerability carries a CVSS score of 9.8 and is classified under CWE-177 for improper handling of URL encoding. The flaw allows unauthenticated attackers to bypass authentication and seize administrative control by exploiting improper URI encoding handling.</p>

<p>Cisco ISE versions 3.1.0 through 3.5.0 remain vulnerable to CVE-2026-76460, allowing unauthenticated attackers to bypass login by misusing privileged APIs. By exploiting this encoding weakness, an unauthenticated remote attacker can gain access to the API with the privileges of the admin user. Similarly, Cisco Catalyst SD-WAN Manager versions 17.2.4 through 18.4.3 let an unauthenticated attacker bypass session rules by double-encoding the URI path. The vulnerability affects all configurations of the Cisco Catalyst SD-WAN Manager, including releases prior to 20[.]9[.]10[.]1. Affected versions range from 3.1.0 p8 through 3.5.0, allowing remote code execution and data theft without prior authentication. That improper URL handling grants admin privileges immediately, matching the high integrity and availability scores in the CISA catalog. Exploitation grants full device control across versions from 3.1.0 p8 through 3.5.0.</p>

<p>This creates remaining uncertainty about whether your current monitoring is catching these requests, so the most useful investigation focus is to search the serviceproxy-access[.]log and vmanage-server[.]log for any unauthorized requests from unknown IP addresses that do not match your known management traffic patterns. You should verify if these requests successfully triggered administrative actions, as that would confirm the exploit chain is active despite your current logging rules. This incident is part of a broader pattern of Cisco SD-WAN targeting, as it is the eighth related CVE added to the CISA Known Exploited Vulnerabilities catalog this year. Apply the Cisco software updates for CVE-2026-76504 immediately, as no workarounds exist for this authentication bypass. Block HTTP TRACE and verify API assumptions immediately to stop privilege escalation. Validate input against known-good specifications now, rejecting any request that does not strictly conform to the API spec. Verify your ISE software version today and isolate affected nodes until Cisco releases a fix for the privilege escalation. Restrict HTTP TRACE requests to prevent cross-site tracing attacks that could leverage this flaw. Block all unauthenticated API traffic to affected Cisco Catalyst SD-WAN Manager instances until a vendor patch arrives. Validate all HTTP inputs against known-good specifications and reject any malformed encoding to stop the unauthorized admin takeover. Isolate affected ISE nodes until vendors release fixes for these specific patches.</p>

<p>The CVSS score signals high severity, but the exploit chain demands either HTTP TRACE enablement or a process hijacking bug to succeed. Current evidence does not establish active exploitation for CVE-2026-76460 in Cisco Identity Services Engine, despite its KEV catalog status. It remains unknown whether the URI encoding flaw in CVE-2026-76504 has pivoted into other internal services beyond the SD-WAN Manager. Monitor for inbound network access to remote service ports that correlates with near-time instability or abnormal restarts in the SD-WAN Manager service.</p>

<h3 id="vulnerabilities-1">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-76460</strong> — CVSS 10 (Critical) · CISA KEV · CWE-648 · Cisco Cisco Identity Services Engine Software; Cisco Cisco ISE Passive Identity Connector. A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication.</li>
  <li><strong>CVE-2026-76504</strong> — CVSS 9.8 (Critical) · CISA KEV · CWE-177 · Cisco Cisco Catalyst SD-WAN Manager. A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.</li>
</ul>

<h3 id="techniques-1">Techniques</h3>

<ul>
  <li><strong>AML.T0106</strong> Exploitation for Credential Access (Credential Access)</li>
  <li><strong>T1190</strong> Exploit Public-Facing Application (Initial Access)</li>
  <li><strong>T1203</strong> Exploitation for Client Execution (Execution)</li>
  <li><strong>T1210</strong> Exploitation of Remote Services (Lateral Movement)</li>
  <li><strong>T1212</strong> Exploitation for Credential Access (Credential Access)</li>
  <li><strong>T1590.004</strong> Network Topology (Reconnaissance)</li>
</ul>

<h3 id="indicators-1">Indicators</h3>

<ul>
  <li>6 indicators on file</li>
</ul>

<h3 id="coverage-1">Coverage</h3>

<ul>
  <li><a href="https://rapid7.com/db/vulnerabilities/cve-2026-76504">CVE-2026-76504: Cisco Cisco Catalyst SD-WAN Manager: A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an…</a></li>
  <li><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU?vs_f=Cisco+Security+Advisory%26vs_cat%3DSecurity+Intelligence%26vs_type%3DRSS%26vs_p%3DCisco+Catalyst+SD-WAN+Manager+API+Authentication+Bypass+Vulnerability%26vs_k%3D1">Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability</a></li>
  <li><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU">Cisco Security Advisory: Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability</a></li>
  <li><a href="https://www.cisa.gov/news-events/alerts/2026/09/30/cisa-adds-one-known-exploited-vulnerability-catalog">CISA Adds One Known Exploited Vulnerability to Catalog</a></li>
  <li><a href="https://gbhackers.com/critical-cisco-sd-wan-vulnerability/">Critical Cisco SD-WAN Vulnerability Lets Remote Attackers Bypass Authentication as Admin</a></li>
  <li><a href="https://cybersecuritynews.com/cisco-sd-wan-manager-0-day-flaw">Cisco SD-WAN Manager Authentication 0-day Vulnerability Actively Exploited in the Wild</a></li>
  <li><a href="https://thehackernews.com/2026/10/cisa-adds-exploited-cisco-catalyst-sd.html">CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV</a></li>
  <li><a href="https://www.helpnetsecurity.com/2026/10/01/new-cisco-sd-wan-zero-day-exploited-in-the-wild-cve-2026-76504/">New Cisco SD-WAN zero-day exploited in-the-wild (CVE-2026-76504)</a></li>
  <li><a href="https://www.securityweek.com/cisco-patches-exploited-catalyst-sd-wan-zero-day-vulnerability/">Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability</a></li>
  <li><a href="https://www.csoonline.com/article/4229603/cisco-sd-wan-manager-hit-by-zero-day-admin-access-attack-2.html">Cisco SD-WAN Manager hit by zero-day admin access attack</a></li>
  <li><a href="https://cisco.com/c/en/us/support/docs/routers/sd-wan/226384-remediate-catalyst-sd-wan-security.html">Remediate Catalyst SD-WAN Security Advisory - September 2026</a></li>
  <li><a href="https://www.infosecurity-magazine.com/news/critical-cisco-catalyst-sdwan/">Critical Cisco Catalyst SD-WAN Zero-Day Under Active Exploitation</a></li>
</ul>

<hr />

<h2 id="3-zimbra-snmp-exploitation-continues-segment">3. Zimbra SNMP Exploitation Continues <em>(Segment)</em></h2>

<p><em>No material change since last show</em></p>

<p>Microsoft confirmed attackers actively exploited CVE-2026-73570 in Zimbra Collaboration Suite between July 28 and August 7, 2026, weeks before public disclosure on August 13. The vulnerability is an unauthenticated command injection bug in the zimbra-snmp package. Attackers executed arbitrary commands via crafted SNMP notifications. The attack chain typically involved deploying JSP web shells, escalating privileges to root through PAM modifications, and exfiltrating mailbox data and credentials to Azure Blob Storage. Shadowserver Foundation reported that approximately ten thousand instances remained compromised at the time of reporting, despite Synacor releasing a patch in version 10.1.20 on July 20, 2026. CISA has added this to its Known Exploited Vulnerabilities catalog, mandating federal patching by August 24. Microsoft Security Research verified the exploitation window and specific attack vectors, corroborated by reports from Ars Technica and other outlets. The dossier lists specific attacker infrastructure, including domains like dnslog[.]pp[.]ua and IP addresses such as 117[.]107[.]25[.]243. Look for unexpected outbound connections from Zimbra servers to Azure Blob Storage or unusual SNMP traffic patterns. Verify if your environment is running unpatched versions of Zimbra, specifically checking for the presence of JSP web shells in web directories.</p>

<p>The flaw stems from improper neutralization of special elements in OS commands, allowing attackers to bypass input validation through multiple parser passes. Attackers then escalated privileges to root by modifying PAM configurations and established persistent access through a systemd service named zimlog[.]service. Microsoft observed active scanning and probing across multiple regions between July 28 and August 7, showing the exploitation was not limited to a single sector or geographic area.</p>

<p>Unauthenticated attackers executed arbitrary commands on Zimbra servers between July 28 and August 7, 2026, to deploy JSP web shells and escalate privileges to root. This remote code execution flaw carries a CVSS score of 8.9, granting attackers full system control as the Zimbra user. The exploitation chain resulted in the theft of mailbox data and authentication credentials, leaving approximately ten thousand instances compromised. Operators must disable SNMP notifications immediately to prevent further full system compromise. Search web directories for unauthorized JSP files and inspect system configurations for the zimlog[.]service systemd unit to identify persistent access mechanisms deployed by attackers.</p>

<p>The vulnerability only affects Zimbra Collaboration versions prior to 10.1.20 where the optional zimbra-snmp package is installed and SNMP notifications are enabled. Automated static analysis tools may produce false positives when detecting this weakness because they may not recognize when proper input validation is being performed. Watch for unexpected file creation in web directories followed by web server processes spawning command shells or script interpreters to detect web shell deployment. Also watch for repeated detection of control characters by filters, which indicates an attacker is using multiple input interpretation layers to bypass validation logic.</p>

<h3 id="vulnerabilities-2">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-73570</strong> — CVSS 8.9 (High) · CISA KEV · CWE-78 · Zimbra Collaboration. A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled.</li>
</ul>

<h3 id="techniques-2">Techniques</h3>

<ul>
  <li><strong>AML.T0006</strong> Active Scanning (Reconnaissance)</li>
  <li><strong>AML.T0049</strong> Exploit Public-Facing Application (Initial Access)</li>
  <li><strong>AML.T0050</strong> Command and Scripting Interpreter (Execution)</li>
  <li><strong>AML.T0072</strong> Reverse Shell (Command And Control)</li>
  <li><strong>EMERGING-0035</strong> RedFlick</li>
  <li><strong>T1053</strong> Scheduled Task/Job (Execution)</li>
  <li><strong>T1053.005</strong> Scheduled Task (Execution)</li>
  <li><strong>T1078.003</strong> Local Accounts (Stealth)</li>
  <li><strong>T1087.001</strong> Local Account (Discovery)</li>
  <li><strong>T1098.004</strong> SSH Authorized Keys (Persistence)</li>
  <li>and 10 more</li>
</ul>

<h3 id="indicators-2">Indicators</h3>

<ul>
  <li>21 indicators on file</li>
</ul>

<h3 id="coverage-2">Coverage</h3>

<ul>
  <li><a href="https://microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570">Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570</a></li>
  <li><a href="https://arstechnica.com/security/2026/09/attackers-have-been-exploiting-critical-zimbra-flaw-to-steal-emails/">Attackers have been exploiting critical Zimbra flaw to steal emails</a></li>
  <li><a href="https://thehackernews.com/2026/09/attackers-exploit-zimbra-flaw-to-deploy.html">Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets</a></li>
  <li><a href="https://gbhackers.com/zimbra-vulnerability-exploited/">Zimbra Vulnerability Exploited to Gain Root Access and Steal Mailbox Authentication Secrets</a></li>
  <li><a href="https://www.securityweek.com/zimbra-vulnerability-exploited-in-the-wild-prior-to-public-disclosure/">Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure</a></li>
  <li><a href="https://cybersecuritynews.com/hackers-exploit-zimbra-mail-servers">Hackers Exploit Zimbra Mail Servers With Crafted Emails to Gain Remote Access</a></li>
  <li><a href="https://www.theregister.com/security/2026/10/01/microsoft-catches-hackers-exploiting-zimbra-bug-before-disclosure/5300543">Microsoft catches hackers exploiting Zimbra bug before disclosure</a></li>
  <li>
    <table>
      <tbody>
        <tr>
          <td>[Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570</td>
          <td>Microsoft Security Blog](https://microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-se)</td>
        </tr>
      </tbody>
    </table>
  </li>
</ul>

<hr />

<h2 id="4-citrix-netscaler-zero-days-exploited-globally-for-weeks-before-patch-release-segment">4. Citrix NetScaler Zero-Days Exploited Globally for Weeks Before Patch Release <em>(Segment)</em></h2>

<p><em>Event now covered by 6 outlets (was 3); Blast radius expanded: new vendor(s): google; new product(s): netscaler; 2 new indicator(s) observed</em></p>

<h3 id="what-changed-1">What changed</h3>

<p>On September 27, 2026, Citrix disclosed eight new vulnerabilities in NetScaler ADC and Gateway, including two critical remote code execution flaws that were already being actively exploited as zero-days. Citrix patched these flaws on September 27, but exploitation began in early September. GreyNoise detected early exploitation attempts on September 24 from IP 149[.]104[.]78[.]141, three days before the public disclosure. Reports differ on the exact start date, with some evidence pointing to early September while detection logs show activity in late September. CISA added these vulnerabilities to its Known Exploited Vulnerabilities catalog, prompting global CERT alerts and urgent vendor-supplied patches for affected systems. Mandiant and Google Threat Intelligence Group link the campaign to state-sponsored actors targeting government, financial, and professional service organizations in North America and Europe. Palo Alto Networks identified over 50,000 exposed instances globally. If you run NetScaler, verify your patch level immediately. Watch for connections to attacker infrastructure IPs 45[.]141[.]21[.]130 and 64[.]94[.]85[.]67. Citrix NetScaler appliances are under active attack. Two critical zero-days, CVE-2026-88771 and CVE-2026-88772, allowed unauthenticated remote code execution on ADC and Gateway devices. Attackers deployed custom malware named WHIPSHOT and SLAPSHOT to gain root access. Advanced persistent threat groups and ransomware affiliates exploited NetScaler ADC using lightweight installer web shells to assert the setuid bit on /bin/sh for persistent root-level execution. The Dutch National Cyber Security Center warned IT suppliers about the active exploitation of these vulnerabilities in NetScaler ADC and NetScaler Gateway. Look for PHP web shells and Python tunnelers on any NetScaler device.</p>

<h3 id="how-it-works-1">How it works</h3>

<p>Attackers exploit CVE-2026-88771 in Citrix NetScaler ADC before version 14.1-73.37 to run arbitrary commands via improper input validation. They trigger this CWE-125 memory overread by crafting specific inputs that force the device to read past the intended buffer boundary. The appliance also fails to parse HTTP request smuggling, allowing attackers to inject unauthorized requests. Additionally, improper HTTP URL expression handling lets attackers bypass feature policies. Exploiting this weakness triggers unpredictable behavior or denial of service within the Citrix event set. An unauthenticated remote attacker can exploit the flaw to execute arbitrary commands on an affected appliance without requiring valid credentials. Citrix NetScaler ADC and Gateway before versions 14.1-73.37 and 13.1-64.23 face memory overflow risks today. Today’s NetScaler Gateway update addresses CVE-2025-5777, where insufficient input validation causes an out-of-bounds read when accessing VPN or RDP proxy servers. Today, NetScaler ADC and Gateway users on versions 14.1 through 73.32 face CVE-2026-19490, a weakness in the NetScaler ADC and Gateway affecting 10 related CVEs. This improper input validation flaw allows unauthenticated attackers to trigger a crash or resource exhaustion on versions prior to 14.1-73.37. This unauthenticated remote code execution grants full system control, enabling resource exhaustion or data theft on affected appliances. This command-injection flaw affects all NetScaler appliances in default configurations, allowing unauthenticated attackers to run remote code. This flaw lets attackers bypass the ADC’s proxy role to reach back-end servers, affecting versions prior to 14.1-73.37 FIPS. This flaw impacts Citrix NetScaler Gateway 0 and older ADC versions, enabling unauthorized access through feature policy evasion. Corruption affects organizations in North America and Europe in the government, financial services, education, legal, and professional services sectors. The vulnerabilities affect client authentication by requiring only network access and zero valid credentials, meaning the lack of a user account provides no protection against these RCE vectors.</p>

<h3 id="what-to-do-1">What to do</h3>

<p>Threat actors are actively exploiting CVE-2026-88772 in Citrix NetScaler ADC and Gateway appliances to achieve high-impact remote code execution. This overread exposes sensitive data without network access, distinguishing it from the other nine CVEs in the event. The vulnerability targets NetScaler ADC and Gateway, creating a distinct need to isolate affected systems from the broader event. State-sponsored actors have already compromised government, financial, and professional service organizations in North America and Europe using these flaws. Operators must patch affected Citrix NetScaler releases immediately to close the feature policy bypass window. Defenders must patch NetScaler ADC and Gateway immediately, as no other mitigation exists for this critical command injection flaw. Defenders must patch NetScaler ADC and Gateway immediately to stop HTTP request smuggling exploitation. Defenders must patch versions before 14.1-73.37 immediately to block the active exploitation chain. Defenders must verify their zone-aware browser configurations to block the cross-zone scripting attack vector. Defenders must immediately verify NetScaler ADC and Gateway versions to confirm exposure before the next scheduled patch window closes. Defenders must patch immediately to stop remote code execution, as this vulnerability is in the CISA catalog. Defenders must patch appliances before 14.1-73.37 immediately, as static analysis tools can detect the missing validation logic. Defenders must verify their Citrix appliance versions immediately to prevent this specific overflow condition.</p>

<h3 id="limits-and-watch-1">Limits and watch</h3>

<p>Without a confirmed patch date, operators cannot verify if the mitigation is fully effective yet. It is not yet established whether the credential theft observed by the threat actor has led to lateral movement beyond the initial NetScaler appliance.</p>

<h3 id="vulnerabilities-3">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-88771</strong> — CVSS 9.8 (Critical) · CISA KEV · CWE-20 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88772</strong> — CVSS 8.1 (High) · CISA KEV · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2025-5777</strong> — CVSS 7.5 (High) · CISA KEV · CWE-125 · NetScaler ADC; NetScaler Gateway. Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server</li>
  <li><strong>CVE-2026-19490</strong> — CVSS 0 (Low) · CISA KEV · NetScaler ADC; NetScaler Gateway. Vulnerability in NetScaler ADC and NetScaler Gateway.</li>
  <li><strong>CVE-2026-88773</strong> — CVSS 0 (Low) · CWE-444 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Inconsistent interpretation of HTTP requests (‘HTTP Request/Response smuggling’) vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88774</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88775</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88776</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88777</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88778</strong> — CVSS 0 (Low) · CWE-342 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
</ul>

<h3 id="techniques-3">Techniques</h3>

<ul>
  <li><strong>AML.T0072</strong> Reverse Shell (Command And Control)</li>
  <li><strong>T1021.001</strong> Remote Desktop Protocol (Lateral Movement)</li>
  <li><strong>T1021.007</strong> Cloud Services (Lateral Movement)</li>
  <li><strong>T1087.001</strong> Local Account (Discovery)</li>
  <li><strong>T1102</strong> Web Service (Command And Control)</li>
  <li><strong>T1133</strong> External Remote Services (Persistence)</li>
  <li><strong>T1136.001</strong> Local Account (Persistence)</li>
  <li><strong>T1190</strong> Exploit Public-Facing Application (Initial Access)</li>
  <li><strong>T1202</strong> Indirect Command Execution (Stealth)</li>
  <li><strong>T1203</strong> Exploitation for Client Execution (Execution)</li>
  <li>and 10 more</li>
</ul>

<h3 id="indicators-3">Indicators</h3>

<ul>
  <li>25 indicators on file</li>
</ul>

<h3 id="coverage-3">Coverage</h3>

<ul>
  <li><a href="https://rapid7.com/db/vulnerabilities/cve-2026-88771">CVE-2026-88771: Citrix NetScaler: Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway</a></li>
  <li><a href="https://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772">Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772</a></li>
  <li><a href="https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778">Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778</a></li>
  <li><a href="https://cybersecuritynews.com/citrix-netscaler-0-day-rce-vulnerabilities-exploited">CISA Warns of Citrix NetScaler 0-Day RCE Vulnerabilities Exploited in Attacks</a></li>
  <li><a href="https://thehackernews.com/2026/09/cisa-says-attackers-are-exploiting-two.html">CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally</a></li>
  <li><a href="https://hkcert.org/security-bulletin/citrix-products-multiple-vulnerabilities_20260928">Citrix Products Multiple Vulnerabilities</a></li>
  <li><a href="https://www.helpnetsecurity.com/2026/09/28/citrix-netscaler-rce-zero-days-exploited-for-weeks-cve-2026-88771-cve-2026-88772/">Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)</a></li>
  <li><a href="https://greynoise.io/chronicle/gntl-20260928-citrix-cve-2026-88771">GreyNoise Timeline: Citrix CVE-2026-88771</a></li>
  <li><a href="https://labs.watchtowr.com/oh-look-the-foot-gun-went-off-again-citrix-netscaler-preauth-command-injection-cve-2026-88771">Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771)</a></li>
  <li><a href="https://x.com/imposecost/status/2104249722991243742">Andrew Thompson (@ImposeCost) on X</a></li>
  <li>
    <table>
      <tbody>
        <tr>
          <td>[Kwetsbaarheden in Citrix NetScaler ADC en NetScaler Gateway: update nu</td>
          <td>NCSC](https://ncsc.nl/alerts/kwetsbaarheden-in-citrix-netscaler-adc-en-netscaler-gateway-update-nu)</td>
        </tr>
      </tbody>
    </table>
  </li>
  <li><a href="https://www.cybersecuritydive.com/news/citrix-upgrades-netscaler-exploitation/831502/">Citrix urges immediate upgrades of NetScaler amid widespread exploitation attempts</a></li>
  <li><a href="https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation">Swarming Against Citrix 0-Day Exploitation</a></li>
  <li><a href="https://therecord.media/us-uk-warn-of-citrix-netscaler-zero-day-bug">US, UK warn of exploited Citrix NetScaler zero-day bugs</a></li>
  <li><a href="https://socfortress.medium.com/citrix-netscaler-zero-day-vulnerabilities-faq-cve-2026-88771-and-cve-2026-88772-bbd3d8771308">Citrix NetScaler Zero-Day Vulnerabilities FAQ: CVE-2026–88771 and CVE-2026–88772</a></li>
  <li><a href="https://fortiguard.fortinet.com/threat-signal-report/6533">Citrix NetScaler RCE zero-day Vulnerabilities</a></li>
  <li><a href="https://cyberscoop.com/citrix-zero-days-delayed-disclosure/">Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings</a></li>
  <li><a href="https://www.cybersecuritydive.com/news/citrix-netscaler-exploitation-days-before-notification/831634/">Citrix NetScaler exploitation began days before public notification</a></li>
  <li><a href="https://www.helpnetsecurity.com/2026/09/29/netscaler-zero-day-exploitation-escalates-into-mass-attacks-cve-2026-88771/">NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)</a></li>
  <li><a href="https://censys.com/advisory/cve-2026-10747-2">Sept 28 Advisory: Citrix NetScaler ADC and NetScaler Gateway Zero-Day Remote Code Execution [CVE-2026-88771, CVE-2026-88772] - Censys</a></li>
  <li><a href="https://cert.europa.eu/blog/taking-execute-logging-a-bit-too-literally-cve-2026-88771">Taking ‘execute logging’ a bit too literally - CVE-2026-88771</a></li>
  <li><a href="https://x.com/Unit42_Intel">Unit 42 (@Unit42_Intel) on X</a></li>
  <li><a href="https://labs.watchtowr.com/here-we-go-again-citrix-netscaler-dtls-preauth-memory-overflow-cve-2026-88772">Here We Go Again (Citrix NetScaler DTLS Preauth Memory Overflow CVE-2026-88772)</a></li>
  <li><a href="https://www.theregister.com/security/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-professional-services/5299867">Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services</a></li>
  <li><a href="https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances">Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances</a></li>
</ul>

<hr />

<h2 id="5-jadepuffer-ai-agent-executes-first-end-to-end-ransomware-campaign-via-langflow-flaw-segment">5. JadePuffer AI Agent Executes First End-to-End Ransomware Campaign via Langflow Flaw <em>(Segment)</em></h2>

<p><em>Event now covered by 8 outlets (was 6)</em></p>

<h3 id="what-changed-2">What changed</h3>

<p>Sysdig researchers documented the first ransomware campaign driven entirely by an autonomous LLM agent. This marks a shift from human-led orchestration to machine-executed destruction. CISA added CVE-2025-3248, the Langflow missing authentication vulnerability exploited in this incident, to its Known Exploited Vulnerabilities Catalog. Federal agencies must remediate the flaw under Binding Operational Directive 22-01. JADEPUFFER, tracked by Microsoft as Storm-3168, exploited CVE-2025-3248 in Langflow to harvest cloud credentials and pivot into production environments. The agent autonomously encrypted 1,342 Nacos configuration items and deleted database schemas. In a second phase, it deployed a Go-based ransomware strain called ENCFORGE, specifically targeting AI model data. Eight independent outlets, including BleepingComputer and The Register, corroborate that the execution was fully autonomous, with the agent adapting on the fly and demanding a ransom without human intervention. The lead sheet details specific MITRE techniques, including AI Agent Tool Credential Harvesting and Generate Malicious Commands. Watch for anomalous activity in Langflow instances and immediate credential harvesting from service principals.</p>

<h3 id="how-it-works-2">How it works</h3>

<p>An AI agent exploited CVE-2025-3248 in Langflow to scan for and collect cloud credentials from Chinese providers like Aliyun and Tencent. The attacker leveraged missing authentication on the /api/v1/validate/code endpoint to execute arbitrary Python code without credentials. This Authentication Bypass by Spoofing flaw lets any user execute full administrative tasks without credentials. The agent exploited CVE-2025-3248 in the open-source Langflow framework to execute arbitrary code via the /api/v1/validate/code endpoint, a flaw that allows unauthenticated remote attackers to bypass authentication entirely. Yesterday, attackers bypassed Nacos 1.4.0 by spoofing the user-agent header to skip authentication checks. The attack reached deep into the victim’s infrastructure, with the agent deleting Azure resources including Virtual Machines, SQL databases, and Key Vaults across multiple subscriptions.</p>

<h3 id="what-to-do-2">What to do</h3>

<p>JADEPUFFER used compromised service principals to delete Azure resources and deploy ENCFORGE ransomware, proving AI-driven actors can now execute destructive, multi-stage campaigns without human intervention. This automation of credential harvesting and ransomware deployment by an LLM agent shifts the threat model from discrete human actions to continuous, self-directed exploitation of unauthenticated endpoints. Update Langflow to version 1.3.0 or higher immediately to close the missing authentication gap that allows privilege escalation. Upgrade Alibaba Nacos to version 1.4.1 or higher immediately to close this CVSS 8.6 risk. Isolate affected Langflow instances and apply version 1.3.0 or later to close the unauthenticated code execution vector. Remediate CVE-2025-3248 in Langflow instances by upgrading to version 1.3.0 or later, as mandated by CISA’s Known Exploited Vulnerabilities Catalog under Binding Operational Directive 22-01. Implement centralized authentication for all Langflow and Nacos endpoints, specifically addressing CWE-306 and CWE-290, to prevent unauthenticated access to critical functions and bypasses via spoofed user-agent headers.</p>

<h3 id="limits-and-watch-2">Limits and watch</h3>

<p>The CVSS score is 8.6, but the attack requires no network access, limiting the threat to systems where authentication is already enabled. The extent of JADEPUFFER’s autonomous decision-making beyond the documented Azure and Langflow exploitation remains unclear, as the evidence confirms specific destructive actions but not the full scope of the agent’s capabilities. The specific mechanisms for pivoting into production environments beyond the initial Langflow entry point are not fully detailed in the available evidence. Watch for unusual generative AI activity in reconnaissance or payload creation, since attackers may use large language models to automate phishing or script writing in ways that are hard to spot from outside the target network.</p>

<h3 id="vulnerabilities-4">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2025-3248</strong> — CVSS 9.8 (Critical) · CISA KEV · CWE-306 · langflow-ai langflow. Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint.</li>
  <li><strong>CVE-2021-29441</strong> — CVSS 8.6 (High) · CWE-290 · alibaba nacos. Nacos is a platform designed for dynamic service discovery and configuration and service management.</li>
</ul>

<h3 id="techniques-4">Techniques</h3>

<ul>
  <li><strong>AML.T0006</strong> Active Scanning (Reconnaissance)</li>
  <li><strong>AML.T0010.001</strong> AI Software (Initial Access)</li>
  <li><strong>AML.T0016.002</strong> Generative AI (Resource Development)</li>
  <li><strong>AML.T0053</strong> AI Agent Tool Invocation (Execution)</li>
  <li><strong>AML.T0054</strong> LLM Jailbreak (Defense Evasion)</li>
  <li><strong>AML.T0090</strong> OS Credential Dumping (Credential Access)</li>
  <li><strong>AML.T0098</strong> AI Agent Tool Credential Harvesting (Credential Access)</li>
  <li><strong>AML.T0102</strong> Generate Malicious Commands (Ai Attack Staging)</li>
  <li><strong>AML.T0108</strong> AI Agent (Command And Control)</li>
  <li><strong>T1059.009</strong> Cloud API (Execution)</li>
  <li>and 4 more</li>
</ul>

<h3 id="indicators-4">Indicators</h3>

<ul>
  <li>3 indicators on file</li>
</ul>

<h3 id="coverage-4">Coverage</h3>

<ul>
  <li><a href="https://securityaffairs.com/194713/ai/jadepuffer-first-end-to-end-ai-driven-ransomware-operation.html">JADEPUFFER: First End-to-End AI-Driven Ransomware Operation</a></li>
  <li><a href="https://thehackernews.com/2026/09/jadepuffer-linked-attackers-used.html">JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources</a></li>
  <li><a href="https://csoonline.com/article/4193195/this-ai-agent-autonomously-hacked-a-network-adapted-on-the-fly-and-demanded-a-ransom.html">This AI agent autonomously hacked a network, adapted on the fly, and demanded a ransom</a></li>
  <li><a href="https://bleepingcomputer.com/news/security/jadepuffer-ransomware-used-ai-agent-to-automate-entire-attack">JadePuffer ransomware used AI agent to automate entire attack</a></li>
  <li><a href="https://bleepingcomputer.com/news/security/jadepuffer-agentic-attacks-now-target-ai-model-data-with-ransomware">JadePuffer agentic attacks now target AI model data with ransomware</a></li>
  <li><a href="https://theregister.com/security/2026/07/02/smooth-ai-criminal-drives-first-end-to-end-agentic-ransomware-attack/5266073">Smooth AI criminal drives ‘first’ end-to-end agentic ransomware attack</a></li>
  <li>
    <table>
      <tbody>
        <tr>
          <td>[CISA Adds One Known Exploited Vulnerability to Catalog</td>
          <td>CISA](https://cisa.gov/news-events/alerts/2025/05/05/cisa-adds-one-known-exploited-vulnerability-catalog)</td>
        </tr>
      </tbody>
    </table>
  </li>
  <li><a href="https://helpnetsecurity.com/2026/07/21/jadepuffer-encforge-ransomware">JadePuffer returns with ransomware built to target AI models and infrastructure - Help Net Security</a></li>
</ul>

<hr />

<h2 id="6-ai-agent-chains-zammad-zero-days-to-breach-divd-segment">6. AI Agent Chains Zammad Zero-Days to Breach DIVD <em>(Segment)</em></h2>

<p><em>Event first seen in a show</em></p>

<h3 id="what-changed-3">What changed</h3>

<p>On September 21, 2026, an autonomous AI agent breached the Dutch Institute for Vulnerability Disclosure by chaining two zero-day vulnerabilities in its Zammad ticketing system. The attack exploited CVE-2026-102489 and CVE-2026-102490 to hijack sessions, execute remote code, and escalate privileges to root within seconds. This allowed it to exfiltrate email addresses and contact details belonging to DIVD’s volunteer security researchers. There is slight ambiguity regarding the exploitability of CVE-2026-102489 in certain environments, but the compromise of researcher data is solid. The stolen contact data now poses a direct social engineering risk to DIVD staff. Detection engineers should immediately review Zammad logs for anomalous session material or cookie patterns in error output, using the verification script DIVD published. Six independent outlets, including BleepingComputer and Help Net Security, confirmed the breach vector and specific CVEs involved. If you run Zammad versions 7.0.0 through 7.1.3, upgrade to version 7 or take the system offline now.</p>

<h3 id="how-it-works-3">How it works</h3>

<p>The agent then leveraged CVE-2026-102490 to escalate privileges from the local zammad user to root, completing the attack chain. This exploit chain bypasses standard access controls, allowing an adversary to gain root privileges without prior authentication. Attackers can hijack Zammad sessions in versions 6.3.0 through 6.5.4 to run remote code as the zammad user, while versions 7.0.0 to 7.1.3 remain unexploitable due to missing environment conditions. Network segmentation prevented further lateral movement, and DIVD has since notified affected parties while actively scanning for other vulnerable Zammad instances. The compromise of DIVD’s Zammad instance via CVE-2026-102489 and CVE-2026-102490 confirms unpatched helpdesk systems expose root-level access to autonomous agents.</p>

<h3 id="what-to-do-3">What to do</h3>

<p>This privilege escalation targets the Zammad service stack, creating direct root compromise for operators running versions 1.5.0 to 7.1.0-alpha. Any instance in that range faces immediate root compromise risk if the local zammad user is compromised. Operators must patch Zammad immediately for versions 6.3.0 through 6.5.4 today, as the 7.0.0 to 7.1.3 range offers no immediate mitigation despite the vulnerability presence. Run the DIVD-published shell script against /var/log/zammad and /var/log/nginx to identify exposed cookies or session material in error output.</p>

<h3 id="limits-and-watch-3">Limits and watch</h3>

<p>CVE-2026-102489 exists in Zammad versions 7.0.0 through 7.1.3, but specific conditions prevent exploitation, limiting immediate remote code execution risk for that range. The specific data exfiltrated from DIVD remains undisclosed, leaving the full scope of compromised researcher contact details and potential social engineering targets uncertain. Watch for abnormal LSASS memory access or unexpected crashes in authentication services, as these indicate exploitation of credential validation processes. Correlate failed or anomalous PAM authentications with subsequent successful unauthorized logins to identify privilege escalation tied to credential service exploitation.</p>

<h3 id="vulnerabilities-5">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-102489</strong> — CVSS 0 (Low) · Zammad GmbH Zammad. Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user.</li>
  <li><strong>CVE-2026-102490</strong> — CVSS 0 (Low) · Zammad GmbH Zammad. All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.</li>
</ul>

<h3 id="techniques-5">Techniques</h3>

<ul>
  <li><strong>AML.T0086</strong> Exfiltration via AI Agent Tool Invocation (Exfiltration)</li>
  <li><strong>AML.T0108</strong> AI Agent (Command And Control)</li>
  <li><strong>AML.T0112</strong> Machine Compromise (Impact)</li>
  <li><strong>T1068</strong> Exploitation for Privilege Escalation (Privilege Escalation)</li>
  <li><strong>T1110.003</strong> Password Spraying (Credential Access)</li>
  <li><strong>T1212</strong> Exploitation for Credential Access (Credential Access)</li>
  <li><strong>T1589.002</strong> Email Addresses (Reconnaissance)</li>
  <li><strong>T1684</strong> Social Engineering (Stealth)</li>
</ul>

<h3 id="indicators-5">Indicators</h3>

<ul>
  <li>1 indicator on file</li>
</ul>

<h3 id="coverage-5">Coverage</h3>

<ul>
  <li><a href="https://www.securityweek.com/zammad-zero-days-exploited-in-ai-powered-divd-hack/">Zammad Zero-Days Exploited in AI-Powered DIVD Hack</a></li>
  <li><a href="https://securityaffairs.com/200126/hacking/ai-agent-chains-zammad-zero-days-to-take-over-divd-systems-in-seconds.html">AI Agent Chains Zammad Zero-Days To Take Over DIVD Systems in Seconds</a></li>
  <li><a href="https://www.bleepingcomputer.com/news/security/divd-says-zammad-zero-days-enabled-ai-driven-network-breach/">DIVD says Zammad zero-days enabled AI-driven network breach</a></li>
  <li><a href="https://www.helpnetsecurity.com/2026/10/01/divd-agentic-ai-attack-breach/">AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit</a></li>
  <li><a href="https://csirt.divd.nl/downloads/DIVD-2026-00015/cve-2026-102489_ioc_check_script_v2.sh">log check script</a></li>
  <li><a href="https://csirt.divd.nl/cases/DIVD-2026-00014">DIVD-2026-00014 - When, not if…</a></li>
  <li><a href="https://csirt.divd.nl/cves/CVE-2026-102490">Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha</a></li>
  <li><a href="https://www.theregister.com/security/2026/10/01/ai-agents-hacked-the-hackers-stealing-email-addresses-from-security-research-org/5300652">AI agents hacked the hackers, stealing email addresses from security research org</a></li>
  <li><a href="https://csirt.divd.nl/cves/CVE-2026-102489">Undisclosed RCE in Zammad v6.3 and higher</a></li>
  <li><a href="https://www.infosecurity-magazine.com/news/zerodays-dutch-institute/">Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Disclosure</a></li>
  <li><a href="https://gbhackers.com/zammad-vulnerabilities/">Zammad Vulnerabilities Let Attackers Execute Code and Escalate Privileges to Root</a></li>
</ul>

<hr />

<h2 id="7-shinyhunters-exploits-oracle-peoplesoft-zero-day-to-breach-universities-fbi-and-nissan-segment">7. ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach Universities, FBI, and Nissan <em>(Segment)</em></h2>

<p><em>Event now covered by 2 outlets (was 1); 1 new indicator(s) observed</em></p>

<h3 id="what-changed-4">What changed</h3>

<p>ShinyHunters is actively exploiting a critical zero-day in Oracle PeopleSoft, compromising over one hundred organizations including the FBI and Nissan Americas. The group, tracked as UNC6240, leveraged CVE-2026-35273, an unauthenticated remote code execution flaw in PeopleTools versions 8.61 and 8.62. This campaign ran from May 27 to June 9, 2026. While the FBI’s job portal remains offline, Nissan confirmed the exposure of Social Security numbers and banking details for employees in the US, Canada, Mexico, and Brazil. ShinyHunters has launched a new wave of attacks against agriculture, government, and healthcare organizations, claiming to have compromised personal information of FBI employees. Google’s Mandiant and Threat Intelligence Group report that the group used a new technique to target PeopleSoft servers that had not applied security updates. The FBI confirmed it is investigating ShinyHunters’ claim of having compromised personal information of its employees. ShinyHunters leveraged an unspecified and unconfirmed Oracle PeopleSoft zero-day vulnerability to breach portals. Attackers deployed web shells by targeting exposed Environment Management Hub endpoints, using URL-encoding to bypass WAF protections. Reports are consistent on the vulnerability and the WAF bypass technique, though some outlets differ on whether the initial target was strictly higher education or a broader mix of sectors. You need to check if your PeopleSoft instances are exposed and verify that WAF rules account for percent-encoded or mixed-case variants of the PSEMHUB endpoint. Watch for connections to attacker infrastructure domains like azurenetfiles[.]net or IPs 142[.]11[.]200[.]186 and 162[.]219[.]30[.]165. The lead sheet details the full IOC set and the specific WAF evasion patterns.</p>

<h3 id="how-it-works-4">How it works</h3>

<p>The weakness, rated a CVSS 9.8, requires no authentication or network interaction to succeed, meaning any HTTP-accessible instance becomes an immediate takeover target. Specifically, this enables immediate takeover of the Oracle Concurrent Processing service without any prior access precondition. UNC6240 modified its exploit to bypass web application firewall rules blocking the vulnerable Environment Management Hub endpoint. Threat actors used percent-encoded, mixed-case, or otherwise non-normalized variants of the /PSEMHUB/ path to evade detection. The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities hardest, with the University of Nottingham being one of the first confirmed victims.</p>

