Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (28 September 2026)
Published: Loading…
At a Glance
- Two unpatched Citrix NetScaler ADC and Gateway zero-days enabling remote code execution are being actively exploited, prompting some administrators to take appliances offline.
- CISA added Microsoft SharePoint flaw CVE-2026-65660 and MikroTik RouterOS flaw CVE-2026-67279 to its KEV catalogue after confirming active exploitation.
- ShinyHunters bypassed web application firewall rules by URL-encoding the PSEMHUB path, resuming mass exploitation of Oracle PeopleSoft flaw CVE-2026-35273.
- The Lunex stealer abused a vulnerable AMD driver to disable security monitoring before stealing browser credentials from Ukrainian-speaking users.
- Kiteworks urged customers to shut down systems for nine hours after receiving intelligence that a threat actor may target its platforms.
- Cloudflare fixed a Containers flaw that let Workers Paid customers recover residual data from other tenants' containers on shared hosts.
Editorial Analysis
Citrix's NetScaler disclosure moved from private warnings to a published fix within a day, leaving administrators to make decisions in the gap. On 26 September, watchTowr reported two unpatched remote code execution zero-days, and some administrators took appliances offline rather than wait for a fix. Citrix's bulletin, published on 27 September, lists eight vulnerabilities and confirms exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated deployments. CVE-2026-88771 requires no particular feature or configuration, affecting every NetScaler ADC and Gateway deployment, while DTLS, enabled by default on VPN virtual servers, exposes appliances to CVE-2026-88772. Administrators therefore had limited scope to reduce exposure through configuration changes while waiting for the fixed builds.
The renewed ShinyHunters campaign against Oracle PeopleSoft shows how a security control can appear effective while traffic is still reaching the vulnerable application. Web application firewall rules matched the literal /PSEMHUB/ path, while the application server decoded /%50SEMHUB/ and routed it to the same vulnerable servlet. Mandiant found the group targeting organisations that had added WAF rules but had not patched CVE-2026-35273, with web shells already deployed on dozens of systems. The issue was in how the two layers interpreted the request, leaving the WAF unable to recognise what the application ultimately processed.
Lunex provides a separate look at endpoint protection. Its loader uses the vulnerable AMD driver PDFWKRNL.sys to zero the kernel callbacks of 20 security drivers, leaving the products running but unable to monitor the stealer. Ontinue reported that neither HVCI nor Microsoft's vulnerable driver blocklist prevented the variant from loading, despite LOLDrivers having catalogued the driver since March. The malware also registers a Chrome Native Messaging Host, com.lunex.explorer, preserving filesystem access after the main binary is deleted. Ontinue has identified 28 panels across 13 countries, up from six documented in June.
Highlights of the Day
CISA Adds Exploited SharePoint and MikroTik RouterOS Flaws to KEV Catalogue
CISA added two vulnerabilities to its Known Exploited Vulnerabilities Catalogue after finding evidence of active exploitation. The entries are CVE-2026-65660, a code injection flaw in Microsoft SharePoint, and CVE-2026-67279, an improper enforcement of behavioural workflow flaw in MikroTik RouterOS. Under Binding Operational Directive 26-04, federal civilian agencies must prioritise rapid remediation of catalogued flaws on publicly exposed assets that grant total control after exploitation.
ShinyHunters Bypasses WAF Rules to Exploit Oracle PeopleSoft Flaw
Mandiant and Google Threat Intelligence Group identified renewed exploitation of CVE-2026-35273 by UNC6240, also known as ShinyHunters, which bypasses firewall rules by URL-encoding one character in the vulnerable PSEMHUB path. The group deployed web shells on dozens of systems worldwide across higher education, technology, healthcare, government and other sectors. Follow-on tooling included the SIDEEYE backdoor, the Neo-reGeorg tunnelling toolkit and the MeshAgent remote management tool.
Lunex Stealer Uses Vulnerable AMD Driver to Blind Security Tools
Ontinue analysed a four-stage Lunex campaign that begins with a fake CAPTCHA page and uses a vulnerable AMD driver, PDFWKRNL.sys, to zero out kernel callbacks belonging to security products. The final payload steals credentials from seven Chromium-based browsers and cryptocurrency wallet data. It also registers a Chrome Native Messaging Host that gives attackers filesystem access after the stealer is deleted.
Citrix Patches Eight NetScaler Flaws Including Two Exploited Critical Bugs
Citrix disclosed eight vulnerabilities in NetScaler ADC and NetScaler Gateway, including CVE-2026-88771, an unauthenticated remote code execution flaw affecting default configurations, and CVE-2026-88772, a DTLS memory overflow. Both have CVSS v4.0 scores of 9.5, and exploitation of each has been observed on unmitigated deployments. The remaining flaws cover request smuggling, policy bypass, memory overflows and predictable TCP sequence numbers, and fixes are available in builds 14.1-73.37 and 13.1-64.23.
Attackers Exploit Old Telerik UI Flaw to Plant Web Shell and Scanner
AhnLab's ASEC observed two attacks exploiting CVE-2019-18935, a .NET deserialisation flaw in Telerik UI for ASP.NET AJAX, against unpatched Windows IIS servers in Korea. In the first, attackers opened a reverse shell, used SweetPotato to gain SYSTEM privileges and loaded a Godzilla-style web shell into memory. In the second, they ran a Rust-based scanner that searches for exposed WordPress setup pages and reports hits through Telegram.
Cloudflare Fixes Container Flaw That Exposed Residual Data Across Customers
A researcher from Accomplish reported that Cloudflare Containers and Sandboxes ran storage pools with block zeroing disabled, letting a Workers Paid customer recover leftover disk blocks from other tenants on the same host. Residual data was recovered on 18 of 24 tested placements, including directory structures, database pages and SQLite databases. Cloudflare removed the setting fleet-wide, retired affected disks and cached snapshots, and found no evidence of malicious exploitation.
Daily Coverage