Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Weekly Cybersecurity Briefing (21 September – 27 September 2026)
Published: Loading…
This briefing covers 288 reports published from 21 September to 27 September 2026.
At a Glance
- Citrix disclosed eight NetScaler vulnerabilities and confirmed exploitation of two critical flaws, CVE-2026-88771 and CVE-2026-88772, after watchTowr reported unpatched zero-days.
- ShinyHunters resumed mass exploitation of Oracle PeopleSoft flaw CVE-2026-35273 by URL-encoding the PSEMHUB path to bypass web application firewall rules.
- ShinyHunters also hijacked Cl0p's dark web leak site and posted an eight-figure extortion demand aimed at the ransomware gang.
- Suspected North Korean actors stole $351.6 million from Bitget, and the exchange later raised its estimated loss to $387.5 million.
- Exploited flaws hit F5 BIG-IP APM, Check Point gateways, WordPress core and Microsoft SharePoint, with CISA adding SharePoint and MikroTik RouterOS bugs to its KEV catalogue.
Editorial Analysis
ShinyHunters appeared in several of this week's stories, and the surrounding reporting shows how little the ransomware brand itself tells us about an extortion operation. The group renewed mass exploitation of Oracle PeopleSoft CVE-2026-35273, seized Cl0p's leak site with an eight-figure demand tied to the gang's Oracle E-Business Suite campaign, and claimed a breach of FBI Jobs, which the FBI says it is investigating. Elsewhere, encryption became optional. PAYLOAD disrupted a Middle Eastern manufacturer through a malicious Group Policy Object without running a ransomware binary on Windows machines. The new n0n group threatens to destroy backups and shadow copies after gaining access with infostealer credentials, and claimed 13 victims in its first week. Microsoft's Storm-2570 research found one affiliate deploying Qilin, DragonForce, Anubis and BERT while reusing MeshAgent, ntdsutil, s5cmd and Rclone. The tools and branding change between incidents, while access, credential theft and exfiltration remain central to the operations.
Several exploited weaknesses this week had been public for months. The PeopleSoft flaw was a zero-day between 27 May and 9 June, Oracle patched it on 10 June, and the September campaign targeted organisations that had added WAF rules but had not applied the patch. ASEC reported attacks on unpatched Korean IIS servers through CVE-2019-18935, while the Mini Shai-Hulud worm continued spreading through the hijacked actions-cool/issues-helper GitHub Action, which had gone unaddressed for four months. Six more repositories were infected between 20 and 24 September through routine workflows.
Cryptocurrency theft ran at two very different scales. Bitget lost $351.6 million in a single backend compromise attributed to suspected North Korean actors, with Arkham tracing roughly $228 million leaving in 18 minutes. The Contagious Interview campaign works through individual developers instead, using fake recruiters to reach more than 30,000 devices and more than 7,000 wallets, and now targeting Rust crates.io maintainers. The criminal cases resolved this week moved much more slowly. Vardanyan was sentenced for Ryuk-related access work from 2019 and 2020, while Wagenius received 70 months for the AT&T and Verizon extortion, in both cases years after the underlying intrusions.
Highlights of the Week
Citrix Patches Eight NetScaler Flaws, Two Exploited in the Wild
Citrix disclosed eight NetScaler ADC and Gateway vulnerabilities on 27 September, confirming exploitation of CVE-2026-88771, an unauthenticated remote code execution flaw affecting default configurations, and CVE-2026-88772, a DTLS memory overflow, both scoring 9.5 on CVSS v4.0. watchTowr had reported the zero-days a day earlier, and some administrators took appliances offline. Fixes are available in builds 14.1-73.37 and 13.1-64.23.
ShinyHunters Bypasses WAF Rules to Exploit Oracle PeopleSoft Flaw
Mandiant and Google Threat Intelligence Group reported renewed mass exploitation of Oracle PeopleSoft flaw CVE-2026-35273 by ShinyHunters, tracked as UNC6240. The group bypasses web application firewall rules by URL-encoding one character of the PSEMHUB path and has deployed web shells on dozens of systems across education, technology, healthcare and government. Follow-on tools include the SIDEEYE backdoor and the Neo-reGeorg tunnelling toolkit.
North Korean Hackers Steal $351.6M From Bitget
Bitget confirmed suspected North Korean actors stole $351.6 million from hot and warm wallets on 24 September. Attackers compromised backend wallet infrastructure, spoofed transaction data and triggered the authorisation process to move funds across Ethereum, XRP Ledger, Arbitrum, Optimism, BSC and Base. The exchange later raised its loss estimate to $387.5 million after identifying additional stolen assets on Zcash and TRON.
WordPress Core Flaws Enable Admin Takeover and Remote Code Execution
WordPress patched CVE-2026-93485, an unauthenticated stored cross-site scripting flaw in core comment handling that can be chained to remote code execution, and CVE-2026-87902, a path traversal flaw allowing inclusion of arbitrary local PHP files. Attacks on CVE-2026-87902 began within hours of the 22 September release. Fixes arrived in versions 7.1.1 and 7.1.2, backported as far as 4.7.
Threats
ShinyHunters Hijacks Cl0p Ransomware Gang's Leak Site
ShinyHunters seized Cl0p's dark web leak site and defaced it with an eight-figure demand tied to the gang's Oracle E-Business Suite campaign. Cl0p later restored a message asking ShinyHunters to make contact through another platform.
