Weekly briefing: September 28 to October 4, 2026

CISA says attackers are actively exploiting two Citrix NetScaler flaws globally, and Citrix released patches for the critical NetScaler vulnerabilities tracked as CVE-2026-88771 and CVE-2026-88772. Cisco released security updates for a critical Catalyst SD-WAN Manager zero-day tracked as CVE-2026-76504 that attackers are actively exploiting to escalate to administrative privileges. Fortinet warned customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks. An international law enforcement operation seized the KillSec ransomware gang's data leak site and servers, arrested three suspects, and identified a 16-year-old as the alleged administrator.

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

Citrix patched eight critical and high-severity vulnerabilities in NetScaler ADC and NetScaler Gateway, including CVE-2026-88771 and CVE-2026-88772, which have been exploited in zero-day attacks. Cybersecurity firms reported attackers exploited the CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks.

Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

Apple released iOS and macOS updates to patch an actively exploited zero-day vulnerability tracked as CVE-2026-86950 in the Core Graphics framework. Apple stated it is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

Cisco warns of new SD-WAN zero-day exploited in attacks

Cisco released security updates to address CVE-2026-76504 in the Catalyst SD-WAN Manager, which attackers are exploiting to access APIs as admin without credentials. CISA added CVE-2026-76504 to its Known Exploited Vulnerabilities catalog on September 30, 2026, based on evidence of active exploitation.

Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

Fortinet warned customers that attackers are exploiting CVE-2026-104286, a critical zero-day path traversal vulnerability in FortiMail, to execute unauthorized code or commands. Fortinet urged customers to apply a shared workaround until fixes are available, and CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on October 1, 2026.

Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign

Dutch police confirmed that a 24-year-old Amsterdam man was arrested as part of an investigation into the ShinyHunters hacking group. ShinyHunters told The Register they leveraged an unconfirmed Oracle PeopleSoft zero-day vulnerability to breach FBI job portals, while the agency confirmed investigating claims of compromised employee personal data.

16-year-old suspected leader of KillSec ransomware group arrested

Operation KillSwitch seized the KillSec ransomware gang's data leak site and servers, leading to three arrests and the identification of a 16-year-old as the group's alleged administrator. Eurojust stated that KillSec has been active since 2024 and is responsible for almost 1,000 attacks worldwide.

Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

Star Blizzard launched phishing campaigns using fake event invites and a novel malware delivery technique dubbed RedFlick to deploy the CosmicPulse backdoor on Windows systems. Microsoft says the cyberespionage campaign has hit U.S. and U.K. targets, relying on sheer volume and requiring only a single victim interaction.

GitLab warns of critical RCE vulnerability in AI Gateway service

GitLab warned customers to patch a critical AI Gateway vulnerability tracked as CVE-2026-90970 that could let logged-in Duo Agent Platform users run commands on self-hosted gateways. CERT-FR reported that GitLab disclosed CVE-2026-85706 is being actively exploited.

Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

Attackers exploited CVE-2026-73570 in Zimbra to deploy web shells and access mailbox data on servers with SNMP notifications enabled. Under certain conditions, CVE-2026-73570 can be exploited via specially crafted emails without user interaction to remotely inject OS commands.

Pentagon Personnel Agency Data Breach Impacts 3 Million People

The Pentagon's Defense Manpower Data Center is notifying millions of people that hackers accessed their personal data after breaching the human resources management system in October 2025. A Defense Department official told CNN that the breach affects 2.76 million living individuals and 294,000 deceased individuals.

Hackers Use ChatGPT Custom GPTs in ClickFix Attacks

Attackers abused custom variants of ChatGPT promoted in sponsored Google results to direct users to malicious sites deploying ClickFix attacks. The personalized versions of ChatGPT impersonated legitimate products and tricked users into executing PowerShell commands to deliver a RAT, infecting at least 40 users.

Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware framework used in targeted intrusions to maintain long-term access. Microsoft observed a China-based actor using the malware in intrusions against telcos, universities, medical, and government organizations.

Written by a language model from the linked articles only. Each sentence cites its sources and was checked against them, mechanically and by a model; sentences that failed either check were removed.