Daily briefing: Monday, September 28, 2026

CISA says attackers are actively exploiting two Citrix NetScaler flaws globally; Citrix has released patches for the critical NetScaler vulnerabilities tracked as CVE-2026-88771 and CVE-2026-88772. The FBI's online job applicant portals remain unavailable after ShinyHunters said they used an unspecified Oracle PeopleSoft zero-day to breach them, while the group has modified its exploit to target CVE-2026-35273.

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

Citrix has patched eight critical and high-severity vulnerabilities in NetScaler ADC and NetScaler Gateway, two of which (CVE-2026-88771, CVE-2026-88772) have been exploited in zero-day attacks to plant webshells on compromised devices. CISA added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalog on September 27, 2026.

Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign

The FBI's online job applicant portals remain unavailable after ShinyHunters said they used an unspecified Oracle PeopleSoft zero-day to breach them. ShinyHunters has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273.

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

JADEPUFFER used compromised Azure service principals to delete most targeted storage accounts in an 18-hour intrusion, Microsoft says. The JadePuffer ransomware operator targets Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components.

US soldier gets 70 months in prison for extorting 10 tech, telecom firms

A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024. Cameron John Wagenius, 22, was part of the group that stole data from telecom companies, including AT&T, and from Snowflake customer accounts in 2024.

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

Carbonato targets unauthenticated Docker daemons, installs Hermes Agent, and uses Telegram to run operator-directed AI-generated commands. The Carbonato botnet compromises exposed Docker hosts, deploys an AI agent to steal AI API keys, and then spreads to other exposed Docker services.

Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

NeedyMantis maintains long-term access in targeted intrusions using DLL sideloading and HTTPS-to-WebSocket command-and-control. Microsoft Threat Intelligence identified NeedyMantis as a modular post-compromise malware framework used in targeted intrusions that combines custom loaders, encrypted archives, and extensible components.

Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog

NVIDIA has introduced an open software platform and a hardware-based reference design intended to keep AI agents within limits set by organizations. The Open Agent Safety Platform includes OpenShell, software that controls what an agent can access, and Sentry, a watchdog in the reference design that monitors agent activity from separate hardware.

Written by a language model from the linked articles only. Each sentence cites its sources and was checked against them, mechanically and by a model; sentences that failed either check were removed.