Daily briefing: Monday, September 28, 2026
CISA says attackers are actively exploiting two Citrix NetScaler flaws globally; Citrix has released patches for the critical NetScaler vulnerabilities tracked as CVE-2026-88771 and CVE-2026-88772. The FBI's online job applicant portals remain unavailable after ShinyHunters said they used an unspecified Oracle PeopleSoft zero-day to breach them, while the group has modified its exploit to target CVE-2026-35273.
CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
Citrix has patched eight critical and high-severity vulnerabilities in NetScaler ADC and NetScaler Gateway, two of which (CVE-2026-88771, CVE-2026-88772) have been exploited in zero-day attacks to plant webshells on compromised devices. CISA added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalog on September 27, 2026.
- CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally The Hacker News
- Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug SecurityWeek
- Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772) Help Net Security
- Multiple vulnerabilities in Citrix NetScaler ADC and Gateway CERT-FR
- Multiple vulnerabilities in NetScaler ADC and NetScaler Gateway (CVE-2026-88771, CVE-2026-88772 and others) JPCERT/CC
- Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway UK National Cyber Security Centre
- Citrix security advisory (AV26-965) Canadian Centre for Cyber Security
- Multiple Vulnerabilities in NetScaler ADC and NetScaler Gateway Could Allow for Remote Code Execution CIS MS-ISAC
Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
The FBI's online job applicant portals remain unavailable after ShinyHunters said they used an unspecified Oracle PeopleSoft zero-day to breach them. ShinyHunters has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273.
- Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign SecurityWeek
- FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day Help Net Security
- ShinyHunters trades financial extortion for a reckless war of ego with the FBI CyberScoop
- Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation Krebs on Security
JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
JADEPUFFER used compromised Azure service principals to delete most targeted storage accounts in an 18-hour intrusion, Microsoft says. The JadePuffer ransomware operator targets Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components.
US soldier gets 70 months in prison for extorting 10 tech, telecom firms
A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024. Cameron John Wagenius, 22, was part of the group that stole data from telecom companies, including AT&T, and from Snowflake customer accounts in 2024.
Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent
Carbonato targets unauthenticated Docker daemons, installs Hermes Agent, and uses Telegram to run operator-directed AI-generated commands. The Carbonato botnet compromises exposed Docker hosts, deploys an AI agent to steal AI API keys, and then spreads to other exposed Docker services.
Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
NeedyMantis maintains long-term access in targeted intrusions using DLL sideloading and HTTPS-to-WebSocket command-and-control. Microsoft Threat Intelligence identified NeedyMantis as a modular post-compromise malware framework used in targeted intrusions that combines custom loaders, encrypted archives, and extensible components.
- Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks The Hacker News
- NeedyMantis: Unpacking a post-compromise malware family used in targeted operations Microsoft Threat Intelligence
Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog
NVIDIA has introduced an open software platform and a hardware-based reference design intended to keep AI agents within limits set by organizations. The Open Agent Safety Platform includes OpenShell, software that controls what an agent can access, and Sentry, a watchdog in the reference design that monitors agent activity from separate hardware.
Written by a language model from the linked articles only. Each sentence cites its sources and was checked against them, mechanically and by a model; sentences that failed either check were removed.