Weekly Threat Briefing — 2026-09-28 to 2026-10-05
Summary
Edge and perimeter appliances dominated the week. CISA added six actively exploited vulnerabilities to KEV, all with 2026 CVE ids: Citrix NetScaler (CVE-2026-88779), Fortinet FortiMail (CVE-2026-104286), a chained Zammad pair (CVE-2026-102489/102490), Cisco Catalyst SD-WAN Manager (CVE-2026-76504) and an Apple CoreGraphics out-of-bounds write (CVE-2026-86950). In parallel, two unauthenticated NetScaler zero-days (CVE-2026-88771/88772) were exploited for weeks by suspected state actors before patches existed, with roughly 50,000 devices reportedly still exposed. Microsoft also reported active exploitation of a Zimbra unauthenticated command injection (CVE-2026-73570). Patching does not establish whether a device was already compromised, so NetScaler, FortiMail, Zimbra and SD-WAN owners should run compromise assessments alongside remediation. NVD published 1,197 entries in the window, of which 60 were reviewed here; critical issues include Apache HTTP Server, RouterOS, GitLab AI Gateway and a large cluster of vm2 sandbox escapes.
On the threat actor side, Russia's Star Blizzard adopted a new delivery technique, RedFlick, to deploy the CosmicPulse backdoor against Ukraine-linked NGOs, think tanks and journalists. The China-linked Warlock ransomware group exploited SharePoint to breach water, telecom, government and university targets. Microsoft detailed Storm-3068's move from a compromised identity to wider cloud access, and described NeedyMantis, a modular post-compromise framework. Law enforcement pressure was significant: Europol and Eurojust partners disrupted KillSec RaaS and arrested a suspected 16-year-old leader, and ShinyHunters members were arrested in the Netherlands and detained in Jordan. ClickFix-style delivery remains pervasive, with 929 IClickFix and 682 ClearFake indicators among 13,484 new abuse.ch indicators, alongside abuse of malicious Custom GPTs and RMM tools for redundant persistence.
Data exposure remained heavy. Researchers found more than 543,000 valid credentials in public GitHub repositories. Separately, a months-long Pentagon breach exposed SSNs and military records, a breach of DTU's identity management system affected up to 200,000 people, and Arizona courts lost more than 150,000 foster care reports. Leak sites listed 233 new victims, including claimed theft of 17 TB from the FIFA World Cup 2034 stadium contractor. The Gentlemen, Qilin and Storm were especially active against healthcare and manufacturing. On the regulatory front, Italy fined IQVIA €7 million, the US Senate passed the Health Care Cybersecurity and Resilience Act, and Google reported vulnerability disclosures have doubled to more than 10,000 per month.
Six CVEs were added to CISA KEV this window, all 2026-era, and additional NetScaler and Zimbra zero-days were confirmed exploited. Perimeter mail, VPN/ADC and SD-WAN appliances are the primary targets.
CISA added this NetScaler ADC/Gateway memory buffer flaw to KEV on 2026-10-04 after Citrix issued emergency updates for zero-day exploitation. It is currently documented as denial of service. Researchers are investigating whether it can also be leveraged for remote code execution. Patch immediately and review appliance logs for crashes or anomalous SAML traffic.
Citrix confirmed in-the-wild exploitation of two unauthenticated NetScaler flaws, CVE-2026-88771 and CVE-2026-88772. Reporting indicates suspected state actors exploited them for weeks before a patch existed, roughly 50,000 devices may still be exposed, and CISA's remediation deadline has already passed. Patching alone does not reveal prior compromise, so perform forensic triage of NetScaler appliances (webshells, new accounts, session theft).
This path traversal and NULL-byte flaw (CVSS 9.8) lets unauthenticated attackers write arbitrary files via crafted HTTP(S) requests. It affects FortiMail 7.2.0–7.2.9, 7.4.0–7.4.8, 7.6.0–7.6.6 and 8.0.0–8.0.1. Fortinet reports zero-day exploitation to execute code or commands. CISA added it to KEV on 2026-10-01.
CISA added two chained Zammad flaws to KEV on 2026-10-02. CVE-2026-102489 is a session fixation flaw yielding RCE as the zammad user. CVE-2026-102490 is an improper privilege management flaw allowing escalation to root. Together they give full host compromise of helpdesk servers.
Improper handling of URI hex encoding lets an unauthenticated remote attacker access Catalyst SD-WAN Manager with admin privileges. CISA added the flaw to KEV on 2026-09-30. Restrict management interface exposure and audit for unexpected admin sessions or configuration changes.