North Korean Contagious Interview Campaign Targets Rust Developers
The Rust Project warned that Contagious Interview operators are posing as recruiters to target crates.io maintainers with malware. Authorities report over 30,000 infected devices and credentials stolen from more than 7,000 cryptocurrency wallets since December 2025.
Ransomware Affiliate Storm-2570 Reuses Toolset Across Brands
Microsoft tracked ransomware affiliate Storm-2570 deploying Qilin, DragonForce, Anubis and BERT payloads while reusing MeshAgent, ntdsutil, s5cmd and Rclone. The actor has been active since April 2025 and affected healthcare, government and financial organisations.
Infrastructure & Exploits
F5 Patches Actively Exploited BIG-IP APM Zero-Day
F5 disclosed CVE-2026-94127, a heap-based buffer overflow in BIG-IP APM configured as an OAuth Authorisation Server that allows unauthenticated remote code execution. F5 confirmed in-the-wild exploitation and released engineering hotfixes for affected branches.
Check Point Firewalls and Management Servers Under Active Attack
Check Point confirmed exploitation of CVE-2026-85102, a pre-authentication RCE in Security Gateway VPN certificate handling, since 12 September. It also disclosed zero-day CVE-2026-93616, a Security Management path traversal flaw, with fixes available for both.
CISA Adds Exploited SharePoint and MikroTik RouterOS Flaws to KEV Catalogue
CISA added Microsoft SharePoint flaw CVE-2026-65660 and MikroTik RouterOS flaw CVE-2026-67279 to its Known Exploited Vulnerabilities Catalogue on evidence of active exploitation. Federal agencies had a patching deadline of 28 September for the SharePoint flaw.
Tools & Techniques
First Malware Using AI Models as Command and Control
Cisco Talos disclosed CLOSEDQUORUM, a Windows implant in which four commercial large language model providers vote on actions such as credential theft, process injection or persistence. The majority choice executes automatically, and stolen data leaves through an encrypted Discord webhook.
Lunex Stealer Uses Vulnerable AMD Driver to Blind Security Tools
Ontinue analysed a Lunex campaign that uses AMD's PDFWKRNL.sys driver to zero the kernel callbacks of 20 listed security drivers before deploying a browser and wallet stealer. It also registers a Chrome Native Messaging Host that survives deletion of the stealer.
PAYLOAD Ransomware Disrupts Systems Through Group Policy
Kaspersky investigated an April 2026 attack on a Middle East manufacturer in which actors with domain admin access created a malicious Group Policy Object that delivered ransom notes and disabled the local administrator account. No ransomware binary ran on Windows machines.
Policy & Legal
Ryuk Ransomware Access Broker Sentenced to 24 Months
Karen Serobovich Vardanyan, extradited from Ukraine, was sentenced to 24 months in prison for gaining network access used in Ryuk ransomware attacks between March 2019 and June 2020. Prosecutors said he and co-conspirators received about 1,610 bitcoins in ransom payments.
US Soldier Sentenced to 70 Months for AT&T and Verizon Extortion
Cameron Wagenius, known as "Kiberphant0m", was sentenced to 70 months in prison and ordered to pay $294,978 in restitution. He stole call and text metadata for over 100 million AT&T customers using exposed Snowflake credentials and extorted the victims.
Weekly Topic Distribution

Weekly Coverage
Developments
Citrix Netscaler Zero-Days Shinyhunters Peoplesoft Campaign Cl0P Leak Site Hijack Bitget Hack
Vulnerabilities
CVE-2026-35273Peoplesoft Enterprise Peopletools 8.61 (Critical)CVE-2026-88771Adc (Critical)CVE-2026-88772Adc (Critical)CVE-2026-87902Wordpress (High)CVE-2019-18935N/A N/A (Critical)CVE-2026-93485Wordpress 7.1 (High)CVE-2026-94127Big-Ip 21.1.0 (Critical)CVE-2026-85102Quantum Security Gateway R82.10 With Jumbo Hotfix Take 43 Or Below (Critical)CVE-2026-93616Quantum Security Management R82.20 With No Jumbo Hotfix (Critical)CVE-2026-65660Microsoft Sharepoint Enterprise Server 2016 16.0.0 (High)
Threat Groups
Scattered SpiderScattered Spider is a native Englishspeaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. Scattered Spider relies heavily on social engineering, including impersonating IT and helpdesk staff, to gain initial access, bypass multifactor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. Scattered Spider had expanded into hybrid cloud and identity environments, using helpdesk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.AkiraAkira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access singlefactor external access mechanisms such as VPNs for initial access, then various publiclyavailable tools and techniques for lateral movement. Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.LAPSUS$LAPSUS$ is cyber criminal threat group that has been active since at least mid2021. LAPSUS$ specializes in largescale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.APT28APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U. S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including closeaccess operations) conducted between 2014 and 2018 against the World AntiDoping Agency (WADA), the US AntiDoping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.CHROMIUMEarth Lusca is a suspected Chinabased cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.Salt TyphoonSalt Typhoon is a People's Republic of China (PRC) statebacked actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at major U. S. telecommunication and internet service providers (ISP).MuddyWaterMuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, defense, and oil and natural gas organizations, in the Middle East, Asia, Africa, Europe, and North America.Contagious InterviewContagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrencyrelated activities.Lazarus GroupLazarus Group is a North Korean statesponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.