Weekly briefing: September 28 to October 4, 2026
CISA says attackers are actively exploiting two Citrix NetScaler flaws globally, and Citrix released patches for the critical NetScaler vulnerabilities tracked as CVE-2026-88771 and CVE-2026-88772. Cisco released security updates for a critical Catalyst SD-WAN Manager zero-day tracked as CVE-2026-76504 that attackers are actively exploiting to escalate to administrative privileges. Fortinet warned customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks. An international law enforcement operation seized the KillSec ransomware gang's data leak site and servers, arrested three suspects, and identified a 16-year-old as the alleged administrator.
CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
Citrix patched eight critical and high-severity vulnerabilities in NetScaler ADC and NetScaler Gateway, including CVE-2026-88771 and CVE-2026-88772, which have been exploited in zero-day attacks. Cybersecurity firms reported attackers exploited the CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks.
- CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally The Hacker News
- Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug SecurityWeek
- Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772) Help Net Security
- Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings CyberScoop
- Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers Dark Reading
- Hackers exploit Citrix NetScaler zero-day to deploy web shells BleepingComputer
- Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances Google Threat Intelligence
- Multiple vulnerabilities in Citrix NetScaler ADC and Gateway CERT-FR
- Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway UK National Cyber Security Centre
- Citrix security advisory (AV26-965) Canadian Centre for Cyber Security
- Multiple Vulnerabilities in NetScaler ADC and NetScaler Gateway Could Allow for Remote Code Execution CIS MS-ISAC
- Multiple vulnerabilities in NetScaler ADC and NetScaler Gateway (CVE-2026-88771, CVE-2026-88772 and others) JPCERT/CC
Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
Apple released iOS and macOS updates to patch an actively exploited zero-day vulnerability tracked as CVE-2026-86950 in the Core Graphics framework. Apple stated it is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
- Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks The Hacker News
- Apple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’ SecurityWeek
- Apple patches CoreGraphics zero-day flaw exploited in attacks BleepingComputer
- Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950) Help Net Security
- Apple Zero-Day Vulnerability Weaponized in Targeted Attacks Dark Reading
- Apple changes full-disk access permissions to curb abuse from AI agents Ars Technica
- Vulnerability in Apple products CERT-FR
- CISA Adds One Known Exploited Vulnerability to Catalog CISA
- Apple security advisory (AV26-971) Canadian Centre for Cyber Security
- A Vulnerability in Apple Products Could Allow for Arbitrary Code Execution CIS MS-ISAC
Cisco warns of new SD-WAN zero-day exploited in attacks
Cisco released security updates to address CVE-2026-76504 in the Catalyst SD-WAN Manager, which attackers are exploiting to access APIs as admin without credentials. CISA added CVE-2026-76504 to its Known Exploited Vulnerabilities catalog on September 30, 2026, based on evidence of active exploitation.
- Cisco warns of new SD-WAN zero-day exploited in attacks BleepingComputer
- Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager The Hacker News
- Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability SecurityWeek
- New Cisco SD-WAN zero-day exploited in-the-wild (CVE-2026-76504) Help Net Security
- Revenge of the SD-WAN: Exploring and Exploiting Yet Another Critical Cisco SD-WAN Vulnerability (CVE-2026-76504) VulnCheck Blog
- CISA Adds One Known Exploited Vulnerability to Catalog CISA
- A Vulnerability in Cisco Catalyst SD-WAN Manager Could Allow for Authentication Bypass CIS MS-ISAC
- Vulnerability in Cisco Catalyst SD-WAN CERT-FR
- Cisco security advisory (AV26-978) Canadian Centre for Cyber Security
Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
Fortinet warned customers that attackers are exploiting CVE-2026-104286, a critical zero-day path traversal vulnerability in FortiMail, to execute unauthorized code or commands. Fortinet urged customers to apply a shared workaround until fixes are available, and CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on October 1, 2026.
- Fortinet warns of critical FortiMail flaw exploited in zero-day attacks BleepingComputer
- Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes The Hacker News
- Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action SecurityWeek
- Critical FortiMail zero-day exploited in the wild (CVE-2026-104286) Help Net Security
- CISA Adds One Known Exploited Vulnerability to Catalog CISA
- Vulnerability in Fortinet FortiMail CERT-FR
- Fortinet security advisory (AV26-989) Canadian Centre for Cyber Security
- A Vulnerability in Fortinet FortiMail Could Allow for Arbitrary Code Execution CIS MS-ISAC
Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
Dutch police confirmed that a 24-year-old Amsterdam man was arrested as part of an investigation into the ShinyHunters hacking group. ShinyHunters told The Register they leveraged an unconfirmed Oracle PeopleSoft zero-day vulnerability to breach FBI job portals, while the agency confirmed investigating claims of compromised employee personal data.
- Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign SecurityWeek
- FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day Help Net Security
- ShinyHunters trades financial extortion for a reckless war of ego with the FBI CyberScoop
- Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation Krebs on Security
- Dutch police confirm arrest in ShinyHunters hacking investigation BleepingComputer
- Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation The Hacker News
16-year-old suspected leader of KillSec ransomware group arrested
Operation KillSwitch seized the KillSec ransomware gang's data leak site and servers, leading to three arrests and the identification of a 16-year-old as the group's alleged administrator. Eurojust stated that KillSec has been active since 2024 and is responsible for almost 1,000 attacks worldwide.
- 16-year-old suspected leader of KillSec ransomware group arrested Help Net Security
- Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader SecurityWeek
- Police dismantle KillSec ransomware gang allegedly led by 16-year-old BleepingComputer
- Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers The Hacker News
- Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members CyberScoop
- Alleged KillSec Ransomware Mastermind a 16-Year-Old Dark Reading
Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor
Star Blizzard launched phishing campaigns using fake event invites and a novel malware delivery technique dubbed RedFlick to deploy the CosmicPulse backdoor on Windows systems. Microsoft says the cyberespionage campaign has hit U.S. and U.K. targets, relying on sheer volume and requiring only a single victim interaction.
- Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor The Hacker News
- Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond CyberScoop
- Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks SecurityWeek
- Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net Dark Reading
- Russian state hackers use new RedFlick technique to push malware BleepingComputer
- Star Blizzard refines phishing and malware delivery with the RedFlick technique Microsoft Threat Intelligence
GitLab warns of critical RCE vulnerability in AI Gateway service
GitLab warned customers to patch a critical AI Gateway vulnerability tracked as CVE-2026-90970 that could let logged-in Duo Agent Platform users run commands on self-hosted gateways. CERT-FR reported that GitLab disclosed CVE-2026-85706 is being actively exploited.
- GitLab warns of critical RCE vulnerability in AI Gateway service BleepingComputer
- GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers The Hacker News
- Multiple vulnerabilities in GitLab CERT-FR
- GitLab security advisory (AV26-994) Canadian Centre for Cyber Security
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
Attackers exploited CVE-2026-73570 in Zimbra to deploy web shells and access mailbox data on servers with SNMP notifications enabled. Under certain conditions, CVE-2026-73570 can be exploited via specially crafted emails without user interaction to remotely inject OS commands.
- Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets The Hacker News
- Attackers have been exploiting critical Zimbra flaw to steal emails Ars Technica
- Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure SecurityWeek
- Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 Microsoft Threat Intelligence
Pentagon Personnel Agency Data Breach Impacts 3 Million People
The Pentagon's Defense Manpower Data Center is notifying millions of people that hackers accessed their personal data after breaching the human resources management system in October 2025. A Defense Department official told CNN that the breach affects 2.76 million living individuals and 294,000 deceased individuals.
- Pentagon Personnel Agency Data Breach Impacts 3 Million People SecurityWeek
- Hackers stole Pentagon personnel records of over 3 million people BleepingComputer
- Pentagon breach exposes personal data of more than 3 million people Help Net Security
- Pentagon breach exposes Social Security numbers and military records of millions Malwarebytes Labs
Hackers Use ChatGPT Custom GPTs in ClickFix Attacks
Attackers abused custom variants of ChatGPT promoted in sponsored Google results to direct users to malicious sites deploying ClickFix attacks. The personalized versions of ChatGPT impersonated legitimate products and tricked users into executing PowerShell commands to deliver a RAT, infecting at least 40 users.
- Hackers Use ChatGPT Custom GPTs in ClickFix Attacks SecurityWeek
- Custom ChatGPTs push ClickFix attacks to deploy RAT malware BleepingComputer
- Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures The Hacker News
- Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure Dark Reading
Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware framework used in targeted intrusions to maintain long-term access. Microsoft observed a China-based actor using the malware in intrusions against telcos, universities, medical, and government organizations.
- Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks The Hacker News
- Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft SecurityWeek
- 'NeedyMantis' Provides Long-Term Access to Compromised Networks Dark Reading
- NeedyMantis: Unpacking a post-compromise malware family used in targeted operations Microsoft Threat Intelligence
Written by a language model from the linked articles only. Each sentence cites its sources and was checked against them, mechanically and by a model; sentences that failed either check were removed.