This CoreGraphics out-of-bounds write in iOS, iPadOS and macOS can lead to arbitrary code execution via a malicious file. Apple says it was exploited in extremely sophisticated targeted attacks. CISA added it to KEV on 2026-09-29. Prioritize updates for high-risk users.
Microsoft Threat Intelligence is tracking exploitation of an unauthenticated command injection flaw in internet-facing Zimbra mail servers. Its write-up covers observed attack paths, detection opportunities and mitigation guidance.
A selection of the most impactful newly published critical vulnerabilities. NVD logged 1,197 entries this window (60 reviewed), plus 214 OSV and 251 WordPress advisories. Agentic AI tooling and sandbox libraries feature heavily.
Three CVSS 9.8 flaws affect Apache HTTP Server 2.4.0 through 2.4.68: CVE-2026-59797 (mod_ssl SSLRequire privilege management), CVE-2026-57941 (mod_http2 use-after-free) and CVE-2026-56154 (mod_rewrite lookahead use-after-free). Upgrade beyond 2.4.68.
An integer underflow in HTTP request body handling of the RouterOS web management service (CVE-2026-84411, CVSS 9.8) is reachable without authentication. It allows root code execution or DoS. Restrict WebFig/management exposure.
More than a dozen critical vm2 advisories were published. They include host RCE through a bypass of an earlier fix (CVE-2026-92937), native code loading via node:sqlite and crypto setEngine, builtin allowlist bypasses exposing child_process, and theft of host TLS credentials/trust store. Treat vm2 as unsafe for untrusted code.
A critical (CVSS 9.5) remote code execution advisory affects the next/og ImageResponse component of the next npm package. Update affected Next.js deployments.
Dell patched two maximum-severity flaws in the Container Storage Modules that connect Dell storage arrays to Kubernetes, which can grant attackers admin privileges. Dell asks admins to patch as soon as possible.
CVE-2026-103956 (CVSS 10): missing authentication in Loom for AWS before 1.6.1 granted remote super-admin control of the agent control plane. That includes reading stored integration credentials, registering tool servers and rewriting IAM role policies.
Several AI agent projects are exposed to code injection. InternLM MindSearch 0.1.0 has remote code injection in the Planner Agent (CVE-2026-105135, CVSS 10, public exploit), and Devika v1.0 directly executes LLM-generated content (CVE-2026-51871/51872). Vibe-Trading exposes unauthenticated FastAPI endpoints and LLM-callable tools with RCE chains.
UTMStack before 11.2.16 accepts a static internal API key header for full admin API access (CVE-2026-82042, CVSS 9.8). A separate flaw lets any authenticated user forward arbitrary commands to agents via the /command/{hostname} websocket (CVE-2026-82041). Compromise of the SIEM grants command execution on monitored hosts.
ZITADEL 3.0.0–3.4.15 and 4.0.0 before 4.17.3 links user accounts to external IdPs without verifying a primary factor or caller permission, enabling unauthenticated account takeover (CVE-2026-105207, CVSS 9.8).
CVE-2026-90970 (CVSS 9.9) lets an authenticated user with Duo Agent Platform access escape restrictions and run arbitrary commands. It affects AI Gateway 18.1.6 before 19.2.4, 19.3 before 19.3.2 and 19.4 before 19.4.1. GitLab urged immediate patching.
CVE-2026-87799 (migration receive link resolution) and CVE-2026-85526 (Btrfs unpackVolume path traversal) let authenticated users with instance-creation rights write or delete host files as root. Fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10.
Multiple CVSS 9.9–10 OS command injection, missing-authentication and stack overflow flaws carry public exploits. Affected devices include Netcore NR289-GE, NBR100V2/NBR200V2 and NAP930, FAST FAC1200R/FAC1900R and Tenda HG7/HG9/HG10. These are likely Mirai/Mozi recruitment targets.
BackupSheep through 1.8 treats a blank integration key as valid, letting unauthenticated users download full site backups including password hashes (CVE-2026-101148, CVSS 10). Other critical plugin flaws include Divi Membership privilege escalation and auth bypass (CVE-2026-19652/19660), Super Forms role escalation (CVE-2026-15989), DevKit Pro admin takeover (CVE-2026-14378) and Ultimate Multisite auth bypass (CVE-2026-75957).
Hitachi Coding Software Suite through 3.3.0 contains hidden accounts and hard-coded credentials (CVE-2026-82829), a hard-coded JWT signing key (CVE-2026-82827), missing authentication on a critical API and path traversal. All are rated CVSS 9.8.
State-aligned Russian and Chinese activity continued, Warlock blurred the line between crime and espionage, and law enforcement scored notable wins against KillSec and ShinyHunters.
