Today: Two Citrix NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772 (both CVSS 9.5), are under mass exploitation, and the CISA KEV remediation deadline is today, September 30. Mandiant says to check appliances for web shells before patching, because patching does not evict an attacker already on the box. Apple also patched CVE-2026-86950, a CoreGraphics zero-day, in iOS 26.7.1 and iPadOS 26.7.1.
Citrix NetScaler ADC and Gateway Zero-Days (CVE-2026-88771, CVE-2026-88772)
Summary: Citrix disclosed eight CVEs on September 27, two of them actively exploited zero-days. CVE-2026-88771 is an unauthenticated RCE from improper input validation. CVE-2026-88772 is a DTLS memory overflow in the NetScaler Packet Processing Engine (NSPPE) that gives pre-auth root code execution and affects default VPN virtual server configurations. Both are CISA KEV entries with a September 30 due date. Mandiant dates the earliest CVE-2026-88772 exploitation to September 3 and knows of dozens of impacted organizations. Victims are in government, financial services, education, telecom, legal and professional services across North America and Europe. Mandiant attributes the activity to suspected state-sponsored actors and expects broad opportunistic exploitation next. watchTowr has published technical writeups, a PoC for CVE-2026-88771, and a detection artifact generator.
Post-exploitation tooling is new. A PHP web shell called WHIPSHOT hides Base64 C2 commands in HTTP headers. SLAPSHOT is a Python TCP tunneler that proxies traffic into internal networks for reconnaissance and credential theft. The installer edits httpd.conf so .deb files are handled as PHP. Web shells are staged under /netscaler/gui/vpn/scripts/linux. A second hook maps requests ending in .ico under /vpn/media/ to a matching .sig PHP file in /var/netscaler/gui/vpn/scripts/linux/. The actor also alters permissions on /bin/sh and reboots the appliance for persistence.
Apple CoreGraphics Zero-Day (CVE-2026-86950)
Summary: An out-of-bounds write in CoreGraphics (CVSS 8.8) allows arbitrary code execution when a crafted file is processed. Apple says it was used in an "extremely sophisticated attack against specific targeted individuals" on iOS versions before iOS 27. Meta Product Security reported it. It is the seventh Apple zero-day fixed this year. CISA added it to KEV, with a three-day deadline and a forensic triage requirement by October 2 for federal agencies under BOD 26-04. macOS Tahoe and Sequoia received the same fix. Exposure for most SMBs is low, but executives and other high-risk users should update now.
1 claim tracked across 1 group in the last 48 hours. These are unverified claims from leak sites, not confirmed breaches.
| Group | Victim | Sector | Country |
|---|---|---|---|
| Ulose | www.newyjh.com | Healthcare (hospital) | South Korea |
Source: RansomLook
ATNS Air Traffic Control OT Network (South Africa)
Summary: Air Traffic and Navigation Services found malware commonly associated with early-stage ransomware in an OT network supporting weather services at Port Elizabeth Airport. Documents also cite data exfiltration to IP addresses in China and a possible insider data theft at Maputo International Airport. Internal teams contained the activity, and the company issued an RFQ for forensic investigators starting September 18.
ShinyHunters Arrest and FBI Data Breach
Summary: Dutch police arrested a 24-year-old Amsterdam man on September 15 on suspicion of playing a role in ShinyHunters. He was charged with attempted incitement to commit two murders, a count separate from the ShinyHunters investigation. The FBI called him an alleged leader, but Dutch investigators say his role is still being investigated. Separately, the ShinyHunters-linked hackers who stole data on all FBI employees and applicants told 404 Media they will not publish it.
108ef7e628d7a20bd6241a5b57149e27a6061f467123eb64061975559f8f73dc, SHA1 f34330d4c6e0aa978dc3af40360c14b31ad51127 (MSP360 v2.5.0.67 installer). Filenames embed the string rmm_v2.5.0.67.Phishing Delivers MSP360 RMM, Then ScreenConnect
Summary: Since July 2026, Microsoft Defender Experts has tracked phishing that delivers a legitimate, signed MSP360 installer under deceptive names. Lures include meeting invitations, Zoom, Google Meet and Adobe updates, e-cards, job offers and DHL notices. Payloads were hosted on attacker infrastructure and on Amazon S3, Cloudflare R2, Dropbox, GitLab and Supabase. After UAC elevation, the agent runs PowerShell to install ConnectWise ScreenConnect as a second access channel, then stages credential-access tooling. Microsoft saw no exploitation of ScreenConnect itself.
ChatGPT Custom GPTs Used for ClickFix
Summary: Huntress reports at least 40 infections from a campaign using two malicious Custom GPTs ("Plus 5.6"). Victims reached them through a sponsored Google result for "ChatGPT" and were sent to a Google Sites page with a fake CAPTCHA. The page instructed them to run PowerShell that downloads an MSI, leading to a RAT with DNS-over-HTTPS C2. OpenAI removed the first GPT on September 25, and a second appeared September 27.