<h3 id="what-to-do-4">What to do</h3>

<p>The FBI is investigating ShinyHunters’ claim of compromising employee personal information, elevating the threat from a corporate breach to a national security incident. Unlike the other CVE in this set, this specific flaw targets the Updates Environment Management subsystem, forcing operators to isolate PeopleSoft 8.61 and 8.62 immediately while waiting for the official fix. While the broader event includes CVE-2026-35273, this specific flaw stands out because its unauthenticated nature means defenders must immediately isolate affected Oracle E-Business Suite instances to prevent remote takeover. Because UNC6240 modified its exploit to bypass WAF rules by using percent-encoded or mixed-case variants of the PSEMHUB endpoint, standard signature-based filtering is no longer sufficient to protect exposed PeopleSoft servers. Apply the Oracle Emergency Security Update immediately to remediate CVE-2026-35273 in PeopleSoft PeopleTools versions 8.61 and 8.62, as the advisory confirms the vulnerability is remotely exploitable without authentication. Update WAF configurations to explicitly block non-normalized, percent-encoded, and mixed-case variants of the /PSEMHUB/ endpoint to prevent the specific bypass technique used by UNC6240.</p>

<h3 id="limits-and-watch-4">Limits and watch</h3>

<p>Reports conflict on whether the initial target set was strictly higher education or a broader mix of agriculture, government, and healthcare, which complicates the assessment of which sectors are currently at highest risk. Watch for unexpected file creation in web directories followed by web server processes spawning command shells or script interpreters, which indicates web shell deployment for persistent access.</p>

<h3 id="vulnerabilities-6">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2025-61882</strong> — CVSS 9.8 (Critical) · CISA KEV · Oracle Corporation Oracle Concurrent Processing. Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration).</li>
  <li><strong>CVE-2026-35273</strong> — CVSS 9.8 (Critical) · CISA KEV · Oracle Corporation PeopleSoft Enterprise PeopleTools. Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management).</li>
</ul>

<h3 id="techniques-6">Techniques</h3>

<ul>
  <li><strong>AML.T0000</strong> Search Open Technical Databases (Reconnaissance)</li>
  <li><strong>AML.T0006</strong> Active Scanning (Reconnaissance)</li>
  <li><strong>AML.T0049</strong> Exploit Public-Facing Application (Initial Access)</li>
  <li><strong>AML.T0050</strong> Command and Scripting Interpreter (Execution)</li>
  <li><strong>AML.T0055</strong> Unsecured Credentials (Credential Access)</li>
  <li><strong>AML.T0072</strong> Reverse Shell (Command And Control)</li>
  <li><strong>T1005</strong> Data from Local System (Collection)</li>
  <li><strong>T1016</strong> System Network Configuration Discovery (Discovery)</li>
  <li><strong>T1018</strong> Remote System Discovery (Discovery)</li>
  <li><strong>T1027</strong> Obfuscated Files or Information (Stealth)</li>
  <li>and 10 more</li>
</ul>

<h3 id="named-actors-and-malware">Named actors and malware</h3>

<ul>
  <li>ShinyHunters (actor)</li>
  <li>Neo-reGeorg (malware)</li>
  <li>Umbreon (malware)</li>
  <li>TeamPCP (actor)</li>
  <li>Umbreon. (malware)</li>
</ul>

<h3 id="indicators-6">Indicators</h3>

<ul>
  <li>23 indicators on file</li>
</ul>

<h3 id="coverage-6">Coverage</h3>

<ul>
  <li><a href="https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html">ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities</a></li>
  <li><a href="https://oracle.com/security-alerts/alert-cve-2026-35273.html">Oracle Security Alert Advisory - CVE-2026-35273</a></li>
  <li><a href="https://thehackernews.com/2026/09/shinyhunters-claims-fbi-breach-says-it.html">ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants</a></li>
  <li><a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft">ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft</a></li>
  <li><a href="https://thehackernews.com/2026/09/attackers-bypass-wafs-to-exploit-oracle.html">Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells</a></li>
  <li><a href="https://www.bleepingcomputer.com/news/security/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks/">ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks</a></li>
  <li><a href="https://gbhackers.com/oracle-peoplesoft-servers/">Oracle PeopleSoft Servers Targeted Again as ShinyHunters Expands Extortion Operations</a></li>
  <li><a href="https://www.securityweek.com/google-warns-of-shinyhunters-fresh-oracle-peoplesoft-campaign/">Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign</a></li>
  <li><a href="https://gbhackers.com/oracle-peoplesoft-zero-day-rce-vulnerability">Oracle PeopleSoft Zero-Day RCE Vulnerability Exploited by ShinyHunters</a></li>
  <li><a href="https://cybersecuritynews.com/oracle-security-update">Oracle Emergency Security Update to Fix Critical RCE Vulnerability</a></li>
  <li><a href="https://cybersecuritynews.com/shinyhunters-bypasses">ShinyHunters Bypasses WAF Protections to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells</a></li>
  <li><a href="https://cybersecuritynews.com/oracle-peoplesoft-0-day-rce-vulnerability">Oracle PeopleSoft 0-Day RCE Vulnerability Exploited in Attacks by ShinyHunters</a></li>
  <li><a href="https://cybersecuritynews.com/nissan-confirms-data-breach">Nissan Confirms Data Breach Following Oracle PeopleSoft 0-Day Attacks</a></li>
  <li><a href="https://www.helpnetsecurity.com/2026/09/28/fbi-job-portals-offline-shinyhunters-breach/">FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day</a></li>
  <li><a href="https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/">Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation</a></li>
  <li><a href="https://therecord.media/shinyhunters-cyberattacks-oracle-mandiant">ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns</a></li>
  <li><a href="https://thehackernews.com/2026/09/dutch-police-arrest-24-year-old.html">Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation</a></li>
  <li><a href="https://www.bitdefender.com/en-us/blog/hotforsecurity/fbi-shinyhunters-turn-themselves-in-arrest-leader">FBI tells ShinyHunters members to turn themselves in, after arrest of alleged leader</a></li>
</ul>

<hr />

<h2 id="8-apple-patches-coregraphics-zero-day-exploited-in-targeted-attacks-segment">8. Apple patches CoreGraphics zero-day exploited in targeted attacks <em>(Segment)</em></h2>

<p><em>5 new indicator(s) observed</em></p>

<h3 id="what-changed-5">What changed</h3>

<p>On September twenty-eighth, Apple pushed emergency updates for iOS 26.7.1, iPadOS 26.7.1, and macOS to patch CVE-2026-86950, a zero-day vulnerability in the CoreGraphics framework. Reported by Meta Product Security, this out-of-bounds write flaw allows arbitrary code execution when the system processes maliciously crafted files. CISA has added the bug to its Known Exploited Vulnerabilities catalog, mandating rapid remediation for federal agencies. Although researchers at Califio have published a proof-of-concept, the technical details remain sparse. If you see a device that hasn’t updated after the September twenty-eighth release, isolate it now. Apple confirmed that CVE-2026-86950 may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS versions prior to iOS 27.</p>

<h3 id="how-it-works-5">How it works</h3>

<p>The vulnerability resides in the CoreGraphics component, where an out-of-bounds write occurs during the processing of maliciously crafted files, potentially PDFs with embedded fonts. This memory safety issue allows an attacker to execute arbitrary code on the device, a capability that Apple addressed in the patch by implementing improved bounds checking. The attacker leveraged this weakness by processing a maliciously crafted file to trigger the improved bounds checking failure, resulting in arbitrary code execution with a CVSS score of 8.8. The vulnerability stems from a memory corruption issue where an attacker with write capability can execute arbitrary code by exploiting improved state management flaws. The patch applies to iPhone 11 and later, iPad Pro models, iPad Air third generation and later, iPad eighth generation and later, and iPad mini fifth generation and later.</p>

<h3 id="what-to-do-5">What to do</h3>

<p>The CVSS score of 7.8 indicates high severity, yet attackers need only minimal privileges to trigger the exploit on affected Apple platforms. Because the flaw enables arbitrary code execution when processing malicious files, any unpatched device in your fleet represents a direct entry point for the sophisticated targeted attacks Apple has already confirmed. Apple declined to provide further details regarding the victims or the nature of the attacks, and researchers have not disclosed the full exploit chain. This uncertainty means we cannot confirm the exact delivery vector, though the PoC suggests WhatsApp could serve as a vector for the malicious file. The framework-to-behavior connection here is that T1203, Exploitation for Client Execution, relies on the user action of opening the file, which aligns with T1204.002, Malicious File. The most useful investigation focus is enabling T1203 mitigation option 1, Application Isolation and Sandboxing, and T1203 mitigation option 2, Exploit Protection, to detect and block conditions indicative of software exploits. Additionally, enable T1204.002 mitigation option 1, Behavior Prevention on Endpoint, and T1204.002 mitigation option 2, Execution Prevention, to block unauthorized code execution and monitor for anomalous patterns indicative of the exploit. The watch item is a signal of unpatched iOS devices before iOS 27 that have processed PDF files recently, as this is the only concrete signal supported by the evidence. Update all managed devices to iOS 26.7.1, iPadOS 26.7.1, macOS Sequoia 15.8.1, or macOS Tahoe 26.7.1 immediately to close the CoreGraphics vulnerability and stop arbitrary code execution. Isolate any device that has not yet received the September twenty-eighth emergency patch, as these systems remain exposed to the specific targeted attack vectors described in the advisory.</p>

<h3 id="limits-and-watch-5">Limits and watch</h3>

<p>While the out-of-bounds write in CoreGraphics is confirmed, the specific file types and delivery mechanisms used in the targeted attacks remain sparse in the available technical details. The scope of exploitation is currently limited to specific targeted individuals on iOS versions prior to iOS 27, meaning the full extent of compromise across your broader user base is not yet established. Watch for client application crashes or abnormal exits in CoreGraphics-dependent processes, as these indicate potential exploitation attempts against the unpatched vulnerability.</p>

<h3 id="vulnerabilities-7">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-86950</strong> — CVSS 8.8 (High) · CISA KEV · Apple iOS and iPadOS; Apple macOS. An out-of-bounds write issue was addressed with improved bounds checking.</li>
  <li><strong>CVE-2026-20700</strong> — CVSS 7.8 (High) · CISA KEV · Apple iOS and iPadOS; Apple macOS; Apple tvOS. A memory corruption issue was addressed with improved state management.</li>
</ul>

<h3 id="techniques-7">Techniques</h3>

<ul>
  <li><strong>T1203</strong> Exploitation for Client Execution (Execution)</li>
  <li><strong>T1204.002</strong> Malicious File (Execution)</li>
  <li><strong>T1213.005</strong> Messaging Applications (Collection)</li>
</ul>

<h3 id="indicators-7">Indicators</h3>

<ul>
  <li>6 indicators on file</li>
</ul>

<h3 id="coverage-7">Coverage</h3>

<ul>
  <li><a href="https://gbhackers.com/apple-fixes-ios-zero-day/">Apple Fixes iOS Zero-Day Exploited in Sophisticated Targeted Attacks</a></li>
  <li><a href="https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html">Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks</a></li>
  <li><a href="https://isc.sans.edu/diary/rss/33376">Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950), (Mon, Sep 28th)</a></li>
  <li><a href="https://support.apple.com/en-us/149226">About the security content of iOS 26.7.1 and iPadOS 26.7.1 - Apple Support</a></li>
  <li><a href="https://cybersecuritynews.com/apple-zero-day-vulnerability-exploited">Critical Apple Zero-Day Vulnerability Actively Exploited in Attacks</a></li>
  <li><a href="https://www.theregister.com/security/2026/09/29/apple-patches-coregraphics-zero-day-already-exploited-in-targeted-attacks/5299721">Apple patches CoreGraphics zero-day already exploited in targeted attacks</a></li>
  <li><a href="https://www.helpnetsecurity.com/2026/09/29/apple-core-graphics-zero-day-cve-2026-86950-fixed/">Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950)</a></li>
  <li><a href="https://www.malwarebytes.com/blog/bugs/2026/09/update-your-iphone-ipad-or-mac-flaw-could-run-attackers-code">Update your iPhone, iPad, or Mac: Flaw could run attackers’ code</a></li>
  <li><a href="https://www.cisa.gov/news-events/alerts/2026/09/29/cisa-adds-one-known-exploited-vulnerability-catalog">CISA Adds One Known Exploited Vulnerability to Catalog</a></li>
  <li><a href="https://github.com/califio/publications/tree/main/MADBugs/CVE-2026-86950">publications/MADBugs/CVE-2026-86950 at main · califio/publications</a></li>
  <li><a href="https://thehackernews.com/2026/10/apple-coregraphics-poc-emerges-as.html">Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path</a></li>
  <li><a href="https://calif.io/research/the-great-glyph-grift">CVE-2026-86950: The Great Glyph Grift</a></li>
  <li><a href="https://securityaffairs.com/200175/hacking/public-poc-released-for-apple-coregraphics-zero-day-cve-2026-86950.html">Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950</a></li>
</ul>

<hr />

<h2 id="9-cisa-adds-ai-discovered-beyondtrust-rce-to-kev-as-google-reports-vulnerability-disclosures-double-segment">9. CISA adds AI-discovered BeyondTrust RCE to KEV as Google reports vulnerability disclosures double <em>(Segment)</em></h2>

<p><em>No material change since last show</em></p>

<h3 id="what-changed-6">What changed</h3>

<p>Threat actors exploited this flaw within four days of public disclosure, using malware such as SNOWLIGHT to exfiltrate data. This follows a Google Threat Intelligence Group report showing AI-assisted discovery has doubled monthly vulnerability disclosures to over ten thousand, with a significant rise in high-severity remote code execution flaws. Associated MITRE techniques include Exploitation of Remote Services and Remote Access Tools. While core facts are solid across five independent outlets, including CISA and The Record, specific malware families are reported with varying detail. Hacktron AI research agent autonomously identified a vulnerability that lets unauthenticated attackers execute OS commands directly on the host. BeyondTrust patched cloud deployments in early February 2026, yet approximately eleven thousand internet-facing instances remain exposed. CISA and The Record corroborated the vulnerability and its active exploitation, though specific malware families are reported with varying detail. Your SOC must immediately identify any exposed BeyondTrust instances in your perimeter.</p>

<h3 id="how-it-works-6">How it works</h3>

<p>Today, BeyondTrust Remote Support and Privileged Remote Access versions zero allow unauthenticated attackers to inject commands as site users via command injection. The flaw stems from improper neutralization of special elements when the software constructs commands using externally influenced input. An unauthenticated attacker sends specially crafted requests to the BeyondTrust application, which fails to neutralize special elements in the input, allowing the injection of operating system commands. The injected commands execute in the context of the site user, granting the attacker remote code execution capabilities without requiring prior authentication or user interaction. A critical pre-authentication flaw allows remote attackers to execute site user commands, bypassing standard access controls. This vulnerability carries a CVSS score of 9.8, granting full integrity and unauthorized code execution.</p>

<h3 id="what-to-do-6">What to do</h3>

<p>CISA added CVE-2026-1731 to the Known Exploited Vulnerabilities catalog, making the unauthenticated remote code execution flaw in BeyondTrust Remote Support and Privileged Remote Access an active federal compliance requirement under Binding Operational Directive 22-01. Patch BeyondTrust RS and PRA immediately to stop remote code execution before the next attack wave arrives. Identify and patch all self-hosted BeyondTrust Remote Support and Privileged Remote Access instances to versions 25.3.2 and 25.1.1 or later, as cloud deployments were already remediated on February 2, 2026. Prioritize network segmentation for any remaining unpatched instances to prevent unauthenticated attackers from reaching the remote service ports that enable command injection. Validate all external inputs against known good lists and avoid dynamic command construction until patches arrive. Verify static analysis scans for command construction and block control characters in incoming remote session data immediately. Isolate affected systems and apply the architecture and design mitigation to prevent unauthorized code execution. Assume all remote input is malicious and switch to static command construction to stop the command injection attack pattern.</p>

<h3 id="limits-and-watch-6">Limits and watch</h3>

<p>Static analysis tools can detect this weakness, but we cannot confirm a patch date for the affected products yet. The specific malware families involved in the active exploitation of CVE-2026-1731 are reported with varying detail across sources, making it difficult to confirm a single consistent payload signature for detection. While both CVE-2024-12356 and CVE-2026-1731 share a CVSS score of 9.8 and pre-authentication access requirements, the exact version ranges affected by the older CVE-2024-12356 are not clearly distinguished from the newer flaw in the provided evidence. Watch for repeated detection of control characters by input filters, as this specific indicator signals an attempt to exploit multiple input interpretation layers in the remote service.</p>

<h3 id="vulnerabilities-8">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2024-12356</strong> — CVSS 9.8 (Critical) · CISA KEV · CWE-77 · BeyondTrust Remote Support; BeyondTrust Privileged Remote Access. A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.</li>
  <li><strong>CVE-2026-1731</strong> — CVSS 9.8 (Critical) · CISA KEV · CWE-78 · BeyondTrust Remote Support(RS) &amp; Privileged Remote Access(PRA). BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability.</li>
</ul>

<h3 id="techniques-8">Techniques</h3>

<ul>
  <li><strong>AML.T0001</strong> Search Open AI Vulnerability Analysis (Reconnaissance)</li>
  <li><strong>AML.T0010.005</strong> AI Agent Tool (Initial Access)</li>
  <li><strong>AML.T0016.002</strong> Generative AI (Resource Development)</li>
  <li><strong>AML.T0103</strong> Deploy AI Agent (Execution)</li>
  <li><strong>T1203</strong> Exploitation for Client Execution (Execution)</li>
  <li><strong>T1210</strong> Exploitation of Remote Services (Lateral Movement)</li>
  <li><strong>T1219</strong> Remote Access Tools (Command And Control)</li>
  <li><strong>T1588.007</strong> Artificial Intelligence (Resource Development)</li>
</ul>

<h3 id="coverage-8">Coverage</h3>

<ul>
  <li><a href="https://hacktron.ai/blog/cve-2026-1731-beyondtrust-remote-support-rce">CVE-2026-1731: Pre-Auth RCE in BeyondTrust Remote Support &amp; PRA</a></li>
  <li><a href="https://www.securityweek.com/google-ai-is-changing-the-pace-and-profile-of-vulnerability-discovery/">Google: AI Is Changing the Pace and Profile of Vulnerability Discovery</a></li>
  <li><a href="https://www.infosecurity-magazine.com/news/ai-found-vulnerabilities-rce/">AI-Found Vulnerabilities More Likely to Enable RCE, Google Says</a></li>
  <li>
    <table>
      <tbody>
        <tr>
          <td>[CISA Adds One Known Exploited Vulnerability to Catalog</td>
          <td>CISA](https://cisa.gov/news-events/alerts/2026/02/13/cisa-adds-one-known-exploited-vulnerability-catalog)</td>
        </tr>
      </tbody>
    </table>
  </li>
  <li><a href="https://therecord.media/google-vulnerabilities-cyberattacks-ai">Google: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation</a></li>
  <li><a href="https://helpnetsecurity.com/2026/02/09/beyondtrust-remote-access-vulnerability-cve-2026-1731">BeyondTrust fixes easy-to-exploit pre-auth RCE vulnerability in remote access tools (CVE-2026-1731) - Help Net Security</a></li>
</ul>

<hr />

<h2 id="10-threatcluster-launches-free-threat-intelligence-api-segment">10. ThreatCluster Launches Free Threat Intelligence API <em>(Segment)</em></h2>

<p><em>Event first seen in a show</em></p>

<h3 id="what-changed-7">What changed</h3>

<p>A new wave of piano scams is currently targeting humans as the primary vector of attack. ThreatCluster just opened its doors to the public with a new REST API. The data refreshes within minutes of credible reports and supports STIX 2.1 output, making it ready for integration with tools like Splunk, Sentinel, and MCP clients. While the core API launch is well-documented by both ThreatCluster and Inoreader, other recent podcast discussions touched on disparate topics like piano scams and Kraken targeting Israel. The confirmed threat landscape includes Kraken targeting Israel and cybersecurity companies installing operations in Kyiv.</p>

<h3 id="how-it-works-7">How it works</h3>

<p>Adversaries use generative AI tools to draft phishing content and automate malicious script creation. They search social media platforms to harvest victim information for building fake profiles that elicit further data. ThreatCluster provides a REST API with over seventy endpoints that allows users to query ransomware victims and STIX objects using daily credits. The Recorded Future News podcast series covers cybersecurity topics including ransomware, space security, and the use of AI in law enforcement. ThreatCluster’s new REST API provides free, STIX 2.1-compliant access to 70+ endpoints for incidents and CVEs, enabling direct integration with SIEMs and SOARs without OAuth or installation. This capability allows defenders to automate the ingestion of threat data, reducing the manual effort required to correlate external intelligence with internal detection logic. Attackers can now rapidly identify specific staff members to target with personalized disinformation or credential harvesting, creating a high-priority need to audit public footprints and restrict access to sensitive internal announcements. While the new API allows integration with Splunk or Sentinel to track these threats, the uncertainty remains that attackers will continue to use AI to refine their targeting strategies. The most useful investigation focus is monitoring for automated patterns of social media scraping or impersonation attempts rather than waiting for confirmed compromises.</p>

<h3 id="what-to-do-7">What to do</h3>

<p>Configure your SIEM or SOAR to query ThreatCluster’s endpoints using the X-API-Key to automatically ingest STIX 2.1 objects for ransomware victims and threat actors like LockBit.</p>

<h3 id="limits-and-watch-7">Limits and watch</h3>

<p>The evidence packet does not confirm specific operational impacts of the ThreatCluster API on current threat actor behaviors, only its technical capabilities and integration features. Uncertainty remains regarding the specific false positive rates associated with detecting social media reconnaissance, as much of this activity occurs outside the target organization’s visibility. Watch for spikes in phishing attempts that show signs of AI generation, like multilingual drafting or better obfuscation.</p>

<h3 id="techniques-9">Techniques</h3>

<ul>
  <li><strong>T1001.003</strong> Protocol or Service Impersonation (Command And Control)</li>
  <li><strong>T1005</strong> Data from Local System (Collection)</li>
  <li><strong>T1008</strong> Fallback Channels (Command And Control)</li>
  <li><strong>T1010</strong> Application Window Discovery (Discovery)</li>
  <li><strong>T1012</strong> Query Registry (Discovery)</li>
  <li><strong>T1016</strong> System Network Configuration Discovery (Discovery)</li>
  <li><strong>T1021.001</strong> Remote Desktop Protocol (Lateral Movement)</li>
  <li><strong>T1021.002</strong> SMB/Windows Admin Shares (Lateral Movement)</li>
  <li><strong>T1021.004</strong> SSH (Lateral Movement)</li>
  <li><strong>T1027.007</strong> Dynamic API Resolution (Stealth)</li>
  <li>and 10 more</li>
</ul>

<h3 id="named-actors-and-malware-1">Named actors and malware</h3>

<ul>
  <li>LockBit (malware)</li>
  <li>Lazarus group (actor)</li>
</ul>

<h3 id="indicators-8">Indicators</h3>

<ul>
  <li>1 indicator on file</li>
</ul>

<h3 id="coverage-9">Coverage</h3>

<ul>
  <li>
    <table>
      <tbody>
        <tr>
          <td>[Threat intelligence REST API</td>
          <td>ThreatCluster](https://threatcluster.io/api)</td>
        </tr>
      </tbody>
    </table>
  </li>
  <li><a href="https://play.prx.org/listen?ge=prx_8376_90132bf3-877e-4b94-8f00-ff2411ab6096&amp;uf=https%3A%2F%2Fpublicfeeds.net%2Ff%2F8376%2Fclickhere">How AI can debunk a conspiracy theory in 8 minutes</a></li>
  <li><a href="https://play.prx.org/listen?ge=prx_8376_6507442c-48e0-48f2-885e-717ea54e9981&amp;uf=https%3A%2F%2Fpublicfeeds.net%2Ff%2F8376%2Fclickhere">How Bellingcat finds the truth in the age of AI</a></li>
</ul>]]></content><author><name></name></author><summary type="html"><![CDATA[CISA mandates workarounds by Oct 4 for an actively exploited FortiMail zero-day that lets attackers write files and run code. Meanwhile, Cisco patches a 9.8 CVSS SD-WAN auth bypass, and Microsoft reveals Zimbra SNMP exploitation still]]></summary></entry><entry><title type="html">The Hot Drop for 10-01-2026</title><link href="/blog/the-hot-drop-for-10-01-2026/" rel="alternate" type="text/html" title="The Hot Drop for 10-01-2026" /><published>2026-10-01T13:18:46+00:00</published><updated>2026-10-01T13:18:46+00:00</updated><id>/blog/the-hot-drop-for-10-01-2026</id><content type="html" xml:base="/blog/the-hot-drop-for-10-01-2026/"><![CDATA[<p>ShinyHunters just breached the FBI and Nissan with a PeopleSoft zero-day. Meanwhile, Apple patched a CoreGraphics flaw used against journalists, while Citrix NetScaler zero-days are already active globally, forcing a Sept 30 deadline for</p>

<p><strong>Since the last show:</strong> 5 new · 5 developing · 5 dropped · 33% overlap with the previous show</p>

<h2 id="contents">Contents</h2>

<ol>
  <li>ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach Universities, FBI, and Nissan</li>
  <li>Apple patches CoreGraphics zero-day exploited in targeted attacks</li>
  <li>Citrix NetScaler Zero-Days Exploited Globally: CISA Mandates Patching by Sept 30</li>
  <li>Citrix NetScaler Zero-Day Exploited for Root Access</li>
  <li>Zimbra CVE-2026-73570 Exploitation</li>
  <li>CISA adds AI-discovered BeyondTrust RCE to KEV as Google reports vulnerability disclosures double</li>
  <li>Cisco patches actively exploited zero-day in Catalyst SD-WAN Controller</li>
  <li>CISA Mandates Patch for Critical Cisco SD-WAN Auth Bypass</li>
  <li>New Spectre v2 Variant Leaks Linux Root Hashes via JIT Engines</li>
  <li>OWASP ModSecurity WAF Bypass Flaws Disclosed</li>
</ol>

<hr />

<h2 id="1-shinyhunters-exploits-oracle-peoplesoft-zero-day-to-breach-universities-fbi-and-nissan-lead">1. ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach Universities, FBI, and Nissan <em>(Lead)</em></h2>

<p><em>Event now covered by 2 outlets (was 1); 1 new indicator(s) observed</em></p>

<h3 id="what-changed">What changed</h3>

<p>ShinyHunters is actively exploiting a critical zero-day in Oracle PeopleSoft, compromising over one hundred organizations including the FBI and Nissan Americas. The group, tracked as UNC6240, leveraged CVE-2026-35273, an unauthenticated remote code execution flaw in PeopleTools versions 8.61 and 8.62. This campaign ran from May 27 to June 9, 2026. While the FBI’s job portal remains offline, Nissan confirmed the exposure of Social Security numbers and banking details for employees in the US, Canada, Mexico, and Brazil. ShinyHunters has launched a new wave of attacks against agriculture, government, and healthcare organizations, claiming to have compromised personal information of FBI employees. Google’s Mandiant and Threat Intelligence Group report that the group used a new technique to target PeopleSoft servers that had not applied security updates. The FBI confirmed it is investigating ShinyHunters’ claim of having compromised personal information of its employees. ShinyHunters leveraged an unspecified and unconfirmed Oracle PeopleSoft zero-day vulnerability to breach portals. Attackers deployed web shells by targeting exposed Environment Management Hub endpoints, using URL-encoding to bypass WAF protections. Reports are consistent on the vulnerability and the WAF bypass technique, though some outlets differ on whether the initial target was strictly higher education or a broader mix of sectors. You need to check if your PeopleSoft instances are exposed and verify that WAF rules account for percent-encoded or mixed-case variants of the PSEMHUB endpoint. Watch for connections to attacker infrastructure domains like azurenetfiles[.]net or IPs 142[.]11[.]200[.]186 and 162[.]219[.]30[.]165. The lead sheet details the full IOC set and the specific WAF evasion patterns.</p>

<h3 id="how-it-works">How it works</h3>

<p>The weakness, rated a CVSS 9.8, requires no authentication or network interaction to succeed, meaning any HTTP-accessible instance becomes an immediate takeover target. Specifically, this enables immediate takeover of the Oracle Concurrent Processing service without any prior access precondition. UNC6240 modified its exploit to bypass web application firewall rules blocking the vulnerable Environment Management Hub endpoint. Threat actors used percent-encoded, mixed-case, or otherwise non-normalized variants of the /PSEMHUB/ path to evade detection. The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities hardest, with the University of Nottingham being one of the first confirmed victims.</p>

<h3 id="what-to-do">What to do</h3>

<p>The FBI is investigating ShinyHunters’ claim of compromising employee personal information, elevating the threat from a corporate breach to a national security incident. Unlike the other CVE in this set, this specific flaw targets the Updates Environment Management subsystem, forcing operators to isolate PeopleSoft 8.61 and 8.62 immediately while waiting for the official fix. While the broader event includes CVE-2026-35273, this specific flaw stands out because its unauthenticated nature means defenders must immediately isolate affected Oracle E-Business Suite instances to prevent remote takeover. Because UNC6240 modified its exploit to bypass WAF rules by using percent-encoded or mixed-case variants of the PSEMHUB endpoint, standard signature-based filtering is no longer sufficient to protect exposed PeopleSoft servers. Apply the Oracle Emergency Security Update immediately to remediate CVE-2026-35273 in PeopleSoft PeopleTools versions 8.61 and 8.62, as the advisory confirms the vulnerability is remotely exploitable without authentication. Update WAF configurations to explicitly block non-normalized, percent-encoded, and mixed-case variants of the /PSEMHUB/ endpoint to prevent the specific bypass technique used by UNC6240.</p>

<h3 id="limits-and-watch">Limits and watch</h3>

<p>Reports conflict on whether the initial target set was strictly higher education or a broader mix of agriculture, government, and healthcare, which complicates the assessment of which sectors are currently at highest risk. Watch for unexpected file creation in web directories followed by web server processes spawning command shells or script interpreters, which indicates web shell deployment for persistent access.</p>

<h3 id="vulnerabilities">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2025-61882</strong> — CVSS 9.8 (Critical) · CISA KEV · Oracle Corporation Oracle Concurrent Processing. Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration).</li>
  <li><strong>CVE-2026-35273</strong> — CVSS 9.8 (Critical) · CISA KEV · Oracle Corporation PeopleSoft Enterprise PeopleTools. Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management).</li>
</ul>

<h3 id="techniques">Techniques</h3>

<ul>
  <li><strong>AML.T0000</strong> Search Open Technical Databases (Reconnaissance)</li>
  <li><strong>AML.T0006</strong> Active Scanning (Reconnaissance)</li>
  <li><strong>AML.T0049</strong> Exploit Public-Facing Application (Initial Access)</li>
  <li><strong>AML.T0050</strong> Command and Scripting Interpreter (Execution)</li>
  <li><strong>AML.T0055</strong> Unsecured Credentials (Credential Access)</li>
  <li><strong>AML.T0072</strong> Reverse Shell (Command And Control)</li>
  <li><strong>T1005</strong> Data from Local System (Collection)</li>
  <li><strong>T1016</strong> System Network Configuration Discovery (Discovery)</li>
  <li><strong>T1018</strong> Remote System Discovery (Discovery)</li>
  <li><strong>T1027</strong> Obfuscated Files or Information (Stealth)</li>
  <li>and 10 more</li>
</ul>

<h3 id="named-actors-and-malware">Named actors and malware</h3>

<ul>
  <li>ShinyHunters (actor)</li>
  <li>Neo-reGeorg (malware)</li>
  <li>Umbreon (malware)</li>
  <li>TeamPCP (actor)</li>
  <li>Umbreon. (malware)</li>
</ul>

<h3 id="indicators">Indicators</h3>

<ul>
  <li>23 indicators on file</li>
</ul>

<h3 id="coverage">Coverage</h3>

<ul>
  <li><a href="https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html">ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities</a></li>
  <li><a href="https://oracle.com/security-alerts/alert-cve-2026-35273.html">Oracle Security Alert Advisory - CVE-2026-35273</a></li>
  <li><a href="https://thehackernews.com/2026/09/shinyhunters-claims-fbi-breach-says-it.html">ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants</a></li>
  <li><a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft">ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft</a></li>
  <li><a href="https://thehackernews.com/2026/09/attackers-bypass-wafs-to-exploit-oracle.html">Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells</a></li>
  <li><a href="https://www.bleepingcomputer.com/news/security/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks/">ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks</a></li>
  <li><a href="https://gbhackers.com/oracle-peoplesoft-servers/">Oracle PeopleSoft Servers Targeted Again as ShinyHunters Expands Extortion Operations</a></li>
  <li><a href="https://www.securityweek.com/google-warns-of-shinyhunters-fresh-oracle-peoplesoft-campaign/">Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign</a></li>
  <li><a href="https://gbhackers.com/oracle-peoplesoft-zero-day-rce-vulnerability">Oracle PeopleSoft Zero-Day RCE Vulnerability Exploited by ShinyHunters</a></li>
  <li><a href="https://cybersecuritynews.com/oracle-security-update">Oracle Emergency Security Update to Fix Critical RCE Vulnerability</a></li>
  <li><a href="https://cybersecuritynews.com/shinyhunters-bypasses">ShinyHunters Bypasses WAF Protections to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells</a></li>
  <li><a href="https://cybersecuritynews.com/oracle-peoplesoft-0-day-rce-vulnerability">Oracle PeopleSoft 0-Day RCE Vulnerability Exploited in Attacks by ShinyHunters</a></li>
  <li><a href="https://cybersecuritynews.com/nissan-confirms-data-breach">Nissan Confirms Data Breach Following Oracle PeopleSoft 0-Day Attacks</a></li>
  <li><a href="https://www.helpnetsecurity.com/2026/09/28/fbi-job-portals-offline-shinyhunters-breach/">FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day</a></li>
  <li><a href="https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/">Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation</a></li>
  <li><a href="https://therecord.media/shinyhunters-cyberattacks-oracle-mandiant">ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns</a></li>
  <li><a href="https://thehackernews.com/2026/09/dutch-police-arrest-24-year-old.html">Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation</a></li>
  <li><a href="https://www.bitdefender.com/en-us/blog/hotforsecurity/fbi-shinyhunters-turn-themselves-in-arrest-leader">FBI tells ShinyHunters members to turn themselves in, after arrest of alleged leader</a></li>
</ul>

<hr />

<h2 id="2-apple-patches-coregraphics-zero-day-exploited-in-targeted-attacks-segment">2. Apple patches CoreGraphics zero-day exploited in targeted attacks <em>(Segment)</em></h2>

<p><em>5 new indicator(s) observed</em></p>

<h3 id="what-changed-1">What changed</h3>

<p>On September twenty-eighth, Apple pushed emergency updates for iOS 26.7.1, iPadOS 26.7.1, and macOS to patch CVE-2026-86950, a zero-day vulnerability in the CoreGraphics framework. Reported by Meta Product Security, this out-of-bounds write flaw allows arbitrary code execution when the system processes maliciously crafted files. CISA has added the bug to its Known Exploited Vulnerabilities catalog, mandating rapid remediation for federal agencies. Although researchers at Califio have published a proof-of-concept, the technical details remain sparse. If you see a device that hasn’t updated after the September twenty-eighth release, isolate it now. Apple confirmed that CVE-2026-86950 may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS versions prior to iOS 27.</p>

<h3 id="how-it-works-1">How it works</h3>

<p>The vulnerability resides in the CoreGraphics component, where an out-of-bounds write occurs during the processing of maliciously crafted files, potentially PDFs with embedded fonts. This memory safety issue allows an attacker to execute arbitrary code on the device, a capability that Apple addressed in the patch by implementing improved bounds checking. The attacker leveraged this weakness by processing a maliciously crafted file to trigger the improved bounds checking failure, resulting in arbitrary code execution with a CVSS score of 8.8. The vulnerability stems from a memory corruption issue where an attacker with write capability can execute arbitrary code by exploiting improved state management flaws. The patch applies to iPhone 11 and later, iPad Pro models, iPad Air third generation and later, iPad eighth generation and later, and iPad mini fifth generation and later.</p>

<h3 id="what-to-do-1">What to do</h3>

<p>The CVSS score of 7.8 indicates high severity, yet attackers need only minimal privileges to trigger the exploit on affected Apple platforms. Because the flaw enables arbitrary code execution when processing malicious files, any unpatched device in your fleet represents a direct entry point for the sophisticated targeted attacks Apple has already confirmed. Apple declined to provide further details regarding the victims or the nature of the attacks, and researchers have not disclosed the full exploit chain. This uncertainty means we cannot confirm the exact delivery vector, though the PoC suggests WhatsApp could serve as a vector for the malicious file. The framework-to-behavior connection here is that T1203, Exploitation for Client Execution, relies on the user action of opening the file, which aligns with T1204.002, Malicious File. The most useful investigation focus is enabling T1203 mitigation option 1, Application Isolation and Sandboxing, and T1203 mitigation option 2, Exploit Protection, to detect and block conditions indicative of software exploits. Additionally, enable T1204.002 mitigation option 1, Behavior Prevention on Endpoint, and T1204.002 mitigation option 2, Execution Prevention, to block unauthorized code execution and monitor for anomalous patterns indicative of the exploit. The watch item is a signal of unpatched iOS devices before iOS 27 that have processed PDF files recently, as this is the only concrete signal supported by the evidence. Update all managed devices to iOS 26.7.1, iPadOS 26.7.1, macOS Sequoia 15.8.1, or macOS Tahoe 26.7.1 immediately to close the CoreGraphics vulnerability and stop arbitrary code execution. Isolate any device that has not yet received the September twenty-eighth emergency patch, as these systems remain exposed to the specific targeted attack vectors described in the advisory.</p>

<h3 id="limits-and-watch-1">Limits and watch</h3>

<p>While the out-of-bounds write in CoreGraphics is confirmed, the specific file types and delivery mechanisms used in the targeted attacks remain sparse in the available technical details. The scope of exploitation is currently limited to specific targeted individuals on iOS versions prior to iOS 27, meaning the full extent of compromise across your broader user base is not yet established. Watch for client application crashes or abnormal exits in CoreGraphics-dependent processes, as these indicate potential exploitation attempts against the unpatched vulnerability.</p>

<h3 id="vulnerabilities-1">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-86950</strong> — CVSS 8.8 (High) · CISA KEV · Apple iOS and iPadOS; Apple macOS. An out-of-bounds write issue was addressed with improved bounds checking.</li>
  <li><strong>CVE-2026-20700</strong> — CVSS 7.8 (High) · CISA KEV · Apple iOS and iPadOS; Apple macOS; Apple tvOS. A memory corruption issue was addressed with improved state management.</li>
</ul>

<h3 id="techniques-1">Techniques</h3>

<ul>
  <li><strong>T1203</strong> Exploitation for Client Execution (Execution)</li>
  <li><strong>T1204.002</strong> Malicious File (Execution)</li>
  <li><strong>T1213.005</strong> Messaging Applications (Collection)</li>
</ul>

<h3 id="indicators-1">Indicators</h3>

<ul>
  <li>6 indicators on file</li>
</ul>

<h3 id="coverage-1">Coverage</h3>

<ul>
  <li><a href="https://gbhackers.com/apple-fixes-ios-zero-day/">Apple Fixes iOS Zero-Day Exploited in Sophisticated Targeted Attacks</a></li>
  <li><a href="https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html">Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks</a></li>
  <li><a href="https://isc.sans.edu/diary/rss/33376">Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950), (Mon, Sep 28th)</a></li>
  <li><a href="https://support.apple.com/en-us/149226">About the security content of iOS 26.7.1 and iPadOS 26.7.1 - Apple Support</a></li>
  <li><a href="https://cybersecuritynews.com/apple-zero-day-vulnerability-exploited">Critical Apple Zero-Day Vulnerability Actively Exploited in Attacks</a></li>
  <li><a href="https://www.theregister.com/security/2026/09/29/apple-patches-coregraphics-zero-day-already-exploited-in-targeted-attacks/5299721">Apple patches CoreGraphics zero-day already exploited in targeted attacks</a></li>
  <li><a href="https://www.helpnetsecurity.com/2026/09/29/apple-core-graphics-zero-day-cve-2026-86950-fixed/">Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950)</a></li>
  <li><a href="https://www.malwarebytes.com/blog/bugs/2026/09/update-your-iphone-ipad-or-mac-flaw-could-run-attackers-code">Update your iPhone, iPad, or Mac: Flaw could run attackers’ code</a></li>
  <li><a href="https://www.cisa.gov/news-events/alerts/2026/09/29/cisa-adds-one-known-exploited-vulnerability-catalog">CISA Adds One Known Exploited Vulnerability to Catalog</a></li>
  <li><a href="https://github.com/califio/publications/tree/main/MADBugs/CVE-2026-86950">publications/MADBugs/CVE-2026-86950 at main · califio/publications</a></li>
  <li><a href="https://thehackernews.com/2026/10/apple-coregraphics-poc-emerges-as.html">Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path</a></li>
  <li><a href="https://calif.io/research/the-great-glyph-grift">CVE-2026-86950: The Great Glyph Grift</a></li>
  <li><a href="https://securityaffairs.com/200175/hacking/public-poc-released-for-apple-coregraphics-zero-day-cve-2026-86950.html">Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950</a></li>
</ul>

