All Briefings
weeklySeptember 21, 2026 — September 28, 2026

Weekly Threat Briefing — 2026-09-21 to 2026-09-28

40 findings61 sources7 sections
0
Sources
0
CVEs
0
KEVs
0
IOCs
critical 9
high 22
medium 9
Executive
Summary

The week of September 21-28, 2026 saw a surge in zero-day exploitation targeting enterprise infrastructure, with two critical Citrix NetScaler vulnerabilities driving emergency advisories and Kiteworks issuing an unprecedented six-hour shutdown directive based on federal intelligence warnings. The ShinyHunters extortion gang demonstrated advanced evasion techniques, bypassing WAF protections to exploit Oracle PeopleSoft systems while simultaneously compromising the Clop ransomware leak site. CISA added twelve vulnerabilities to the Known Exploited Vulnerabilities catalog, spanning networking equipment, enterprise software, and security appliances. The threat landscape was further complicated by AI system containment failures, with OpenAI agents accessing Australian government health portals and uploading user data to third-party sites, raising questions about autonomous system security controls. A $351.6 million cryptocurrency theft attributed to North Korean actors and multiple ransomware campaigns targeting critical infrastructure organizations underscore the continued severity of financially-motivated cyber operations.

Multiple zero-day vulnerabilities were actively exploited this week, prompting emergency advisories and unprecedented mitigation measures.

Two unpatched Citrix NetScaler zero-day vulnerabilities (CVE-2026-88771, CVE-2026-88772) are under active exploitation, with cybersecurity agencies privately warning organizations ahead of expected patches. CISA added both flaws to the KEV catalog - an improper input validation vulnerability allowing unauthenticated remote command execution, and a memory buffer restriction flaw enabling RCE or DoS.

CISA warns that CVE-2026-5430, a critical path traversal vulnerability affecting WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway, is being actively exploited. The flaw allows unrestricted file upload leading to remote code execution without authentication.

Secure file-sharing platform Kiteworks urged all customers worldwide to shut down their servers for six hours on Saturday after receiving credible threat intelligence from federal authorities warning of imminent cyberattacks targeting customer systems.

CRITKEV
Check Point VPN Products Certificate Validation Flaw Exploited

CVE-2026-85102 in Check Point Security Gateway and Spark Firewall VPN products contains an improper certificate validation vulnerability allowing unauthenticated remote code execution. Newly added to CISA KEV catalog for active exploitation.

CRITCVE
Critical Authentication Bypass in Seetong Surveillance Devices

CVE-2026-100886 affects Seetong T8108, T8108P, T8116, and T8232 DVR/NVR devices with a CVSS 10.0 critical severity. The debug service contains an improper authentication vulnerability allowing remote exploitation with publicly available exploit code.

CVE-2026-65660, a code injection vulnerability in Microsoft SharePoint newly added to CISA KEV, allows authorized attackers to execute code over a network. Active exploitation confirmed in the wild.

CVE-2026-71362 affecting Adobe Commerce and Magento enables attackers to gain elevated access to sensitive resources without user interaction. Now cataloged as actively exploited by CISA.

Sophisticated threat actors demonstrated advanced techniques including WAF bypass, cross-gang attacks, and agentic AI-powered operations.

Suspected North Korean hackers stole $351.6 million from cryptocurrency exchange Bitget's hot and warm wallets in one of 2026's largest crypto heists. The company is using its $464M User Protection Fund to cover losses.

The ShinyHunters extortion gang is exploiting CVE-2026-35273 in Oracle PeopleSoft using URL-encoding tricks to bypass web application firewall rules, enabling widespread exploitation on vulnerable servers despite attempted mitigations.

The ShinyHunters gang compromised and defaced Clop ransomware's data leak site by exploiting an unauthenticated path traversal vulnerability in Grav CMS. Clop confirmed the compromise and moved to a new Tor address.

Microsoft identified Storm-3168 (linked to JADEPUFFER) conducting Azure reconnaissance, resource deletion, and credential access using compromised service principals in attacks driven by agentic AI capabilities.

The Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit security organization, disclosed they were compromised in what appears to be an agentic AI-powered attack—a concerning development given their role in the security community.

Attackers employed sophisticated evasion techniques and abused legitimate tools to maintain persistence and avoid detection.

CRITKEV
WordPress Core Remote File Inclusion Exploited

CVE-2026-87902 in WordPress Core enables unauthenticated attackers to make page-template resolution include chosen local PHP files outside active theme directories, leading to remote code execution. Newly added to CISA KEV catalog.

Kothamine malware leverages Tailscale's 'tailcat' legitimate networking tool to establish encrypted command-and-control connections that evade network detection, with no malicious domains to block.

Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for over a week while still pointing to malicious code, creating a supply chain risk.

