Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Weekly Cybersecurity Briefing (28 September – 4 October 2026)
Published: Loading…
This briefing covers 269 reports published from 28 September to 4 October 2026.
At a Glance
- Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 were exploited for weeks before disclosure, and CISA added both to its Known Exploited Vulnerabilities Catalogue.
- Cisco SD-WAN vManage flaw CVE-2026-76504 lets attackers bypass authentication with one request, and Cisco confirmed it was exploited as a zero-day.
- ShinyHunters breached the FBI jobs portal through Oracle PeopleSoft flaw CVE-2026-35273, while two alleged members were detained in the Netherlands and Jordan.
- A Defense Manpower Data Center breach exposed Social Security numbers of nearly 2.8 million living individuals and 294,000 deceased people with military ties.
- Horizon3's Mythos model found Rejetto HFS flaw CVE-2026-61500, which VulnCheck saw exploited within a day of disclosure.
Editorial Analysis
Citrix NetScaler, Zimbra and Cisco SD-WAN vManage were all being exploited before defenders had public notice of the vulnerabilities. Mandiant places the start of NetScaler exploitation in early September, about three weeks before Citrix published its advisory, while GreyNoise recorded attempts against a NetScaler Gateway three days before the bulletin. Microsoft's timeline puts Zimbra exploitation between the 20 July fix and the 13 August disclosure. Cisco's incident responders discovered the vManage exploitation while investigating a routine support case. The subsequent activity also provided a clearer view of how compromised systems were being used, including WHIPSHOT and SLAPSHOT, which Mandiant found disguised as .deb and .sig files.
Several of the week's attacks also depended on small differences in how security controls and applications interpret the same request. The PeopleSoft attack on the FBI jobs portal used /%50SEMHUB/ to bypass a WAF rule matching /PSEMHUB/, while Cisco vManage had a similar mismatch between its login module and application server over URL decoding. The PeopleSoft victims had added WAF rules without applying Oracle's June patch, leaving the control in place while the vulnerable code remained reachable. In vManage, a single percent-encoded character was enough to bypass authentication.
Enforcement against ShinyHunters accelerated during the week without bringing the group's activity to an immediate halt. Dutch police arrested Pepijn van der Stap on 15 September, the FBI publicly urged remaining members to surrender, and Reuters reported that Saif al-Din Khader, known as Rey, was detained in Jordan and is cooperating with investigators. During the same period, ShinyHunters claimed the FBI jobs breach and escalated its activity to medical records under reportedly more aggressive leadership. Khader's identity and alleged role had been public for more than a year, and Krebs reported last year that he had claimed to have stopped and was cooperating. The group's dark-web site has been offline since Wednesday, but its operators have told Reuters they want no further escalation with the FBI.
Highlights of the Week
Citrix NetScaler Zero-Days Exploited Before Disclosure, Added to CISA Catalogue
Citrix confirmed exploitation of NetScaler ADC and Gateway flaws CVE-2026-88771 and CVE-2026-88772, and CISA added both to its Known Exploited Vulnerabilities Catalogue. Mandiant traced exploitation of CVE-2026-88772 to early September, with WHIPSHOT web shells and SLAPSHOT tunnelling tools disguised as .deb and .sig files. Sygnia separately found a variant that poisons appliance logs so a maintenance script executes commands as root.
ShinyHunters Breaches FBI Jobs Portal as Suspected Members Are Detained
ShinyHunters accessed the FBI jobs portal by exploiting Oracle PeopleSoft flaw CVE-2026-35273 through a single-character path substitution that bypassed firewall rules, claiming 2 to 3 terabytes of data. Dutch police arrested Pepijn van der Stap, and the FBI urged remaining members to surrender. Reuters reported suspected member Saif al-Din Khader was detained in Jordan and is cooperating with the FBI.
Cisco SD-WAN vManage Authentication Bypass Grants Admin Access
VulnCheck reproduced CVE-2026-76504, a Cisco Catalyst SD-WAN vManage authentication bypass caused by two components disagreeing on how URL-encoded request paths are decoded. A percent-encoded path skips the password check, and one of four hardcoded internal usernames yields an admin session in a single request. Around 1,500 internet-exposed devices were identified, and Cisco disclosed the flaw as an exploited zero-day.
Pentagon Breach Exposes Records of About 3 Million Military-Linked Individuals
A breach of the Defense Manpower Data Center exposed unencrypted Social Security numbers and dates of birth for nearly 2.8 million living individuals and 294,000 deceased people with military ties. Unauthorised users had access from October 2025 to July 2026, until a file-sharing vulnerability was patched on 16 July. Affected individuals will receive 12 months of credit monitoring.
Mythos-Discovered Rejetto HFS Flaw Exploited Within a Day
Horizon3 used Anthropic's Mythos model to find CVE-2026-61500 in Rejetto HFS, where session cookies are signed with a key derived from V8's Math.random(). An unauthenticated endpoint leaks raw outputs, letting the Z3 solver recover the key and forge admin cookies for code execution. VulnCheck detected exploitation within a day of disclosure, initially from a China-hosted IP address.
Threats
Warlock Ransomware Hits Water and Telecom Operators via SharePoint
Symantec attributes Warlock ransomware attacks on a water utility and a telecoms provider to China-nexus group Longlegs, which exploits SharePoint vulnerabilities and disables security software using the vulnerable K7RKScan driver. In one intrusion, the tool reached over 40 hosts within two hours and Warlock infected at least 33 machines.