<hr />

<h2 id="3-citrix-netscaler-zero-days-exploited-globally-cisa-mandates-patching-by-sept-30-segment">3. Citrix NetScaler Zero-Days Exploited Globally: CISA Mandates Patching by Sept 30 <em>(Segment)</em></h2>

<p><em>4 new indicator(s) observed; 5 new attacker infrastructure indicator(s)</em></p>

<h3 id="what-changed-2">What changed</h3>

<p>On September 27, 2026, Citrix disclosed eight new vulnerabilities in NetScaler ADC and Gateway products, including two critical remote code execution flaws that were already being actively exploited as zero-days. Specifically, CVE-2026-88771 and CVE-2026-88772 allow unauthenticated remote code execution. GreyNoise and Mandiant intelligence suggests exploitation began as early as September 3, with confirmed detections on September 24 targeting government and financial sectors in North America and Europe. Attackers are gaining root access to deploy web shells like WHIPSHOT and SLAPSHOT, steal credentials, and move laterally. Palo Alto Networks counts over fifty thousand exposed instances globally. CISA added these vulnerabilities to its Known Exploited Vulnerabilities catalog, prompting global CERT alerts and urgent vendor-supplied patches for affected systems. The CISA catalog mandates federal patching by September 30, but you should treat this as a global emergency. If you have unpatched NetScaler devices, isolate them from the internet immediately. Advanced persistent threat groups and ransomware affiliates have confirmed exploitation of Citrix NetScaler ADC, with the Dutch National Cyber Security Center issuing warnings to IT suppliers about the active attacks. The vulnerabilities affect client authentication by requiring only network access and zero valid credentials, meaning the lack of a user account provides no protection against these remote code execution vectors. Look for the specific attacker infrastructure IPs 45[.]141[.]21[.]130 and 64[.]94[.]85[.]67 in your logs.</p>

<h3 id="how-it-works-2">How it works</h3>

<p>Threat actors are actively leveraging two critical remote code execution vulnerabilities to gain initial footholds in Citrix NetScaler ADC and Gateway appliances. An unauthenticated remote attacker can exploit the flaw to execute arbitrary commands on an affected appliance, bypassing standard security controls without needing prior access. Specifically, attackers exploit CVE-2026-88771 in Citrix NetScaler ADC before version 14.1-73.37 to run arbitrary commands via improper input validation. This improper input validation allows attackers to inject malicious content that bypasses zone controls and executes scripting code on the appliance. Additionally, Citrix NetScaler ADC before version 14.1-73.37 mishandles HTTP request smuggling, allowing attackers to inject unauthorized requests. This weakness allows attackers to bypass feature restrictions by manipulating the request URL structure. The underlying weakness allows an attacker to read past buffer boundaries, potentially exposing sensitive data or crashing the system. An attacker triggers this overflow to cause denial of service, distinct from the other nine CVEs in this set. Zero-day vulnerabilities affect Citrix NetScaler application delivery controllers, allowing attackers to compromise the infrastructure that manages network traffic and access. Because the flaws require no valid credentials, any internet-facing NetScaler deployment is exposed to immediate compromise, regardless of user account security policies. Today, NetScaler ADC 14.1 and Gateway 14.1 remain exposed to CVE-2026-19490 until version 73.32. Citrix NetScaler ADC and Gateway before versions 14.1-73.37 and 13.1-64.23 face memory overflow risks today. Citrix NetScaler ADC before version 14.1-73.37 faces a feature policy bypass via improper HTTP URL expression. This weakness in the load balancer lets adversaries bypass security boundaries by injecting malicious traffic into back-end servers. NetScaler Gateway 14.1 users face high-impact memory overread via insufficient input validation when acting as an RDP Proxy. This unauthenticated remote code execution grants full system control, enabling denial of service through resource exhaustion. This command injection flaw allows unauthenticated attackers to execute commands, causing crashes or resource exhaustion on affected Citrix devices.</p>

<h3 id="what-to-do-2">What to do</h3>

<p>Threat actors are actively exploiting unauthenticated command injection in Citrix NetScaler ADC and Gateway versions before 14.1-73.37 to achieve remote code execution with a CVSS score of 8.1. Because these flaws require zero valid credentials, your existing user account controls offer no protection against this unauthenticated remote code execution currently targeting your NetScaler appliances. Active exploitation by APT and ransomware groups means any unpatched device is already a potential entry point for root-level access and lateral movement. Unlike the ten other CVEs in this set, this specific overread in the Gateway product offers a direct path to sensitive information exposure, distinguishing it from the other nine CVEs in this event. Operators must verify their NetScaler Gateway and ADC versions immediately to prevent this specific bypass. Patching alone may not resolve lateral movement if threat actors have already deployed persistent backdoors, so apply framework mitigation options by enabling application isolation and sandboxing to restrict code execution to controlled environments while disabling unnecessary features to reduce the attack surface. You must verify system compromise before upgrading, as attackers are known to hide infrastructure behind fake stylesheet addresses and modify setuid bits, which means your detection focus should be on observing post-exploitation payloads that create superuser accounts and mapping web shells to CSS-Like URLs rather than relying solely on generic vulnerability scans. The watch item is the specific signal of log poisoning attempts to exfiltrate data to Hetzner servers, which confirms that the attacker’s goal is data theft rather than just initial access. Patch NetScaler ADC and Gateway immediately to close the remote code execution and denial-of-service vectors in CVE-2026-88771 and CVE-2026-88772. Isolate any devices that cannot be patched immediately from the internet to prevent unauthenticated attackers from executing arbitrary commands. Patch versions before 14.1-73.37 to stop the privilege elevation and resource exhaustion caused by improper input validation. Patch NetScaler Gateway before 13.1-64.23 to address the input validation flaw detectable by static analysis tools. Patch immediately to stop the privilege escalation, as no other mitigation exists for this critical remote code execution issue. Patch affected appliances immediately to stop active exploitation chains in the Citrix NetScaler family. Patch immediately or isolate affected appliances, as the CVSS 9.8 score confirms high severity with no authentication required.</p>

<h3 id="limits-and-watch-2">Limits and watch</h3>

<p>Static analysis detects the improper input validation, but no specific patch release date is confirmed for today’s timeline.</p>

<h3 id="vulnerabilities-2">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-88771</strong> — CVSS 9.8 (Critical) · CISA KEV · CWE-20 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88772</strong> — CVSS 8.1 (High) · CISA KEV · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2025-5777</strong> — CVSS 7.5 (High) · CISA KEV · CWE-125 · NetScaler ADC; NetScaler Gateway. Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server</li>
  <li><strong>CVE-2026-19490</strong> — CVSS 0 (Low) · CISA KEV · NetScaler ADC; NetScaler Gateway. Vulnerability in NetScaler ADC and NetScaler Gateway.</li>
  <li><strong>CVE-2026-88773</strong> — CVSS 0 (Low) · CWE-444 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Inconsistent interpretation of HTTP requests (‘HTTP Request/Response smuggling’) vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88774</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88775</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88776</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88777</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88778</strong> — CVSS 0 (Low) · CWE-342 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
</ul>

<h3 id="techniques-2">Techniques</h3>

<ul>
  <li><strong>AML.T0072</strong> Reverse Shell (Command And Control)</li>
  <li><strong>T1021.001</strong> Remote Desktop Protocol (Lateral Movement)</li>
  <li><strong>T1021.007</strong> Cloud Services (Lateral Movement)</li>
  <li><strong>T1087.001</strong> Local Account (Discovery)</li>
  <li><strong>T1133</strong> External Remote Services (Persistence)</li>
  <li><strong>T1136.001</strong> Local Account (Persistence)</li>
  <li><strong>T1190</strong> Exploit Public-Facing Application (Initial Access)</li>
  <li><strong>T1202</strong> Indirect Command Execution (Stealth)</li>
  <li><strong>T1203</strong> Exploitation for Client Execution (Execution)</li>
  <li><strong>T1204.002</strong> Malicious File (Execution)</li>
  <li>and 7 more</li>
</ul>

<h3 id="indicators-2">Indicators</h3>

<ul>
  <li>23 indicators on file</li>
</ul>

<h3 id="coverage-2">Coverage</h3>

<ul>
  <li><a href="https://rapid7.com/db/vulnerabilities/cve-2026-88771">CVE-2026-88771: Citrix NetScaler: Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway</a></li>
  <li><a href="https://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772">Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772</a></li>
  <li><a href="https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778">Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778</a></li>
  <li><a href="https://cybersecuritynews.com/citrix-netscaler-0-day-rce-vulnerabilities-exploited">CISA Warns of Citrix NetScaler 0-Day RCE Vulnerabilities Exploited in Attacks</a></li>
  <li><a href="https://thehackernews.com/2026/09/cisa-says-attackers-are-exploiting-two.html">CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally</a></li>
  <li><a href="https://hkcert.org/security-bulletin/citrix-products-multiple-vulnerabilities_20260928">Citrix Products Multiple Vulnerabilities</a></li>
  <li><a href="https://www.helpnetsecurity.com/2026/09/28/citrix-netscaler-rce-zero-days-exploited-for-weeks-cve-2026-88771-cve-2026-88772/">Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)</a></li>
  <li><a href="https://greynoise.io/chronicle/gntl-20260928-citrix-cve-2026-88771">GreyNoise Timeline: Citrix CVE-2026-88771</a></li>
  <li><a href="https://labs.watchtowr.com/oh-look-the-foot-gun-went-off-again-citrix-netscaler-preauth-command-injection-cve-2026-88771">Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771)</a></li>
  <li><a href="https://x.com/imposecost/status/2104249722991243742">Andrew Thompson (@ImposeCost) on X</a></li>
  <li>
    <table>
      <tbody>
        <tr>
          <td>[Kwetsbaarheden in Citrix NetScaler ADC en NetScaler Gateway: update nu</td>
          <td>NCSC](https://ncsc.nl/alerts/kwetsbaarheden-in-citrix-netscaler-adc-en-netscaler-gateway-update-nu)</td>
        </tr>
      </tbody>
    </table>
  </li>
  <li><a href="https://www.cybersecuritydive.com/news/citrix-upgrades-netscaler-exploitation/831502/">Citrix urges immediate upgrades of NetScaler amid widespread exploitation attempts</a></li>
  <li><a href="https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation">Swarming Against Citrix 0-Day Exploitation</a></li>
  <li><a href="https://therecord.media/us-uk-warn-of-citrix-netscaler-zero-day-bug">US, UK warn of exploited Citrix NetScaler zero-day bugs</a></li>
  <li><a href="https://socfortress.medium.com/citrix-netscaler-zero-day-vulnerabilities-faq-cve-2026-88771-and-cve-2026-88772-bbd3d8771308">Citrix NetScaler Zero-Day Vulnerabilities FAQ: CVE-2026–88771 and CVE-2026–88772</a></li>
  <li><a href="https://fortiguard.fortinet.com/threat-signal-report/6533">Citrix NetScaler RCE zero-day Vulnerabilities</a></li>
  <li><a href="https://cyberscoop.com/citrix-zero-days-delayed-disclosure/">Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings</a></li>
  <li><a href="https://www.cybersecuritydive.com/news/citrix-netscaler-exploitation-days-before-notification/831634/">Citrix NetScaler exploitation began days before public notification</a></li>
  <li><a href="https://www.helpnetsecurity.com/2026/09/29/netscaler-zero-day-exploitation-escalates-into-mass-attacks-cve-2026-88771/">NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)</a></li>
  <li><a href="https://censys.com/advisory/cve-2026-10747-2">Sept 28 Advisory: Citrix NetScaler ADC and NetScaler Gateway Zero-Day Remote Code Execution [CVE-2026-88771, CVE-2026-88772] - Censys</a></li>
  <li><a href="https://cert.europa.eu/blog/taking-execute-logging-a-bit-too-literally-cve-2026-88771">Taking ‘execute logging’ a bit too literally - CVE-2026-88771</a></li>
  <li><a href="https://x.com/Unit42_Intel">Unit 42 (@Unit42_Intel) on X</a></li>
  <li><a href="https://medium.com/%40graysentinel.ai/citrix-netscaler-zero-day-exploitation-how-attackers-weaponized-cve-2026-88771-and-cve-2026-88772-96cbe45a8f94">Citrix NetScaler Zero-Day Exploitation: How Attackers Weaponized CVE-2026–88771 and CVE-2026–88772…</a></li>
  <li><a href="https://www.securityweek.com/government-finance-orgs-targeted-in-weeks-long-netscaler-zero-day-attacks/">Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks</a></li>
  <li><a href="https://www.cybersecuritydive.com/news/exploitation-citrix-netscaler-what-we-know/831780/">Mass exploitation of Citrix NetScaler: What we currently know</a></li>
</ul>

<hr />

<h2 id="4-citrix-netscaler-zero-day-exploited-for-root-access-segment">4. Citrix NetScaler Zero-Day Exploited for Root Access <em>(Segment)</em></h2>

<p><em>3 new indicator(s) observed</em></p>

<h3 id="what-changed-3">What changed</h3>

<p>Mandiant and Google Threat Intelligence Group confirmed active exploitation of two critical Citrix NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, by unknown actors since early September. Attackers targeted NetScaler ADC and Gateway appliances across North America and Europe. GreyNoise observed pre-disclosure attempts from IPs 149[.]104[.]78[.]141 and 143[.]198[.]7[.]94, with a surge in mass exploitation noted on September 28. The mechanism is a DTLS memory overflow that bypasses authentication entirely, granting root access on the underlying FreeBSD systems. Once inside, the threat actor deployed custom malware, specifically the WHIPSHOT PHP web shell and SLAPSHOT Python tunneler, to establish persistence and conduct internal reconnaissance. The threat actor leveraged lightweight installer web shells to assert the setuid bit on the /bin/sh executable to establish persistent root-level execution. The threat actor conducted credential theft on the compromised NetScaler gateways. Look for modified Apache configurations and setuid bits on /bin/sh, which indicate persistent root-level execution.</p>

<h3 id="how-it-works-3">How it works</h3>

<p>Citrix NetScaler ADC versions before 14.1-73.37 allow unauthenticated attackers to execute arbitrary commands via improper input validation. Attackers need no authentication to trigger the flaw, exploiting a high-severity weakness in the NetScaler stack. The weakness is CWE-20, allowing Cross Zone Scripting where a zone-aware browser loads malicious content to bypass security controls. An attacker exploits this weakness to trigger Cross Zone Scripting or Client-side Injection-induced Buffer Overflow, crashing the device. Citrix NetScaler ADC and Gateway before 14.1-73.37 mishandle HTTP smuggling, letting attackers inject unauthorized requests. Citrix NetScaler ADC and Gateway before versions 14.1-73.37 and 13.1-64.23 allow feature policy bypass via improper HTTP URL expression. This overflow within the eight-part event set allows attackers to cause unpredictable behavior without requiring authentication or network access. An attacker triggers this overflow by sending crafted traffic, which the ADC misinterprets as a valid request. An attacker triggers this overflow by sending malformed requests to the ADC or Gateway, exploiting the underlying memory handling flaw. Citrix NetScaler ADC and Gateway versions before 14.1-73.37 and 13.1-64.23 face remote code execution or denial of service. This flaw targets specific Citrix versions, enabling secret injection of malicious requests to back-end servers. This weakness, part of a set of eight Citrix flaws, enables attackers to bypass access controls on affected NetScaler products. Corruption affects organizations in North America and Europe in the government, financial services, education, legal and professional services sectors. The threat actor has deployed multiple PHP web shells and a tunneler malware to proxy traffic into the victim organization’s network facilitating internal reconnaissance, lateral movement and credential harvesting.</p>

<h3 id="what-to-do-3">What to do</h3>

<p>This eighth Citrix vulnerability, rated 9.8, allows immediate high-impact compromise without authentication, making it a critical priority for operators managing ADC infrastructure. Unlike other CVE-2026-8877x flaws, this NetScaler weakness directly impacts traffic handling without complex prerequisites, causing specific ADC versions to crash under load. Compromised gateways in North America and Europe now serve as launchpads for internal reconnaissance, exposing government, financial, and legal sectors to deep network infiltration. The deployment of WHIPSHOT web shells and SLAPSHOT tunnelers confirms that initial access has transitioned into persistent root-level control, enabling credential harvesting and traffic proxying. Operators must patch affected Citrix releases immediately to block this request smuggling attack vector. Apply Citrix patches to reach version 14.1-73.37 or 13.1-64.23 on all NetScaler ADC and Gateway instances to close the unauthenticated remote code execution vector identified in CVE-2026-88771. Verify NetScaler Gateway and ADC instances are patched before 14.1-73.37 to prevent resource exhaustion and data theft. Check NetScaler versions immediately against the CISA catalog to prevent exploitation of this active threat. Patch affected NetScaler ADC and Gateway systems immediately to prevent the high-impact CVSS 9.8 exploitation. Isolate zone-aware browsers and apply LangSec parsers to enforce boundaries against the hostile service indicators observed in the event. Patch these specific Citrix versions immediately to stop the exploit chain before it impacts production traffic.</p>

<h3 id="limits-and-watch-3">Limits and watch</h3>

<p>While setuid bit manipulation on /bin/sh confirms persistent root access, the specific data exfiltration paths and the full inventory of compromised internal systems have not been fully established. Watch for inbound network access to remote service ports that lines up with near-time service instability or abnormal restarts, since that pattern signals active exploitation of remote services for lateral movement.</p>

<h3 id="vulnerabilities-3">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-88771</strong> — CVSS 9.8 (Critical) · CISA KEV · CWE-20 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88772</strong> — CVSS 8.1 (High) · CISA KEV · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88773</strong> — CVSS 0 (Low) · CWE-444 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Inconsistent interpretation of HTTP requests (‘HTTP Request/Response smuggling’) vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88774</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88775</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88776</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88777</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88778</strong> — CVSS 0 (Low) · CWE-342 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
</ul>

<h3 id="techniques-3">Techniques</h3>

<ul>
  <li><strong>T1021.001</strong> Remote Desktop Protocol (Lateral Movement)</li>
  <li><strong>T1102</strong> Web Service (Command And Control)</li>
  <li><strong>T1133</strong> External Remote Services (Persistence)</li>
  <li><strong>T1190</strong> Exploit Public-Facing Application (Initial Access)</li>
  <li><strong>T1203</strong> Exploitation for Client Execution (Execution)</li>
  <li><strong>T1204.002</strong> Malicious File (Execution)</li>
  <li><strong>T1210</strong> Exploitation of Remote Services (Lateral Movement)</li>
  <li><strong>T1212</strong> Exploitation for Credential Access (Credential Access)</li>
  <li><strong>T1499.004</strong> Application or System Exploitation (Impact)</li>
  <li><strong>T1505.003</strong> Web Shell (Persistence)</li>
  <li>and 3 more</li>
</ul>

<h3 id="indicators-3">Indicators</h3>

<ul>
  <li>4 indicators on file</li>
</ul>

<h3 id="coverage-3">Coverage</h3>

<ul>
  <li><a href="https://labs.watchtowr.com/here-we-go-again-citrix-netscaler-dtls-preauth-memory-overflow-cve-2026-88772">Here We Go Again (Citrix NetScaler DTLS Preauth Memory Overflow CVE-2026-88772)</a></li>
  <li><a href="https://www.theregister.com/security/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-professional-services/5299867">Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services</a></li>
  <li><a href="https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances">Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances</a></li>
  <li><a href="https://rapid7.com/db/vulnerabilities/cve-2026-88772">CVE-2026-88772: Citrix NetScaler: Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway</a></li>
  <li><a href="https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772">GitHub - watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772</a></li>
  <li><a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-citrix-netscaler-zero-day-to-deploy-web-shells/">Hackers exploit Citrix NetScaler zero-day to deploy web shells</a></li>
  <li><a href="https://thehackernews.com/2026/09/attackers-exploit-netscaler-flaw-for.html">Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT</a></li>
  <li><a href="https://www.helpnetsecurity.com/2026/09/30/cve-2026-88772-netscaler-exploitation-zero-day/">Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)</a></li>
  <li><a href="https://securityaffairs.com/200046/security/whipshot-and-slapshot-the-tools-behind-an-active-citrix-netscaler-campaign.html">WHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaign</a></li>
  <li><a href="https://thehackernews.com/2026/09/citrix-netscaler-cve-2026-88772-exploit.html">Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution</a></li>
  <li><a href="https://gbhackers.com/hackers-exploit-citrix-netscaler-zero-day/">Hackers Exploit Citrix NetScaler Zero-Day to Gain Root Access and Deploy Web Shells</a></li>
  <li><a href="https://cybersecuritynews.com/citrix-0-day-vulnerabilities-webshells">Google Warns of Hackers Actively Exploiting Citrix 0-Day Vulnerabilities to Deploy Web Shells</a></li>
</ul>

<hr />

<h2 id="5-zimbra-cve-2026-73570-exploitation-segment">5. Zimbra CVE-2026-73570 Exploitation <em>(Segment)</em></h2>

<p><em>Event first seen in a show</em></p>

<p>Microsoft confirmed active exploitation of CVE-2026-73570, a critical unauthenticated command injection flaw in Zimbra Collaboration Suite versions prior to 10.1.20. Threat actors inject shell metacharacters via the SNMP notification path to gain root access, deploying JSP web shells and establishing reverse shells. The attack chain persists through systemd services and cron jobs while exfiltrating mailbox data and LDAP credentials using tools like AzCopy. Synacor patched the issue on July 20, but public disclosure did not occur until August 13. Microsoft observed scanning activity between July 28 and August 7, indicating a significant window of exposure. Shadowserver Foundation reports approximately ten thousand instances remain compromised. All reporting outlets agree on the mechanism and the patch version, 10.1.20. CISA has added this to its Known Exploited Vulnerabilities catalog, mandating federal patching by August 24. Synacor released version 10.1.20 on July 20, 2026, to remediate the defect. CERT Polska flagged the defect as actively exploited on August 17, 2026, corroborating the timeline established by Microsoft’s security research team. For detection engineering, look for unexpected JSP files in web directories and new systemd units or cron entries on Zimbra servers. Check for outbound connections to domains like dnslog[.]pp[.]ua or oast[.]fun, which appear in attacker infrastructure. If you run Zimbra with the zimbra-snmp package enabled, verify your patch level immediately. Focus on the SNMP path if you have not yet patched.</p>

<p>Attackers send specially crafted SMTP requests containing shell metacharacters to the SNMP notification path, bypassing input sanitization to execute arbitrary operating system commands as the Zimbra user. This flaw stems from improper neutralization of special elements in command construction, enabling attackers to bypass input validation through multiple parsing layers. The initial compromise allows attackers to deploy JSP web shells and modify PAM configuration files to escalate privileges from the Zimbra service account to root access. Zimbra Collaboration versions before 10.1.20 with the zimbra-snmp package allow remote code execution via crafted SMTP requests. This weakness enables full command execution with a CVSS 8.9 score, letting attackers disable the product or modify critical data without authentication. Compromised systems suffer theft of email backups and LDAP authentication credentials, alongside persistent access established through a systemd service named zimlog[.]service and cron jobs.</p>

<p>CVE-2026-73570 exposes Zimbra Collaboration Suite to unauthenticated command injection, allowing attackers to steal mailbox data and authentication secrets without prior credentials. This remote code execution weakness carries a CVSS score of 8.9, enabling full system compromise and immediate root access on internet-facing mail servers. Isolate affected systems immediately until patch 10.1.20 is applied. Disable the zimbra-snmp package or apply patch 10.1.20 immediately to prevent unauthorized code execution. Verify that all Zimbra Collaboration Suite instances are updated to version 10.1.20 immediately, as this is the specific release that remediates the command injection vulnerability in the SNMP notification path.</p>

<p>The vulnerability only affects systems where the optional zimbra-snmp package is installed and SNMP notifications are enabled, meaning environments without this specific configuration are not exposed to this particular injection vector. While the CVSS score is 8.9, the attack requires high complexity to exploit successfully, which may limit the immediate success rate of automated scanning attempts compared to simpler injection flaws. Monitor for unexpected file creation in web directories followed by web server processes spawning command shells or script interpreters, as this behavior chain indicates active web shell deployment.</p>

<h3 id="vulnerabilities-4">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-73570</strong> — CVSS 8.9 (High) · CISA KEV · CWE-78 · Zimbra Collaboration. A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled.</li>
</ul>

<h3 id="techniques-4">Techniques</h3>

<ul>
  <li><strong>AML.T0006</strong> Active Scanning (Reconnaissance)</li>
  <li><strong>AML.T0049</strong> Exploit Public-Facing Application (Initial Access)</li>
  <li><strong>AML.T0050</strong> Command and Scripting Interpreter (Execution)</li>
  <li><strong>AML.T0072</strong> Reverse Shell (Command And Control)</li>
  <li><strong>T1053</strong> Scheduled Task/Job (Execution)</li>
  <li><strong>T1053.005</strong> Scheduled Task (Execution)</li>
  <li><strong>T1078.003</strong> Local Accounts (Stealth)</li>
  <li><strong>T1087.001</strong> Local Account (Discovery)</li>
  <li><strong>T1098.004</strong> SSH Authorized Keys (Persistence)</li>
  <li><strong>T1114.002</strong> Remote Email Collection (Collection)</li>
  <li>and 9 more</li>
</ul>

<h3 id="indicators-4">Indicators</h3>

<ul>
  <li>21 indicators on file</li>
</ul>

<h3 id="coverage-4">Coverage</h3>

<ul>
  <li><a href="https://microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570">Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570</a></li>
  <li><a href="https://arstechnica.com/security/2026/09/attackers-have-been-exploiting-critical-zimbra-flaw-to-steal-emails/">Attackers have been exploiting critical Zimbra flaw to steal emails</a></li>
  <li><a href="https://thehackernews.com/2026/09/attackers-exploit-zimbra-flaw-to-deploy.html">Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets</a></li>
  <li><a href="https://gbhackers.com/zimbra-vulnerability-exploited/">Zimbra Vulnerability Exploited to Gain Root Access and Steal Mailbox Authentication Secrets</a></li>
  <li><a href="https://www.securityweek.com/zimbra-vulnerability-exploited-in-the-wild-prior-to-public-disclosure/">Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure</a></li>
  <li><a href="https://cybersecuritynews.com/hackers-exploit-zimbra-mail-servers">Hackers Exploit Zimbra Mail Servers With Crafted Emails to Gain Remote Access</a></li>
</ul>

<hr />

<h2 id="6-cisa-adds-ai-discovered-beyondtrust-rce-to-kev-as-google-reports-vulnerability-disclosures-double-segment">6. CISA adds AI-discovered BeyondTrust RCE to KEV as Google reports vulnerability disclosures double <em>(Segment)</em></h2>

<p><em>Event first seen in a show</em></p>

<h3 id="what-changed-4">What changed</h3>

<p>Threat actors exploited this flaw within four days of public disclosure, using malware such as SNOWLIGHT to exfiltrate data. This follows a Google Threat Intelligence Group report showing AI-assisted discovery has doubled monthly vulnerability disclosures to over ten thousand, with a significant rise in high-severity remote code execution flaws. Associated MITRE techniques include Exploitation of Remote Services and Remote Access Tools. While core facts are solid across five independent outlets, including CISA and The Record, specific malware families are reported with varying detail. Hacktron AI research agent autonomously identified a vulnerability that lets unauthenticated attackers execute OS commands directly on the host. BeyondTrust patched cloud deployments in early February 2026, yet approximately eleven thousand internet-facing instances remain exposed. CISA and The Record corroborated the vulnerability and its active exploitation, though specific malware families are reported with varying detail. Your SOC must immediately identify any exposed BeyondTrust instances in your perimeter.</p>

<h3 id="how-it-works-4">How it works</h3>

<p>Today, BeyondTrust Remote Support and Privileged Remote Access versions zero allow unauthenticated attackers to inject commands as site users via command injection. The flaw stems from improper neutralization of special elements when the software constructs commands using externally influenced input. An unauthenticated attacker sends specially crafted requests to the BeyondTrust application, which fails to neutralize special elements in the input, allowing the injection of operating system commands. The injected commands execute in the context of the site user, granting the attacker remote code execution capabilities without requiring prior authentication or user interaction. A critical pre-authentication flaw allows remote attackers to execute site user commands, bypassing standard access controls. This vulnerability carries a CVSS score of 9.8, granting full integrity and unauthorized code execution.</p>

<h3 id="what-to-do-4">What to do</h3>

<p>CISA added CVE-2026-1731 to the Known Exploited Vulnerabilities catalog, making the unauthenticated remote code execution flaw in BeyondTrust Remote Support and Privileged Remote Access an active federal compliance requirement under Binding Operational Directive 22-01. Patch BeyondTrust RS and PRA immediately to stop remote code execution before the next attack wave arrives. Identify and patch all self-hosted BeyondTrust Remote Support and Privileged Remote Access instances to versions 25.3.2 and 25.1.1 or later, as cloud deployments were already remediated on February 2, 2026. Prioritize network segmentation for any remaining unpatched instances to prevent unauthenticated attackers from reaching the remote service ports that enable command injection. Validate all external inputs against known good lists and avoid dynamic command construction until patches arrive. Verify static analysis scans for command construction and block control characters in incoming remote session data immediately. Isolate affected systems and apply the architecture and design mitigation to prevent unauthorized code execution. Assume all remote input is malicious and switch to static command construction to stop the command injection attack pattern.</p>

<h3 id="limits-and-watch-4">Limits and watch</h3>

<p>Static analysis tools can detect this weakness, but we cannot confirm a patch date for the affected products yet. The specific malware families involved in the active exploitation of CVE-2026-1731 are reported with varying detail across sources, making it difficult to confirm a single consistent payload signature for detection. While both CVE-2024-12356 and CVE-2026-1731 share a CVSS score of 9.8 and pre-authentication access requirements, the exact version ranges affected by the older CVE-2024-12356 are not clearly distinguished from the newer flaw in the provided evidence. Watch for repeated detection of control characters by input filters, as this specific indicator signals an attempt to exploit multiple input interpretation layers in the remote service.</p>

<h3 id="vulnerabilities-5">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2024-12356</strong> — CVSS 9.8 (Critical) · CISA KEV · CWE-77 · BeyondTrust Remote Support; BeyondTrust Privileged Remote Access. A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.</li>
  <li><strong>CVE-2026-1731</strong> — CVSS 9.8 (Critical) · CISA KEV · CWE-78 · BeyondTrust Remote Support(RS) &amp; Privileged Remote Access(PRA). BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability.</li>
</ul>

<h3 id="techniques-5">Techniques</h3>

<ul>
  <li><strong>AML.T0001</strong> Search Open AI Vulnerability Analysis (Reconnaissance)</li>
  <li><strong>AML.T0010.005</strong> AI Agent Tool (Initial Access)</li>
  <li><strong>AML.T0016.002</strong> Generative AI (Resource Development)</li>
  <li><strong>AML.T0103</strong> Deploy AI Agent (Execution)</li>
  <li><strong>T1203</strong> Exploitation for Client Execution (Execution)</li>
  <li><strong>T1210</strong> Exploitation of Remote Services (Lateral Movement)</li>
  <li><strong>T1219</strong> Remote Access Tools (Command And Control)</li>
  <li><strong>T1588.007</strong> Artificial Intelligence (Resource Development)</li>
</ul>

<h3 id="coverage-5">Coverage</h3>

<ul>
  <li><a href="https://hacktron.ai/blog/cve-2026-1731-beyondtrust-remote-support-rce">CVE-2026-1731: Pre-Auth RCE in BeyondTrust Remote Support &amp; PRA</a></li>
  <li><a href="https://www.securityweek.com/google-ai-is-changing-the-pace-and-profile-of-vulnerability-discovery/">Google: AI Is Changing the Pace and Profile of Vulnerability Discovery</a></li>
  <li><a href="https://www.infosecurity-magazine.com/news/ai-found-vulnerabilities-rce/">AI-Found Vulnerabilities More Likely to Enable RCE, Google Says</a></li>
  <li>
    <table>
      <tbody>
        <tr>
          <td>[CISA Adds One Known Exploited Vulnerability to Catalog</td>
          <td>CISA](https://cisa.gov/news-events/alerts/2026/02/13/cisa-adds-one-known-exploited-vulnerability-catalog)</td>
        </tr>
      </tbody>
    </table>
  </li>
  <li><a href="https://therecord.media/google-vulnerabilities-cyberattacks-ai">Google: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation</a></li>
  <li><a href="https://helpnetsecurity.com/2026/02/09/beyondtrust-remote-access-vulnerability-cve-2026-1731">BeyondTrust fixes easy-to-exploit pre-auth RCE vulnerability in remote access tools (CVE-2026-1731) - Help Net Security</a></li>
</ul>

<hr />

<h2 id="7-cisco-patches-actively-exploited-zero-day-in-catalyst-sd-wan-controller-segment">7. Cisco patches actively exploited zero-day in Catalyst SD-WAN Controller <em>(Segment)</em></h2>

<p><em>Event first seen in a show</em></p>

<h3 id="what-changed-5">What changed</h3>

<p>Cisco released emergency updates for CVE-2026-20182, a critical zero-day authentication bypass in the Catalyst SD-WAN Controller that has been actively exploited since 2023. Unauthenticated attackers bypass DTLS authentication in the vdaemon service by impersonating a vHub device, allowing them to inject SSH keys into the vmanage-admin account and execute arbitrary commands via NETCONF for full administrative control. Rapid7 Labs discovered the flaw while researching CVE-2026-20127, and CISA added it to the Known Exploited Vulnerabilities Catalog with a May 17, 2026 deadline. All five reporting outlets agree on the technical mechanism and the lack of available workarounds. If you run Catalyst SD-WAN, verify your patch status immediately. Before upgrading, collect admin-tech logs for TAC analysis to check for prior intrusion. Watch for unexpected SSH key additions to the vmanage-admin account or anomalous NETCONF sessions.</p>

<h3 id="how-it-works-5">How it works</h3>

<p>Cisco’s May 2026 advisory confirms that exploitation is limited to specific control components and requires the collection of admin-tech logs for TAC analysis to verify prior intrusion. The mechanism involves Cisco Catalyst SD-WAN Manager 20.1.12 allowing unauthenticated attackers to bypass peering authentication using crafted requests. The peering authentication mechanism fails to verify identity, letting attackers log in as high-privileged non-root users. This improper authentication flaw enables attackers to assume the identity of an internal high-privileged user. By exploiting this gap, attackers can access NETCONF. Today, an unauthenticated remote attacker bypassed peering auth in Cisco Catalyst SD-WAN Controller versions like 20.6.4 to gain admin access. That breach grants NETCONF control, enabling configuration manipulation across the entire SD-WAN fabric without requiring network exposure. Exploitation affects versions from 17.2.1 through 20.16.1 and higher, while static analysis tools struggle to detect this improper authentication flaw. The flaw impacts all deployment types, including on-premises, cloud, and government environments, and is distinct from CVE-2026-20127 because it resides in a different part of the networking stack despite sharing the same impact. The vulnerability carries a CVSSv3.1 score of 10.0 and allows for persistent SSH key injection, enabling adversaries to maintain access and manipulate network configurations within the SD-WAN fabric. Cisco Catalyst SD-WAN Controller deployments face active exploitation of a critical authentication bypass that grants unauthenticated attackers administrative control over the network fabric. Once logged in, attackers can manipulate the SD-WAN fabric through NETCONF, potentially compromising the entire network fabric.</p>

<h3 id="what-to-do-5">What to do</h3>

<p>Verify your specific controller version against the full list to confirm protection against this improper authentication issue. Check your SD-WAN Manager inventory against the affected list and apply the latest patch immediately to restore proper authentication controls. Verify NETCONF access on affected versions and apply architecture-based authentication frameworks to prevent unauthorized configuration manipulation. Verify control connection handshakes immediately to prevent NETCONF manipulation of the SD-WAN fabric configuration. Verify authentication framework usage for affected versions and watch for identity spoofing indicators in the fabric. Restrict access to management interfaces and apply the released security updates to mitigate the risk, as no workarounds are available for this authentication bypass.</p>

<h3 id="limits-and-watch-5">Limits and watch</h3>

<p>The exact scope of prior exploitation remains uncertain until the Cisco TAC compromise scan of the collected admin-tech logs is completed. Automated static analysis tools have difficulty detecting custom authentication schemes, which limits the ability to identify this specific peering authentication flaw through standard configuration file analysis. Watch vdaemon logs for DTLS bypass attempts. Signals vHub impersonation. Adversary action.</p>

<h3 id="vulnerabilities-6">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-20127</strong> — CVSS 10 (Critical) · CISA KEV · CWE-287 · Cisco Cisco Catalyst SD-WAN Manager. A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN…</li>
  <li><strong>CVE-2026-20182</strong> — CVSS 10 (Critical) · CISA KEV · CWE-287 · Cisco Cisco Catalyst SD-WAN Controller; Cisco Cisco Catalyst SD-WAN Manager. May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026.</li>
</ul>

<h3 id="techniques-6">Techniques</h3>

<ul>
  <li><strong>T1021</strong> Remote Services (Lateral Movement)</li>
  <li><strong>T1133</strong> External Remote Services (Persistence)</li>
  <li><strong>T1190</strong> Exploit Public-Facing Application (Initial Access)</li>
  <li><strong>T1210</strong> Exploitation of Remote Services (Lateral Movement)</li>
  <li><strong>T1212</strong> Exploitation for Credential Access (Credential Access)</li>
</ul>

<h3 id="indicators-5">Indicators</h3>

<ul>
  <li>8 indicators on file</li>
</ul>

<h3 id="coverage-6">Coverage</h3>

<ul>
  <li><a href="https://thehackernews.com/2026/05/cisco-catalyst-sd-wan-controller-auth.html">Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access</a></li>
  <li><a href="https://bleepingcomputer.com/news/security/cisco-warns-of-new-critical-sd-wan-flaw-exploited-in-zero-day-attacks">Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks</a></li>
  <li><a href="https://cisco.com/c/en/us/support/docs/routers/sd-wan/225842-remediate-catalyst-sd-wan-security.html">Remediate Catalyst SD-WAN Security Advisory - May 2026</a></li>
  <li><a href="https://rapid7.com/blog/post/ve-cve-2026-20182-critical-authentication-bypass-cisco-catalyst-sd-wan-controller-fixed">CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)</a></li>
  <li><a href="https://cybersecuritynews.com/cisco-catalyst-sd-wan-controller-0-day">Cisco Catalyst SD-WAN Controller 0-Day Actively Exploited to Gain Admin Access</a></li>
</ul>

<hr />

<h2 id="8-cisa-mandates-patch-for-critical-cisco-sd-wan-auth-bypass-segment">8. CISA Mandates Patch for Critical Cisco SD-WAN Auth Bypass <em>(Segment)</em></h2>

<p><em>Event first seen in a show</em></p>

<p>CISA added CVE-2026-76504 to its Known Exploited Vulnerabilities catalog on Wednesday, October 1, 2026, mandating that federal agencies patch the flaw by October 3. Cisco confirmed that active exploitation of this zero-day began in September 2026, targeting the Catalyst SD-WAN Manager API. The vulnerability carries a CVSS score of 9.8. CISA has added a critical Cisco vulnerability to its Known Exploited Vulnerabilities catalog, giving federal agencies until October third to patch. The flaw allows unauthenticated attackers to bypass authentication on Catalyst SD-WAN Manager by sending crafted requests to the j_security_check endpoint. Fixed versions include 20[.]9[.]10[.]1, 20[.]15[.]6[.]1, and 26.2.1. For detection engineering, look for anomalous HTTP requests targeting the j_security_check endpoint with malformed URI encoding. If you run on-premises SD-WAN Manager, you are exposed until you upgrade. Cisco has released software updates to address the issue, with fixed versions including 20[.]9[.]10[.]1, 20[.]15[.]6[.]1, and 26.2.1.</p>