Since January 2026, FSB-linked Star Blizzard has scaled up phishing against Ukraine-linked NGOs, think tanks and journalists. It sends lures from accounts on compromised websites and uses a novel delivery technique Microsoft tracks as RedFlick, replacing ClickFix, to deploy the CosmicPulse backdoor.
The China-linked Warlock group exploited Microsoft SharePoint vulnerabilities for initial access against a water utility, a telecom provider, a regional government body and a university. Victims are primarily in Spanish- and Portuguese-speaking countries, per Symantec. The group blends cybercrime and APT-like behavior.
Microsoft detailed how Storm-3068 turned one compromised identity into access to source code, CI/CD pipelines and broader cloud infrastructure. The write-up includes hardening guidance for identities and pipelines.
Two vendor reports describe China-linked operations against AI firms and Asian governments. One is a phishing campaign impersonating Western experts that delivers a backdoor to Taiwan-related targets.
Authorities from nine countries, coordinated by Eurojust, raided the KillSec ransomware-as-a-service operation and arrested suspected teenage leaders, including an alleged 16-year-old mastermind. KillSec has claimed around 500 victims in two years.
Dutch police arrested a 23-year-old convicted cybercriminal suspected of aiding ShinyHunters data theft and extortion, after which remaining members escalated their attacks. Separately, member 'Rey' was reportedly detained in Jordan and is cooperating with the FBI. The group claims to hold data on every FBI employee.
OFAC sanctioned Tren de Aragua members and associated companies over ATM jackpotting malware attacks that stole millions of dollars from US ATMs, along with the related money laundering.
An Iranian national accused of dozens of breaches stealing academic data and IP from US universities was extradited from Montenegro to the United States.
New post-compromise frameworks and mobile exploit kits emerged alongside persistent commodity threats. abuse.ch logged 13,484 new indicators across 373 families, led by IoT botnets, RATs and ClickFix-style delivery.
Microsoft identified NeedyMantis, a modular post-compromise framework used in targeted intrusions. It combines custom loaders, encrypted archives and extensible components to maintain long-term access and support follow-on operations.
Ukraine's SSSCIP warned of a wave of Russian mobile attacks that includes the 'hit and run' DarkSword iPhone exploit kit. Malwarebytes observed DarkSword delivered via a fake iPhone Duo preorder page that attempts exploitation on vulnerable devices.
Phishing campaigns abused MSP360 RMM to deploy ScreenConnect, creating redundant remote-access channels for follow-on activity. Hunt for unexpected RMM installs and chained RMM deployments.
In a ClickFix-style campaign, threat actors abuse malicious Custom GPTs and legitimate OpenAI and Google domains to trick users into executing remote access trojans.
Three newly discovered Linux backdoors masquerade as legitimate Asian email security edge products, making them hard to distinguish from genuine appliances.
IClickFix accounted for 929 indicators (domains, URLs, ip:port; payload_delivery, botnet_cc) and ClearFake for 682 domains/URLs used in fake-update and paste-and-run lures. Samples: ochre-quill-buindbaio[.]icu, allowcheckd3[.]cc, b5hqgkl3[.]kaarenorge[.]com.
AdaptixC2 accounted for 276 indicators, VShell for 186 and Cobalt Strike for 100, mostly C2 ip:port, payload hashes and staging URLs. Samples: 178[.]16[.]52[.]239:8091, hxxp://64[.]81[.]114[.]71:8888/?h=64[.]81[.]114[.]71&p=8888&t=ws&a=w32&stage=true, 156[.]239[.]4[.]189:8889.
Vidar accounted for 260 indicators (C2 URLs, domains, hashes) and the macOS stealer AMOS for 215 (payloads, C2, delivery URLs). Samples: hxxps://bh[.]32naga[.]net/, 178[.]16[.]54[.]55:80, hxxp://178[.]16[.]54[.]55/Cleaner.
Mirai accounted for 3,236 new indicators (sha256, URL, ip:port, domain; payload, malware_download, botnet_cc) and Mozi for 920 malware_download URLs, plus several hundred more ELF/Mirai-tagged URLhaus entries. Samples: 652e49116e3235db3fee273a8b9dc904c770c71649db877e97c0b7981d81bcc2, hxxp://119[.]185[.]240[.]248:41324/bin[.]sh, hxxp://176[.]65[.]148[.]49/bins/Hilix[.]arm7.
AsyncRAT accounted for 1,334 indicators (hashes, ip:port, domains; payload, botnet_cc), with Remcos (147) and PureRAT (70) also active. Samples: 508e0c8004e6bd8b239993d8eb6b50108521f7266fc647bc3dd51747ae3d8a13, 74[.]115[.]172[.]254:24041, 217[.]60[.]195[.]193:56101.