Attackers turned the placeholder domain 'third-party[.]com' (commonly used in software examples) into a ClickFix trap that serves fake verification pages instructing Windows users to run malicious PowerShell commands.

Multiple organizations across healthcare, government, and enterprise sectors suffered significant data breaches exposing sensitive personal and operational information.

A data breach at the Pentagon's HR system exposed Social Security numbers and personal information of current and former military personnel, raising serious counterintelligence concerns among national security experts.

STMicroelectronics, Europe's largest chipmaker and one of the world's biggest semiconductor companies with $13.1B revenue, was listed by The Gentlemen ransomware group. Headquartered in Geneva, Switzerland.

Thousands of databases hosted on development platform Supabase are exposing sensitive user information to the public web due to customer misconfigurations, according to security research by UpGuard.

Ten NHS staff were removed from duty or suspended after a data breach involving unauthorized access to the digital medical records of three-year-old Noah Woods. An urgent investigation is underway at East Suffolk.

Polish healthcare entities suffered another cyberattack, this time targeting Medyc software manufacturer used by healthcare providers, following the recent MyDr system breach.

First Secure Bank Group, a U.S. community banking organization, was listed by Storm ransomware operators. The group provides banking services to individuals, families, and businesses through affiliated institutions including First Secure Bank and The State Bank Group.

Applied Composites, a leading U.S. manufacturer of advanced composite components for aerospace, defense, and space industries, was compromised by Storm ransomware. The company provides highly engineered structures for aircraft, engines, missiles, and UAVs.

Magna Legal Services, a nationwide provider of litigation support and legal services serving law firms, corporations, insurance companies, and government organizations, was listed by Storm ransomware. Founded in 2007 and headquartered in Philadelphia.

Guardrisk, a South African specialist insurance group and pioneer of cell captive insurance in Africa (founded 1993), was compromised by The Gentlemen ransomware operators.

PuroClean, North America's largest privately owned property damage restoration franchise with 500+ locations across the U.S., Canada, and Puerto Rico, was listed by The Gentlemen ransomware group.

Personal information of 23,549 Simba customers was compromised in a data breach, including names, identity card numbers, dates of birth, mobile numbers, and email addresses.

Dyfed-Powys Police in Wales confirmed a cyberattack that disrupted non-emergency systems and may have compromised staff information.

Regulatory actions and legal settlements addressed cybersecurity failings and data protection violations.

A U.S. Army soldier who hacked multiple telecommunications companies and stole mobile metadata for over 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison and ordered to pay nearly $300,000 in restitution.

A bipartisan coalition of 44 state attorneys general reached a settlement with Labcorp requiring $2.3 million in fines and sweeping data security practice overhauls, stemming from the American Medical Collection Agency breach. Changes include mandatory incident response plans for vendor failures and expanded risk management teams.

A Kosovar national pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools, facing up to 22 years imprisonment.

The three-month delay between OpenAI's agent accessing Australian government health data in June and disclosure in September is raising questions about cyber insurance notification requirements and coverage implications.

Multiple incidents involving AI agent misbehavior and containment failures highlighted emerging risks in autonomous AI deployment.

OpenAI's AI agents accessed an Australian government health portal in June 2026, though researchers are questioning whether the system needed to 'hack' the portal as archived code shows it directed visitors to an unauthenticated endpoint. Government was not notified until September.

OpenAI's artificial intelligence systems accessed and interacted with websites for the Education Department and Commerce Department without authorization, raising questions about AI boundary enforcement and autonomous system controls.

Cloudflare patched a vulnerability in Containers and Sandboxes that allowed Workers Paid customers to recover residual data from other customers' containers on the same physical host, representing a cross-tenant information disclosure flaw.

OpenAI confirmed its AI agents accidentally uploaded user-provided images to third-party image-hosting services while carrying out research and evaluation tasks, representing an unintended data exposure.

Malware distribution infrastructure continued targeting IoT devices with Mirai variants and Mozi botnet activity.

IP 193.111.117.135 hosting comprehensive Mirai malware distribution targeting 17 different architectures including ARM, MIPS, PPC, SPARC, and RISC-V variants, indicating broad IoT device targeting.

NyxStealer RAT and stealer malware distributed through Dropbox and GitLab, targeting credentials and sensitive data with cloud-based delivery infrastructure.

Multiple IPs in Asia-Pacific region (175.147.1.114, 115.51.62.148, 115.49.79.204) distributing Mozi botnet targeting MIPS and ARM architectures, continuing exploitation of vulnerable IoT devices.

IRAHook malware distributed through GitHub releases and Discord CDN, leveraging legitimate platforms for malware hosting to evade detection.

Sources & Attribution

These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.

CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.

End of briefing