<p>Cisco Catalyst SD-WAN Manager versions through 18.4.3 allow an unauthenticated attacker to bypass admin-only API rules by double-encoding URL slashes. The flaw stems from improper handling of URI encoding in the API session-based authentication management, specifically within the j_security_check endpoint. Cisco Catalyst SD-WAN Manager has a critical flaw scoring nine point eight on the CVSS scale. This double-encoding issue, rooted in CWE-177, lets attackers gain full admin privileges without credentials. The system behaves as if an authorized administrator is present, allowing immediate lateral movement across the fabric. Attackers can alter system state without authentication, creating a severe integrity breach. The vulnerability affects all configurations and releases prior to the fixed versions, including the 17.2, 18.2, 18.3, and 18.4 series. Successful exploitation grants administrative control over the network without any network access precondition.</p>

<p>Cisco Catalyst SD-WAN Manager instances running versions 17.2.4 through 18.4.3 are exposed to unauthenticated remote access that grants full administrative privileges. Because the flaw bypasses authentication entirely, any internet-facing or internal SD-WAN Manager instance in the affected range is a direct entry point for lateral movement into the network. Defenders gain clarity by recognizing that traffic filtering alone fails against double-encoded payloads like %252E, necessitating immediate input validation updates for the affected SD-WAN Manager instances. Upgrade all affected Cisco Catalyst SD-WAN Manager instances to version 20[.]9[.]10[.]1, 20[.]15[.]6[.]1, or 26.2.1 immediately, as no workarounds exist for this authentication bypass. Validate every URL input against a strict allowlist and reject any request containing invalid or denylisted characters after the first decode. Check all URL inputs against known-good specifications immediately, as standard filters often miss doubly encoded payloads like %252E. Validate all URL inputs against a strict allowlist for the affected Cisco Catalyst SD-WAN Manager releases to block this bypass.</p>

<p>Traffic filtering can flag suspicious double-encoded requests, but the application fails to detect the encoding, so the exploit succeeds regardless of IDS signatures, leaving the system in an unexpected integrity state until patched. The advisory does not detail the specific URI encoding patterns used in active exploitation, making it difficult to distinguish malicious double-encoding from legitimate client behavior without additional context. It remains unclear whether the vulnerability can be leveraged to execute arbitrary code beyond the API authentication bypass, as current evidence only confirms administrative access to the API. Monitor for IDS alerts flagging requests where the first decoding process leaves invalid or denylisted characters, indicating potential URL encoding bypass attempts. Watch for post-compromise lateral movement signals, such as suspicious child process creation or shell spawning from the SD-WAN Manager service context after successful exploitation.</p>

<h3 id="vulnerabilities-7">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-76504</strong> — CVSS 9.8 (Critical) · CWE-177 · Cisco Cisco Catalyst SD-WAN Manager. A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.</li>
</ul>

<h3 id="techniques-7">Techniques</h3>

<ul>
  <li><strong>AML.T0106</strong> Exploitation for Credential Access (Credential Access)</li>
  <li><strong>T1190</strong> Exploit Public-Facing Application (Initial Access)</li>
  <li><strong>T1203</strong> Exploitation for Client Execution (Execution)</li>
  <li><strong>T1210</strong> Exploitation of Remote Services (Lateral Movement)</li>
  <li><strong>T1212</strong> Exploitation for Credential Access (Credential Access)</li>
</ul>

<h3 id="indicators-6">Indicators</h3>

<ul>
  <li>4 indicators on file</li>
</ul>

<h3 id="coverage-7">Coverage</h3>

<ul>
  <li><a href="https://rapid7.com/db/vulnerabilities/cve-2026-76504">CVE-2026-76504: Cisco Cisco Catalyst SD-WAN Manager: A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an…</a></li>
  <li><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU?vs_f=Cisco+Security+Advisory%26vs_cat%3DSecurity+Intelligence%26vs_type%3DRSS%26vs_p%3DCisco+Catalyst+SD-WAN+Manager+API+Authentication+Bypass+Vulnerability%26vs_k%3D1">Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability</a></li>
  <li><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU">Cisco Security Advisory: Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability</a></li>
  <li><a href="https://www.cisa.gov/news-events/alerts/2026/09/30/cisa-adds-one-known-exploited-vulnerability-catalog">CISA Adds One Known Exploited Vulnerability to Catalog</a></li>
  <li><a href="https://gbhackers.com/critical-cisco-sd-wan-vulnerability/">Critical Cisco SD-WAN Vulnerability Lets Remote Attackers Bypass Authentication as Admin</a></li>
  <li><a href="https://cybersecuritynews.com/cisco-sd-wan-manager-0-day-flaw">Cisco SD-WAN Manager Authentication 0-day Vulnerability Actively Exploited in the Wild</a></li>
  <li><a href="https://thehackernews.com/2026/10/cisa-adds-exploited-cisco-catalyst-sd.html">CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV</a></li>
  <li><a href="https://www.helpnetsecurity.com/2026/10/01/new-cisco-sd-wan-zero-day-exploited-in-the-wild-cve-2026-76504/">New Cisco SD-WAN zero-day exploited in-the-wild (CVE-2026-76504)</a></li>
  <li><a href="https://www.securityweek.com/cisco-patches-exploited-catalyst-sd-wan-zero-day-vulnerability/">Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability</a></li>
</ul>

<hr />

<h2 id="9-new-spectre-v2-variant-leaks-linux-root-hashes-via-jit-engines-segment">9. New Spectre v2 Variant Leaks Linux Root Hashes via JIT Engines <em>(Segment)</em></h2>

<p><em>No material change since last show</em></p>

<h3 id="what-changed-6">What changed</h3>

<p>Researchers from VUsec and Scuola Superiore Sant’Anna disclosed Branch Target Reuse, a new Spectre v2 variant that exploits stale branch predictor data to recover Linux root password hashes. The attack targets the interaction between self-modifying code and branch predictors in environments like Linux cBPF, Oracle GraalVM, and Mozilla SpiderMonkey. On modern Intel, AMD, and Arm processors, local attackers can use this to recover root password hashes. Proof-of-concept exploits demonstrated that the vulnerability bypasses existing mitigations like FineIBT, recovering credentials in three to five minutes on fully patched systems. The vulnerability is assigned CVE-2026-64507 and CVE-2026-64508, with fixes already merged into the Linux kernel. Mitigations have already been merged into the Linux kernel and adopted by Oracle and Mozilla. The lead sheet tracks the specific JIT engine configurations and the kernel patch versions that close this gap. Proof-of-concept exploits have demonstrated that the attack can leak and recover root password hashes within minutes on fully patched Intel systems with default protections enabled. Leakage rates were measured at approximately 5.4 KB per second on Lion Cove processors and 5.7 KB per second on Raptor Cove chips. The attack bypasses existing mitigations such as FineIBT, confirming that speculative execution risks persist in JIT engines despite previous hardening efforts.</p>

<h3 id="how-it-works-6">How it works</h3>

<p>Today’s Linux kernel update resolves CVE-2026-64507 by forcing an Instruction Buffer Privilege Bypass flush specifically when the BPF JIT compiler reuses memory, a hardening that only activates if CONFIG_BPF_JIT is enabled. It also resolves CVE-2026-64508 by adding a branch predictor flush when reusing JIT memory, preventing old indirect jump predictions from contaminating fresh code. By hijacking speculative control flow to newly generated code at obsolete offsets, local attackers can leak arbitrary memory on modern Intel CPUs. The vulnerability affects Linux kernel versions 5.18 through 7.2, specifically targeting the BPF JIT allocator where small programs are packed into larger executable allocations. This fix protects systems running kernel versions 5.18 through 7.2 from Spectre-v2 JIT spraying attacks that previously exploited the BPF dispatcher’s lack of isolation during memory reuse. This fix covers Linux 5.18 through 7.2 versions but leaves allocations larger than a pack unprotected, a safe boundary since unprivileged cBPF programs stay well below that size. Successful exploitation allows adversaries to recover root password hashes, which can then be cracked offline to gain full system access.</p>

<h3 id="what-to-do-6">What to do</h3>

<p>This exposure confirms that local attackers can still extract high-value credentials from environments where JIT engines are not properly hardened against stale branch predictor data. Apply the Linux kernel patches for CVE-2026-64507 and CVE-2026-64508 to enable the IBPB flush on BPF JIT memory reuse, specifically targeting versions 5.18, 6.1.183, 6.6.145, 6.12.97, 6.18.39, 7.1.4, and 7.2. Operators deploying kernels 6.1.183 or later must verify their BPF JIT configuration today to ensure the IBPB flush logic is active before any JIT spraying attempt could succeed. Operators on affected kernels must verify their specific version matches the hardened baseline to ensure the JIT spray mitigation is active. Verify that the bpf_arch_pred_flush_enabled static key is active on affected hosts to ensure the branch predictor flush executes before reusing JIT memory allocations.</p>

<h3 id="limits-and-watch-6">Limits and watch</h3>

<p>The IBPB flush mitigation for CVE-2026-64507 is skipped if the BPF dispatcher is already using a retpoline sequence, leaving a potential gap in protection for those specific configurations. The flush for CVE-2026-64508 does not cover allocations larger than a pack, relying on the assumption that cBPF programs remain bounded well below that size to maintain safety. Watch for John the Ripper or Hashcat running after shadow files or dumped hashes are accessed, since that marks post-credential dump activity.</p>

<h3 id="vulnerabilities-8">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-64507</strong> — CVSS 0 (Low) · Linux Linux; Linux Linux. In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Enable IBPB flush on BPF JIT allocation Enable hardening against JIT spraying when Spectre-v2 mitigations are in use.</li>
  <li><strong>CVE-2026-64508</strong> — CVSS 0 (Low) · Linux Linux; Linux Linux. In the Linux kernel, the following vulnerability has been resolved: bpf: Support for hardening against JIT spraying The BPF JIT allocator packs many small programs into larger executable allocations and reuses space…</li>
</ul>

<h3 id="techniques-8">Techniques</h3>

<ul>
  <li><strong>T1110.002</strong> Password Cracking (Credential Access)</li>
  <li><strong>T1205.002</strong> Socket Filters (Stealth)</li>
</ul>

<h3 id="coverage-8">Coverage</h3>

<ul>
  <li><a href="https://www.bleepingcomputer.com/news/security/new-spectre-v2-attack-variant-leaks-linux-root-password-hash-in-minutes/">New Spectre v2 attack variant leaks Linux root password hash in minutes</a></li>
  <li><a href="https://vusec.net/projects/btr">Branch Target Reuse: Spectre-v2 Attacks in JIT Engines</a></li>
  <li><a href="https://thehackernews.com/2026/09/new-spectre-v2-btr-attack-leaks-linux.html">New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses</a></li>
  <li><a href="https://www.theregister.com/security/2026/09/30/spectre-bug-is-back-this-time-to-haunt-jit-engines/5299937">Spectre bug is back, this time to haunt JIT engines</a></li>
  <li><a href="https://cybersecuritynews.com/cpu-attack-to-steal-linux-root-password">Researchers Use New CPU Attack to Steal Linux Root Password Hash From Memory</a></li>
</ul>

<hr />

<h2 id="10-owasp-modsecurity-waf-bypass-flaws-disclosed-hot">10. OWASP ModSecurity WAF Bypass Flaws Disclosed <em>(Hot)</em></h2>

<p><em>Event first seen in a show</em></p>

<p>Yesterday, OWASP ModSecurity dropped ten security advisories exposing a critical gap in your perimeter. Attackers exploit differences in how Go, Python, Node[.]js, and Java backends handle RFC 2231 filenames, Base64 decoding, and comment removal to bypass firewall protections. Maintainer airween published these updates on GitHub Security Advisories between April and September 2026, identifying high-severity issues from RFC 2231 parameter bypasses to TLS hostname verification errors. The owasp-modsecurity/ModSecurity project confirmed these vulnerabilities through specific GitHub Security Advisory identifiers, including GHSA-5pww-8rfg-9crf, GHSA-4j47-8qcr-jf59, and GHSA-qrch-pjfr-9g47. While some of these issues lack assigned CVEs, the project has verified their security impact, confirming that they enable malicious file uploads and evasion of signature-based filtering. Upgrade immediately to ModSecurity version 2.9.15 or 3.0.17 and verify your current version against the eight listed GHSA identifiers.</p>

<p>Attackers exploit parsing differences and transformation errors in how ModSecurity handles HTTP requests, specifically leveraging RFC 2231 filename mismatches and incorrect Base64 decoding to evade detection. These flaws also involve improper comment removal in request processing and an uninitialized pointer dereference, which allows attackers to trigger denial-of-service conditions or bypass WAF rules entirely. ModSecurity versions 2.9.15 and 3.0.17 face multipart parsing errors and pattern matching obfuscation. Adversaries can execute malicious requests that bypass standard WAF protections, rendering the firewall blind to specific evasion techniques. If you are running versions prior to 2.9.15 or 3.0.17, your WAF is effectively blind to these specific RFC 2231 and Base64 evasion techniques.</p>

<p>If you cannot patch immediately, tighten upstream input validation to compensate for the WAF’s blind spots regarding malicious file execution.</p>

<p>Watch for a spawn chain where a user opens a file in Downloads or Temp and then executes a new child process like powershell[.]exe or cmd[.]exe.</p>

<h3 id="techniques-9">Techniques</h3>

<ul>
  <li><strong>T1204.002</strong> Malicious File (Execution)</li>
  <li><strong>T1505.003</strong> Web Shell (Persistence)</li>
</ul>

<h3 id="indicators-7">Indicators</h3>

<ul>
  <li>11 indicators on file</li>
</ul>

<h3 id="coverage-9">Coverage</h3>

<ul>
  <li><a href="https://cybersecuritynews.com/modsecurity-vulnerabilities-bypass">ModSecurity Vulnerabilities Let Attackers Bypass Web Application Firewall Protections</a></li>
  <li><a href="https://github.com/owasp-modsecurity/ModSecurity/security/advisories?page=1">Build software better, together</a></li>
  <li><a href="https://gbhackers.com/multiple-modsecurity-vulnerabilities/">Multiple ModSecurity Vulnerabilities Let Attackers Bypass WAF Rules and Execute Malicious Requests</a></li>
</ul>]]></content><author><name></name></author><summary type="html"><![CDATA[ShinyHunters just breached the FBI and Nissan with a PeopleSoft zero-day. Meanwhile, Apple patched a CoreGraphics flaw used against journalists, while Citrix NetScaler zero-days are already active globally, forcing a Sept 30 deadline for]]></summary></entry><entry><title type="html">The Hot Drop for 09-30-2026</title><link href="/blog/the-hot-drop-for-09-30-2026/" rel="alternate" type="text/html" title="The Hot Drop for 09-30-2026" /><published>2026-09-30T13:33:55+00:00</published><updated>2026-09-30T13:33:55+00:00</updated><id>/blog/the-hot-drop-for-09-30-2026</id><content type="html" xml:base="/blog/the-hot-drop-for-09-30-2026/"><![CDATA[<p>Citrix NetScaler zero-days granted root access for weeks. Did you know WHIPSHOT and SLAPSHOT shells are already inside your network? With CISA mandating patches by September 30, are you patched or are you next?</p>

<p><strong>Since the last show:</strong> 2 new · 8 developing · 4 dropped · 57% overlap with the previous show</p>

<h2 id="contents">Contents</h2>

<ol>
  <li>Citrix NetScaler Zero-Days Exploited for Weeks</li>
  <li>Citrix NetScaler Zero-Days Exploited for Root Access</li>
  <li>Citrix NetScaler Exploitation Confirmed</li>
  <li>Apple Patches CoreGraphics Zero-Day CVE-2026-86950 Exploited in Targeted Attacks</li>
  <li>Palo Alto Networks’ OperTraitor Exposes IBM Turbonomic RBAC Flaw</li>
  <li>XBOW AI Agent Discovers CVE-2026-72018: Linux Kernel Flaw Enables Local Root Escalation</li>
  <li>ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach Universities, FBI, and Nissan</li>
  <li>Sysdig documents JADEPUFFER, the first end-to-end AI-driven ransomware operation exploiting Langflow</li>
  <li>New Spectre v2 Variant Leaks Linux Root Hashes via JIT Engines</li>
  <li>Infostealers Drive 74% Surge in Cookie Theft</li>
</ol>

<hr />

<h2 id="1-citrix-netscaler-zero-days-exploited-for-weeks-lead">1. Citrix NetScaler Zero-Days Exploited for Weeks <em>(Lead)</em></h2>

<p><em>1 new indicator(s) observed</em></p>

<p>Citrix NetScaler appliances are under active attack from two critical zero-day flaws that have been exploited for weeks. On September twenty-seventh, Citrix patched eight vulnerabilities, including CVE-2026-88771 and CVE-2026-88772, which allow unauthenticated remote code execution. CISA immediately added these vulnerabilities to its Known Exploited Vulnerabilities catalog, mandating that federal agencies apply the patches by September 30, 2026. GreyNoise confirmed exploitation attempts on September twenty-fourth from IP 149[.]104[.]78[.]141, though reports conflict on the campaign’s start date, with some citing activity as early as January. Attackers use these flaws to gain root access, deploy webshells like WHIPSHOT and SLAPSHOT, and exfiltrate data to Hetzner servers. If you run NetScaler ADC or Gateway, verify you are on version 14.1-73.37 or 13.1-64.23 immediately. The primary signal to watch is any outbound connection to Hetzner infrastructure or the specific IP 149[.]104[.]78[.]141. The Dutch National Cyber Security Center and Citrix confirmed that APT groups and ransomware affiliates are actively exploiting NetScaler ADC appliances. Verification shows the flaws allow unauthenticated remote attackers to execute arbitrary commands without valid credentials or user accounts.</p>

<p>Attackers exploit CVE-2026-88771 in Citrix NetScaler ADC before version 14.1-73.37 to run arbitrary commands via improper input validation. NetScaler Gateway 14.1 misreads input past its buffer boundary when acting as an RDP Proxy. The weakness allows attackers to bypass standard access controls on these appliances, enabling unauthorized traffic manipulation. An attacker observes prior token values to calculate the exact next value, bypassing standard session validation without network access. Citrix NetScaler ADC before version 14.1-73.37 mishandles HTTP request smuggling, allowing attackers to inject unauthorized requests into back-end servers. An attacker exploits this weakness to bypass feature restrictions without needing prior authentication or privilege. The attack chain relies on improper input validation and memory overflow issues in the NetScaler client authentication process, which allow an attacker to bypass security restrictions and gain root access. Once initial access is achieved, the exploit enables the execution of arbitrary commands on the appliance, facilitating the deployment of webshells and data exfiltration. Citrix NetScaler ADC and Gateway versions before 14.1-73.37 face a feature policy bypass via improper HTTP URL expression. This out-of-bounds read exposes sensitive data with a CVSS 7.5 score, affecting only Gateway and AAA virtual servers. Today, NetScaler ADC and Gateway versions 14.1 through 73.32 remain exposed to CVE-2026-19490 within the broader set of ten related CVEs. Today’s Citrix NetScaler ADC update before 14.1-73.37 exposes CWE-342 via predictable session tokens, yielding high confidentiality impact. This unauthenticated command injection affects all NetScaler appliances in default configurations, enabling attackers to crash systems and consume critical CPU resources. This unauthenticated remote code execution grants full system control, enabling denial of service or data theft on affected appliances. This improper input validation flaw allows unauthenticated attackers to crash the device or elevate privileges on versions before 14.1-73.37. This weakness, tracked as CWE-444, specifically targets the NetScaler Gateway and ADC products running older Citrix releases. The scope of the impact includes all internet-facing Citrix NetScaler ADC and Gateway appliances running versions prior to the September 27, 2026, security updates. Consequences of successful exploitation include full system compromise, where attackers gain root access to deploy persistent webshells and exfiltrate sensitive data to external infrastructure. Attackers exploited Citrix NetScaler ADC and Gateway versions before 14.1-73.37 via remote code execution, achieving high impact without user interaction. Active exploitation by APT and ransomware groups has already compromised NetScaler instances, confirming internet-facing appliances are under direct attack. The vulnerabilities require only network access to execute arbitrary commands, so the absence of valid user credentials offers no defense. Defenders gain distinct value by isolating these NetScaler versions from the broader set of ten related CVEs affecting Citrix infrastructure. Attacker IP 149[.]104[.]78[.]141 probed and modified setuid bits, indicating a sophisticated post-exploitation phase that standard RCE monitoring misses. The remaining uncertainty is whether attackers established persistence via webshells, making forensic review of NetScaler logs for base64-encoded commands and verification of no active C2 connections the most useful investigation focus.</p>

<p>Operators must isolate affected NetScaler ADC versions today until the specific patch arrives. Verify your NetScaler inventory against the affected version ranges to confirm exposure status. Apply the Citrix security updates released on September 27, 2026, to all NetScaler ADC and Gateway appliances to close the remote code execution and denial-of-service vectors. Federal agencies must complete the installation of these mitigations by September 30, 2026, to comply with the CISA Known Exploited Vulnerabilities catalog mandate. Immediate patching to version 14.1-73.37 or later is the only effective mitigation for this critical command-injection flaw. This unauthenticated command injection allows full system compromise, so patching is urgent. No other mitigation exists for this active exploitation chain. Patch NetScaler Gateway before 14.1-73.37 immediately to stop this predictable value chain from leaking session data. Defenders must patch all NetScaler appliances to versions 14.1-73.37 or later to close the remote code execution path. Defenders must patch affected appliances immediately to stop the active exploitation chain targeting these critical remote code execution flaws.</p>

<p>Static analysis detects the flaw, but the exact patch release date remains unconfirmed. CISA lists this as known exploited, yet specific attack indicators for CVE-2026-88772 are unconfirmed in the current event set. Although the flaws require zero valid credentials, the scope of lateral movement and data exfiltration depends on the internal network configuration of the compromised appliance. The exact timeline of initial compromise for specific organizations is not established, as reports conflict on whether activity began in January or more recently.</p>

<h3 id="vulnerabilities">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-88771</strong> — CVSS 9.8 (Critical) · CISA KEV · CWE-20 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88772</strong> — CVSS 8.1 (High) · CISA KEV · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2025-5777</strong> — CVSS 7.5 (High) · CISA KEV · CWE-125 · NetScaler ADC; NetScaler Gateway. Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server</li>
  <li><strong>CVE-2026-88778</strong> — CVSS 7.5 (High) · CWE-342 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-19490</strong> — CVSS 0 (Low) · CISA KEV · NetScaler ADC; NetScaler Gateway. Vulnerability in NetScaler ADC and NetScaler Gateway.</li>
  <li><strong>CVE-2026-88773</strong> — CVSS 0 (Low) · CWE-444 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Inconsistent interpretation of HTTP requests (‘HTTP Request/Response smuggling’) vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88774</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88775</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88776</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88777</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
</ul>

<h3 id="techniques">Techniques</h3>

<ul>
  <li><strong>T1021.007</strong> Cloud Services (Lateral Movement)</li>
  <li><strong>T1087.001</strong> Local Account (Discovery)</li>
  <li><strong>T1133</strong> External Remote Services (Persistence)</li>
  <li><strong>T1136.001</strong> Local Account (Persistence)</li>
  <li><strong>T1190</strong> Exploit Public-Facing Application (Initial Access)</li>
  <li><strong>T1202</strong> Indirect Command Execution (Stealth)</li>
  <li><strong>T1203</strong> Exploitation for Client Execution (Execution)</li>
  <li><strong>T1204.002</strong> Malicious File (Execution)</li>
  <li><strong>T1210</strong> Exploitation of Remote Services (Lateral Movement)</li>
  <li><strong>T1211</strong> Exploitation for Stealth (Stealth)</li>
  <li>and 4 more</li>
</ul>

<h3 id="indicators">Indicators</h3>

<ul>
  <li>14 indicators on file</li>
</ul>

<h3 id="coverage">Coverage</h3>

<ul>
  <li><a href="https://rapid7.com/db/vulnerabilities/cve-2026-88771">CVE-2026-88771: Citrix NetScaler: Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway</a></li>
  <li><a href="https://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772">Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772</a></li>
  <li><a href="https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778">Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778</a></li>
  <li><a href="https://cybersecuritynews.com/citrix-netscaler-0-day-rce-vulnerabilities-exploited">CISA Warns of Citrix NetScaler 0-Day RCE Vulnerabilities Exploited in Attacks</a></li>
  <li><a href="https://thehackernews.com/2026/09/cisa-says-attackers-are-exploiting-two.html">CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally</a></li>
  <li><a href="https://hkcert.org/security-bulletin/citrix-products-multiple-vulnerabilities_20260928">Citrix Products Multiple Vulnerabilities</a></li>
  <li><a href="https://www.helpnetsecurity.com/2026/09/28/citrix-netscaler-rce-zero-days-exploited-for-weeks-cve-2026-88771-cve-2026-88772/">Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)</a></li>
  <li><a href="https://greynoise.io/chronicle/gntl-20260928-citrix-cve-2026-88771">GreyNoise Timeline: Citrix CVE-2026-88771</a></li>
  <li><a href="https://labs.watchtowr.com/oh-look-the-foot-gun-went-off-again-citrix-netscaler-preauth-command-injection-cve-2026-88771">Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771)</a></li>
  <li><a href="https://x.com/imposecost/status/2104249722991243742">Andrew Thompson (@ImposeCost) on X</a></li>
  <li>
    <table>
      <tbody>
        <tr>
          <td>[Kwetsbaarheden in Citrix NetScaler ADC en NetScaler Gateway: update nu</td>
          <td>NCSC](https://ncsc.nl/alerts/kwetsbaarheden-in-citrix-netscaler-adc-en-netscaler-gateway-update-nu)</td>
        </tr>
      </tbody>
    </table>
  </li>
  <li><a href="https://www.cybersecuritydive.com/news/citrix-upgrades-netscaler-exploitation/831502/">Citrix urges immediate upgrades of NetScaler amid widespread exploitation attempts</a></li>
  <li><a href="https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation">Swarming Against Citrix 0-Day Exploitation</a></li>
  <li><a href="https://therecord.media/us-uk-warn-of-citrix-netscaler-zero-day-bug">US, UK warn of exploited Citrix NetScaler zero-day bugs</a></li>
  <li><a href="https://socfortress.medium.com/citrix-netscaler-zero-day-vulnerabilities-faq-cve-2026-88771-and-cve-2026-88772-bbd3d8771308">Citrix NetScaler Zero-Day Vulnerabilities FAQ: CVE-2026–88771 and CVE-2026–88772</a></li>
  <li><a href="https://fortiguard.fortinet.com/threat-signal-report/6533">Citrix NetScaler RCE zero-day Vulnerabilities</a></li>
  <li><a href="https://cyberscoop.com/citrix-zero-days-delayed-disclosure/">Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings</a></li>
  <li><a href="https://www.cybersecuritydive.com/news/citrix-netscaler-exploitation-days-before-notification/831634/">Citrix NetScaler exploitation began days before public notification</a></li>
  <li><a href="https://www.helpnetsecurity.com/2026/09/29/netscaler-zero-day-exploitation-escalates-into-mass-attacks-cve-2026-88771/">NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)</a></li>
  <li><a href="https://censys.com/advisory/cve-2026-10747-2">Sept 28 Advisory: Citrix NetScaler ADC and NetScaler Gateway Zero-Day Remote Code Execution [CVE-2026-88771, CVE-2026-88772] - Censys</a></li>
  <li><a href="https://cert.europa.eu/blog/taking-execute-logging-a-bit-too-literally-cve-2026-88771">Taking ‘execute logging’ a bit too literally - CVE-2026-88771</a></li>
  <li><a href="https://x.com/Unit42_Intel">Unit 42 (@Unit42_Intel) on X</a></li>
  <li><a href="https://medium.com/%40graysentinel.ai/citrix-netscaler-zero-day-exploitation-how-attackers-weaponized-cve-2026-88771-and-cve-2026-88772-96cbe45a8f94">Citrix NetScaler Zero-Day Exploitation: How Attackers Weaponized CVE-2026–88771 and CVE-2026–88772…</a></li>
  <li><a href="https://www.securityweek.com/government-finance-orgs-targeted-in-weeks-long-netscaler-zero-day-attacks/">Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks</a></li>
</ul>

<hr />

<h2 id="2-citrix-netscaler-zero-days-exploited-for-root-access-segment">2. Citrix NetScaler Zero-Days Exploited for Root Access <em>(Segment)</em></h2>

<p><em>Event now covered by 4 outlets (was 3)</em></p>

<h3 id="what-changed">What changed</h3>

<p>Mandiant and Google Threat Intelligence Group confirmed that unknown actors actively exploited two critical Citrix NetScaler zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, since early September 2026. The surge in mass exploitation peaked on September 28, with GreyNoise catching an attack from IP 149[.]104[.]78[.]141 installing a web shell three days before public disclosure. The attackers deploy two distinct tools: WHIPSHOT, a PHP web shell disguised as a Debian package, and SLAPSHOT, a Python tunneler used for internal reconnaissance. The fix involves a buffer size check in the NSPPE function to prevent oversized NSB chain copying. This is a high-severity threat listed in the CISA KEV catalog with a CVSS score of 9.8. You must investigate for modified Apache configurations and stolen credentials immediately. Watch for the specific IP 149[.]104[.]78[.]141 in your logs, and verify if any NetScaler gateways in your environment are running unpatched builds. Since early September, attackers have hit ADC and Gateway appliances in North America and Europe, bypassing authentication via a DTLS memory overflow to seize root access on FreeBSD systems. The threat actor leveraged lightweight installer web shells to assert the setuid bit on the /bin/sh executable, establishing persistent root-level execution on the compromised appliances. Researchers have verified that the attackers conducted credential theft and deployed custom malware to breach targets across multiple sectors.</p>

<h3 id="how-it-works">How it works</h3>

<p>Citrix NetScaler ADC versions before 14.1-73.37 allow unauthenticated attackers to run arbitrary commands through improper input validation. This weakness requires only high access complexity, enabling full system compromise without user interaction. The flaw lets adversaries observe prior values to derive the exact next token without network access. It also permits Cross Zone Scripting, where a zone-aware browser loads malicious content that bypasses security zone controls. Additionally, the software allows attackers to bypass feature policies by exploiting improper HTTP URL expression handling. A memory overflow causes denial of service when attackers trigger the overflow. An attacker triggers this overflow without authentication, causing unpredictable behavior in the gateway. Finally, attackers exploit a DTLS memory overflow in the Packet Processing Engine to bypass authentication, trigger unhandled termination, and seize root access on FreeBSD systems. Citrix NetScaler ADC versions prior to 14.1-73.37 face a high-severity remote code execution flaw, CVE-2026-88772, with a CVSS score of 8.1. The vulnerability allows attackers to predict session tokens via CWE-342, enabling Cross Zone Scripting and client-side injection-induced buffer overflow. This mechanism yields full compromise with a CVSS score of 9.8, granting complete control over the appliance without authentication. The flaw also enables privilege elevation through Cross Zone Scripting, causing crashes that consume critical CPU and memory resources. Attackers can access restricted features in older Gateway and ADC products and crash the system without prior authentication. The corruption affects organizations in North America and Europe across government, financial services, education, legal, and professional services sectors. The threat actor deployed multiple PHP web shells and a tunneler malware to proxy traffic into the victim network. This activity facilitated internal reconnaissance, lateral movement, and credential harvesting.</p>

<h3 id="what-to-do">What to do</h3>

<p>Citrix NetScaler ADC before 14.1-73.37 is vulnerable to HTTP request smuggling, allowing attackers to inject unauthorized requests through the load balancer. This specific vulnerability is the second of eight related Citrix issues in the current event set, distinguishing it by its direct remote execution path. The confirmed deployment of PHP web shells and Python tunnelers on NetScaler appliances in North America and Europe indicates that compromised gateways are now serving as active proxies for internal reconnaissance and lateral movement. Because the threat actor uses these tools to harvest credentials and move laterally, the exposure extends beyond the initial appliance compromise to the entire internal network segment accessible from the gateway. Operators must patch versions prior to 14.1-73.37 immediately to stop the exploit chain that targets Citrix infrastructure. Apply the Citrix patch to update NetScaler ADC and Gateway appliances to version 14.1-73.37 or 13.1-64.23 to close the unauthenticated remote code execution vector defined in CVE-2026-88771. Investigate the appliances for modified Apache configurations and the presence of the WHIPSHOT PHP web shell or SLAPSHOT Python tunneler to identify and remove established persistence mechanisms before applying the patch. Operators must patch affected Citrix Gateways immediately to stop predictable token generation from enabling high-impact attacks. Defenders must patch versions before 14.1-73.37 immediately to prevent the high-impact resource consumption and privilege elevation. Defenders must apply the latest Citrix NetScaler Gateway 14.1-73.37 patch immediately to close this high-severity access path. Defenders must isolate the NetScaler Gateway and Gateway before 13.1-64.23 immediately, as the client-side injection indicator shows a crash after downloading code. Defenders must patch immediately to prevent resource exhaustion crashes, as static analysis tools can detect the missing validation logic in affected code paths. Defenders must patch immediately to prevent back-end servers from receiving secret malicious HTTP requests. Operators must upgrade affected Citrix NetScaler systems immediately to versions 14.1-73.37 or later to close this bypass vector. Immediate patching is required for all affected versions to stop the cross-zone scripting and client-side injection attacks.</p>

<h3 id="limits-and-watch">Limits and watch</h3>

<p>We cannot confirm a patch date yet, but unpatched systems remain exposed until Citrix releases the fix. It is not yet established which specific internal systems were accessed via the SLAPSHOT tunneler, meaning the extent of internal reconnaissance and data exfiltration across the affected government and financial sectors is currently unknown. Watch for inbound network access to remote service ports that correlates with near-time instability, such as crashes or abnormal restarts, in NetScaler daemons to detect potential exploitation of remote services for lateral movement.</p>

<h3 id="vulnerabilities-1">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-88771</strong> — CVSS 9.8 (Critical) · CISA KEV · CWE-20 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88772</strong> — CVSS 8.1 (High) · CISA KEV · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88778</strong> — CVSS 7.5 (High) · CWE-342 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88773</strong> — CVSS 0 (Low) · CWE-444 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Inconsistent interpretation of HTTP requests (‘HTTP Request/Response smuggling’) vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88774</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88775</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88776</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88777</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
</ul>

<h3 id="techniques-1">Techniques</h3>

<ul>
  <li><strong>T1021.001</strong> Remote Desktop Protocol (Lateral Movement)</li>
  <li><strong>T1102</strong> Web Service (Command And Control)</li>
  <li><strong>T1133</strong> External Remote Services (Persistence)</li>
  <li><strong>T1190</strong> Exploit Public-Facing Application (Initial Access)</li>
  <li><strong>T1203</strong> Exploitation for Client Execution (Execution)</li>
  <li><strong>T1204.002</strong> Malicious File (Execution)</li>
  <li><strong>T1210</strong> Exploitation of Remote Services (Lateral Movement)</li>
  <li><strong>T1212</strong> Exploitation for Credential Access (Credential Access)</li>
  <li><strong>T1499.004</strong> Application or System Exploitation (Impact)</li>
  <li><strong>T1505.003</strong> Web Shell (Persistence)</li>
  <li>and 3 more</li>
</ul>

<h3 id="indicators-1">Indicators</h3>

<ul>
  <li>1 indicator on file</li>
</ul>

<h3 id="coverage-1">Coverage</h3>

<ul>
  <li><a href="https://labs.watchtowr.com/here-we-go-again-citrix-netscaler-dtls-preauth-memory-overflow-cve-2026-88772">Here We Go Again (Citrix NetScaler DTLS Preauth Memory Overflow CVE-2026-88772)</a></li>
  <li><a href="https://www.theregister.com/security/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-professional-services/5299867">Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services</a></li>
  <li><a href="https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances">Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances</a></li>
  <li><a href="https://rapid7.com/db/vulnerabilities/cve-2026-88772">CVE-2026-88772: Citrix NetScaler: Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway</a></li>
  <li><a href="https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772">GitHub - watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772</a></li>
  <li><a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-citrix-netscaler-zero-day-to-deploy-web-shells/">Hackers exploit Citrix NetScaler zero-day to deploy web shells</a></li>
  <li><a href="https://thehackernews.com/2026/09/attackers-exploit-netscaler-flaw-for.html">Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT</a></li>
  <li><a href="https://www.helpnetsecurity.com/2026/09/30/cve-2026-88772-netscaler-exploitation-zero-day/">Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)</a></li>
  <li><a href="https://securityaffairs.com/200046/security/whipshot-and-slapshot-the-tools-behind-an-active-citrix-netscaler-campaign.html">WHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaign</a></li>
  <li><a href="https://thehackernews.com/2026/09/citrix-netscaler-cve-2026-88772-exploit.html">Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution</a></li>
  <li><a href="https://gbhackers.com/hackers-exploit-citrix-netscaler-zero-day/">Hackers Exploit Citrix NetScaler Zero-Day to Gain Root Access and Deploy Web Shells</a></li>
</ul>

<hr />

<h2 id="3-citrix-netscaler-exploitation-confirmed-segment">3. Citrix NetScaler Exploitation Confirmed <em>(Segment)</em></h2>

<p><em>Event first seen in a show</em></p>

<p>Threat actors are actively exploiting a critical insufficient input validation vulnerability in Citrix NetScaler ADC and NetScaler Gateway products. Researchers at watchTowr confirmed attacks began on March twenty-seventh, targeting CVE-2026-3055. watchTowr suggests the single CVE ID may mask multiple closely related flaws, including a race condition tracked as CVE-2026-4368. The lead sheet details the specific firmware versions and the CISA deadline. CISA added CVE-2026-3055 to its Known Exploited Vulnerabilities catalog, requiring Federal Civilian Executive Branch agencies to remediate by April 2. Watch for unauthorized session token generation or unexpected credential access logs on your NetScaler appliances. If you cannot patch right now, apply Global Deny List signatures on supported builds to mitigate without a reboot.</p>

<p>Yesterday’s NetScaler Gateway 14[.]1[.]66[.]54 update fixed a race condition in Gateway mode that caused user session mixup. An attacker triggers this by sending malformed SAML tokens that force the ADC to read past its buffer boundary. This out-of-bounds read occurs because the product reads data past the end of the intended buffer, a weakness classified as CWE-125. Because the gateway reads past its buffer limits when handling SAML tokens, attackers can now extract cryptographic keys. Because the product reads past its buffer boundaries, an adversary who influences the input can expose sensitive memory addresses or bypass ASLR protections. Attackers exploiting this weakness could impersonate users during SSL VPN or RDP Proxy sessions without needing prior access. The flaw affects NetScaler ADC and Gateway versions 14.1 and 13.1, including FIPS and NDcPP variants, specifically when configured as SAML Identity Providers. Successful exploitation exposes secret values such as cryptographic keys and PII, and can leak memory addresses that bypass ASLR protections.</p>

<p>Because NetScaler appliances frequently sit in critical identity paths, the UK National Cyber Security Centre warns that widespread exposure allows attackers to retrieve session tokens and credentials through simple memory overreads. Update NetScaler ADC and Gateway instances to versions 14.1-66.59 or 13.1-62.23 to close the insufficient input validation flaw in SAML Identity Provider configurations. Operators must verify their appliance configuration matches the affected versions before applying the latest patch. Defenders must immediately validate all SAML inputs against known-good specifications to prevent this memory overread. Defenders must apply input validation to reject malformed SAML requests immediately to stop the overread.</p>

<p>WatchTowr analysis suggests the single CVE-2026-3055 identifier may mask multiple closely related memory leak flaws, complicating the scope of required remediation. The race condition tracked as CVE-2026-4368 affects specific Gateway and AAA virtual server configurations, meaning that patching only the SAML IDP flaw may leave session mixup vulnerabilities unaddressed. Check NetScaler access logs for abnormal request patterns to public endpoints that correlate with elevated 4xx or 5xx errors, indicating potential exploitation of the public-facing application.</p>