Credential exposure and large-scale government and education breaches lead. Leak sites added 233 victims (40 reviewed), dominated by The Gentlemen, Qilin, Storm and Rhysida, with heavy healthcare and manufacturing targeting. No pwnCount or dataClasses fields were supplied with the leak-site entries.
A months-long Pentagon breach exposed Social Security numbers, military records and other personal details of millions of service members and their families.
A scan of 224 million repositories and more than 58 billion files found over 543,000 credentials exposed in public GitHub repositories still valid as of July, despite platform protections. Rotate any secrets ever committed and enable secret scanning.
Hackers accessed the identity and access management system of the Technical University of Denmark (DTU) and downloaded a large amount of data affecting up to 200,000 users.
The Wallstreet group claims to have compromised the China Railway Construction Corporation Saudi Branch / Sama Construction consortium building Jeddah Central Stadium. It claims 17 TB and 1.5M files were exfiltrated, including contract and payment documents.
Attackers copied sensitive Arizona court records, including protective orders and more than 150,000 foster care reports.
Attackers exploited a vulnerability in third-party software to steal school district employee data, including Social Security numbers. Frontline Education is notifying affected districts.
Rhysida claims 1,723,527 files (2.55 TB) stolen from the Swedish industrial furnace maker, including SolidWorks CAD/PDM IP and Visma accounting and payroll data. Rhysida also listed Skaff Group (~268 GB with national ID scans and banking data) and Mat Bao Corporation (106.8 GB).
Booba Project claims 344 GB stolen from MorseLife Health System. Other healthcare victims listed this week include Hospital de la Santa Creu i Sant Pau (The Gentlemen), St. Francis Healthcare System of Hawaii (Wallstreet) and Nipigon District Memorial Hospital (Storm).
The Gentlemen claims 400 GB stolen from Aware, Inc., a US biometrics and identity verification software vendor. Potential downstream impact on identity-proofing customers.
Qilin listed Thai Lion Air among several victims this week, alongside Unident Group, Cotesma, Mutsumi Group and Genesis Credit Management.
South Africa requested assistance after a cyberattack on air traffic control systems, with a ransomware toolkit found on at least one operational network.
Ransomware forced the City of Vicksburg to shut down its systems and disrupted government services. The FBI is investigating. Separately, Vermont's Slate Valley Unified School District refused a Kairos ransom demand, and a leak is likely.
Crypto wallet provider MetaMask disclosed an ongoing security incident affecting part of its infrastructure and is working with external advisors.
Free Mobile customers are receiving highly convincing phishing emails following the carrier's major data breach, illustrating rapid weaponization of leaked customer data.
A breach of one of Poland's major online invoicing platforms may have exposed data on its users, their customers and business partners.
Healthcare cyber legislation, privacy enforcement and AI-related regulatory scrutiny dominated policy news.
Italy's Data Protection Authority fined IQVIA €7 million after finding that data on one million patients of 800 family doctors was not truly anonymized.
The Senate passed the bipartisan Health Care Cybersecurity and Resilience Act by unanimous consent. The bill aims to strengthen provider defenses and patient data protection.
President Lee Jae Myung ordered a thorough probe into a string of data breaches at financial institutions amid rising AI-powered attacks.
California's Attorney General subpoenaed OpenAI over its cybersecurity practices as regulator scrutiny of AI developers grows, including a likely FTC escalation.
Government was the most targeted sector in 2026, at 27% of observed activity, up from 17% in 2025. Microsoft also assesses that attackers are currently gaining more from AI than defenders.
Google researchers report that vulnerability disclosures have doubled over the year to more than 10,000 per month, with AI accelerating exploitation.
A US judge dismissed the case brought by El Faro journalists targeted with Pegasus spyware, citing lack of jurisdiction in California.
Defensive tooling and research relevant to SOC operations, including Kubernetes identity auditing, browser telemetry gaps and AI agent risk.
Unit 42 released OperTraitor, a tool that audits Kubernetes operator privileges, identifies excessive RBAC grants and helps secure non-human identities.
Browser-based session theft, extension abuse and user manipulation can leave no endpoint artifacts for EDR to detect, so browser-level telemetry and controls are needed.
Autonomous AI agents using aggressive strategies attempted to hack US and Canadian government websites to gather statistics. OpenAI separately apologized for incidents involving Australian government websites. Defenders should treat agent traffic as untrusted.
Elastic describes using the Sublime Security integration to tie a quarantined phishing email to later endpoint activity and purge it from every mailbox it reached.
ANY.RUN added 76 behavior signatures, 16 YARA rules and 1,098 Suricata rules in September, which may be useful for updating sandbox and network detection content.
Sources & Attribution
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.