Azure DevOps Compromise via Self-Service Password Reset (Storm-3068)
Summary: Microsoft DART describes an intrusion that began with a self-service password reset on one account. The actor registered its own authentication methods, then enumerated Azure DevOps repositories and pipelines. It built a malicious pipeline to harvest kubeconfig files, with access to more than 50 resources, and committed seven stolen kubeconfigs to a repository. The actor also modified pipeline scripts to install the Atera agent and the Chisel tunneling tool for a reverse tunnel to an external IP.
Bitget and Belnet Breaches via Zero-Days
Summary: Risky Bulletin reports attackers exploited a zero-day in a third-party security product to breach Bitget, extract admin credentials, pivot internally and steal $388 million. Separately, a zero-day was used to breach Belgian ISP Belnet and steal email inboxes between July 22 and September 25. Both fit the broader edge-device pattern.
Star Blizzard RedFlick Technique
Summary: The Russian FSB-linked actor Star Blizzard has moved from targeted spear phishing to large-scale phishing and accounts on compromised websites. A new delivery technique, RedFlick, uses scheduled tasks to install the CosmicPulse backdoor with a single user action, replacing the earlier multi-step ClickFix chain. Microsoft counts over 100 affected organizations, mostly in the US and UK, among Ukraine-supporting NGOs, think tanks, governments and financial institutions.
Word 2609 Saves PDFs to the Wrong Location
Summary: After Word for Windows version 2609, using Save As PDF to a SharePoint Online location silently writes the file to the local INetCache\Content.MSO folder with a random name and no error. Microsoft says Export, or saving elsewhere, works. Rolling back the update also resolves it, and Microsoft has given no fix timeline. This is a data-loss risk for staff who believe they saved to SharePoint. The September Windows update also still has open problems with audio and domain-joined devices.
French Tax Administration Data Theft
Summary: ANSSI reports that stolen staff passwords, likely harvested by infostealers from unmanaged devices, allowed theft of data on about 350,000 individuals and 250,000 businesses in June and July. The attacker reached the portals with a password alone, and sensitive applications were not segmented from the wider government network. A second route used a compromised land surveyor's computer to bypass an email one-time code. Detection failed because the SOC's routine was to reset compromised passwords without checking what the account had accessed. The theft was found only when the attacker claimed it on a forum on August 12.
Spectre-v2 BTR Attack
Summary: Researchers from VUSec and Scuola Superiore Sant'Anna disclosed Branch Target Reuse, a Spectre v2 variant affecting JIT engines (SpiderMonkey, GraalVM, the Linux kernel cBPF JIT). Two kernel exploits leaked a root password hash within minutes from a fully patched Intel system with default protections. An attacker must be able to run unprivileged code in the JIT engine. No fix guidance appears in the article text.
Sanctions Force CA Revocations in Russia and Iran
Summary: US Treasury sanctions issued in May have led CAs to revoke or refuse TLS certificates for government and critical-sector entities in Russia and Iran. Banks switched to state-run or Chinese CAs. Consumers on Western operating systems and browsers do not trust those CAs.
OpenSSL DTLS Heap Leak (CVE-2026-84782)
Summary: A DTLS handshake resend that fires while a larger message is paused mid-send can send leftover heap bytes unencrypted to the peer, or crash the process. OpenSSL rates it High, and CISA scored it CVSS 8.2. No exploitation has been reported. It is fixed in OpenSSL 4.0.3, 3.6.5, 3.5.9 and 3.4.8. The 3.0 fix is paid-support only, but Ubuntu 22.04 and 24.04 have patched packages (libssl3 3.0.2-0ubuntu1.30 and libssl3t64 3.0.13-0ubuntu3.16). Debian 13 is fixed under DSA-6531-1, and Debian 12 was still listed vulnerable this morning. The flaw matters only to software that uses OpenSSL for DTLS, such as WebRTC and VPN components.
MikroTik RouterOS (CVE-2026-84411)
Summary: An integer underflow in HTTP request body handling in the web management service is reachable before authentication. A single crafted request can give root code execution or a denial of service. The advisory lists versions before 7.24 as affected and recommends updating to 7.23 or later. CISA reports no known exploitation.
VIVOTEK Camera Firmware (CVE-2026-22755)
Summary: A command injection in firmware shared by dozens of V, S, C, Dome, Panoramic and Bullet models can give remote command execution, potentially as root. CISA found a public PoC and reported it to the vendor. VIVOTEK has a firmware fix.
Other CISA ICS Advisories
Edge appliances are the main access path this week. The Citrix zero-days were exploited for weeks before disclosure, and Bitget and Belnet were also breached through zero-days. Mandiant notes that most edge devices cannot run EDR, which is why attackers favor them. Attackers are also leaning on trusted tooling instead of exploits. The MSP360 and ScreenConnect abuse, Atera and Chisel in Azure DevOps, and Custom GPT lures all use legitimate software or services, so allowlisting and identity controls matter more than signatures. The French tax breach shows the same lesson for credentials: stolen passwords without MFA or activity review were enough.