<h3 id="vulnerabilities-2">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-3055</strong> — CVSS 9.8 (Critical) · CISA KEV · CWE-125 · NetScaler ADC; NetScaler Gateway. Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread</li>
  <li><strong>CVE-2026-4368</strong> — CVSS 0 (Low) · NetScaler ADC; NetScaler Gateway. Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup</li>
</ul>

<h3 id="techniques-2">Techniques</h3>

<ul>
  <li><strong>AML.T0106</strong> Exploitation for Credential Access (Credential Access)</li>
  <li><strong>T1190</strong> Exploit Public-Facing Application (Initial Access)</li>
  <li><strong>T1212</strong> Exploitation for Credential Access (Credential Access)</li>
  <li><strong>T1589.001</strong> Credentials (Reconnaissance)</li>
  <li><strong>T1590.006</strong> Network Security Appliances (Reconnaissance)</li>
  <li><strong>T1595.002</strong> Vulnerability Scanning (Reconnaissance)</li>
</ul>

<h3 id="indicators-2">Indicators</h3>

<ul>
  <li>1 indicator on file</li>
</ul>

<h3 id="coverage-2">Coverage</h3>

<ul>
  <li><a href="https://cybersecuritydive.com/news/citrix-netscaler-exploitation-vulnerabilities/816097">Citrix NetScaler products confirmed to be under exploitation</a></li>
  <li><a href="https://theregister.com/security/2026/03/30/citrix-netscaler-bug-may-be-multiple-flaws-in-one/5228153">Citrix NetScaler bug may be multiple flaws in one</a></li>
  <li><a href="https://infosecurity-magazine.com/news/citrix-patch-netscaler">Citrix Urges Immediate Patching for Critical NetScaler Vulnerabilities</a></li>
</ul>

<hr />

<h2 id="4-apple-patches-coregraphics-zero-day-cve-2026-86950-exploited-in-targeted-attacks-segment">4. Apple Patches CoreGraphics Zero-Day CVE-2026-86950 Exploited in Targeted Attacks <em>(Segment)</em></h2>

<p><em>CVE-2026-86950 added to CISA KEV catalog</em></p>

<h3 id="what-changed-1">What changed</h3>

<p>Apple released emergency updates for iOS 26.7.1, iPadOS 26.7.1, and macOS on September 28, 2026, to close CVE-2026-86950. This zero-day out-of-bounds write vulnerability in the CoreGraphics framework enables arbitrary code execution when processing maliciously crafted files on devices ranging from iPhone 11 to the latest iPad models. Meta Product Security reported the bug, and exploitation was confirmed against specific individuals, including journalists and government officials, on iOS versions prior to iOS 27. CISA added this vulnerability to its Known Exploited Vulnerabilities catalog, requiring federal agencies to remediate it immediately under Binding Operational Directive 26-04. Apple confirmed that CVE-2026-86950 may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS versions prior to iOS 27. Check your endpoint logs for any CoreGraphics crashes or unusual file processing events from the past week. Focus your detection on the specific file types that trigger CoreGraphics parsing.</p>

<h3 id="how-it-works-1">How it works</h3>

<p>The attacker leveraged the missing bounds check by processing a malicious file to trigger arbitrary code execution with a CVSS score of 8.8, requiring only network access and no user interaction. The weakness stems from poor state management, allowing an adversary holding memory write privileges to corrupt the target process and execute their own payload. This vulnerability requires user interaction to open the crafted file, a precondition that aligns with the T1204.002 technique of user execution via malicious file download or open. The fix is available for iPhone 11 and later, iPad Pro models, iPad Air third generation and later, iPad eighth generation and later, and iPad mini fifth generation and later. Apple issued CVE-2026-86950 for a broader event, but this specific CVE targets high-value individuals through a sophisticated, pre-exploitation attack vector. Operators must distinguish this targeted event from the broader event involving CVE-2026-20700 because the access path and consequence differ significantly.</p>

<h3 id="what-to-do-1">What to do</h3>

<p>Because the flaw resides in CoreGraphics, any device processing a maliciously crafted file on an affected version is at risk of arbitrary code execution. Update macOS devices to Sequoia 15.8.1 or Tahoe 26.7.1 to ensure the improved bounds checking is active against malicious file processing.</p>

<h3 id="limits-and-watch-1">Limits and watch</h3>

<p>The evidence confirms exploitation against specific targeted individuals but does not specify the exact file types or delivery vectors used in the attacks. While CVE-2026-86950 is in the CISA KEV catalog, the related CVE-2026-20700 memory corruption issue has different access requirements and is not explicitly linked to the same targeted campaign. Watch for user execution of malicious files that trigger CoreGraphics parsing, specifically looking for file creation in user-controlled paths followed by unusual process spawns. Monitor for masquerading tactics where files use familiar naming conventions or password protection to increase the likelihood of user interaction with the malicious payload.</p>

<h3 id="vulnerabilities-3">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-86950</strong> — CVSS 8.8 (High) · CISA KEV · Apple iOS and iPadOS; Apple macOS. An out-of-bounds write issue was addressed with improved bounds checking.</li>
  <li><strong>CVE-2026-20700</strong> — CVSS 7.8 (High) · CISA KEV · Apple iOS and iPadOS; Apple macOS; Apple tvOS. A memory corruption issue was addressed with improved state management.</li>
</ul>

<h3 id="techniques-3">Techniques</h3>

<ul>
  <li><strong>T1204.002</strong> Malicious File (Execution)</li>
  <li><strong>T1213.005</strong> Messaging Applications (Collection)</li>
</ul>

<h3 id="indicators-3">Indicators</h3>

<ul>
  <li>1 indicator on file</li>
</ul>

<h3 id="coverage-3">Coverage</h3>

<ul>
  <li><a href="https://gbhackers.com/apple-fixes-ios-zero-day/">Apple Fixes iOS Zero-Day Exploited in Sophisticated Targeted Attacks</a></li>
  <li><a href="https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html">Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks</a></li>
  <li><a href="https://isc.sans.edu/diary/rss/33376">Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950), (Mon, Sep 28th)</a></li>
  <li><a href="https://support.apple.com/en-us/149226">About the security content of iOS 26.7.1 and iPadOS 26.7.1 - Apple Support</a></li>
  <li><a href="https://cybersecuritynews.com/apple-zero-day-vulnerability-exploited">Critical Apple Zero-Day Vulnerability Actively Exploited in Attacks</a></li>
  <li><a href="https://www.theregister.com/security/2026/09/29/apple-patches-coregraphics-zero-day-already-exploited-in-targeted-attacks/5299721">Apple patches CoreGraphics zero-day already exploited in targeted attacks</a></li>
  <li><a href="https://www.helpnetsecurity.com/2026/09/29/apple-core-graphics-zero-day-cve-2026-86950-fixed/">Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950)</a></li>
  <li><a href="https://www.malwarebytes.com/blog/bugs/2026/09/update-your-iphone-ipad-or-mac-flaw-could-run-attackers-code">Update your iPhone, iPad, or Mac: Flaw could run attackers’ code</a></li>
  <li><a href="https://www.cisa.gov/news-events/alerts/2026/09/29/cisa-adds-one-known-exploited-vulnerability-catalog">CISA Adds One Known Exploited Vulnerability to Catalog</a></li>
</ul>

<hr />

<h2 id="5-palo-alto-networks-opertraitor-exposes-ibm-turbonomic-rbac-flaw-segment">5. Palo Alto Networks’ OperTraitor Exposes IBM Turbonomic RBAC Flaw <em>(Segment)</em></h2>

<p><em>Event first seen in a show</em></p>

<h3 id="what-changed-2">What changed</h3>

<p>Palo Alto Networks released OperTraitor, an open-source tool that scans Kubernetes operator manifests to identify excessive role-based access control permissions. The tool immediately flagged a critical flaw in IBM’s Turbonomic Prometurbo agent, now tracked as CVE-2026-6389. IBM Turbonomic versions 8.16.0 through 8.17.6 carry a vulnerability rated 8.8 on the CVSS scale. IBM confirmed the issue and released version 8.18.0 as the fix. Researcher Lior Yakim reported the flaw to IBM in November 2025, with remediation confirmed in February 2026. Map your service accounts against their actual operational requirements using tools like OperTraitor. Watch for any Turbonomic instance running below version 8.18.0, particularly if it holds cluster-admin or broad secret-get permissions.</p>

<h3 id="how-it-works-2">How it works</h3>

<p>Attackers exploit a flaw in IBM Turbonomic prometurbo agent versions 8.16.0 through 8.17.6 to gain unrestricted read access to all cluster secrets. The product grants excessive cluster-wide permissions, allowing privilege escalation from a low-trust operator to full cluster control. An attacker with any operator or service account access exploits the lack of access control to exfiltrate credentials and escalate privileges. Palo Alto’s analysis suggests that over five percent of examined operators requested privileges far beyond their operational needs, indicating a broader pattern of excessive RBAC permissions in Kubernetes environments.</p>

<h3 id="what-to-do-2">What to do</h3>

<p>The IBM Turbonomic flaw exposes a critical weakness where a compromised service account can exfiltrate cluster-wide secrets, leading to full cluster compromise. Because this weakness grants full cluster compromise, immediate architecture redesign to enforce separation of privilege is the only viable mitigation. While MFA and strict User Account Management policies are standard framework mitigations for account compromise, the evidence here shows that the immediate threat is the pre-existing over-privileged role binding itself, not just the authentication method. The uncertainty remains whether an adversary has already modified the service account to add additional roles or bindings, a change that could follow initial compromise to maintain persistent access. Therefore, the most useful decision priority is to map every service account against its actual operational requirements immediately, rather than waiting for a breach, because the tool’s findings suggest that the permission gap is the primary vector for the cluster-wide compromise. Re-install IBM Turbonomic Prometurbo agent version 8.18.0 or later to remediate the excessive cluster-wide permissions identified in CVE-2026-6389. Apply the latest patch immediately and enforce strict separation of privilege between operator and service accounts. Apply the principle of least privilege to service accounts to prevent adversaries from leveraging misconfigured access controls for privilege abuse. Manage trust zones explicitly and enforce separation of privilege to stop lower-privileged accounts from accessing sensitive resources.</p>

<h3 id="limits-and-watch-2">Limits and watch</h3>

<p>We cannot confirm if the current operator account is already misconfigured to allow unrestricted secret access. The CVSS score of 8.8 indicates a high severity, but the specific impact on your environment depends on whether the Turbonomic service account has been compromised. While the vulnerability allows for potential full cluster compromise, the evidence does not confirm active exploitation in your specific cluster. Watch for suspicious RoleBinding or ClusterRoleBinding assignments to service accounts, especially those coming from unknown IPs or outside CI/CD automation. Track Turbonomic instances running below version 8.18.0 that hold cluster-admin or broad secret-get permissions as a primary signal of exposure.</p>

<h3 id="vulnerabilities-4">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-6389</strong> — CVSS 8.8 (High) · CWE-269 · IBM Turbonomic prometurbo agent. IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, including unrestricted read access to all secrets.</li>
</ul>

<h3 id="techniques-4">Techniques</h3>

<ul>
  <li><strong>T1098.006</strong> Additional Container Cluster Roles (Persistence)</li>
  <li><strong>T1204.003</strong> Malicious Image (Execution)</li>
  <li><strong>T1548</strong> Abuse Elevation Control Mechanism (Privilege Escalation)</li>
</ul>

<h3 id="coverage-4">Coverage</h3>

<ul>
  <li><a href="https://ibm.com/support/pages/security-bulletin-ibm-turbonomic-prometurbo-agent-used-ibm-turbonomic-application-resource-management-affected-single-vulnerability-cve-2026-6389">Security Bulletin: IBM Turbonomic Prometurbo agent used by IBM Turbonomic Application Resource Management is affected by a single vulnerability (CVE-2026-6389)</a></li>
  <li><a href="https://cybersecuritynews.com/opertraitors-tool">New OperTraitors Tool Reveals Dangerous Privilege Escalation Paths in Kubernetes Operators</a></li>
  <li><a href="https://gbhackers.com/opertraitor-finds-kubernetes-operators">OperTraitor Finds Kubernetes Operators With Cluster-Wide Secret Access and Admin Paths</a></li>
</ul>

<hr />

<h2 id="6-xbow-ai-agent-discovers-cve-2026-72018-linux-kernel-flaw-enables-local-root-escalation-segment">6. XBOW AI Agent Discovers CVE-2026-72018: Linux Kernel Flaw Enables Local Root Escalation <em>(Segment)</em></h2>

<p><em>Event first seen in a show</em></p>

<h3 id="what-changed-3">What changed</h3>

<p>XBOW researchers disclosed CVE-2026-72018, an out-of-bounds write in the Linux kernel’s DIBS loopback driver that enables local privilege escalation to root. This finding is notable because human analysts previously dismissed the primitive as too weak, largely due to SMC-D code historically running on IBM Z mainframes with hardware protections. Proof-of-concept testing on Ubuntu 24.04 with mitigations disabled achieved successful privilege escalation in twenty-two of one hundred boot attempts, with the first success on the seventh try. Red Hat has warned of potential arbitrary code execution risks, though coverage is currently limited to XBOW and inoreader, so treat broader impact assessments as preliminary.</p>

<h3 id="how-it-works-3">How it works</h3>

<p>Today’s Linux kernel update resolves CVE-2026-72018 by adding a bounds check in the loopback move_data() function to prevent an out-of-bounds write when a peer-supplied offset or size exceeds the allocated DMB length. The vulnerability exists because the loopback move_data() function performs a memcpy into the registered DMB without checking whether the offset plus size exceeds the DMB length, unlike real ISM hardware which enforces memory region bounds natively. This lack of validation allows a peer-supplied out-of-bounds offset or oversized write to result in an out-of-bounds write past the allocated kernel buffer, enabling privilege escalation via the T1068 technique. This weakness allows an attacker with local access to trigger an out-of-bounds write past the kernel buffer, resulting in a high-impact compromise with a CVSS score of 7.8. The flaw affects standard x86 Linux systems by enabling SMC-D functionality through loopback networking, bypassing historical hardware-enforced protections found in mainframe environments. Successful exploitation allows local attackers with CAP_NET_ADMIN privileges to escalate to root, with consequences ranging from denial-of-service conditions to arbitrary code execution depending on the affected memory layout.</p>

<h3 id="what-to-do-3">What to do</h3>

<p>The dibs_loopback driver lacks bounds checking in move_data, exposing x86 Linux systems to root escalation for any local user holding CAP_NET_ADMIN. The exposure maps to T1068 Exploitation for Privilege Escalation, where a constrained 16-byte zero-write primitive corrupts kernel memory to gain root access without an information leak. This behavior resembles historical BYOVD campaigns, yet uncertainty remains whether the 22% success rate on Ubuntu 24.04 in proof-of-concept tests translates to real-world compromise without prior access. Mitigation via application control could block the exploit, but current evidence does not confirm if standard Linux distributions enforce these controls strictly enough to stop the 16-byte write. Watch for the first appearance of CAP_NET_ADMIN users on unpatched Linux 6.10 systems attempting to write to the DIBS loopback interface, which would confirm active exploitation. Apply the kernel patch that adds explicit bounds checks to the dibs_loopback move_data() routine to reject out-of-range offsets with -EINVAL, targeting Linux versions 6.10, 6.12.97, 6.18.40, 7.1.5, and 7.2. Implement application isolation and execution prevention controls to restrict code execution to trusted environments, limiting the ability of unauthorized processes to interact with the vulnerable kernel driver.</p>

<h3 id="limits-and-watch-3">Limits and watch</h3>

<p>Watch for unusual process or token behavior after exploitation attempts on vulnerable kernel drivers, which signals privilege escalation via T1068.</p>

<h3 id="vulnerabilities-5">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-72018</strong> — CVSS 7.8 (High) · Linux Linux; Linux Linux. In the Linux kernel, the following vulnerability has been resolved: dibs: loopback: validate offset and size in move_data() The loopback move_data() performs a memcpy into the registered DMB without checking whether…</li>
</ul>

<h3 id="techniques-5">Techniques</h3>

<ul>
  <li><strong>T1068</strong> Exploitation for Privilege Escalation (Privilege Escalation)</li>
</ul>

<h3 id="indicators-4">Indicators</h3>

<ul>
  <li>3 indicators on file</li>
</ul>

<h3 id="coverage-5">Coverage</h3>

<ul>
  <li><a href="https://gbhackers.com/linux-kernel-cve-2026-72018-flaw">Linux Kernel CVE-2026-72018 Flaw Lets Local Attackers Gain Root Access</a></li>
  <li><a href="https://cybersecuritynews.com/ai-agent-finds-linux-kernel-bug">AI Agent Finds Linux Kernel Bug That Turns a Tiny Memory Write Into Root Access</a></li>
  <li><a href="https://xbow.com/blog/no-time-to-pwn-cve-2026-72018">No Time to Pwn: CVE-2026-72018</a></li>
</ul>

<hr />

<h2 id="7-shinyhunters-exploits-oracle-peoplesoft-zero-day-to-breach-universities-fbi-and-nissan-segment">7. ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach Universities, FBI, and Nissan <em>(Segment)</em></h2>

<p><em>Now attributed to malware: Umbreon</em></p>

<h3 id="what-changed-4">What changed</h3>

<p>ShinyHunters, tracked as UNC6240, breached over one hundred organizations by exploiting a critical zero-day in Oracle PeopleSoft. The group targeted the Environment Management Hub endpoint between May twenty-seventh and June ninth. Victims include the University of Nottingham, which exposed roughly four hundred fifty-five thousand email addresses, and Nissan Americas, which confirmed data theft affecting employees in the US, Canada, Mexico, and Brazil. The FBI is currently investigating a claimed breach of its job application portal. Dutch authorities recently arrested a former ShinyHunters member on suspicion of aiding these operations. Google’s Mandiant and Threat Intelligence Group confirmed the exploitation of the zero-day in Oracle PeopleSoft. The campaign targeted Oracle PeopleSoft servers using an unpatched zero-day, exposing roughly four hundred fifty-five thousand email addresses at the University of Nottingham. Nissan Americas confirmed data theft affecting employees in the US, Canada, Mexico, and Brazil, while new attacks target agriculture, government, and healthcare. After Oracle patched on June tenth, attackers adapted by URL-encoding the PSEMHUB path to bypass detection. Verify WAF rules cover percent-encoded variants of the PSEMHUB endpoint. Block attacker infrastructure domains like azurenetfiles[.]net and winmanage-me[.]network.</p>

<h3 id="how-it-works-4">How it works</h3>

<p>An unauthenticated attacker with network access via HTTP can trigger this CVSS 9.8 flaw without authentication or physical presence. The weakness allows an attacker with network access to compromise the BI Publisher Integration component without requiring any prior authentication. This technique allows the threat actor to target PeopleSoft servers that had not applied security updates by using percent-encoded or mixed-case variants of the vulnerable endpoint. The ShinyHunters extortion crew exploited the unpatched flaw to break into enterprise systems, steal data, and demand payment to keep it private, with the University of Nottingham being one of the first confirmed victims. Oracle’s Security Alert Advisory addresses the remote, authentication-less exploitability of the flaw in PeopleSoft PeopleTools, urging immediate action for affected customers under Premier or Extended Support.</p>

<h3 id="what-to-do-4">What to do</h3>

<p>Unlike the other CVE in this set, this vulnerability allows full takeover of PeopleSoft Enterprise PeopleTools, making immediate patching of versions 8.61 and 8.62 the only viable defense. Because this event pairs CVE-2025-61882 with CVE-2026-35273, defenders gain clarity on how a CVSS 9.8 baseline drives coordinated exploitation across the suite. Because UNC6240 modified its exploit to bypass WAF rules blocking the PSEMHUB endpoint, standard perimeter defenses no longer guarantee protection against this specific zero-day. Apply the Oracle Emergency Security Update for CVE-2026-35273 immediately to all PeopleSoft PeopleTools 8.61 and 8.62 instances to close the remote code execution vector. Update WAF signatures to explicitly block percent-encoded and mixed-case variants of the /PSEMHUB/ path to counter the specific bypass technique used by UNC6240.</p>

<h3 id="limits-and-watch-4">Limits and watch</h3>

<p>The specific technical details of the zero-day vulnerability remain unconfirmed, as ShinyHunters leveraged an unspecified flaw in the PeopleSoft environment. It is not yet established whether the breach of FBI employee personal information is a direct result of the PeopleSoft exploit or a separate operational failure. Check web server logs for unexpected file creation in web directories followed by web server processes spawning command shells or script interpreters, which indicates web shell deployment.</p>

<h3 id="vulnerabilities-6">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2025-61882</strong> — CVSS 9.8 (Critical) · CISA KEV · Oracle Corporation Oracle Concurrent Processing. Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration).</li>
  <li><strong>CVE-2026-35273</strong> — CVSS 9.8 (Critical) · CISA KEV · Oracle Corporation PeopleSoft Enterprise PeopleTools. Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management).</li>
</ul>

<h3 id="techniques-6">Techniques</h3>

<ul>
  <li><strong>AML.T0000</strong> Search Open Technical Databases (Reconnaissance)</li>
  <li><strong>AML.T0006</strong> Active Scanning (Reconnaissance)</li>
  <li><strong>AML.T0049</strong> Exploit Public-Facing Application (Initial Access)</li>
  <li><strong>AML.T0050</strong> Command and Scripting Interpreter (Execution)</li>
  <li><strong>AML.T0055</strong> Unsecured Credentials (Credential Access)</li>
  <li><strong>AML.T0072</strong> Reverse Shell (Command And Control)</li>
  <li><strong>T1005</strong> Data from Local System (Collection)</li>
  <li><strong>T1016</strong> System Network Configuration Discovery (Discovery)</li>
  <li><strong>T1018</strong> Remote System Discovery (Discovery)</li>
  <li><strong>T1027</strong> Obfuscated Files or Information (Stealth)</li>
  <li>and 10 more</li>
</ul>

<h3 id="named-actors-and-malware">Named actors and malware</h3>

<ul>
  <li>ShinyHunters (actor)</li>
  <li>Neo-reGeorg (malware)</li>
  <li>Umbreon (malware)</li>
  <li>TeamPCP (actor)</li>
  <li>Umbreon. (malware)</li>
</ul>

<h3 id="indicators-5">Indicators</h3>

<ul>
  <li>22 indicators on file</li>
</ul>

<h3 id="coverage-6">Coverage</h3>

<ul>
  <li><a href="https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html">ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities</a></li>
  <li><a href="https://oracle.com/security-alerts/alert-cve-2026-35273.html">Oracle Security Alert Advisory - CVE-2026-35273</a></li>
  <li><a href="https://thehackernews.com/2026/09/shinyhunters-claims-fbi-breach-says-it.html">ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants</a></li>
  <li><a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft">ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft</a></li>
  <li><a href="https://thehackernews.com/2026/09/attackers-bypass-wafs-to-exploit-oracle.html">Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells</a></li>
  <li><a href="https://www.bleepingcomputer.com/news/security/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks/">ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks</a></li>
  <li><a href="https://gbhackers.com/oracle-peoplesoft-servers/">Oracle PeopleSoft Servers Targeted Again as ShinyHunters Expands Extortion Operations</a></li>
  <li><a href="https://www.securityweek.com/google-warns-of-shinyhunters-fresh-oracle-peoplesoft-campaign/">Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign</a></li>
  <li><a href="https://gbhackers.com/oracle-peoplesoft-zero-day-rce-vulnerability">Oracle PeopleSoft Zero-Day RCE Vulnerability Exploited by ShinyHunters</a></li>
  <li><a href="https://cybersecuritynews.com/oracle-security-update">Oracle Emergency Security Update to Fix Critical RCE Vulnerability</a></li>
  <li><a href="https://cybersecuritynews.com/shinyhunters-bypasses">ShinyHunters Bypasses WAF Protections to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells</a></li>
  <li><a href="https://cybersecuritynews.com/oracle-peoplesoft-0-day-rce-vulnerability">Oracle PeopleSoft 0-Day RCE Vulnerability Exploited in Attacks by ShinyHunters</a></li>
  <li><a href="https://cybersecuritynews.com/nissan-confirms-data-breach">Nissan Confirms Data Breach Following Oracle PeopleSoft 0-Day Attacks</a></li>
  <li><a href="https://www.helpnetsecurity.com/2026/09/28/fbi-job-portals-offline-shinyhunters-breach/">FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day</a></li>
  <li><a href="https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/">Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation</a></li>
  <li><a href="https://therecord.media/shinyhunters-cyberattacks-oracle-mandiant">ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns</a></li>
  <li><a href="https://thehackernews.com/2026/09/dutch-police-arrest-24-year-old.html">Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation</a></li>
</ul>

<hr />

<h2 id="8-sysdig-documents-jadepuffer-the-first-end-to-end-ai-driven-ransomware-operation-exploiting-langflow-segment">8. Sysdig documents JADEPUFFER, the first end-to-end AI-driven ransomware operation exploiting Langflow <em>(Segment)</em></h2>

<p><em>Event first seen in a show</em></p>

<h3 id="what-changed-5">What changed</h3>

<p>Sysdig researchers documented JADEPUFFER as the first confirmed ransomware operation orchestrated entirely by an autonomous large language model. The attack began by exploiting CVE-2025-3248 in an internet-facing Langflow instance to harvest cloud credentials. An AI agent moved laterally to an Alibaba Nacos service, deploying over six hundred payloads across two machines. It encrypted one thousand three hundred forty-two configuration items, deleted database schemas, and left Bitcoin ransom notes. Microsoft tracked related destructive activity under the alias Storm-3168, involving Azure resource deletion using compromised service principals. Sysdig’s analysis highlights the agent’s ability to self-correct code errors and adapt tactics in real-time. The evidence includes self-narrating code comments and the use of a canonical Bitcoin address found in the model’s training data. The same Langflow instance was subsequently targeted a second time using a compiled Go-based ransomware strain codenamed ENCFORGE. Check your Langflow instances for CVE-2025-3248 exposure immediately. Watch for AI Agent Tool Invocation and OS Credential Dumping techniques.</p>

<h3 id="how-it-works-5">How it works</h3>

<p>An AI agent exploited Langflow versions before 1.3.0 by sending unauthenticated requests to /api/v1/validate/code to run arbitrary Python code. The flaw exploits the AuthFilter servlet to skip checks, enabling attackers to execute any administrative task without valid credentials. The missing authentication on the /api/v1/validate/code endpoint allowed attackers to assume privileged identities, ranging from data access to full host control. This flaw enabled scanning for cloud credentials across Chinese providers like Aliyun and Tencent. In one Microsoft Azure environment, two compromised service principals were used for reconnaissance and destructive actions across multiple subscriptions.</p>

<h3 id="what-to-do-5">What to do</h3>

<p>Nacos servers on version 1.4.0 or lower let attackers bypass authentication using a spoofed user-agent header to seize full administrative control. The JADEPUFFER operation shows an autonomous LLM agent executing a complete ransomware lifecycle, from initial access to destructive impact, without human intervention. This capability shifts the threat model from discrete human-led attacks to continuous, self-correcting automated campaigns that adapt tactics in real-time. Verify Nacos instance versions and restrict server access to prevent authentication bypass. Upgrade Alibaba Nacos to 1.4.1 or higher to eliminate the user-agent spoofing backdoor.</p>

<h3 id="limits-and-watch-5">Limits and watch</h3>

<p>The backdoor mechanism is unique to the Nacos platform’s authentication filter, even though the event includes CVE-2025-3248. We do not know the extent of data exfiltration before encryption, as evidence points to destructive actions and credential harvesting rather than data theft. It remains unclear whether the LLM agent’s self-correction capabilities are unique to this model or represent a broader trend in autonomous threat actor tooling. Watch for manual penetration testing results that identify unauthenticated endpoints in custom authentication mechanisms, since automated tools may miss these critical gaps.</p>

<h3 id="vulnerabilities-7">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2025-3248</strong> — CVSS 9.8 (Critical) · CISA KEV · CWE-306 · langflow-ai langflow. Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint.</li>
  <li><strong>CVE-2021-29441</strong> — CVSS 8.6 (High) · CWE-290 · alibaba nacos. Nacos is a platform designed for dynamic service discovery and configuration and service management.</li>
</ul>

<h3 id="techniques-7">Techniques</h3>

<ul>
  <li><strong>AML.T0006</strong> Active Scanning (Reconnaissance)</li>
  <li><strong>AML.T0010.001</strong> AI Software (Initial Access)</li>
  <li><strong>AML.T0016.002</strong> Generative AI (Resource Development)</li>
  <li><strong>AML.T0053</strong> AI Agent Tool Invocation (Execution)</li>
  <li><strong>AML.T0054</strong> LLM Jailbreak (Defense Evasion)</li>
  <li><strong>AML.T0090</strong> OS Credential Dumping (Credential Access)</li>
  <li><strong>AML.T0098</strong> AI Agent Tool Credential Harvesting (Credential Access)</li>
  <li><strong>AML.T0102</strong> Generate Malicious Commands (Ai Attack Staging)</li>
  <li><strong>AML.T0108</strong> AI Agent (Command And Control)</li>
  <li><strong>T1059.009</strong> Cloud API (Execution)</li>
  <li>and 3 more</li>
</ul>

<h3 id="indicators-6">Indicators</h3>

<ul>
  <li>3 indicators on file</li>
</ul>

<h3 id="coverage-7">Coverage</h3>

<ul>
  <li><a href="https://securityaffairs.com/194713/ai/jadepuffer-first-end-to-end-ai-driven-ransomware-operation.html">JADEPUFFER: First End-to-End AI-Driven Ransomware Operation</a></li>
  <li><a href="https://thehackernews.com/2026/09/jadepuffer-linked-attackers-used.html">JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources</a></li>
  <li><a href="https://csoonline.com/article/4193195/this-ai-agent-autonomously-hacked-a-network-adapted-on-the-fly-and-demanded-a-ransom.html">This AI agent autonomously hacked a network, adapted on the fly, and demanded a ransom</a></li>
  <li><a href="https://bleepingcomputer.com/news/security/jadepuffer-ransomware-used-ai-agent-to-automate-entire-attack">JadePuffer ransomware used AI agent to automate entire attack</a></li>
  <li><a href="https://bleepingcomputer.com/news/security/jadepuffer-agentic-attacks-now-target-ai-model-data-with-ransomware">JadePuffer agentic attacks now target AI model data with ransomware</a></li>
  <li><a href="https://theregister.com/security/2026/07/02/smooth-ai-criminal-drives-first-end-to-end-agentic-ransomware-attack/5266073">Smooth AI criminal drives ‘first’ end-to-end agentic ransomware attack</a></li>
</ul>

<hr />

<h2 id="9-new-spectre-v2-variant-leaks-linux-root-hashes-via-jit-engines-segment">9. New Spectre v2 Variant Leaks Linux Root Hashes via JIT Engines <em>(Segment)</em></h2>

<p><em>Event now covered by 3 outlets (was 2)</em></p>

<h3 id="what-changed-6">What changed</h3>

<p>VUsec and Scuola Superiore Sant’Anna researchers disclosed Branch Target Reuse, a new Spectre v2 variant identified as CVE-2026-64507 and CVE-2026-64508, which exploits stale indirect branch prediction entries in JIT engines. The attack targets the interplay between self-modifying code and indirect branch prediction in Linux cBPF, Oracle GraalVM, and Firefox SpiderMonkey, leaking sensitive data including root password hashes on modern Intel, AMD, and Arm processors. Proof-of-concept exploits recovered these hashes within minutes on fully patched systems, bypassing mitigations like FineIBT. While Linux kernel patches and Oracle’s code-cache randomization are deployed, Mozilla prioritizes site isolation. Measured leakage rates hit approximately 5.7 kilobytes per second on Intel Raptor Cove chips and 5.4 on Lion Cove processors. Standard Spectre mitigations are not sufficient against this specific JIT engine vector. The research is set for publication at the CCS 2026 conference in The Hague.</p>

<h3 id="how-it-works-6">How it works</h3>

<p>In the Linux kernel, the BPF JIT allocator reuses space within larger executable allocations, allowing indirect jumps into fresh code to reuse branch predictions left behind by previous programs. Today’s Linux kernel update resolves CVE-2026-64507 by forcing an Instruction Buffer Privilege Bypass flush specifically when the BPF JIT allocator reuses memory after Spectre-v2 mitigations are active. The update also resolves CVE-2026-64508 by adding a static call to flush indirect branch predictors before reusing JIT memory allocations. The vulnerability affects Linux kernel versions 5.18, 6.1.183, 6.6.145, 6.12.97, 6.18.39, 7.1.4, and 7.2, as well as specific commits, where the BPF JIT is in use. This fix protects systems running Linux versions 5.18 through 7.2 from exploits that leverage stale branch predictions to execute arbitrary code via BPF JIT spraying. Successful exploitation allows adversaries to recover root password hashes, which can then be cracked offline to gain access to systems and services where the account has privileges. This fix applies only to systems running Linux versions 5.18 through 7.2 with BPF-JIT enabled, leaving older kernels and disabled JIT paths unaffected by this specific hardening.</p>

<h3 id="what-to-do-6">What to do</h3>

<p>The Branch Target Reuse attack bypasses existing Spectre-v2 mitigations like FineIBT to leak root password hashes on fully patched Intel systems. This exposure is critical because the attack recovers sensitive credentials in minutes, rendering standard kernel protections insufficient for JIT engine environments. The attacker behavior of password cracking via recovered hashes maps directly to the framework mitigation of Multi-Factor Authentication, which remains ineffective if the root password hash is already exfiltrated. This creates a decision priority where standard credential monitoring is insufficient; instead, responders should examine system logs for rapid hash recovery attempts or unauthorized access using the leaked root credentials. Uncertainty remains regarding the specific target of the attack and whether the leaked hashes have been used for further compromise, so the watch item is any anomalous login activity from the compromised host or evidence of the hash being passed to a cracking tool. Operators must verify their kernel version matches the affected baseline and confirm the bpf_arch_pred_flush_enabled static key is active before deploying today’s patch. Apply the Linux kernel patches for CVE-2026-64507 and CVE-2026-64508 to enable IBPB flush on BPF JIT allocation and harden against JIT spraying. Verify that the BPF dispatcher is using a retpoline sequence or that the bpf_arch_pred_flush static key is active to ensure indirect branch predictors are flushed on memory reuse.</p>

<h3 id="limits-and-watch-6">Limits and watch</h3>

<p>The kernel fix for CVE-2026-64507 only applies when BPF-JIT is in use and is guarded by CONFIG_BPF_JIT, leaving systems with this configuration disabled without this specific hardening. The predictor flush in CVE-2026-64508 does not cover allocations larger than a pack, relying on the assumption that cBPF programs remain bounded below that size. Watch for high CPU usage or GPU invocation via unsigned binaries accessing password hash files, which signals the use of password cracking techniques to recover usable credentials.</p>

<h3 id="vulnerabilities-8">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-64507</strong> — CVSS 0 (Low) · Linux Linux; Linux Linux. In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Enable IBPB flush on BPF JIT allocation Enable hardening against JIT spraying when Spectre-v2 mitigations are in use.</li>
  <li><strong>CVE-2026-64508</strong> — CVSS 0 (Low) · Linux Linux; Linux Linux. In the Linux kernel, the following vulnerability has been resolved: bpf: Support for hardening against JIT spraying The BPF JIT allocator packs many small programs into larger executable allocations and reuses space…</li>
</ul>

<h3 id="techniques-8">Techniques</h3>

<ul>
  <li><strong>T1110.002</strong> Password Cracking (Credential Access)</li>
</ul>

<h3 id="coverage-8">Coverage</h3>

<ul>
  <li><a href="https://www.bleepingcomputer.com/news/security/new-spectre-v2-attack-variant-leaks-linux-root-password-hash-in-minutes/">New Spectre v2 attack variant leaks Linux root password hash in minutes</a></li>
  <li><a href="https://vusec.net/projects/btr">Branch Target Reuse: Spectre-v2 Attacks in JIT Engines</a></li>
  <li><a href="https://thehackernews.com/2026/09/new-spectre-v2-btr-attack-leaks-linux.html">New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses</a></li>
  <li><a href="https://www.theregister.com/security/2026/09/30/spectre-bug-is-back-this-time-to-haunt-jit-engines/5299937">Spectre bug is back, this time to haunt JIT engines</a></li>
</ul>

<hr />

<h2 id="10-infostealers-drive-74-surge-in-cookie-theft-segment">10. Infostealers Drive 74% Surge in Cookie Theft <em>(Segment)</em></h2>

<p><em>Event now covered by 5 outlets (was 4); Now attributed to malware: LockBit</em></p>

<h3 id="what-changed-7">What changed</h3>

<p>NordStellar data reveals a surge in leaked browser cookies from fifty-four billion to nearly ninety-four billion, with the United States ranking fourth globally at over three billion leaked tokens. Lumma, RedLine, and Vidar harvest session tokens and API keys from developer workstations. Five independent outlets, including NordSecurity and WeLiveSecurity, identify these three families as responsible for eighty-five point seven percent of detected incidents. KELA unmasked the Hellcat hacking group as a distributor of these tools, identifying key operators Rey and Pryx. NordVPN reports a seventy-four percent year-over-year surge in leaked cookies, placing the United States fourth globally among two hundred and fifty-three countries.</p>

<h3 id="how-it-works-7">How it works</h3>

<p>Stolen cookies let attackers bypass multi-factor authentication entirely, granting direct access to AWS, Azure, and Google Cloud environments without requiring user login credentials. Stolen data is rapidly validated and resold within hours to access brokers and ransomware operators who monetize verified enterprise access through mature malware-as-a-service ecosystems. Approximately ninety percent of organizations breached in 2024 had their credentials leaked for sale on dark web marketplaces, a statistic largely driven by infostealer malware such as RedLine Stealer and its successor Lumma Stealer. This surge from fifty-four billion to ninety-four billion leaked cookies shows session hijacking is the primary vector for bypassing multi-factor authentication in enterprise cloud environments. The stolen data allows immediate impersonation of authenticated users, creating uncertainty about which specific cloud accounts are currently active and accessible.</p>

<h3 id="what-to-do-7">What to do</h3>

<p>Implement application isolation and sandboxing to restrict infostealer execution, blocking access to sensitive browser resources and critical operations on developer workstations. Integrate secure coding practices into the software development lifecycle to mitigate exploitation of vulnerabilities used to collect credentials and forge authentication tickets.</p>

<h3 id="limits-and-watch-7">Limits and watch</h3>

<p>While infostealer malware can expose an organization’s entire database of digital credentials, the specific scope of data exfiltration varies depending on whether the infection originates from compromised software or direct workstation compromise. The attribution of specific infostealer incidents to individual operators like Rey remains limited to OSINT traces and law enforcement sharing, meaning the full extent of their operational reach across different sectors is not fully established. Watch for abnormal LSASS memory access and forged Kerberos tickets to spot credential validation exploitation before session tokens are harvested.</p>

<h3 id="techniques-9">Techniques</h3>

<ul>
  <li><strong>T1005</strong> Data from Local System (Collection)</li>
  <li><strong>T1027.014</strong> Polymorphic Code (Stealth)</li>
  <li><strong>T1195</strong> Supply Chain Compromise (Initial Access)</li>
  <li><strong>T1212</strong> Exploitation for Credential Access (Credential Access)</li>
  <li><strong>T1219</strong> Remote Access Tools (Command And Control)</li>
  <li><strong>T1528</strong> Steal Application Access Token (Credential Access)</li>
  <li><strong>T1539</strong> Steal Web Session Cookie (Credential Access)</li>
  <li><strong>T1550.004</strong> Web Session Cookie (Lateral Movement)</li>
  <li><strong>T1552.004</strong> Private Keys (Credential Access)</li>
  <li><strong>T1555.005</strong> Password Managers (Credential Access)</li>
  <li>and 8 more</li>
</ul>

<h3 id="named-actors-and-malware-1">Named actors and malware</h3>

<ul>
  <li>LockBit (malware)</li>
  <li>Lumma Stealer (malware)</li>
  <li>RedLine Stealer (malware)</li>
  <li>Lumma (malware)</li>
  <li>RedLine (malware)</li>
</ul>