China-Aligned TA419 Impersonates Policymakers to Phish AI Experts
Proofpoint identified TA419 impersonating a former White House science policy official to phish AI policy experts at US think tanks and universities. A Browser-in-the-Browser kit relays genuine Microsoft sign-in traffic and captures session cookies even after multi-factor authentication succeeds.
BPFDoor and AVERAT Implants Target Telecom Mail Appliances
Rapid7 analysed Linux implants that impersonate vendor software on South Korean and Taiwanese mail security appliances. AVERAT communicates over port 25 using SMTP, and its payloads are deleted ten seconds after launch, leaving processes running without files on disk.
Infrastructure & Exploits
Zimbra Flaw Exploited Before Public Disclosure
Microsoft tracked exploitation of Zimbra command injection flaw CVE-2026-73570 beginning before its 13 August disclosure. Attackers used a crafted email to deploy JSP web shells, escalate privileges through PAM configuration changes and move laterally using the server's SSH identity.
Fortinet Warns of Exploited FortiMail Path Traversal Zero-Day
Fortinet disclosed CVE-2026-104286, a critical FortiMail path traversal flaw with a CVSS score of 9.8 that allows unauthenticated arbitrary file writes. It affects versions 7.2 to 8.0, exploitation has been reported in the wild, and patched releases are upcoming.
Apple Patches CoreGraphics Zero-Day Reported by Meta
Apple fixed CVE-2026-86950, a CoreGraphics out-of-bounds write that may have been exploited in an extremely sophisticated attack against specific individuals. Fixes are available in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1.
Tools & Techniques
PolinRider Malware Hides Command Servers in Ethereum Transactions
SafeDep identified 35 GitHub repositories carrying the PolinRider loader, which reads Ethereum transactions from operator wallets to find command servers encoded in recipient addresses. It installs an infostealer targeting environment secrets, browser data and wallets.
Agentic Attack Chains Two Zammad Zero-Days to Breach DIVD
The Dutch Institute for Vulnerability Disclosure said an agentic AI-powered attack exploited Zammad zero-days CVE-2026-102489 and CVE-2026-102490 to hijack sessions and escalate to root. Network segmentation limited access, although volunteer data was exfiltrated.
Fake ChatGPT Custom GPT Delivers Multi-Stage RAT
Huntress identified a fake Custom GPT called "Plus 5.6" that directs victims to a ClickFix-style attack triggering an eight-stage infection chain. The final remote access trojan can capture camera and microphone input, and at least 40 incidents are confirmed.
Policy & Legal
Ex-US Soldier Sentenced to 70 Months for Telecom Hacking
Former US Army soldier Cameron Wagenius, known as "kiberphant0m", was sentenced to 70 months and ordered to pay nearly $295,000 in restitution. He breached at least 10 organisations using a tool called SSH Brute, including activity tied to the 2024 Snowflake data theft.
Operation KillSwitch Dismantles KillSec Ransomware Leak Site
A Dutch national known as Archduke was indicted and arrested in the UK for operating KillSec. Authorities made three provisional arrests and seized a leak site holding at least 110 terabytes of data, covering around 1,000 suspected attacks.
Weekly Topic Distribution

Weekly Coverage
Developments
Citrix Netscaler Zero-Days Cisco Sd-Wan Auth Bypass Shinyhunters Fbi Breach Shinyhunters Arrests
Vulnerabilities
CVE-2026-88772Adc (Critical)CVE-2026-88771Adc (Critical)CVE-2026-76504Cisco Catalyst Sd-Wan Manager 18.3.6 (Critical)CVE-2026-35273Peoplesoft Enterprise Peopletools 8.61 (Critical)CVE-2026-61500Hfs 3.0.0 (Critical)CVE-2026-73570Collaboration (High)CVE-2026-104286Fortimail 8.0.0 (Critical)CVE-2026-86950Ios And Ipados (High)CVE-2026-102489Zammad 6.3.0 (Critical)CVE-2026-102490Zammad 1.5.0 (Critical)
Threat Groups
Scattered SpiderScattered Spider is a native Englishspeaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. Scattered Spider relies heavily on social engineering, including impersonating IT and helpdesk staff, to gain initial access, bypass multifactor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. Scattered Spider had expanded into hybrid cloud and identity environments, using helpdesk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.AkiraAkira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access singlefactor external access mechanisms such as VPNs for initial access, then various publiclyavailable tools and techniques for lateral movement. Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.LAPSUS$LAPSUS$ is cyber criminal threat group that has been active since at least mid2021. LAPSUS$ specializes in largescale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.APT28APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U. S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including closeaccess operations) conducted between 2014 and 2018 against the World AntiDoping Agency (WADA), the US AntiDoping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.CHROMIUMEarth Lusca is a suspected Chinabased cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.Salt TyphoonSalt Typhoon is a People's Republic of China (PRC) statebacked actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at major U. S. telecommunication and internet service providers (ISP).MuddyWaterMuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, defense, and oil and natural gas organizations, in the Middle East, Asia, Africa, Europe, and North America.Contagious InterviewContagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrencyrelated activities.Lazarus GroupLazarus Group is a North Korean statesponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.