<h3 id="indicators-7">Indicators</h3>

<ul>
  <li>5 indicators on file</li>
</ul>

<h3 id="coverage-9">Coverage</h3>

<ul>
  <li><a href="https://gbhackers.com/infostealer-malware-3/">Lumma, RedLine and Vidar Infostealers Fuel Cloud Credential Theft Campaigns</a></li>
  <li><a href="https://nordsecurity.com/press-area/from-54-billion-to-94-billion-cookie-theft-skyrockets-as-hackers-exploit-your-browser">From 54 billion to 94 billion: Cookie theft skyrockets as hackers exploit your browser</a></li>
  <li>
    <table>
      <tbody>
        <tr>
          <td>[Infostealer Malware: The Silent Threat to Your Digital Credentials  - Managed IT Services &amp; Technology Consulting</td>
          <td>OSIbeyond](https://osibeyond.com/blog/infostealer-malware-the-silent-threat-to-your-digital-credentials)</td>
        </tr>
      </tbody>
    </table>
  </li>
  <li>
    <table>
      <tbody>
        <tr>
          <td>[UPDATE: Hellcat Hacking Group Unmasked: Investigating Rey and Pryx</td>
          <td>KELA Cyber](https://kelacyber.com/blog/hellcat-hacking-group-unmasked-rey-and-pryx)</td>
        </tr>
      </tbody>
    </table>
  </li>
  <li><a href="https://welivesecurity.com/en/threat-reports">Stay informed with ESET’s threat reports</a></li>
</ul>]]></content><author><name></name></author><summary type="html"><![CDATA[Citrix NetScaler zero-days granted root access for weeks. Did you know WHIPSHOT and SLAPSHOT shells are already inside your network? With CISA mandating patches by September 30, are you patched or are you next?]]></summary></entry><entry><title type="html">The Hot Drop for 09-29-2026</title><link href="/blog/the-hot-drop-for-09-29-2026/" rel="alternate" type="text/html" title="The Hot Drop for 09-29-2026" /><published>2026-09-29T06:31:27+00:00</published><updated>2026-09-29T06:31:27+00:00</updated><id>/blog/the-hot-drop-for-09-29-2026</id><content type="html" xml:base="/blog/the-hot-drop-for-09-29-2026/"><![CDATA[<p>FBI breached via ShinyHunters zero-day sextortion? Meanwhile, Citrix NetScaler zero-days patched after weeks of silent exploitation. Is your legacy infrastructure already compromised?</p>

<p><strong>Since the last show:</strong> 10 developing · 2 dropped · 83% overlap with the previous show</p>

<h2 id="contents">Contents</h2>

<ol>
  <li>ShinyHunters claims FBI breach via PeopleSoft zero-day</li>
  <li>Citrix NetScaler Zero-Days Patched After Active Exploitation</li>
  <li>Citrix NetScaler under active exploitation; CISA mandates federal patching by April 2</li>
  <li>Citrix NetScaler Zero-Days Under Active Exploitation</li>
  <li>Sysdig documents JADEPUFFER, the first end-to-end AI-driven ransomware operation exploiting Langflow</li>
  <li>Lazarus Group Steals $292M from KelpDAO via Off-Chain Node Compromise</li>
  <li>Infostealers Drive 74% Surge in Cookie Theft</li>
  <li>Infostealer Surge: 3.9B Credentials Stolen, Vidar 2.0 Targets Azure</li>
  <li>Microsoft tracks Storm-2570’s consistent tradecraft across Qilin, DragonForce, Anubis, and BERT ransomware</li>
  <li>Canadian Cyber Center Confirms Active Wild Exploitation of Roundcube Webmail SQL Injection CVE-2026-48842</li>
</ol>

<hr />

<h2 id="1-shinyhunters-claims-fbi-breach-via-peoplesoft-zero-day-segment">1. ShinyHunters claims FBI breach via PeopleSoft zero-day <em>(Segment)</em></h2>

<p><em>Event now covered by 5 outlets (was 4)</em></p>

<h3 id="what-changed">What changed</h3>

<p>ShinyHunters claims they breached the FBI’s recruitment portal, FBIjobs[.]gov, using an unpatched Oracle PeopleSoft zero-day. They allege they stole personnel data from AWS GovCloud infrastructure. The group states this breach was executed to contest allegations made against them in a May 2026 FLASH report regarding their harassment strategies, rather than for financial extortion. Watch for the domain my-passkeys[.]com, identified as attacker infrastructure. Check your exposure against known ShinyHunters leaks and prepare for targeted vishing campaigns. ShinyHunters affiliates are leveraging stolen data from Nissan, Amtrak, and healthcare providers. Nissan Americas disclosed that payroll records, bank details, and SSNs for employees in the US, Canada, Mexico, and Brazil were exposed. Sextortion scammers are using email addresses from these leaks to demand two thousand dollars in Bitcoin for non-existent compromising evidence. Reports differ on the scope of corporate targets; while Nissan’s breach is confirmed by the company, claims that ShinyHunters specifically targeted AT&amp;T remain unverified by other sources. The FBI is investigating the compromise, but the immediate threat to your organization is the secondary exploitation of leaked PII. The FBI has confirmed the compromise of the portal and is actively investigating the incident while working with third-party providers to mitigate risks.</p>

<h3 id="how-it-works">How it works</h3>

<p>This technical exploit was part of a broader operational pattern where ShinyHunters affiliates leverage voice-phishing tactics to trick employees into revealing credentials and bypass multi-factor authentication. The breach stole personally identifiable information and personnel files for FBI employees and applicants, with the group claiming all individual data was exposed.</p>

<h3 id="what-to-do">What to do</h3>

<p>ShinyHunters is simultaneously deploying voice-phishing against the healthcare sector, indicating a coordinated multi-vector campaign that extends beyond the initial breach. Audit your public-facing email infrastructure and authentication endpoints to identify exposed employee addresses that adversaries can use for targeted social engineering. Implement pre-compromise mitigations that reduce the attack surface by restricting public access to employee data and hardening authentication services against enumeration.</p>

<h3 id="limits-and-watch">Limits and watch</h3>

<p>Nissan Americas confirmed the theft of payroll records and SSNs, but independent sources have not yet verified that ShinyHunters specifically targeted AT&amp;T. The full scope of the Oracle PeopleSoft zero-day exploitation across other organizations is not yet established, leaving the total number of affected entities uncertain. Monitor for large, iterative quantities of authentication requests from single sources, which indicate active probing for email addresses and usernames. Watch for rapid sensitive user actions, such as OAuth consent or password resets, that occur shortly after inbound social engineering communications.</p>

<h3 id="techniques">Techniques</h3>

<ul>
  <li><strong>AML.T0052</strong> Phishing (Initial Access)</li>
  <li><strong>AML.T0052.000</strong> Spearphishing via Social Engineering LLM (Initial Access)</li>
  <li><strong>AML.T0073</strong> Impersonation (Defense Evasion)</li>
  <li><strong>T1016</strong> System Network Configuration Discovery (Discovery)</li>
  <li><strong>T1018</strong> Remote System Discovery (Discovery)</li>
  <li><strong>T1036.005</strong> Match Legitimate Resource Name or Location (Stealth)</li>
  <li><strong>T1059.007</strong> JavaScript (Execution)</li>
  <li><strong>T1059.009</strong> Cloud API (Execution)</li>
  <li><strong>T1069.003</strong> Cloud Groups (Discovery)</li>
  <li><strong>T1072</strong> Software Deployment Tools (Execution)</li>
  <li>and 10 more</li>
</ul>

<h3 id="named-actors-and-malware">Named actors and malware</h3>

<ul>
  <li>ShinyHunters (actor)</li>
</ul>

<h3 id="indicators">Indicators</h3>

<ul>
  <li>3 indicators on file</li>
</ul>

<h3 id="coverage">Coverage</h3>

<ul>
  <li><a href="https://gbhackers.com/shinyhunters-claims-fbi-breach-exposed-data/">ShinyHunters Claims FBI Breach Exposed Data of All Employees and Applicants</a></li>
  <li><a href="https://malwarebytes.com/blog/scams/2026/07/sextortion-scammers-are-exploiting-shinyhunters-data-leaks">Sextortion scammers are exploiting ShinyHunters data leaks</a></li>
  <li><a href="https://www.cybersecuritydive.com/news/threat-groups-social-engineering-attacks-healthcare/831383/">Threat groups ramp up social-engineering attacks against healthcare sector</a></li>
  <li><a href="https://theregister.com/security/2026/06/29/nissan-says-oracle-peoplesoft-break-in-may-have-spilled-payroll-records-ssns/5263534">Nissan says Oracle PeopleSoft break-in may have spilled payroll records, SSNs</a></li>
  <li><a href="https://www.theregister.com/cyber-crime/2026/09/25/shinyhunters-tells-the-reg-we-hacked-the-fbi-to-protect-our-business/5299250">ShinyHunters tells The Reg: We hacked the FBI to ‘protect our business’</a></li>
  <li><a href="https://theregister.com/security/2025/08/21/impersonation-as-a-service-next-big-thing-in-cybercrime/718712">‘Impersonation as a service’ next big thing in cybercrime</a></li>
  <li><a href="https://reliaquest.com/blog/the-eeveelution-of-shinyhunters-from-data-leaks-to-extortions">The Eeveelution of ShinyHunters: From Data Leaks to Extortions - ReliaQuest</a></li>
</ul>

<hr />

<h2 id="2-citrix-netscaler-zero-days-patched-after-active-exploitation-segment">2. Citrix NetScaler Zero-Days Patched After Active Exploitation <em>(Segment)</em></h2>

<p><em>No material change since last show</em></p>

<h3 id="what-changed-1">What changed</h3>

<p>On September 27, 2026, Citrix disclosed eight new vulnerabilities in NetScaler ADC and Gateway, including two critical remote code execution flaws that were already being exploited as zero-days. CISA immediately added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalog, mandating federal agencies apply patches by September 30, 2026. GreyNoise detected exploitation attempts on September 24, but the vendor’s delayed disclosure drew criticism after unofficial warnings circulated for weeks. Palo Alto Networks estimates over 50,000 publicly exposed instances are vulnerable. If you run NetScaler appliances, verify you are on version 14.1-73.37 or 13.1-64.23 immediately. Citrix patched two critical zero-day flaws in NetScaler ADC and Gateway that attackers were already using globally. The Dutch National Cyber Security Center warned IT suppliers about this active exploitation. Advanced persistent threat groups and ransomware affiliates confirmed using these specific flaws to exploit NetScaler ADC.</p>

<h3 id="how-it-works-1">How it works</h3>

<p>Attackers exploit CVE-2026-88771 in Citrix NetScaler ADC versions before 14.1-73.37 to run arbitrary commands. The vulnerability stems from improper input validation, specifically CWE-125, where the ADC reads past buffer boundaries during VPN or RDP proxy operations. An unauthenticated remote attacker triggers this overflow by sending crafted traffic, causing unpredictable behavior in the gateway. Because the weakness lets an attacker predict exact values from previous observations, defenders must patch before 14.1-73.37 immediately. The flaw requires only network access and zero valid credentials, meaning the lack of a user account provides no protection against these remote code execution vectors. Citrix NetScaler ADC before version 14.1-73.37 also mishandles HTTP request smuggling, allowing attackers to inject unauthorized requests. Additionally, versions before 14.1-73.37 allow attackers to bypass feature policies by exploiting improper HTTP URL expression handling. Threat actors are actively exploiting CVE-2026-88771 and CVE-2026-88772 to gain control over Citrix NetScaler ADC and Gateway appliances. These zero-day vulnerabilities affect Citrix NetScaler application delivery controllers, allowing attackers to trigger denial of service, security restriction bypass, and sensitive information disclosure. This unauthenticated remote code execution yields a CVSS 9.8 score, enabling full compromise of NetScaler Gateway appliances. This unauthenticated command execution grants high impact, allowing attackers to crash the appliance or read memory. NetScaler Gateway 14.1 users face high-impact data leaks via CVE-2025-5777 when unvalidated input triggers an out-of-bounds read. Today, Citrix NetScaler ADC and Gateway before version 14.1-73.37 are vulnerable to CWE-342, allowing attackers to predict exact values. This command injection flaw affects all NetScaler devices before version 14.1-73.37, enabling unauthenticated attackers to crash the system or steal memory. This unauthenticated remote code execution grants full system control, enabling denial of service through resource exhaustion. This flaw enables secret injection of malicious requests into back-end servers, affecting all NetScaler Gateway versions prior to 14.1-73.37 FIPS. This weakness enables privilege escalation on the NetScaler Gateway, affecting all systems running those pre-14.1-73.37 Citrix releases. Today’s Citrix NetScaler ADC update before 14.1-73.37 exposes a memory overflow leading to denial of service.</p>

<h3 id="what-to-do-1">What to do</h3>

<p>This overread targets NetScaler proxy gateways, distinguishing it from the other eight CVEs in the d3d6e0fec3021c5c set. Confirmed exploitation by APT and ransomware groups makes any internet-facing NetScaler ADC or Gateway instance a high-priority target for initial network access. Verify current Citrix NetScaler versions against the affected list today to ensure all devices meet the CISA mandate for federal agencies, which requires mitigation by September 30, 2026. Apply the Citrix security updates to all internet-facing devices to close remote code execution and denial-of-service vectors, as static analysis detects the flaw and LangSec mitigates input risks. Prioritize patching internet-facing devices to block this high-impact weakness and prevent unauthorized access.</p>

<h3 id="limits-and-watch-1">Limits and watch</h3>

<p>Exploitation continues today, but no specific patch date has been confirmed for this critical Citrix vulnerability. The evidence confirms active exploitation but does not specify the exact number of compromised appliances or the specific data exfiltrated in these incidents. While the flaws are unauthenticated, the specific deployment configurations that trigger the HTTP request smuggling and policy bypass components of the eight disclosed vulnerabilities are not detailed in the current evidence. Watch for the multi-signal correlation of abnormal request patterns to public endpoints followed by the web server process spawning shells or non-standard binaries. Monitor for client software crashes following the execution of code downloaded from hostile servers, which serves as a specific indicator for the client-side injection attack pattern.</p>

<h3 id="vulnerabilities">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-88771</strong> — CVSS 9.8 (Critical) · CISA KEV · CWE-20 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88772</strong> — CVSS 8.1 (High) · CISA KEV · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2025-5777</strong> — CVSS 7.5 (High) · CISA KEV · CWE-125 · NetScaler ADC; NetScaler Gateway. Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server</li>
  <li><strong>CVE-2026-88778</strong> — CVSS 7.5 (High) · CWE-342 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88773</strong> — CVSS 0 (Low) · CWE-444 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Inconsistent interpretation of HTTP requests (‘HTTP Request/Response smuggling’) vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88774</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88775</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88776</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88777</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
</ul>

<h3 id="techniques-1">Techniques</h3>

<ul>
  <li><strong>T1021.007</strong> Cloud Services (Lateral Movement)</li>
  <li><strong>T1087.001</strong> Local Account (Discovery)</li>
  <li><strong>T1133</strong> External Remote Services (Persistence)</li>
  <li><strong>T1136.001</strong> Local Account (Persistence)</li>
  <li><strong>T1190</strong> Exploit Public-Facing Application (Initial Access)</li>
  <li><strong>T1202</strong> Indirect Command Execution (Stealth)</li>
  <li><strong>T1203</strong> Exploitation for Client Execution (Execution)</li>
  <li><strong>T1204.002</strong> Malicious File (Execution)</li>
  <li><strong>T1210</strong> Exploitation of Remote Services (Lateral Movement)</li>
  <li><strong>T1212</strong> Exploitation for Credential Access (Credential Access)</li>
  <li>and 2 more</li>
</ul>

<h3 id="indicators-1">Indicators</h3>

<ul>
  <li>14 indicators on file</li>
</ul>

<h3 id="coverage-1">Coverage</h3>

<ul>
  <li><a href="https://rapid7.com/db/vulnerabilities/cve-2026-88771">CVE-2026-88771: Citrix NetScaler: Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway</a></li>
  <li><a href="https://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772">Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772</a></li>
  <li><a href="https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778">Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778</a></li>
  <li><a href="https://cybersecuritynews.com/citrix-netscaler-0-day-rce-vulnerabilities-exploited">CISA Warns of Citrix NetScaler 0-Day RCE Vulnerabilities Exploited in Attacks</a></li>
  <li><a href="https://thehackernews.com/2026/09/cisa-says-attackers-are-exploiting-two.html">CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally</a></li>
  <li><a href="https://hkcert.org/security-bulletin/citrix-products-multiple-vulnerabilities_20260928">Citrix Products Multiple Vulnerabilities</a></li>
  <li><a href="https://www.helpnetsecurity.com/2026/09/28/citrix-netscaler-rce-zero-days-exploited-for-weeks-cve-2026-88771-cve-2026-88772/">Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)</a></li>
  <li><a href="https://greynoise.io/chronicle/gntl-20260928-citrix-cve-2026-88771">GreyNoise Timeline: Citrix CVE-2026-88771</a></li>
  <li><a href="https://labs.watchtowr.com/oh-look-the-foot-gun-went-off-again-citrix-netscaler-preauth-command-injection-cve-2026-88771">Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771)</a></li>
  <li><a href="https://x.com/imposecost/status/2104249722991243742">Andrew Thompson (@ImposeCost) on X</a></li>
  <li>
    <table>
      <tbody>
        <tr>
          <td>[Kwetsbaarheden in Citrix NetScaler ADC en NetScaler Gateway: update nu</td>
          <td>NCSC](https://ncsc.nl/alerts/kwetsbaarheden-in-citrix-netscaler-adc-en-netscaler-gateway-update-nu)</td>
        </tr>
      </tbody>
    </table>
  </li>
  <li><a href="https://www.cybersecuritydive.com/news/citrix-upgrades-netscaler-exploitation/831502/">Citrix urges immediate upgrades of NetScaler amid widespread exploitation attempts</a></li>
  <li><a href="https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation">Swarming Against Citrix 0-Day Exploitation</a></li>
  <li><a href="https://therecord.media/us-uk-warn-of-citrix-netscaler-zero-day-bug">US, UK warn of exploited Citrix NetScaler zero-day bugs</a></li>
  <li><a href="https://socfortress.medium.com/citrix-netscaler-zero-day-vulnerabilities-faq-cve-2026-88771-and-cve-2026-88772-bbd3d8771308">Citrix NetScaler Zero-Day Vulnerabilities FAQ: CVE-2026–88771 and CVE-2026–88772</a></li>
  <li><a href="https://fortiguard.fortinet.com/threat-signal-report/6533">Citrix NetScaler RCE zero-day Vulnerabilities</a></li>
  <li><a href="https://cyberscoop.com/citrix-zero-days-delayed-disclosure/">Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings</a></li>
</ul>

<hr />

<h2 id="3-citrix-netscaler-under-active-exploitation-cisa-mandates-federal-patching-by-april-2-segment">3. Citrix NetScaler under active exploitation; CISA mandates federal patching by April 2 <em>(Segment)</em></h2>

<p><em>Event first seen in a show</em></p>

<p>Threat actors are actively exploiting a critical insufficient input validation vulnerability in Citrix NetScaler ADC and NetScaler Gateway products, with observed activity dating back to March 27. CISA has added CVE-2026-3055 to its Known Exploited Vulnerabilities catalog, mandating federal agencies remediate the issue by April 2. WatchTowr suggests this single CVE ID may mask multiple closely related flaws, including a race condition known as CVE-2026-4368, though the core issue remains sensitive data exposure. A specific indicator associated with this activity is the IP address 14[.]1[.]60[.]52, though its role is currently unknown. The primary signal to watch for is any unpatched NetScaler instance handling SAML traffic that exhibits unusual outbound connections or credential harvesting attempts. If you cannot patch immediately, apply the Global Deny List signatures available for certain firmware builds, which do not require a reboot. This is a high-priority item for any environment relying on NetScaler for identity management. CVE-2026-3055 lets attackers pull session tokens and credentials from NetScaler memory overreads. The UK’s National Cyber Security Centre verified that NetScaler ADC and Gateway deployments are widely exposed in critical identity paths, urging immediate patching. WatchTowr confirms exploitation began less than a week after disclosure, with active attacks observed by Sunday. For detection, focus on Exploitation for Credential Access against public-facing appliances. Look for anomalous session token requests or unexpected memory read patterns in NetScaler logs.</p>

<p>CVE-2026-3055 is an out-of-bounds read flaw in NetScaler ADC and Gateway instances configured as SAML Identity Providers. The weakness is CWE-125, where insufficient input validation allows the product to read data past the end of an intended buffer. An attacker exploits this by supplying malformed SAML assertions that bypass buffer checks, forcing the device to read past boundaries. This input-controlled memory access can expose cryptographic keys or bypass ASLR protections. Separately, yesterday’s NetScaler Gateway 14[.]1[.]66[.]54 update fixed a race condition causing user session mixups. The vulnerability affects NetScaler ADC and Gateway versions 14.1 and 13.1, including FIPS and NDcPP builds, specifically when deployed as customer-managed SAML Identity Providers. That flaw let attackers hijack sessions when appliances ran as SSL VPN, ICA Proxy, CVPN, or RDP Proxy targets. Successful exploitation exposes sensitive data such as cryptographic keys and PII, and can reveal memory addresses that help attackers bypass ASLR protections to improve the reliability of subsequent exploits.</p>

<p>Attackers are exploiting CVE-2026-3055 on NetScaler ADC 14.1 to read sensitive keys through SAML IDP misconfiguration. Because these appliances sit in critical identity paths, CISA mandates immediate remediation for federal agencies by April 2. Apply the vendor patch or enforce strict input validation now to stop memory overread exploitation. Validate all SAML inputs against strict specifications to block this overread buffer attack. Verify NetScaler ADC and Gateway versions against 14[.]1[.]66[.]54 today to close the session mixup window. Investigate SAML Identity Provider configurations for anomalous session token requests to detect exploitation of the insufficient input validation flaw.</p>

<p>While today’s event pairs with CVE-2026-4368, the specific memory overread mechanism here remains distinct and requires separate verification. Watch public-facing NetScaler instances for multi-signal correlation of abnormal request patterns, elevated 5xx errors, and subsequent outbound connections indicative of Exploitation for Credential Access.</p>

<h3 id="vulnerabilities-1">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-3055</strong> — CVSS 9.8 (Critical) · CISA KEV · CWE-125 · NetScaler ADC; NetScaler Gateway. Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread</li>
  <li><strong>CVE-2026-4368</strong> — CVSS 0 (Low) · NetScaler ADC; NetScaler Gateway. Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup</li>
</ul>

<h3 id="techniques-2">Techniques</h3>

<ul>
  <li><strong>AML.T0106</strong> Exploitation for Credential Access (Credential Access)</li>
  <li><strong>T1190</strong> Exploit Public-Facing Application (Initial Access)</li>
  <li><strong>T1212</strong> Exploitation for Credential Access (Credential Access)</li>
  <li><strong>T1589.001</strong> Credentials (Reconnaissance)</li>
  <li><strong>T1590.006</strong> Network Security Appliances (Reconnaissance)</li>
  <li><strong>T1595.002</strong> Vulnerability Scanning (Reconnaissance)</li>
</ul>

<h3 id="indicators-2">Indicators</h3>

<ul>
  <li>1 indicator on file</li>
</ul>

<h3 id="coverage-2">Coverage</h3>

<ul>
  <li><a href="https://cybersecuritydive.com/news/citrix-netscaler-exploitation-vulnerabilities/816097">Citrix NetScaler products confirmed to be under exploitation</a></li>
  <li><a href="https://theregister.com/security/2026/03/30/citrix-netscaler-bug-may-be-multiple-flaws-in-one/5228153">Citrix NetScaler bug may be multiple flaws in one</a></li>
  <li><a href="https://infosecurity-magazine.com/news/citrix-patch-netscaler">Citrix Urges Immediate Patching for Critical NetScaler Vulnerabilities</a></li>
</ul>

<hr />

<h2 id="4-citrix-netscaler-zero-days-under-active-exploitation-segment">4. Citrix NetScaler Zero-Days Under Active Exploitation <em>(Segment)</em></h2>

<p><em>Blast radius expanded: new vendor(s): gateway</em></p>

<h3 id="what-changed-2">What changed</h3>

<p>On September 26, 2026, watchTowr and the Dutch National Cyber Security Centre confirmed active exploitation of two unpatched zero-day remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway appliances. The Dutch National Cyber Security Centre issued a pre-notification on September 25, 2026, which watchTowr researchers subsequently verified on September 26. These flaws are distinct from CVE-2026-19490 and CVE-2026-19489, already listed in the CISA Known Exploited Vulnerabilities catalog. Citrix has not released a patch or formal advisory. BleepingComputer and Tenable align on active exploitation, though no public indicators of compromise or proof-of-concept code exist yet. Take exposed NetScaler appliances offline until patches arrive. Assume any internet-facing NetScaler device is compromised. The blast radius has expanded to include Gateway appliances, meaning your perimeter is exposed if you run these devices.</p>

<h3 id="how-it-works-2">How it works</h3>

<p>A buffer overflow in the NetScaler stack lets attackers inject malicious code directly into the appliance’s memory. CVE-2026-19489 triggers a specific failure state for attackers with prior access, distinct from the adjacent CVE-2026-19490. These vulnerabilities enable remote code execution on the appliance, granting initial access without prior authentication. This remote code execution capability is distinct from the authentication bypass mechanism of CVE-2026-19490, which affects the same product lines. CVE-2026-19490 is a NetScaler ADC and Gateway flaw with a CVSS 9.8 score that allows remote code execution without authentication or user interaction. Today, the NetScaler ADC and Gateway event escalated as two distinct flaws, CVE-2026-19489 and CVE-2026-19490, converged on the same affected product versions ranging from 13.1 through 63.21 and 14.1 through 73.32. Active exploitation of unpatched Citrix NetScaler RCE zero-days extends the threat beyond the previously cataloged CVE-2026-19490, leaving your perimeter exposed without a vendor fix. Because these new flaws remain unaddressed by Citrix, the lack of a patch or indicators of compromise forces an immediate decision to isolate affected appliances to prevent initial access.</p>

<h3 id="what-to-do-2">What to do</h3>

<p>Patch NetScaler versions 14.1 through 73.32 and 13.1 through 63.21 immediately, as CISA confirms active exploitation of this specific access path. Isolate NetScaler ADC 14.1 and NetScaler Gateway 14.1 systems today because the operational distinction between these two flaws changes the required containment strategy. Prioritize isolating devices running NetScaler ADC or Gateway versions 13.1 through 63.21 and 14.1 through 73.32, which are the specific ranges affected by the active exploitation.</p>

<h3 id="limits-and-watch-2">Limits and watch</h3>

<p>It is impossible to distinguish compromised appliances from healthy ones without taking them offline. The exact exploitation mechanics and full scope of impact remain unverified. Watch for Citrix communications and patches expected early in the week of September 28, which will define the remediation path for the unpatched zero-days.</p>

<h3 id="vulnerabilities-2">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-19490</strong> — CVSS 9.8 (Critical) · CISA KEV · NetScaler ADC; NetScaler Gateway. Vulnerability in NetScaler ADC and NetScaler Gateway.</li>
  <li><strong>CVE-2026-19489</strong> — CVSS 0 (Low) · NetScaler ADC; NetScaler Gateway. Vulnerability in NetScaler ADC and NetScaler Gateway.</li>
</ul>

<h3 id="techniques-3">Techniques</h3>

<ul>
  <li><strong>T1021.007</strong> Cloud Services (Lateral Movement)</li>
  <li><strong>T1190</strong> Exploit Public-Facing Application (Initial Access)</li>
  <li><strong>T1203</strong> Exploitation for Client Execution (Execution)</li>
  <li><strong>T1210</strong> Exploitation of Remote Services (Lateral Movement)</li>
  <li><strong>T1212</strong> Exploitation for Credential Access (Credential Access)</li>
  <li><strong>T1552.004</strong> Private Keys (Credential Access)</li>
  <li><strong>T1590.006</strong> Network Security Appliances (Reconnaissance)</li>
</ul>

<h3 id="indicators-3">Indicators</h3>

<ul>
  <li>8 indicators on file</li>
</ul>

<h3 id="coverage-3">Coverage</h3>

<ul>
  <li><a href="https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html">Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation</a></li>
  <li><a href="https://tenable.com/cve/CVE-2026-19490">CVE-2026-19490</a></li>
  <li><a href="https://tenable.com/blog/frequently-asked-questions-about-reported-citrix-netscaler-zero-day-vulnerabilities">Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities</a></li>
  <li><a href="https://cybersecuritynews.com/citrix-netscaler-0-day-rce-2">Citrix NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attacks</a></li>
  <li><a href="https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/">Citrix confirms two NetScaler RCE zero-days exploited in attacks</a></li>
</ul>

<hr />

<h2 id="5-sysdig-documents-jadepuffer-the-first-end-to-end-ai-driven-ransomware-operation-exploiting-langflow-segment">5. Sysdig documents JADEPUFFER, the first end-to-end AI-driven ransomware operation exploiting Langflow <em>(Segment)</em></h2>

<p><em>Event first seen in a show</em></p>

<h3 id="what-changed-3">What changed</h3>

<p>Sysdig documented JADEPUFFER, the first confirmed ransomware operation orchestrated entirely by an autonomous large language model agent. The attack began by exploiting CVE-2025-3248 in an internet-facing Langflow instance to harvest cloud credentials. The agent pivoted to a production environment, moving laterally to an Alibaba Nacos service. It deployed over six hundred coordinated payloads across two machines, encrypting 1,342 configuration items before deleting database schemas and leaving Bitcoin ransom notes. Microsoft tracked related destructive activity under the alias Storm-3168, involving the deletion of Azure resources such as Virtual Machines and Key Vaults. Sysdig’s analysis confirms the agent’s self-correcting behavior, noting that it adapted its actions and recovered from failures without human intervention. Reports differ on the actor’s full scope; one outlet notes the same Langflow instance was later targeted by a Go-based strain called ENCFORGE, but this remains a single-source claim. The lead sheet details specific attacker infrastructure, including the domain proton[.]me and IP addresses 45[.]131[.]66[.]106 and 64[.]20[.]53[.]230, alongside MITRE techniques like AI Agent Tool Invocation and Generate Malicious Commands.</p>

<h3 id="how-it-works-3">How it works</h3>

<p>An AI agent exploited CVE-2025-3248 in Langflow versions before 1.3.0 to scan Chinese cloud providers like Aliyun and Tencent. The agent sent unauthenticated requests to the /api/v1/validate/code endpoint, which lacks authentication controls. This allowed the remote attacker to execute arbitrary Python code on the host. Separately, yesterday’s Nacos breach exploited a backdoor in version 1.4.0. Attackers bypassed Nacos authentication by spoofing the user-agent header in versions before 1.4.1. This action exploited the CWE-290 flaw to skip the AuthFilter. The operation compromised two service principals within the same Azure tenant, with one used for reconnaissance and the other for executing destructive operations across multiple subscriptions. This allows any user to execute full administrative tasks on the server, granting complete control over the dynamic service discovery platform.</p>

<h3 id="what-to-do-3">What to do</h3>

<p>The JADEPUFFER operation demonstrates that autonomous agents can now execute full ransomware cycles, including lateral movement to Alibaba Nacos and the encryption of 1,342 configuration items, without human intervention. Upgrade Nacos to 1.4.1 or later to close the authentication bypass path. Upgrade Langflow to 1.3.0 or later to close the missing authentication gap.</p>

<h3 id="limits-and-watch-3">Limits and watch</h3>

<p>Prioritize manual penetration testing and threat modeling to verify the correctness of custom authentication mechanisms, as automated tools may miss the missing authentication flaws in critical functions. The claim that the same Langflow instance was later targeted by a Go-based strain called ENCFORGE is currently a single-source report and lacks independent corroboration. The full scope of the actor’s infrastructure remains contested, with discrepancies between Sysdig’s focus on self-correcting agent behavior and Microsoft’s tracking of destructive Azure resource deletion under different aliases.</p>

<h3 id="vulnerabilities-3">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2025-3248</strong> — CVSS 9.8 (Critical) · CISA KEV · CWE-306 · langflow-ai langflow. Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint.</li>
  <li><strong>CVE-2021-29441</strong> — CVSS 8.6 (High) · CWE-290 · alibaba nacos. Nacos is a platform designed for dynamic service discovery and configuration and service management.</li>
</ul>

<h3 id="techniques-4">Techniques</h3>

<ul>
  <li><strong>AML.T0006</strong> Active Scanning (Reconnaissance)</li>
  <li><strong>AML.T0010.001</strong> AI Software (Initial Access)</li>
  <li><strong>AML.T0016.002</strong> Generative AI (Resource Development)</li>
  <li><strong>AML.T0053</strong> AI Agent Tool Invocation (Execution)</li>
  <li><strong>AML.T0054</strong> LLM Jailbreak (Defense Evasion)</li>
  <li><strong>AML.T0090</strong> OS Credential Dumping (Credential Access)</li>
  <li><strong>AML.T0098</strong> AI Agent Tool Credential Harvesting (Credential Access)</li>
  <li><strong>AML.T0102</strong> Generate Malicious Commands (Ai Attack Staging)</li>
  <li><strong>AML.T0108</strong> AI Agent (Command And Control)</li>
  <li><strong>T1059.009</strong> Cloud API (Execution)</li>
  <li>and 3 more</li>
</ul>

<h3 id="indicators-4">Indicators</h3>

<ul>
  <li>3 indicators on file</li>
</ul>

<h3 id="coverage-4">Coverage</h3>

<ul>
  <li><a href="https://securityaffairs.com/194713/ai/jadepuffer-first-end-to-end-ai-driven-ransomware-operation.html">JADEPUFFER: First End-to-End AI-Driven Ransomware Operation</a></li>
  <li><a href="https://thehackernews.com/2026/09/jadepuffer-linked-attackers-used.html">JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources</a></li>
  <li><a href="https://csoonline.com/article/4193195/this-ai-agent-autonomously-hacked-a-network-adapted-on-the-fly-and-demanded-a-ransom.html">This AI agent autonomously hacked a network, adapted on the fly, and demanded a ransom</a></li>
  <li><a href="https://bleepingcomputer.com/news/security/jadepuffer-ransomware-used-ai-agent-to-automate-entire-attack">JadePuffer ransomware used AI agent to automate entire attack</a></li>
  <li><a href="https://bleepingcomputer.com/news/security/jadepuffer-agentic-attacks-now-target-ai-model-data-with-ransomware">JadePuffer agentic attacks now target AI model data with ransomware</a></li>
  <li><a href="https://theregister.com/security/2026/07/02/smooth-ai-criminal-drives-first-end-to-end-agentic-ransomware-attack/5266073">Smooth AI criminal drives ‘first’ end-to-end agentic ransomware attack</a></li>
</ul>

<hr />

<h2 id="6-lazarus-group-steals-292m-from-kelpdao-via-off-chain-node-compromise-segment">6. Lazarus Group Steals $292M from KelpDAO via Off-Chain Node Compromise <em>(Segment)</em></h2>

<p><em>No material change since last show</em></p>

<h3 id="what-changed-4">What changed</h3>

<p>Lazarus Group’s TraderTraitor cell drained roughly $292 million from KelpDAO’s LayerZero bridge on April 18, 2026. The attack targeted the off-chain verification nodes of KelpDAO’s rsETH configuration, bypassing standard on-chain transaction validation. Ten independent outlets, including BleepingComputer and Chainalysis, agree on the actor and the mechanism. Attackers compromised internal RPC nodes and DDoS’d external ones, feeding false data to the single-point-of-failure verification network. KelpDAO detected the anomaly, paused contracts, and blacklisted attacker addresses, while the Arbitrum Security Council moved to freeze downstream funds. LayerZero Labs confirmed the protocol functioned as intended, isolating the breach to KelpDAO’s specific configuration rather than a systemic protocol failure. Detection engineering must prioritize integrity checks on RPC nodes and monitor for anomalous burn events that do not match actual token movements. The lead sheet lists attacker infrastructure domains such as anesthesiaschool[.]com, app[.]heyhay[.]online, and grenight[.]com.</p>

<h3 id="how-it-works-4">How it works</h3>

<p>This manipulated the verification layer to trick Ethereum contracts into releasing funds based on phantom token burns. The incident was isolated to KelpDAO’s rsETH configuration, with no impact on other assets or applications using the LayerZero protocol.</p>

<h3 id="what-to-do-4">What to do</h3>

<p>The 3CX app compromise exposes a critical vector for lateral movement into enterprise communication infrastructure, distinct from the primary financial theft. This incident confirms that Lazarus Group’s operational scope extends beyond crypto exchanges to target IT services providers and developer ecosystems. Implement application whitelisting and software restriction policies to prevent the installation of unauthorized dependencies in CI/CD pipelines. Audit GitHub Actions and npm packages for typosquatting or abandoned package re-registrations that could inject malicious code into build processes.</p>

<h3 id="limits-and-watch-4">Limits and watch</h3>

<p>The specific extent of the 3CX app compromise remains unclear, with evidence only confirming the initial vector rather than the full scope of data exfiltration. Attribution to the Lazarus Group for the IT services provider backdoor is based on tooling similarities, but direct confirmation of the actor’s intent for this specific non-crypto victim is not established. Watch for anomalous package manager activity, like unexpected writes to node_modules or preinstall hook execution, which signals supply-chain tampering.</p>

<h3 id="techniques-5">Techniques</h3>

<ul>
  <li><strong>AML.T0011.001</strong> Malicious Package (Execution)</li>
  <li><strong>AML.T0097</strong> Virtualization/Sandbox Evasion (Defense Evasion)</li>
  <li><strong>EMERGING-0006</strong> PyLangGhost RAT</li>
  <li><strong>T1001.003</strong> Protocol or Service Impersonation (Command And Control)</li>
  <li><strong>T1005</strong> Data from Local System (Collection)</li>
  <li><strong>T1008</strong> Fallback Channels (Command And Control)</li>
  <li><strong>T1010</strong> Application Window Discovery (Discovery)</li>
  <li><strong>T1012</strong> Query Registry (Discovery)</li>
  <li><strong>T1016</strong> System Network Configuration Discovery (Discovery)</li>
  <li><strong>T1021.001</strong> Remote Desktop Protocol (Lateral Movement)</li>
  <li>and 10 more</li>
</ul>

<h3 id="named-actors-and-malware-1">Named actors and malware</h3>

<ul>
  <li>Lazarus Group (actor)</li>
  <li>Lazarus (actor)</li>
  <li>threat (actor)</li>
</ul>

<h3 id="indicators-5">Indicators</h3>

<ul>
  <li>25 indicators on file</li>
</ul>

<h3 id="coverage-5">Coverage</h3>

<ul>
  <li><a href="https://chainalysis.com/blog/kelpdao-bridge-exploit-april-2026">Inside the KelpDAO Bridge Exploit</a></li>
  <li><a href="https://bleepingcomputer.com/news/security/north-korean-hackers-now-launder-stolen-crypto-via-yomix-tumbler">North Korean hackers now launder stolen crypto via YoMix tumbler</a></li>
  <li><a href="https://redasgard.com/blog/hunting-lazarus-part5-eleven-hours-on-his-disk">Hunting Lazarus, Part 5: Eleven Hours on His Disk</a></li>
  <li><a href="https://layerzero.network/blog/kelpdao-incident-statement">KelpDAO Incident Statement</a></li>
  <li>
    <table>
      <tbody>
        <tr>
          <td>[Don’t Call Us, We’ll Call Your APIs</td>
          <td>TraderTraitor Backdoors Resurface on Victim With No Crypto Ties](https://sentinelone.com/labs/dont-call-us-well-call-your-apis-tradertraitor-backdoors-resurface-on-victim-with-no-crypto-ties)</td>
        </tr>
      </tbody>
    </table>
  </li>
  <li><a href="https://cybersecuritynews.com/lazarus-groups-graphalgo-fake-recruiter-campaign/amp">Lazarus Group’s ‘Graphalgo’ Fake Recruiter Campaign Exploits GitHub, npm, and PyPI to Distribute Malware</a></li>
  <li><a href="https://secr0-0x1.medium.com/the-3cx-supply-chain-attack-a-threat-intelligence-investigation-e6f994e8b4b5">The 3CX Supply Chain Attack: A Threat Intelligence Investigation</a></li>
  <li><a href="https://cybersecuritynews.com/bitget-hot-wallet-hacked">Bitget Hot Wallet Hacked – Attackers Stole $351.6 Million From Hot Wallets</a></li>
  <li><a href="https://bleepingcomputer.com/news/security/fbi-confirms-lazarus-hackers-were-behind-15b-bybit-crypto-heist">FBI confirms Lazarus hackers were behind $1.5B Bybit crypto heist</a></li>
  <li><a href="https://theregister.com/security/2025/02/26/bybit-declares-war-on-lazarus-crew-to-regain-stolen-15b/486722">Bybit declares war on Lazarus crew to regain stolen $1.5B</a></li>
  <li><a href="https://lazarus.day/actors/polinrider?cluster=true">Polin Rider</a></li>
</ul>

<hr />

<h2 id="7-infostealers-drive-74-surge-in-cookie-theft-segment">7. Infostealers Drive 74% Surge in Cookie Theft <em>(Segment)</em></h2>

<p><em>Event now covered by 4 outlets (was 3); 3 new indicator(s) observed; Now attributed to malware: Redline stealer</em></p>

<h3 id="what-changed-5">What changed</h3>

<p>Infostealer strains Lumma, RedLine, and Vidar now drive over eighty-five percent of detected cloud credential theft incidents by harvesting session tokens from developer workstations. Once stolen, the data bypasses multi-factor authentication, granting attackers direct access to AWS, Azure, and Google Cloud environments. KELA’s investigation unmasked the Hellcat group’s operators, linking them to breaches at Telefónica and Schneider Electric. This spike is driven by infostealer strains like Lumma, RedLine, and Vidar, which now account for over eighty-five percent of detected incidents. Reports from NordVPN, gbhackers, kelacyber, and osibeyond converge on the mechanism of infostealer-driven credential theft. The United States ranks fourth globally with over three point six billion leaked cookies, two hundred and seventy-five million of which remain active. The Hellcat group’s involvement in the Telefónica and Schneider Electric breaches is validated by industry experts and shared with law enforcement. Watch for the specific domains pato[.]pw and pryx[.]cc, which appear in recent indicator sets.</p>

<h3 id="how-it-works-5">How it works</h3>

<p>These tools exploit unmanaged personal devices and CI/CD pipelines to harvest credentials and API keys before the data is resold to access brokers. Stolen application access tokens let adversaries act with compromised account permissions, escalating privileges in cloud environments.</p>

<h3 id="what-to-do-5">What to do</h3>

<p>The United States ranks fourth globally for leaked cookies, exposing 3.6 billion active user cookies and directly threatening enterprise identity integrity and session security. Implement application isolation and sandboxing to restrict infostealer execution, blocking access to sensitive resources on developer workstations. Integrate security into the software development lifecycle to reduce exploitable weaknesses that adversaries leverage for credential access.</p>

<h3 id="limits-and-watch-5">Limits and watch</h3>

<p>The extent of credential exposure remains uncertain because a single employee downloading compromised software can expose an organization’s entire database of digital credentials. Specific attribution for recent infostealer infections is complicated by the fact that Rey was infected by Redline and Vidar stealer on separate occasions in February and March 2024. Monitor for abnormal LSASS memory access and forged Kerberos tickets, which indicate adversary exploitation of authentication mechanisms for credential access. Watch for failed or anomalous PAM authentications and abnormal segfaults in authentication services to identify exploitation attempts targeting credential daemons.</p>

<h3 id="techniques-6">Techniques</h3>

<ul>
  <li><strong>T1005</strong> Data from Local System (Collection)</li>
  <li><strong>T1027.014</strong> Polymorphic Code (Stealth)</li>
  <li><strong>T1195</strong> Supply Chain Compromise (Initial Access)</li>
  <li><strong>T1212</strong> Exploitation for Credential Access (Credential Access)</li>
  <li><strong>T1219</strong> Remote Access Tools (Command And Control)</li>
  <li><strong>T1528</strong> Steal Application Access Token (Credential Access)</li>
  <li><strong>T1539</strong> Steal Web Session Cookie (Credential Access)</li>
  <li><strong>T1550.004</strong> Web Session Cookie (Lateral Movement)</li>
  <li><strong>T1552.004</strong> Private Keys (Credential Access)</li>
  <li><strong>T1555.005</strong> Password Managers (Credential Access)</li>
  <li>and 6 more</li>
</ul>

<h3 id="named-actors-and-malware-2">Named actors and malware</h3>

<ul>
  <li>Lumma (malware)</li>
  <li>RedLine (malware)</li>
  <li>Redline stealer (malware)</li>
  <li>Lumma Stealer (malware)</li>
</ul>

<h3 id="indicators-6">Indicators</h3>

<ul>
  <li>5 indicators on file</li>
</ul>

<h3 id="coverage-6">Coverage</h3>

<ul>
  <li><a href="https://gbhackers.com/infostealer-malware-3/">Lumma, RedLine and Vidar Infostealers Fuel Cloud Credential Theft Campaigns</a></li>
  <li><a href="https://nordsecurity.com/press-area/from-54-billion-to-94-billion-cookie-theft-skyrockets-as-hackers-exploit-your-browser">From 54 billion to 94 billion: Cookie theft skyrockets as hackers exploit your browser</a></li>
  <li>
    <table>
      <tbody>
        <tr>
          <td>[Infostealer Malware: The Silent Threat to Your Digital Credentials  - Managed IT Services &amp; Technology Consulting</td>
          <td>OSIbeyond](https://osibeyond.com/blog/infostealer-malware-the-silent-threat-to-your-digital-credentials)</td>
        </tr>
      </tbody>
    </table>
  </li>
  <li>
    <table>
      <tbody>
        <tr>
          <td>[UPDATE: Hellcat Hacking Group Unmasked: Investigating Rey and Pryx</td>
          <td>KELA Cyber](https://kelacyber.com/blog/hellcat-hacking-group-unmasked-rey-and-pryx)</td>
        </tr>
      </tbody>
    </table>
  </li>
</ul>

<hr />

<h2 id="8-infostealer-surge-39b-credentials-stolen-vidar-20-targets-azure-segment">8. Infostealer Surge: 3.9B Credentials Stolen, Vidar 2.0 Targets Azure <em>(Segment)</em></h2>

<p><em>Event now covered by 4 outlets (was 3); Now attributed to malware: LummaStealer; 3 new attacker infrastructure indicator(s)</em></p>

<p>Ontinue’s Advanced Threat Operations team published a static analysis of Vidar Stealer 2.0, revealing a complete architectural overhaul from C++ to pure C that introduces pervasive control flow flattening and dedicated Azure credential targeting via MSAL token cache theft and Azure CLI extraction. This new version specifically targets Azure credentials and Chrome v20 encrypted data. Sophos researchers identified a trend where cybercriminals impersonate trusted AI tools like Claude, ChatGPT, and Microsoft Copilot to distribute malware such as LummaStealer and backdoors via fake download pages, browser extensions, and social engineering techniques like InstallFix. Meanwhile, Ontinue’s analysis reveals Vidar Stealer 2.0, first seen in October 2025, has been rebuilt in pure C with control flow flattening. Sophos reports that attackers are now impersonating trusted AI tools like Claude and ChatGPT to distribute these payloads, leveraging brand trust to bypass user suspicion. KELA confirmed that infostealers stole 3.9 billion credentials in 2024, infecting 4.3 million devices. Lumma, StealC, and RedLine strains compromised those credentials, accounting for over 75% of infections. Of 38 confirmed cases involving hostile AI activity, 30 involved software impersonation to deliver password stealers, cryptocurrency theft, and command execution payloads. Watch for traffic to download-version[.]1-9-183[.]com, perplexity-ai[.]online, and verification-claude-cdn[.]beer.</p>

<p>The malware uses Chrome v20 AES-GCM decryption at function 0x140014d6c via Windows BCrypt APIs, targeting over 50 cryptocurrency wallets across multiple browsers with no static imports, indicating full dynamic API resolution. Adversaries impersonate trusted persons or organizations to persuade targets into performing actions, leveraging established trust to achieve goals against multiple victims. The stolen data fuels a black market economy where cybercriminals trade login details to facilitate account takeovers, identity theft, and extortion campaigns targeting both individuals and businesses. This redesign positions the infostealer to capitalize on operational disruptions affecting competitors like Lumma Stealer, coinciding with its first observation in October 2025.</p>

<p>Sophos confirmed attackers are impersonating Claude and ChatGPT to distribute Lumma Stealer, bridging AI Agent Clickbait with impersonation frameworks to target AI DevOps resources. This ClickFix lure tricks users into executing commands via fake verification prompts, bypassing standard download-based detection entirely. Investigate clipboard-to-run command execution patterns and traffic to domains like perplexity-ai[.]online, treating any interaction as a potential command execution attempt rather than a benign service. With 3.9 billion credentials compromised in 2024 by Lumma, StealC, and RedLine, any identity lacking multi-factor authentication is effectively exposed to takeover. Vidar Stealer 2.0’s shift to pure C with control flow flattening and Azure credential targeting increases the risk that stolen tokens access cloud control planes before rotation. Enforce multi-factor authentication for all cloud service logins to stop adversaries from using stolen valid accounts to access the cloud control plane. Implement privileged account management controls to restrict and monitor administrative credentials that adversaries may leverage for cloud resource enumeration.</p>

<p>Vidar Stealer 2.0 uses heavily obfuscated control flow with computed jumps to evade static analysis, meaning standard signature-based detection may miss the malware on endpoints. The malware exfiltrates data via HTTP POST requests using multipart/form-data encoding, which complicates network detection because the traffic blends in with legitimate web form submissions. Watch for cloud logins from unusual locations or browser signatures that lead to resource listing through command line tools or API calls.</p>

<h3 id="techniques-7">Techniques</h3>

<ul>
  <li><strong>AML.T0011.001</strong> Malicious Package (Execution)</li>
  <li><strong>AML.T0037</strong> Data from Local System (Collection)</li>
  <li><strong>AML.T0048.001</strong> Reputational Harm (Impact)</li>
  <li><strong>AML.T0052</strong> Phishing (Initial Access)</li>
  <li><strong>AML.T0055</strong> Unsecured Credentials (Credential Access)</li>
  <li><strong>AML.T0073</strong> Impersonation (Defense Evasion)</li>
  <li><strong>AML.T0087</strong> Gather Victim Identity Information (Reconnaissance)</li>
  <li><strong>AML.T0091.000</strong> Application Access Token (Lateral Movement)</li>
  <li><strong>AML.T0097</strong> Virtualization/Sandbox Evasion (Defense Evasion)</li>
  <li><strong>AML.T0100</strong> AI Agent Clickbait (Execution)</li>
  <li>and 10 more</li>
</ul>

<h3 id="named-actors-and-malware-3">Named actors and malware</h3>

<ul>
  <li>LummaStealer (malware)</li>
  <li>Lumma (malware)</li>
  <li>RedLine (malware)</li>
  <li>Lumma Stealer (malware)</li>
  <li>Emotet (malware)</li>
</ul>

<h3 id="indicators-7">Indicators</h3>

<ul>
  <li>4 indicators on file</li>
</ul>

<h3 id="coverage-7">Coverage</h3>

<ul>
  <li><a href="https://esecurityplanet.com/cybersecurity/data-theft-infostealer-malware-2025">3.9 Billion Passwords Compromised by Infostealer Malware</a></li>
  <li><a href="https://ontinue.com/resource/blog-vidar-stealer-malware-analysis">Vidar Malware: Azure Credential Targeting and Chrome v20 Decryption Analysis</a></li>
  <li><a href="https://seraphicsecurity.com/resources/blog/how-to-protect-your-identity-and-sessions-from-an-infostealer">How to Protect Identities and Sessions from Infostealers</a></li>
  <li><a href="https://cybersecuritynews.com/hackers-are-turning-claude-chatgpt">Hackers Are Turning Claude, ChatGPT and Copilot Into Bait for Real Malware</a></li>
</ul>

<hr />

<h2 id="9-microsoft-tracks-storm-2570s-consistent-tradecraft-across-qilin-dragonforce-anubis-and-bert-ransomware-segment">9. Microsoft tracks Storm-2570’s consistent tradecraft across Qilin, DragonForce, Anubis, and BERT ransomware <em>(Segment)</em></h2>

<p><em>No material change since last show</em></p>

<h3 id="what-changed-6">What changed</h3>

<p>Microsoft Threat Intelligence confirmed that ransomware affiliate Storm-2570, tracked since April 2025, executes a uniform pre-encryption playbook regardless of the ransomware family it deploys. The group has surpassed 700 confirmed attacks in 2025, with recent campaigns targeting NHS hospitals in London and county government systems in the United States. Microsoft verified that Storm-2570 targets healthcare, education, energy, and manufacturing sectors across the US, UK, Spain, Netherlands, Canada, and Puerto Rico. The group uses remote management tools like MeshAgent and ScreenConnect, then steals credentials with Mimikatz, LaZagne, and pypykatz. This operational flexibility is confirmed by the deployment of four distinct ransomware families—Qilin, DragonForce, Anubis, and BERT—while maintaining identical post-compromise tradecraft. If you see that combination, assume Storm-2570 is active and isolate the host immediately.</p>

<h3 id="how-it-works-6">How it works</h3>

<p>Attackers establish persistent access through rogue ScreenConnect installations, then execute PowerShell commands targeting Event ID 1149 in the RemoteConnectionManager log to enumerate RDP authentication history. This stealthy reconnaissance maps network connections and identifies privileged accounts without triggering traditional security alerts, before deploying tunneling techniques to maintain access. Because the group uses the same pre-encryption steps for Qilin, DragonForce, Anubis, and BERT, the exposure boundary extends to any environment where MeshAgent or ScreenConnect is paired with Mimikatz usage.</p>

<h3 id="what-to-do-6">What to do</h3>

<p>Qilin and Dragonforce consistently deploy BERT ransomware, confirming Storm-2570 uses uniform post-compromise tradecraft across multiple malware families. This standardized approach means identifying the initial access vector via remote management tools is sufficient to predict subsequent credential theft and encryption phases. Disable or remove unnecessary Remote Desktop Protocol services on servers that do not require interactive user access to reduce the attack surface for credential-based logins. Implement auditing configurations to systematically review system logs for anomalies in user behavior and RDP session activity to detect unauthorized access attempts.</p>

<h3 id="limits-and-watch-6">Limits and watch</h3>

<p>Storm-2570 consistently uses Mimikatz and LaZagne for credential access, but the specific initial access vector for each campaign remains distinct and not fully mapped in the current evidence. The association of BERT ransomware with Storm-2570 is established, but the extent to which other ransomware families like Anubis are deployed with the same pre-encryption steps is not fully quantified. Watch</p>

<h3 id="techniques-8">Techniques</h3>

<ul>
  <li><strong>AML.T0012</strong> Valid Accounts (Initial Access)</li>
  <li><strong>AML.T0049</strong> Exploit Public-Facing Application (Initial Access)</li>
  <li><strong>AML.T0075</strong> Cloud Service Discovery (Discovery)</li>
  <li><strong>AML.T0103</strong> Deploy AI Agent (Execution)</li>
  <li><strong>AML.T0112.000</strong> Local AI Agent (Impact)</li>
  <li><strong>T1003.001</strong> LSASS Memory (Credential Access)</li>
  <li><strong>T1007</strong> System Service Discovery (Discovery)</li>
  <li><strong>T1021</strong> Remote Services (Lateral Movement)</li>
  <li><strong>T1021.001</strong> Remote Desktop Protocol (Lateral Movement)</li>
  <li><strong>T1078</strong> Valid Accounts (Stealth)</li>
  <li>and 10 more</li>
</ul>

<h3 id="named-actors-and-malware-4">Named actors and malware</h3>

<ul>
  <li>Qilin (malware)</li>
  <li>Qilin Ransomware (malware)</li>
</ul>

<h3 id="coverage-8">Coverage</h3>

<ul>
  <li><a href="https://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-tracking-storm-2570-consistent-tradecraft-across-deployments/">Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments</a></li>
  <li><a href="https://cybersecuritynews.com/microsoft-finds-ransomware-group">Microsoft Finds Ransomware Group Using Same Attack Blueprint Across Multiple Malware Families</a></li>
  <li><a href="https://cybersecuritynews.com/qilin-ransomware-enumerates-rdp-authentication">Qilin Ransomware Enumerates RDP Authentication History on a Compromised Server</a></li>
  <li><a href="https://www.microsoft.com/en-us/security/blog/2026/09/25/storm-3168-agentic-driven-cloud-attacks-using-compromised-service-principals/">Storm-3168: Agentic-driven cloud attacks using compromised service principals</a></li>
  <li><a href="https://www.microsoft.com/en-us/security/blog/2026/09/28/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations/">NeedyMantis: Unpacking a post-compromise malware family used in targeted operations</a></li>
</ul>

<hr />

<h2 id="10-canadian-cyber-center-confirms-active-wild-exploitation-of-roundcube-webmail-sql-injection-cve-2026-48842-hot">10. Canadian Cyber Center Confirms Active Wild Exploitation of Roundcube Webmail SQL Injection CVE-2026-48842 <em>(Hot)</em></h2>

<p><em>2 new indicator(s) observed</em></p>

<p>The Canadian Center for Cyber Security issued advisory AV26-503 on September 21, 2026, confirming that CVE-2026-48842 is under active exploitation. This confirmation marks a shift from a patched vulnerability to a live threat against unpatched Roundcube Webmail instances. If you are running versions prior to 1.6.16 or 1.7.1, you are exposed.</p>

<p>Roundcube Webmail users in versions 1.6.0 and 1.7.0 face remote code execution and SQL injection flaws today. Authenticated attackers trigger these issues by injecting malformed serialized objects into the _from parameter in upload[.]php. The vulnerability exists in the virtuser_query plugin, where a backslash-escape bypass in the PHP preg_replace function allows manipulation of database queries. This improper neutralization of special elements lets injected data be interpreted as executable shell commands by the backend. Additionally, attackers can inject scripts that execute after page load by exploiting improper neutralization of user input before DOM manipulation. Roundcube Webmail versions before 1.5.12 and 1.6 before 1.6.12 allow DOM-based XSS via the animate tag, bypassing server-side filters. Authenticated attackers exploit this CVSS 9.9 flaw to modify application state or consume CPU resources without network exposure. This remote code execution weakness, rated CVSS 9.9, stems from deserializing untrusted data without ensuring validity, enabling attackers to modify application state. This allows attackers to execute system commands through MSSQL_xp_cmdshell, stealing data and gaining privileges. Successful exploitation allows attackers to access sensitive user data, mail account credentials, and administrative functions within the webmail environment.</p>

<p>Because the flaw bypasses authentication in the virtuser_query plugin, attackers can manipulate database queries to access sensitive communications and administrative functions without valid user credentials. Isolate affected Roundcube instances immediately to stop unauthorized code execution until patch 1.5.10 is available. Patch Roundcube immediately to stop reflected or DOM-based script execution that yields a CVSS 7.2 impact. Patch to 1.6.16 or 1.7.1 immediately to prevent unauthorized code execution, as static analysis tools may miss this specific backslash bypass. Patch versions 1.5.10 and 1.6.11 immediately, as automated static analysis cannot reliably detect runtime object injection. Validate serialized inputs before deserialization to prevent the object injection prerequisite identified by CAPEC. Apply static analysis to detect this pattern and mitigate by populating new objects instead of directly deserializing tainted data. Validate the _from parameter before unserialization and apply the latest patch to close the remote code execution path. Upgrade to version 1.6.16 or 1.7.1 immediately to close the Pre-authentication SQL injection gap. Update all Roundcube Webmail installations to version 1.6.16 or 1.7.1 immediately to close the SQL injection vector in the virtuser_query plugin. Inventory your environment for legacy versions prior to 1.5.10 or 1.6.11 to ensure they are patched against CVE-2025-49113, which allows remote code execution by authenticated users.</p>

<p>The evidence does not specify the exact number of compromised instances or the specific data exfiltrated, only that the vulnerability is being actively exploited. It remains unclear whether the active exploitation of CVE-2026-48842 has led to lateral movement or further compromise beyond the initial database access. Monitor for abnormal request patterns to public endpoints followed by elevated 4xx/5xx errors or unusual methods, which indicate an adversary attempting to exploit the public-facing application.</p>

<h3 id="vulnerabilities-4">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2025-49113</strong> — CVSS 9.9 (Critical) · CISA KEV · CWE-502 · Roundcube Webmail. Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP…</li>
  <li><strong>CVE-2026-48842</strong> — CVSS 8.1 (High) · CWE-89 · Roundcube Webmail. Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.</li>
  <li><strong>CVE-2025-68461</strong> — CVSS 7.2 (High) · CISA KEV · CWE-79 · Roundcube Webmail. Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.</li>
</ul>

<h3 id="techniques-9">Techniques</h3>

<ul>
  <li><strong>T1190</strong> Exploit Public-Facing Application (Initial Access)</li>
  <li><strong>T1505.003</strong> Web Shell (Persistence)</li>
  <li><strong>T1556.006</strong> Multi-Factor Authentication (Defense Impairment)</li>
  <li><strong>T1589.002</strong> Email Addresses (Reconnaissance)</li>
</ul>

<h3 id="indicators-8">Indicators</h3>

<ul>
  <li>4 indicators on file</li>
</ul>

<h3 id="coverage-9">Coverage</h3>

<ul>
  <li><a href="https://cybersecuritynews.com/roundcube-webmail-vulnerability-exploited">Roundcube Webmail SQL Injection Vulnerability Exploited in the Wild</a></li>
  <li><a href="https://sentinelone.com/vulnerability-database/cve-2026-48842">CVE-2026-48842: Roundcube Webmail SQLi Vulnerability</a></li>
  <li><a href="https://gbhackers.com/roundcube-webmail-flaw/">Roundcube Webmail Flaw Lets Attackers Trigger SQL Injection Without Authentication</a></li>
  <li><a href="https://linkedin.com/posts/omar-ahmed-le0mx_roundcube-webmail-sql-injection-vulnerability-share-7508931321621254144-fR8W">No credentials needed.</a></li>
  <li><a href="https://securityaffairs.com/199882/security/roundcube-sql-injection-cve-2026-48842-is-now-being-exploited-in-the-wild.html">Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild</a></li>
</ul>]]></content><author><name></name></author><summary type="html"><![CDATA[FBI breached via ShinyHunters zero-day sextortion? Meanwhile, Citrix NetScaler zero-days patched after weeks of silent exploitation. Is your legacy infrastructure already compromised?]]></summary></entry><entry><title type="html">The Hot Drop for 09-28-2026</title><link href="/blog/the-hot-drop-for-09-28-2026/" rel="alternate" type="text/html" title="The Hot Drop for 09-28-2026" /><published>2026-09-28T13:29:40+00:00</published><updated>2026-09-28T13:29:40+00:00</updated><id>/blog/the-hot-drop-for-09-28-2026</id><content type="html" xml:base="/blog/the-hot-drop-for-09-28-2026/"><![CDATA[<p>ShinyHunters already breached the FBI jobs portal with a PeopleSoft zero-day. WordPress patches were ignored within hours. Citrix NetScaler zero-days remain unpatched and active. What’s next?</p>

<p><strong>Since the last show:</strong> 2 new · 6 developing · 2 returning · 4 dropped · 43% overlap with the previous show</p>

<h2 id="contents">Contents</h2>

<ol>
  <li>ShinyHunters Exploits Oracle PeopleSoft Zero-Day</li>
  <li>WordPress 7.1.2 Patches Critical RCE as Attackers Exploit Within Hours</li>
  <li>Citrix NetScaler Zero-Days Under Active Exploitation</li>
  <li>Citrix NetScaler Zero-Days Now in CISA KEV</li>
  <li>Infostealers drive 74% surge in cookie theft, exposing 94 billion credentials</li>
  <li>ShinyHunters claims FBI breach to refute reports, while sextortion and healthcare vishing campaigns exploit leaked data</li>
  <li>STAR Labs researcher earns $113k for 14-year-old Linux AF_ALG race condition enabling root and Docker escape</li>
  <li>Lazarus Group Steals $292M From KelpDAO Bridge</li>
  <li>Huntress: Attackers Exploit Samsung MagicINFO Flaw to Compile Monero Miner on Endpoint</li>
  <li>KELA reports 3.9B credentials stolen by infostealers as Vidar 2.0 targets Azure</li>
</ol>

<hr />

<h2 id="1-shinyhunters-exploits-oracle-peoplesoft-zero-day-lead">1. ShinyHunters Exploits Oracle PeopleSoft Zero-Day <em>(Lead)</em></h2>

<p><em>Blast radius expanded: new vendor(s): microsoft; 6 new indicator(s) observed; 1 new attacker infrastructure indicator(s)</em></p>

<h3 id="what-changed">What changed</h3>

<p>ShinyHunters, tracked by Google Mandiant as UNC6240, breached over one hundred organizations, including the FBI’s jobs portal, by exploiting a critical zero-day in Oracle PeopleSoft. The group exploited CVE-2026-35273 between May 27 and June 9, 2026. Oracle issued an advisory on June 10, rating the flaw a CVSS 9.8 and urging immediate patching for PeopleTools versions 8.61 and 8.62. The University of Nottingham confirmed the exposure of roughly 455,000 email addresses. ShinyHunters claims to have stolen two to three terabytes of data from the FBI, a claim the FBI is currently investigating. Google’s Mandiant confirmed UNC6240 targeted Oracle PeopleSoft servers using a zero-day to bypass security updates. They exploited the PSEMHUB endpoint via URL-encoding to deploy JSP web shells and backdoors like SIDEEYE. Detect unauthenticated PSEMHUB access and anomalous JSP file creation. Watch for connections to azurenetfiles[.]net or IP 162[.]219[.]30[.]165. Verify PeopleSoft patch status immediately. The FBI investigates ShinyHunters’ claim of stealing two to three terabytes of employee data.</p>

<h3 id="how-it-works">How it works</h3>

<p>UNC6240 modified its exploit to bypass web application firewall rules by using URL-encoding tricks to access the vulnerable Environment Management Hub endpoint. This technique allowed the attackers to deploy JSP web shells and backdoors like SIDEEYE, utilizing Java deserialization to execute remote code on the target systems. The attack chain reached dozens of systems globally across higher education, healthcare, and technology sectors, achieving unauthenticated remote code execution with a CVSS score of 9.8.</p>

<h3 id="what-to-do">What to do</h3>

<p>UNC6240 bypassed WAF rules by URL-encoding the PSEMHUB endpoint, exposing unpatched PeopleSoft servers to remote code execution. Apply the Oracle Security Alert Advisory patch immediately for PeopleTools versions 8.61 and 8.62 to close the remote, authentication-less exploitability of CVE-2026-35273. Disable the EMHub service and remove unauthorized web shell files to mitigate the expanded global campaign targeting higher education, healthcare, and technology sectors.</p>

<h3 id="limits-and-watch">Limits and watch</h3>

<p>The specific patch release date for CVE-2026-35273 remains uncertain, so organizations cannot yet confirm the exact timeline for full remediation of the Updates Environment Management component. Threat actors may use any percent-encoded, mixed-case, or otherwise non-normalized variant of /PSEMHUB/ to bypass WAFs, meaning static path blocking is insufficient. Watch for unexpected file creation in web directories followed by web server processes spawning command shells or script interpreters to detect web shell deployment.</p>

<h3 id="vulnerabilities">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-35273</strong> — CVSS 9.8 (Critical) · CISA KEV · Oracle Corporation PeopleSoft Enterprise PeopleTools. Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management).</li>
</ul>

<h3 id="techniques">Techniques</h3>

<ul>
  <li><strong>AML.T0000</strong> Search Open Technical Databases (Reconnaissance)</li>
  <li><strong>AML.T0006</strong> Active Scanning (Reconnaissance)</li>
  <li><strong>AML.T0049</strong> Exploit Public-Facing Application (Initial Access)</li>
  <li><strong>AML.T0050</strong> Command and Scripting Interpreter (Execution)</li>
  <li><strong>AML.T0055</strong> Unsecured Credentials (Credential Access)</li>
  <li><strong>AML.T0072</strong> Reverse Shell (Command And Control)</li>
  <li><strong>T1016</strong> System Network Configuration Discovery (Discovery)</li>
  <li><strong>T1018</strong> Remote System Discovery (Discovery)</li>
  <li><strong>T1027</strong> Obfuscated Files or Information (Stealth)</li>
  <li><strong>T1036.005</strong> Match Legitimate Resource Name or Location (Stealth)</li>
  <li>and 10 more</li>
</ul>

<h3 id="named-actors-and-malware">Named actors and malware</h3>

<ul>
  <li>ShinyHunters (actor)</li>
  <li>Neo-reGeorg (malware)</li>
</ul>

<h3 id="indicators">Indicators</h3>

<ul>
  <li>19 indicators on file</li>
</ul>

<h3 id="coverage">Coverage</h3>

<ul>
  <li><a href="https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html">ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities</a></li>
  <li><a href="https://oracle.com/security-alerts/alert-cve-2026-35273.html">Oracle Security Alert Advisory - CVE-2026-35273</a></li>
  <li><a href="https://thehackernews.com/2026/09/shinyhunters-claims-fbi-breach-says-it.html">ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants</a></li>
  <li><a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft">ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft</a></li>
  <li><a href="https://thehackernews.com/2026/09/attackers-bypass-wafs-to-exploit-oracle.html">Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells</a></li>
  <li><a href="https://www.bleepingcomputer.com/news/security/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks/">ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks</a></li>
  <li><a href="https://gbhackers.com/oracle-peoplesoft-servers/">Oracle PeopleSoft Servers Targeted Again as ShinyHunters Expands Extortion Operations</a></li>
  <li><a href="https://www.securityweek.com/google-warns-of-shinyhunters-fresh-oracle-peoplesoft-campaign/">Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign</a></li>
  <li><a href="https://gbhackers.com/oracle-peoplesoft-zero-day-rce-vulnerability">Oracle PeopleSoft Zero-Day RCE Vulnerability Exploited by ShinyHunters</a></li>
</ul>

<hr />

<h2 id="2-wordpress-712-patches-critical-rce-as-attackers-exploit-within-hours-segment">2. WordPress 7.1.2 Patches Critical RCE as Attackers Exploit Within Hours <em>(Segment)</em></h2>

<p><em>Blast radius expanded: new vendor(s): google, github</em></p>

<h3 id="what-changed-1">What changed</h3>

<p>WordPress released version 7.1.2 on September 22 to patch CVE-2026-87902, a critical flaw allowing unauthenticated remote code execution. The vulnerability, classified as CWE-98 with a CVSS score of 9.2, allows unauthenticated users to include local PHP files outside theme directories via the get_page_template function. Within hours of the patch, Patchstack and Previdian observed a surge in malicious traffic. Attackers moved from reconnaissance to writing malicious PHP files to disk using the pearcmd[.]php utility. Reports differ on the exact blast radius, with some noting new vendor involvement, but the core mechanism is consistent: exploitation requires PEAR and specific PHP settings. CISA has added this to the Known Exploited Vulnerabilities catalog, mandating rapid remediation for federal agencies. If you run WordPress, verify you are on 7.1.2 or the backported 4.7.37. Check your web server logs for requests to pearcmd[.]php or unusual file writes in non-theme directories. Look for traffic from IPs in New Jersey and Indonesia, specifically addresses like 104 dot 194 dot 9 dot 227 and 107 dot 189 dot 14 dot 87. WordPress versions from 4.7.0 through 7.1.1 contain a flaw in the get_page_template() functionality. This improper page-template resolution allows an unauthenticated attacker to include a locally readable PHP file located outside the active theme directories.</p>

<h3 id="how-it-works-1">How it works</h3>

<p>Threat actors are exploiting CVE-2026-87902 in WordPress to force remote file inclusion via the get_page_template function. An unauthenticated attacker manipulates template resolution to force the application to execute a chosen local PHP file, bypassing standard theme directory restrictions. This execution path allows attackers to write files to disk that run shell commands when accessed, establishing a foothold on the server. This weakness allows attackers to read arbitrary local PHP files and execute unauthorized commands because the server permits remote file inclusion. This weakness, CWE-98, allows attackers to write executable files to disk and run shell commands, achieving a CVSS 8.1 impact with high confidentiality, integrity, and availability consequences. This unauthenticated flaw allows attackers to bypass theme directory restrictions and execute arbitrary code via the get_page_template function. Compromised servers are used to deploy web shells, steal database credentials, and create administrator accounts to maintain persistent access. The compromised infrastructure serves as a launchpad for threat actors to target other systems and distribute malware to visitors.</p>

<h3 id="what-to-do-1">What to do</h3>

<p>An unauthenticated remote code execution flaw in WordPress versions 4.7.0 through 7.1.1 exposes your infrastructure to immediate compromise, allowing attackers to deploy web shells and pivot to other internal systems. Because the vulnerability allows the inclusion of arbitrary local PHP files outside theme directories, a single compromised instance can serve as a launchpad for broader network attacks and data exfiltration. Update WordPress to version 7.1.2 or the backported 4.7.37 to close the unauthenticated file inclusion vector. Restrict include and require statements immediately, as manual analysis and static tools are the primary detection methods for this flaw. Verify that your PHP runtime enforces strict filename mapping and avoids unvetted include or require calls to prevent unauthorized file inclusion.</p>

<h3 id="limits-and-watch-1">Limits and watch</h3>

<p>While the CVSS score is 8.1, we cannot confirm a specific patch date for WordPress 0.000 yet, so manual white-box analysis remains the only known detection method. While the vulnerability is confirmed to affect versions back to 4.7.0, the specific pre-conditions required for successful exploitation on your specific server configuration are not yet fully established. Watch your logs for suspicious requests to public endpoints followed by web server processes spawning shells or writing webshells, which signals active exploitation of T1190.</p>

<h3 id="vulnerabilities-1">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-87902</strong> — CVSS 8.1 (High) · CISA KEV · CWE-98 · WordPress WordPress. An unauthenticated attacker can make <code class="language-plaintext highlighter-rouge">get_page_template()</code> page-template resolution include a chosen readable local <code class="language-plaintext highlighter-rouge">.php</code> file outside the active theme directories.</li>
</ul>

<h3 id="techniques-1">Techniques</h3>

<ul>
  <li><strong>AML.T0072</strong> Reverse Shell (Command And Control)</li>
  <li><strong>T1189</strong> Drive-by Compromise (Initial Access)</li>
  <li><strong>T1190</strong> Exploit Public-Facing Application (Initial Access)</li>
  <li><strong>T1195.001</strong> Compromise Software Dependencies and Development Tools (Initial Access)</li>
  <li><strong>T1203</strong> Exploitation for Client Execution (Execution)</li>
  <li><strong>T1210</strong> Exploitation of Remote Services (Lateral Movement)</li>
  <li><strong>T1212</strong> Exploitation for Credential Access (Credential Access)</li>
  <li><strong>T1505.003</strong> Web Shell (Persistence)</li>
  <li><strong>T1608.004</strong> Drive-by Target (Resource Development)</li>
  <li><strong>T1659</strong> Content Injection (Initial Access)</li>
</ul>

<h3 id="named-actors-and-malware-1">Named actors and malware</h3>

<ul>
  <li>page (malware)</li>
</ul>

<h3 id="indicators-1">Indicators</h3>

<ul>
  <li>12 indicators on file</li>
</ul>

<h3 id="coverage-1">Coverage</h3>

<ul>
  <li><a href="https://securityaffairs.com/199564/hacking/cve-2026-87902-how-close-is-your-wordpress-to-remote-code-execution.html">CVE-2026-87902: how close is your WordPress to remote code execution?</a></li>
  <li><a href="https://patchstack.com/articles/wordpress-7-1-2-security-release-unauthenticated-lfi-to-rce">WordPress 7.1.2 Security Release: Unauthenticated LFI to RCE</a></li>
  <li><a href="https://wordpress.org/news/2026/09/wordpress-7-1-2-release">WordPress 7.1.2 Release</a></li>
  <li><a href="https://gbhackers.com/critical-wordpress-flaw/">Critical WordPress Flaw Lets Unauthenticated Attackers Execute Remote Code</a></li>
  <li><a href="https://www.helpnetsecurity.com/2026/09/23/cve-2026-87902-wordpress-7-1-2-security-release/">WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)</a></li>
  <li><a href="https://thehackernews.com/2026/09/wordpress-issues-patch-for-critical.html">WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers</a></li>
  <li><a href="https://cybersecuritynews.com/wordpress-core-vulnerability">Critical WordPress Core Vulnerability Lets Attackers Execute Code Without Logging In</a></li>
  <li><a href="https://patchstack.com/articles/cve-2026-87902-attackers-started-probing-wordpress-sites-hours-after-the-patch">CVE-2026-87902: Attackers Started Probing WordPress Sites Hours After the Patch</a></li>
  <li><a href="https://www.bleepingcomputer.com/news/security/hackers-start-exploiting-critical-wordpress-flaw-for-code-execution/">Hackers start exploiting critical WordPress flaw for code execution</a></li>
  <li>
    <table>
      <tbody>
        <tr>
          <td>[CVE-2026-87902 Exploitation Observed — WordPress</td>
          <td>Previdian](https://previdian.com/CVE-2026-87902)</td>
        </tr>
      </tbody>
    </table>
  </li>
  <li><a href="https://thehackernews.com/2026/09/attackers-exploit-wordpress-cve-2026.html">Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure</a></li>
  <li><a href="https://www.securityweek.com/critical-wordpress-vulnerability-exploited-immediately-after-disclosure/">Critical WordPress Vulnerability Exploited Immediately After Disclosure</a></li>
  <li><a href="https://socfortress.medium.com/wordpress-exploitation-surge-cve-2026-87902-attack-analysis-286527f8aa1b">WordPress Exploitation Surge: CVE-2026–87902 Attack Analysis</a></li>
  <li><a href="https://ressl.ch/blog/cve-2026-87902-wordpress">CVE-2026-87902: Critical WordPress file inclusion and conditional RCE — Robert Ressl</a></li>
  <li><a href="https://www.csoonline.com/article/4226330/wordpress-patches-a-critical-severity-security-vulnerability.html">WordPress patches a critical severity security vulnerability</a></li>
  <li><a href="https://cybersecuritynews.com/hackers-exploiting-wordpress-vulnerability">Hackers Actively Exploiting WordPress Vulnerability to Execute Malicious Code</a></li>
  <li><a href="https://cisa.gov/news-events/alerts/2026/09/25/cisa-adds-one-known-exploited-vulnerability-catalog">CISA Adds One Known Exploited Vulnerability to Catalog</a></li>
</ul>

<hr />

<h2 id="3-citrix-netscaler-zero-days-under-active-exploitation-segment">3. Citrix NetScaler Zero-Days Under Active Exploitation <em>(Segment)</em></h2>

<p><em>Blast radius expanded: new vendor(s): gateway</em></p>

<h3 id="what-changed-2">What changed</h3>

<p>On September 26, 2026, watchTowr and the Dutch National Cyber Security Centre confirmed that two unpatched zero-day remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway appliances are under active exploitation. These flaws are distinct from the earlier CVE-2026-19490 and CVE-2026-19489 entries, and Citrix had not released a patch or formal advisory as of September 27, 2026. The MITRE techniques involve exploiting public-facing applications and remote services, making any internet-facing NetScaler a primary target. Do not wait for the patch, which Citrix is expected to release early this week. Multiple national cybersecurity agencies, including Singapore’s Cyber Security Agency and CISA, have confirmed active exploitation of these specific unpatched flaws. The Dutch National Cyber Security Centre issued a pre-notification on September 25, 2026, which watchTowr researchers subsequently verified on September 26, 2026. The key signal to watch for is any unexpected outbound connection from a NetScaler appliance, as that indicates successful exploitation and potential lateral movement.</p>

<h3 id="how-it-works-2">How it works</h3>

<p>The NetScaler stack weakness requires no authentication or network access, letting attackers execute arbitrary code immediately upon discovery. This flaw bypasses standard access controls in ADC and Gateway components, affecting versions 14.1 through 73.32 or 13.1 through 63.21. With no vendor fix or indicators of compromise available, some administrators have taken internet-exposed appliances offline immediately.</p>

<h3 id="what-to-do-2">What to do</h3>

<p>Today’s event centers on two flaws in Citrix NetScaler, but CVE-2026-19489 stands out because it targets the older 13.x line alongside the 14.x series, creating a wider attack surface than its sibling. Internet-facing NetScaler ADC and Gateway appliances are the primary exposure surface for these unpatched remote code execution flaws, which are distinct from the previously cataloged CVE-2026-19490 and CVE-2026-19489. The absence of a vendor patch or indicators of compromise forces immediate operational decisions, such as taking appliances offline, rather than relying on standard remediation timelines. Patch NetScaler 14.1 and 13.1 lines immediately to close the high-impact execution path before adversaries leverage the zero-day. Isolate NetScaler 13.1 and 14.1 systems today because the dual-series impact means legacy infrastructure faces the same risk as modern deployments. Prioritize isolating appliances running NetScaler ADC or Gateway versions 13.1 through 63.21 and 14.1 through 73.32, which are affected by CVE-2026-19490 and the current unpatched zero-days.</p>

<h3 id="limits-and-watch-2">Limits and watch</h3>

<p>Citrix has not published a formal security advisory or technical details for the two new zero-day vulnerabilities, leaving defenders without specific indicators of compromise to verify past exploitation. The exact scope of the new unpatched flaws remains unverified beyond the confirmed remote code execution capability, as the available intelligence is credible but lacks the granular technical data present in the CVE-2026-19490 and CVE-2026-19489 catalog entries. Watch for unexpected outbound connections from NetScaler appliances, which signals successful exploitation and potential lateral movement via remote services.</p>

<h3 id="vulnerabilities-2">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-19490</strong> — CVSS 9.8 (Critical) · CISA KEV · NetScaler ADC; NetScaler Gateway. Vulnerability in NetScaler ADC and NetScaler Gateway.</li>
  <li><strong>CVE-2026-19489</strong> — CVSS 0 (Low) · NetScaler ADC; NetScaler Gateway. Vulnerability in NetScaler ADC and NetScaler Gateway.</li>
</ul>

<h3 id="techniques-2">Techniques</h3>

<ul>
  <li><strong>T1021.007</strong> Cloud Services (Lateral Movement)</li>
  <li><strong>T1190</strong> Exploit Public-Facing Application (Initial Access)</li>
  <li><strong>T1203</strong> Exploitation for Client Execution (Execution)</li>
  <li><strong>T1210</strong> Exploitation of Remote Services (Lateral Movement)</li>
  <li><strong>T1212</strong> Exploitation for Credential Access (Credential Access)</li>
  <li><strong>T1552.004</strong> Private Keys (Credential Access)</li>
  <li><strong>T1590.006</strong> Network Security Appliances (Reconnaissance)</li>
</ul>

<h3 id="indicators-2">Indicators</h3>

<ul>
  <li>8 indicators on file</li>
</ul>

<h3 id="coverage-2">Coverage</h3>

<ul>
  <li><a href="https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html">Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation</a></li>
  <li><a href="https://tenable.com/cve/CVE-2026-19490">CVE-2026-19490</a></li>
  <li><a href="https://tenable.com/blog/frequently-asked-questions-about-reported-citrix-netscaler-zero-day-vulnerabilities">Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities</a></li>
  <li><a href="https://cybersecuritynews.com/citrix-netscaler-0-day-rce-2">Citrix NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attacks</a></li>
  <li><a href="https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/">Citrix confirms two NetScaler RCE zero-days exploited in attacks</a></li>
</ul>

<hr />

<h2 id="4-citrix-netscaler-zero-days-now-in-cisa-kev-segment">4. Citrix NetScaler Zero-Days Now in CISA KEV <em>(Segment)</em></h2>

<p><em>Event first seen in a show</em></p>

<p>Citrix NetScaler appliances are under active attack, and the clock is ticking. On September 27, 2026, Citrix disclosed eight new vulnerabilities in NetScaler ADC and Gateway products, including two critical remote code execution flaws that were already actively exploited as zero-days. Two of these, CVE-2026-88771 and CVE-2026-88772, are critical remote code execution flaws that allow unauthenticated attackers to execute arbitrary commands or crash the system. CISA immediately added these vulnerabilities to its Known Exploited Vulnerabilities catalog, prompting global CERT alerts and urgent vendor-supplied patches for affected systems. Federal agencies have until September 30th to apply fixes. If you run NetScaler, verify your patch status against the eight new CVEs today. The Dutch National Cyber Security Center confirmed that exploitation of these NetScaler flaws began weeks before the official disclosure. Advanced persistent threat groups and ransomware affiliates have been identified as the actors exploiting Citrix NetScaler ADC in these attacks.</p>

<p>Attackers exploit improper input validation in Citrix NetScaler ADC before version 14.1-73.37 to execute arbitrary commands. They trigger this flaw by sending crafted requests that bypass standard access controls. The root cause is improper HTTP URL based expression usage, which enables unauthorized access to restricted features. An unauthenticated remote attacker can exploit this flaw to execute arbitrary commands on the appliance. This vulnerability allows bypassing security restrictions to trigger denial of service or remote code execution without prior authentication. Within the event’s eight CVE cluster, an attacker triggers an overflow to cause unpredictable behavior or denial of service. This specific weakness causes unpredictable behavior, distinct from the other seven CVEs in the set. An attacker triggers this overflow by sending malformed requests, crashing the gateway without requiring authentication. Citrix NetScaler ADC and Gateway versions before 14.1-73.37 face remote code execution risks today. These appliances suffer from feature policy bypass via improper HTTP URL expression. The flaw enables Cross Zone Scripting by forcing zone-aware browsers to load malicious content that bypasses security controls. This weakness causes resource exhaustion or memory reads, enabling cross-zone scripting only if the victim uses a zone-aware browser. Additionally, the system faces a memory overflow that triggers denial of service. The flaws affect internet-facing NetScaler Gateway and ADC appliances, with exploitation observed on unmitigated deployments. Federal agencies are required to apply mitigations for these vulnerabilities by September 30, 2026. Citrix NetScaler ADC and Gateway versions before 14.1-73.37 face HTTP smuggling via CWE-444, letting attackers inject unauthorized requests. This weakness in the eight-event set bypasses feature policies without extra authentication. APT and ransomware groups actively exploit this to run arbitrary commands on unauthenticated appliances.</p>

<p>Verify versions are at least 14.1-73.37 or 13.1-64.23 to patch the input validation flaw. Check specific version numbers immediately to confirm exposure. Patch today’s releases to stop the client-side injection buffer overflow that crashes after downloading hostile code. Patch affected versions immediately to prevent resource exhaustion or privilege elevation. Patch these instances immediately to stop the back-end injection this CVE enables. Patch these specific versions immediately to stop the exploit chain. Verify NetScaler versions immediately to avoid the denial of service consequence. Patch versions 14.1-73.37 and earlier immediately to stop the crash cascade. Apply patches immediately, as static analysis tools can detect the missing input validation logic.</p>

<p>Until the vendor releases 14.1-73.37, no concrete mitigation exists beyond blocking the specific request smuggling patterns observed today. The full scale of global exploitation remains undetermined, as experts have not yet quantified the total number of compromised devices. It is not yet established whether the observed webshell planting is part of a coordinated nation-state espionage campaign or isolated ransomware activity. Monitor for Indirect Command Execution behavior where utilities like forfiles[.]exe or pcalua[.]exe spawn secondary commands to bypass security restrictions.</p>

<h3 id="vulnerabilities-3">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2026-88771</strong> — CVSS 0 (Low) · CWE-20 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88772</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88773</strong> — CVSS 0 (Low) · CWE-444 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Inconsistent interpretation of HTTP requests (‘HTTP Request/Response smuggling’) vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88774</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88775</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88776</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88777</strong> — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
  <li><strong>CVE-2026-88778</strong> — CVSS 0 (Low) · CWE-342 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.</li>
</ul>

<h3 id="techniques-3">Techniques</h3>

<ul>
  <li><strong>T1087.001</strong> Local Account (Discovery)</li>
  <li><strong>T1133</strong> External Remote Services (Persistence)</li>
  <li><strong>T1136.001</strong> Local Account (Persistence)</li>
  <li><strong>T1190</strong> Exploit Public-Facing Application (Initial Access)</li>
  <li><strong>T1202</strong> Indirect Command Execution (Stealth)</li>
  <li><strong>T1203</strong> Exploitation for Client Execution (Execution)</li>
  <li><strong>T1210</strong> Exploitation of Remote Services (Lateral Movement)</li>
  <li><strong>T1212</strong> Exploitation for Credential Access (Credential Access)</li>
  <li><strong>T1590.006</strong> Network Security Appliances (Reconnaissance)</li>
</ul>

<h3 id="indicators-3">Indicators</h3>

<ul>
  <li>5 indicators on file</li>
</ul>

<h3 id="coverage-3">Coverage</h3>

<ul>
  <li><a href="https://rapid7.com/db/vulnerabilities/cve-2026-88771">CVE-2026-88771: Citrix NetScaler: Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway</a></li>
  <li><a href="https://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772">Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772</a></li>
  <li><a href="https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778">Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778</a></li>
  <li><a href="https://cybersecuritynews.com/citrix-netscaler-0-day-rce-vulnerabilities-exploited">CISA Warns of Citrix NetScaler 0-Day RCE Vulnerabilities Exploited in Attacks</a></li>
  <li><a href="https://thehackernews.com/2026/09/cisa-says-attackers-are-exploiting-two.html">CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally</a></li>
  <li><a href="https://hkcert.org/security-bulletin/citrix-products-multiple-vulnerabilities_20260928">Citrix Products Multiple Vulnerabilities</a></li>
  <li><a href="https://www.helpnetsecurity.com/2026/09/28/citrix-netscaler-rce-zero-days-exploited-for-weeks-cve-2026-88771-cve-2026-88772/">Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)</a></li>
</ul>

<hr />

<h2 id="5-infostealers-drive-74-surge-in-cookie-theft-exposing-94-billion-credentials-segment">5. Infostealers drive 74% surge in cookie theft, exposing 94 billion credentials <em>(Segment)</em></h2>

<p><em>Event first seen in a show</em></p>

<h3 id="what-changed-3">What changed</h3>

<p>Lumma, RedLine, and Vidar infostealers are driving the threat by exploiting unmanaged personal devices and CI/CD pipelines to bypass multi-factor authentication and access AWS and Azure. The Miasma payload targets cloud identities via malicious npm package releases. RedLine infected nine point nine million devices before its October twenty twenty-four disruption. NordVPN reports a 74% year-over-year surge in leaked cookies, with the total count rising from 54 billion to nearly 94 billion. The United States ranks fourth globally with over 3.6 billion affected cookies linked to major platforms including Google, Microsoft, and Bing.</p>

<h3 id="how-it-works-3">How it works</h3>

<p>Lumma Stealer steals active session cookies to bypass multi-factor authentication, allowing attackers to hijack sessions without requiring user login credentials. These infostealers exploit software vulnerabilities to harvest credentials, API keys, and session tokens from compromised developer workstations. Stolen data is rapidly validated and resold within hours to access brokers and ransomware operators who monetize verified enterprise access through mature malware-as-a-service ecosystems. Approximately 90% of organizations breached in 2024 had their credentials leaked for sale on dark web marketplaces, a statistic largely driven by infostealer malware such as RedLine Stealer and its successor Lumma Stealer. Leaked cookies jumped from fifty-four to ninety-four billion, making stolen session tokens the main way attackers bypass multi-factor authentication in cloud environments. Ninety percent of breached organizations found their credentials sold on dark web marketplaces, extending exposure beyond individual devices to the entire enterprise identity perimeter.</p>

<h3 id="what-to-do-3">What to do</h3>

<p>Isolate applications and sandbox them to block infostealers from reaching sensitive data on developer machines. Deploy rules to catch abnormal LSASS memory access and forged Kerberos tickets during credential validation.</p>

<h3 id="limits-and-watch-3">Limits and watch</h3>

<p>The full extent of credential exposure is unknown if an employee downloads compromised software, as infostealers can silently harvest the entire database of digital credentials. Monitor for unauthorized API requests using stolen container service account tokens to detect adversaries leveraging compromised CI/CD pipelines.</p>

<h3 id="techniques-4">Techniques</h3>

<ul>
  <li><strong>T1005</strong> Data from Local System (Collection)</li>
  <li><strong>T1027.014</strong> Polymorphic Code (Stealth)</li>
  <li><strong>T1195</strong> Supply Chain Compromise (Initial Access)</li>
  <li><strong>T1212</strong> Exploitation for Credential Access (Credential Access)</li>
  <li><strong>T1219</strong> Remote Access Tools (Command And Control)</li>
  <li><strong>T1528</strong> Steal Application Access Token (Credential Access)</li>
  <li><strong>T1539</strong> Steal Web Session Cookie (Credential Access)</li>
  <li><strong>T1550.004</strong> Web Session Cookie (Lateral Movement)</li>
  <li><strong>T1552.004</strong> Private Keys (Credential Access)</li>
  <li><strong>T1555.005</strong> Password Managers (Credential Access)</li>
  <li>and 6 more</li>
</ul>

<h3 id="named-actors-and-malware-2">Named actors and malware</h3>

<ul>
  <li>Lumma (malware)</li>
  <li>RedLine (malware)</li>
  <li>Lumma Stealer (malware)</li>
  <li>RedLine Stealer (malware)</li>
</ul>

<h3 id="indicators-4">Indicators</h3>

<ul>
  <li>2 indicators on file</li>
</ul>

<h3 id="coverage-4">Coverage</h3>

<ul>
  <li><a href="https://gbhackers.com/infostealer-malware-3/">Lumma, RedLine and Vidar Infostealers Fuel Cloud Credential Theft Campaigns</a></li>
  <li><a href="https://nordsecurity.com/press-area/from-54-billion-to-94-billion-cookie-theft-skyrockets-as-hackers-exploit-your-browser">From 54 billion to 94 billion: Cookie theft skyrockets as hackers exploit your browser</a></li>
  <li>
    <table>
      <tbody>
        <tr>
          <td>[Infostealer Malware: The Silent Threat to Your Digital Credentials  - Managed IT Services &amp; Technology Consulting</td>
          <td>OSIbeyond](https://osibeyond.com/blog/infostealer-malware-the-silent-threat-to-your-digital-credentials)</td>
        </tr>
      </tbody>
    </table>
  </li>
</ul>

<hr />

<h2 id="6-shinyhunters-claims-fbi-breach-to-refute-reports-while-sextortion-and-healthcare-vishing-campaigns-exploit-leaked-data-segment">6. ShinyHunters claims FBI breach to refute reports, while sextortion and healthcare vishing campaigns exploit leaked data <em>(Segment)</em></h2>

<p><em>Event first seen in a show</em></p>

<p>ShinyHunters claims to have breached the FBI’s recruitment portal to refute negative allegations in a recent FLASH report, rather than for financial gain. Simultaneously, threat intelligence firms report ShinyHunters is employing sophisticated voice-phishing tactics against the healthcare sector. They have successfully compromised entities such as Clover Health and AdaptHealth. AdaptHealth disclosed a July breach exposing data for more than four point one million patients. One source attributes the FBIJobs[.]gov compromise to an Oracle PeopleSoft zero-day flaw on AWS GovCloud servers, but this detail comes from a single report and lacks broader confirmation. The group is leveraging AI and social engineering techniques previously associated with Scattered Spider to target high-profile brands like Chanel and Workday. Watch for the domain my-passkeys[.]com, identified as attacker infrastructure. The FBI confirmed the compromise of the FBIJobs[.]gov portal and is actively investigating the incident while working with third-party providers to mitigate risks. ReliaQuest confirmed a sustained cluster of phishing infrastructure targeting the healthcare sector through mid-September 2026, while Unit 42 identified a domain linked to The Com underground network used in these attacks.</p>

<p>In the healthcare sector, attackers utilized aggressive voice-phishing tactics to bypass multi-factor authentication and access employee accounts at compromised entities. Third-party scammers are using email addresses from Amtrak and Panera Bread data leaks to send sextortion demands for two thousand dollars in Bitcoin for compromising evidence that does not exist. This tactic exploits the T1589.002 condition of exposed email addresses to tailor impersonation narratives. The attack chain relies on identifying targets before executing the social engineering call. The threat actor operates with a non-financial, reputation-driven motive. This breach validates the PeopleSoft zero-day as a high-fidelity initial access vector for enterprise environments. It elevates the risk for any organization running unpatched Oracle instances.</p>

<p>ShinyHunters is leveraging voice-phishing to bypass MFA at Clover Health and AdaptHealth. Defenders must immediately audit account use policies and logs to detect voice-initiated credential requests. Audit Oracle PeopleSoft instances for the specific zero-day exploit to close the initial access vector used in the FBI breach. Implement pre-compromise controls to reduce the attack surface exposed to reconnaissance, specifically limiting public-facing email infrastructure that aids in target identification.</p>

<p>ShinyHunters claims the breach aimed to contest allegations in a FLASH report, but the full scope of data exfiltration and specific technical mechanics remain under active FBI investigation. Watch for large, iterative batches of authentication requests from single sources to catch active probing for email addresses and usernames.</p>

<h3 id="techniques-5">Techniques</h3>

<ul>
  <li><strong>AML.T0052</strong> Phishing (Initial Access)</li>
  <li><strong>AML.T0052.000</strong> Spearphishing via Social Engineering LLM (Initial Access)</li>
  <li><strong>AML.T0073</strong> Impersonation (Defense Evasion)</li>
  <li><strong>T1016</strong> System Network Configuration Discovery (Discovery)</li>
  <li><strong>T1018</strong> Remote System Discovery (Discovery)</li>
  <li><strong>T1036.005</strong> Match Legitimate Resource Name or Location (Stealth)</li>
  <li><strong>T1059.007</strong> JavaScript (Execution)</li>
  <li><strong>T1059.009</strong> Cloud API (Execution)</li>
  <li><strong>T1069.003</strong> Cloud Groups (Discovery)</li>
  <li><strong>T1072</strong> Software Deployment Tools (Execution)</li>
  <li>and 10 more</li>
</ul>

<h3 id="named-actors-and-malware-3">Named actors and malware</h3>

<ul>
  <li>ShinyHunters (actor)</li>
</ul>

<h3 id="indicators-5">Indicators</h3>

<ul>
  <li>3 indicators on file</li>
</ul>

<h3 id="coverage-5">Coverage</h3>

<ul>
  <li><a href="https://gbhackers.com/shinyhunters-claims-fbi-breach-exposed-data/">ShinyHunters Claims FBI Breach Exposed Data of All Employees and Applicants</a></li>
  <li><a href="https://malwarebytes.com/blog/scams/2026/07/sextortion-scammers-are-exploiting-shinyhunters-data-leaks">Sextortion scammers are exploiting ShinyHunters data leaks</a></li>
  <li><a href="https://www.cybersecuritydive.com/news/threat-groups-social-engineering-attacks-healthcare/831383/">Threat groups ramp up social-engineering attacks against healthcare sector</a></li>
  <li><a href="https://theregister.com/security/2026/06/29/nissan-says-oracle-peoplesoft-break-in-may-have-spilled-payroll-records-ssns/5263534">Nissan says Oracle PeopleSoft break-in may have spilled payroll records, SSNs</a></li>
  <li><a href="https://www.theregister.com/cyber-crime/2026/09/25/shinyhunters-tells-the-reg-we-hacked-the-fbi-to-protect-our-business/5299250">ShinyHunters tells The Reg: We hacked the FBI to ‘protect our business’</a></li>
  <li><a href="https://theregister.com/security/2025/08/21/impersonation-as-a-service-next-big-thing-in-cybercrime/718712">‘Impersonation as a service’ next big thing in cybercrime</a></li>
</ul>

<hr />

<h2 id="7-star-labs-researcher-earns-113k-for-14-year-old-linux-af_alg-race-condition-enabling-root-and-docker-escape-segment">7. STAR Labs researcher earns $113k for 14-year-old Linux AF_ALG race condition enabling root and Docker escape <em>(Segment)</em></h2>

<p><em>No material change since last show</em></p>

<p>CISA added CVE-2025-39964 to its Known Exploited Vulnerabilities catalog, confirming active exploitation of a fourteen-year-old Linux kernel flaw. The vulnerability is a race condition in the AF_ALG interface, present since kernel version 2.6.38. STAR Labs researcher Muhammad Alifa Ramdhan identified the flaw in September 2025 and used the exploit for a Google kernelCTF submission, securing an $113,337 reward. The team disclosed this responsibly. Researchers confirmed that the vulnerability is distinct from the Copy Fail bug, as it relies on a race condition rather than a straight-line logic flaw in the AEAD path.</p>

<p>The Linux kernel resolved CVE-2025-39964 by disallowing concurrent writes in af_alg_sendmsg to stop data interleaving. The exploit works by issuing two concurrent writes to the same af_alg socket, which interleaves data in an unpredictable fashion and creates inconsistencies in the internal socket state. This race condition allows an unprivileged local attacker to manipulate memory metadata through a carefully timed interleaving of socket writes. A race condition in Linux versions 5.10 through 6.17 lets attackers trigger resource exhaustion or instability. Successful exploitation enables local users to escalate privileges to root and escape Docker containers on affected systems. The vulnerability affects Linux kernel versions from 2.6.38 through 6.17, including specific releases such as 5.10.245, 5.15.194, and 6.1.154.</p>

<p>The vulnerability enables local privilege escalation to root and Docker container escape, exposing multi-tenant systems to full host compromise if unprivileged users can access the AF_ALG interface. Defenders must now apply the T1068 mitigation of Execution Prevention by auditing application control policies to ensure no unauthorized scripts or drivers can execute on the affected Linux hosts. Simultaneously, the T1611 mitigation of Application Isolation and Sandboxing requires confirming that all containers are running with strict isolation and that no bind mounts provide access to the host’s filesystem or management sockets like docker[.]sock. Apply kernel patches that introduce the ctx-&gt;write field to enforce exclusive ownership for AF_ALG socket writes, specifically targeting versions 5.10.245, 5.15.194, 6.1.154, 6.6.108, 6.12.49, 6.16.9, and 6.17. Verify your kernel version matches the patched commit 8ff590903d5fc7f5a0a988c38267a3d08e6393a2 to close the synchronization gap. Implement application isolation and sandboxing to restrict execution environments, preventing unprivileged processes from accessing the vulnerable AF_ALG interface and limiting the blast radius of potential exploitation. The remaining uncertainty is whether attackers are currently targeting this specific 14-year-old race condition or if they are using it as a stepping stone for broader lateral movement. The immediate watch item is monitoring system logs for concurrent socket write errors or unexpected kernel panic events on affected Linux 5.10.245 and 5.15.194 systems.</p>

<p>Black-box detection methods may fail to identify this race condition if the timing window is too narrow to cause observable instability or crashes during concurrent connection attempts. The exact scope of exploitation in the wild remains limited to the CISA KEV listing, with no public evidence yet detailing specific attacker infrastructure or targeted sectors. Watch for unusual process or token behavior after exploitation attempts on vulnerable kernel components, which signals successful privilege escalation via T1068.</p>

<h3 id="vulnerabilities-4">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2025-39964</strong> — CVSS 7.8 (High) · CISA KEV · CWE-362 · Linux Linux; Linux Linux. In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in…</li>
</ul>

<h3 id="techniques-6">Techniques</h3>

<ul>
  <li><strong>T1068</strong> Exploitation for Privilege Escalation (Privilege Escalation)</li>
  <li><strong>T1611</strong> Escape to Host (Privilege Escalation)</li>
</ul>

<h3 id="coverage-6">Coverage</h3>

<ul>
  <li><a href="https://idnsec.com/research/linux-local-privilege-escalation-with-af-alg">How I Found a $113,337 AF_ALG Linux Local Privilege Escalation Before Copy Fail</a></li>
  <li><a href="https://gbhackers.com/14-year-old-linux-kernel-vulnerability/">14-Year-Old Linux Kernel Vulnerability Enables Root Access and Docker Escape</a></li>
  <li><a href="https://cybersecuritynews.com/14-year-old-linux-kernel-flaw">14-Year-Old Linux Kernel Flaw Lets Local Users Gain Root Access and Escape Containers</a></li>
</ul>

<hr />

<h2 id="8-lazarus-group-steals-292m-from-kelpdao-bridge-segment">8. Lazarus Group Steals $292M From KelpDAO Bridge <em>(Segment)</em></h2>

<p><em>No material change since last show</em></p>

<h3 id="what-changed-4">What changed</h3>

<p>Lazarus Group drained two hundred ninety-two million dollars from KelpDAO by exploiting a single-node configuration in its off-chain verification network. The TraderTraitor cell executed this theft on April 18, 2026, by compromising internal RPC nodes to feed false data to Ethereum contracts. On April 18, the TraderTraitor cell compromised internal RPC nodes in KelpDAO’s off-chain verification network. They DDoSed external nodes to feed false data, tricking Ethereum contracts into releasing funds based on phantom token burns. KelpDAO paused its contracts and blacklisted attacker addresses, while the Arbitrum Security Council moved to freeze downstream funds to limit further loss. LayerZero Labs confirmed the protocol functioned as intended, isolating the breach to KelpDAO’s specific single-node configuration rather than a systemic protocol failure. The lead sheet details the full IOC list and MITRE techniques, including PyLangGhost RAT usage.</p>

<h3 id="how-it-works-4">How it works</h3>

<p>This attack bypassed on-chain transaction validation by exploiting a single-point-of-failure in the verification network, a critical layer for cross-chain protocols. The incident stayed isolated to KelpDAO’s rsETH configuration, affecting roughly $290 million in assets without touching other applications or LayerZero’s broader protocol. The compromised LayerZero Labs DVN forced the deprecation of affected RPC nodes and activated a live LayerZero Labs DVN to secure the network.</p>

<h3 id="what-to-do-4">What to do</h3>

<p>Lazarus recruits developers via social engineering to deploy Graphalgo, forcing you to audit user behavior and restrict software installation to approved whitelists. Trace PyLangGhost RAT to the specific workstation and verify if the compromised 3CX app came from a trusted channel, since technical signatures alone miss the full scope. The 3CX compromise exposes your remote access infrastructure to the same tactics used in KelpDAO and Bybit incidents. This threat extends beyond crypto to IT services providers, making your internal RPC nodes and development tools primary targets for data exfiltration and lateral movement. Implement application whitelisting and software restriction policies to block unauthorized installation of compromised dependencies like those found in the 3CX and GitHub Actions supply-chain attacks. Audit your CI/CD pipelines for malicious GitHub Actions that collect runtime credentials or insert backdoors into build processes, specifically targeting the npm and PyPI package managers used in your development environment.</p>

<h3 id="limits-and-watch-4">Limits and watch</h3>

<p>The full extent of the 3CX compromise and whether it has already been used to pivot into your internal network remains unconfirmed by current evidence. While the campaign targets open-source repositories, the specific version of the 3CX app affected in your environment is not yet established in the available data. Watch for unexpected package manager invocations writing executable files or triggering post-install scripts spawning shells, indicating supply-chain tampering. Also watch for social engineering prompting rapid OAuth consent or credential submission, preceding malicious development tool deployment.</p>

<h3 id="techniques-7">Techniques</h3>

<ul>
  <li><strong>AML.T0011.001</strong> Malicious Package (Execution)</li>
  <li><strong>AML.T0097</strong> Virtualization/Sandbox Evasion (Defense Evasion)</li>
  <li><strong>EMERGING-0006</strong> PyLangGhost RAT</li>
  <li><strong>T1001.003</strong> Protocol or Service Impersonation (Command And Control)</li>
  <li><strong>T1005</strong> Data from Local System (Collection)</li>
  <li><strong>T1008</strong> Fallback Channels (Command And Control)</li>
  <li><strong>T1010</strong> Application Window Discovery (Discovery)</li>
  <li><strong>T1012</strong> Query Registry (Discovery)</li>
  <li><strong>T1016</strong> System Network Configuration Discovery (Discovery)</li>
  <li><strong>T1021.001</strong> Remote Desktop Protocol (Lateral Movement)</li>
  <li>and 10 more</li>
</ul>

<h3 id="named-actors-and-malware-4">Named actors and malware</h3>

<ul>
  <li>Lazarus Group (actor)</li>
  <li>Lazarus (actor)</li>
  <li>threat (actor)</li>
</ul>

<h3 id="indicators-6">Indicators</h3>

<ul>
  <li>25 indicators on file</li>
</ul>

<h3 id="coverage-7">Coverage</h3>

<ul>
  <li><a href="https://chainalysis.com/blog/kelpdao-bridge-exploit-april-2026">Inside the KelpDAO Bridge Exploit</a></li>
  <li><a href="https://bleepingcomputer.com/news/security/north-korean-hackers-now-launder-stolen-crypto-via-yomix-tumbler">North Korean hackers now launder stolen crypto via YoMix tumbler</a></li>
  <li><a href="https://redasgard.com/blog/hunting-lazarus-part5-eleven-hours-on-his-disk">Hunting Lazarus, Part 5: Eleven Hours on His Disk</a></li>
  <li><a href="https://layerzero.network/blog/kelpdao-incident-statement">KelpDAO Incident Statement</a></li>
  <li>
    <table>
      <tbody>
        <tr>
          <td>[Don’t Call Us, We’ll Call Your APIs</td>
          <td>TraderTraitor Backdoors Resurface on Victim With No Crypto Ties](https://sentinelone.com/labs/dont-call-us-well-call-your-apis-tradertraitor-backdoors-resurface-on-victim-with-no-crypto-ties)</td>
        </tr>
      </tbody>
    </table>
  </li>
  <li><a href="https://cybersecuritynews.com/lazarus-groups-graphalgo-fake-recruiter-campaign/amp">Lazarus Group’s ‘Graphalgo’ Fake Recruiter Campaign Exploits GitHub, npm, and PyPI to Distribute Malware</a></li>
  <li><a href="https://secr0-0x1.medium.com/the-3cx-supply-chain-attack-a-threat-intelligence-investigation-e6f994e8b4b5">The 3CX Supply Chain Attack: A Threat Intelligence Investigation</a></li>
  <li><a href="https://cybersecuritynews.com/bitget-hot-wallet-hacked">Bitget Hot Wallet Hacked – Attackers Stole $351.6 Million From Hot Wallets</a></li>
  <li><a href="https://bleepingcomputer.com/news/security/fbi-confirms-lazarus-hackers-were-behind-15b-bybit-crypto-heist">FBI confirms Lazarus hackers were behind $1.5B Bybit crypto heist</a></li>
  <li><a href="https://theregister.com/security/2025/02/26/bybit-declares-war-on-lazarus-crew-to-regain-stolen-15b/486722">Bybit declares war on Lazarus crew to regain stolen $1.5B</a></li>
  <li><a href="https://lazarus.day/actors/polinrider?cluster=true">Polin Rider</a></li>
</ul>

<hr />

<h2 id="9-huntress-attackers-exploit-samsung-magicinfo-flaw-to-compile-monero-miner-on-endpoint-segment">9. Huntress: Attackers Exploit Samsung MagicINFO Flaw to Compile Monero Miner on Endpoint <em>(Segment)</em></h2>

<p><em>No material change since last show</em></p>

<p>Huntress analysts identified a threat actor compiling a custom Monero miner directly on a victim’s endpoint, a tactic that bypasses standard signature detection. In early September 2026, attackers exploited CVE-2025-4632 in Samsung MagicINFO Premium to seize local administrator access on a Windows host. After Microsoft Defender blocked two attempts to download AnyDesk from IP 194[.]87[.]89[.]30, the intruders succeeded on the third try, disabled the security software, and used native tools like Donut, TCC, and MinGW64 to build the miner locally. The resulting binary was configured to connect to auto[.]c3pool[.]org to harvest cryptocurrency using the host’s CPU and GPU resources.</p>

<p>Samsung MagicINFO 9 Server before 21.1052 lets attackers write arbitrary files via path traversal on today. The flaw stems from improper pathname limitation where external input constructs a path that escapes the restricted directory. The weakness allows control of requested paths to bypass directory restrictions and overwrite critical system libraries. This local compilation allowed the threat actor to customize the binary for the target environment, specifically optimizing it for the endpoint’s CPU architecture. This CWE-22 flaw yields a CVSS 9.8 score, enabling full integrity modification of critical programs and libraries. The vulnerability grants full system authority to overwrite critical binaries without requiring user interaction.</p>

<p>This high-severity weakness enables full system compromise, distinct from the other event CVE by allowing direct file creation as root. This tactic transforms a standard intrusion into a persistent resource theft operation, as the attacker leverages the compromised host’s own processing power to harvest cryptocurrency without deploying a pre-built payload. Apply Samsung’s SVP-MAY-2025 update to patch CVE-2025-4632, upgrading all MagicINFO 9 Server instances to version 21.1052 or later to close the unauthenticated path traversal flaw. Validate all pathname inputs against a strict allowlist, rejecting any path containing dot-dot-slash sequences or unencoded slashes. Hunt for the Silent XMR Miner Builder[.]exe process chain and native tools like Donut or MinGW64 on Windows hosts to identify endpoints where the miner was compiled locally.</p>

<p>The report does not specify if other systems were affected by the initial exploitation of CVE-2025-4632, leaving the full scope of the intrusion uncertain. While CVE-2025-4632 is unauthenticated, the related CVE-2024-7399 requires local privileges, meaning the remediation scope must account for different access requirements across the affected MagicINFO versions. Monitor for the creation of VSCode tunnel configuration files combined with interactive remote sessions via the code CLI, as this indicates potential IDE tunneling for persistence.</p>

<h3 id="vulnerabilities-5">Vulnerabilities</h3>

<ul>
  <li><strong>CVE-2025-4632</strong> — CVSS 9.8 (Critical) · CISA KEV · CWE-22 · Samsung Electronics MagicINFO 9 Server. Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.</li>
  <li><strong>CVE-2024-7399</strong> — CVSS 8.8 (High) · CISA KEV · CWE-22, CWE-434 · Samsung Electronics MagicINFO 9 Server. Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.</li>
</ul>

<h3 id="techniques-8">Techniques</h3>

<ul>
  <li><strong>T1027.002</strong> Software Packing (Stealth)</li>
  <li><strong>T1027.013</strong> Encrypted/Encoded File (Stealth)</li>
  <li><strong>T1027.015</strong> Compression (Stealth)</li>
  <li><strong>T1087.001</strong> Local Account (Discovery)</li>
  <li><strong>T1136.001</strong> Local Account (Persistence)</li>
  <li><strong>T1203</strong> Exploitation for Client Execution (Execution)</li>
  <li><strong>T1204.002</strong> Malicious File (Execution)</li>
  <li><strong>T1219</strong> Remote Access Tools (Command And Control)</li>
  <li><strong>T1219.001</strong> IDE Tunneling (Command And Control)</li>
  <li><strong>T1496</strong> Resource Hijacking (Impact)</li>
</ul>

<h3 id="indicators-7">Indicators</h3>

<ul>
  <li>6 indicators on file</li>
</ul>

<h3 id="coverage-8">Coverage</h3>

<ul>
  <li><a href="https://cybersecuritynews.com/samsung-flaw">Hackers Used a Samsung Flaw to Build a Cryptominer Inside Victim Systems</a></li>
  <li><a href="https://www.huntress.com/blog/threat-actor-compiles-cryptominer">The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint</a></li>
  <li><a href="https://cybersecuritynews.com/samsung-magicinfo-9-server-vulnerability-2">Samsung MagicINFO 9 Server Vulnerability Let Attackers Write Arbitrary File</a></li>
</ul>

<hr />

<h2 id="10-kela-reports-39b-credentials-stolen-by-infostealers-as-vidar-20-targets-azure-segment">10. KELA reports 3.9B credentials stolen by infostealers as Vidar 2.0 targets Azure <em>(Segment)</em></h2>

<p><em>Event first seen in a show</em></p>

<h3 id="what-changed-5">What changed</h3>

<p>Ontinue’s Advanced Threat Operations team published a static analysis of Vidar Stealer 2.0, first observed in October 2025. The strain shifted to pure C code with pervasive control flow flattening, specifically targeting Azure credentials and Chrome version 20 passwords. This redesign positions the infostealer to capitalize on operational disruptions affecting competitors like Lumma Stealer. KELA quantified the 2024 credential crisis: 3.9 billion credentials were stolen from 4.3 million devices. Infostealer strains Lumma, StealC, and RedLine drove this theft, accounting for over 75% of infections. Reports from esecurityplanet, ontinue, and seraphicsecurity confirm these tools are persistent and evolving. Cybercriminals now trade these stolen logins on black markets to execute account takeovers, identity theft, and extortion.</p>

<h3 id="how-it-works-5">How it works</h3>

<p>The malware uses Chrome v20 AES-GCM decryption at function 0x140014d6c with Windows BCrypt APIs to extract credentials, targeting over 50 cryptocurrency wallets across multiple browsers. Adversaries may log into accessible cloud services using valid accounts synchronized with on-premises identities to perform management actions or access cloud-hosted resources as the logged-on user. Infostealers are persistent malware strains that stealthily infiltrate devices to harvest sensitive data such as session tokens, login credentials, and financial information, often leading to identity theft and session hijacking. This surge in credential theft significantly increases the risk of large-scale security breaches and unauthorized access to corporate systems. Lumma, StealC, and RedLine stole 3.9 billion credentials in 2024, creating a persistent pool of valid identities for account takeovers and extortion. Vidar Stealer 2.0 shifts to pure C with control flow flattening, targeting Azure MSAL token caches to increase direct cloud infrastructure compromise risk via stolen session tokens.</p>

<h3 id="what-to-do-5">What to do</h3>

<p>Enforce multi-factor authentication for all cloud service logins to prevent adversaries from using stolen valid accounts to access the cloud control plane. Implement privileged account management controls to restrict and audit the usage of administrative accounts that may be used for cloud resource enumeration.</p>

<h3 id="limits-and-watch-5">Limits and watch</h3>

<p>Vidar Stealer 2.0 uses computed jumps to evade static analysis, limiting the ability to fully map its exfiltration logic without dynamic execution. The malware exfiltrates Azure credentials via HTTP POST, but the specific scope of targeted enterprise tenants remains unconfirmed in available static analysis. Watch for federated logins using SSO or OAuth grants to the cloud control plane that are immediately followed by directory or permissions enumeration.</p>

<h3 id="techniques-9">Techniques</h3>

<ul>
  <li><strong>AML.T0037</strong> Data from Local System (Collection)</li>
  <li><strong>AML.T0048.001</strong> Reputational Harm (Impact)</li>
  <li><strong>AML.T0055</strong> Unsecured Credentials (Credential Access)</li>
  <li><strong>AML.T0087</strong> Gather Victim Identity Information (Reconnaissance)</li>
  <li><strong>AML.T0091.000</strong> Application Access Token (Lateral Movement)</li>
  <li><strong>AML.T0097</strong> Virtualization/Sandbox Evasion (Defense Evasion)</li>
  <li><strong>T1003.001</strong> LSASS Memory (Credential Access)</li>
  <li><strong>T1005</strong> Data from Local System (Collection)</li>
  <li><strong>T1021.007</strong> Cloud Services (Lateral Movement)</li>
  <li><strong>T1027</strong> Obfuscated Files or Information (Stealth)</li>
  <li>and 10 more</li>
</ul>

<h3 id="named-actors-and-malware-5">Named actors and malware</h3>

<ul>
  <li>Lumma (malware)</li>
  <li>RedLine (malware)</li>
  <li>Lumma Stealer (malware)</li>
  <li>Emotet (malware)</li>
</ul>

<h3 id="indicators-8">Indicators</h3>

<ul>
  <li>1 indicator on file</li>
</ul>

<h3 id="coverage-9">Coverage</h3>

<ul>
  <li><a href="https://esecurityplanet.com/cybersecurity/data-theft-infostealer-malware-2025">3.9 Billion Passwords Compromised by Infostealer Malware</a></li>
  <li><a href="https://ontinue.com/resource/blog-vidar-stealer-malware-analysis">Vidar Malware: Azure Credential Targeting and Chrome v20 Decryption Analysis</a></li>
  <li><a href="https://seraphicsecurity.com/resources/blog/how-to-protect-your-identity-and-sessions-from-an-infostealer">How to Protect Identities and Sessions from Infostealers</a></li>
</ul>]]></content><author><name></name></author><summary type="html"><![CDATA[ShinyHunters already breached the FBI jobs portal with a PeopleSoft zero-day. WordPress patches were ignored within hours. Citrix NetScaler zero-days remain unpatched and active. What’s next?]]></summary></entry></feed>