Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (29 September 2026)
Published: Loading…
At a Glance
- CISA and international agencies confirmed active exploitation of critical Citrix NetScaler flaws CVE-2026-88771 and CVE-2026-88772, ordering federal agencies to patch by Wednesday.
- Dutch police arrested Pepijn van der Stap over alleged ties to ShinyHunters, days before the group escalated attacks against the FBI and Cl0p.
- ShinyHunters breached the FBI's jobs portal via Oracle PeopleSoft flaw CVE-2026-35273, exposing agents' medical examination records including blood tests and doctors' notes.
- Bitget said an attacker exploited a third-party security product flaw to steal $388 million, obtaining internal credentials used for fraudulent withdrawal commands.
- Microsoft detailed NeedyMantis, a post-compromise malware family linked to threat actor Storm-3069, used to maintain long-term access in targeted networks.
- JadePuffer operator Storm-3168 used compromised Azure service principals to conduct destructive resource deletion and credential collection over an 18-hour period.
Editorial Analysis
The Dutch arrest of Pepijn van der Stap did not stop ShinyHunters' activity. Within days of his detention, the group escalated its claimed FBI breach, with reporting now indicating that the stolen data includes agents' fitness-for-work medical records, blood test results and doctors' notes. Krebs's reporting attributes the change to a leadership dispute, with a teenager linked to ScatteredLapsussHunters reportedly driving the group's more aggressive activity. The arrest removed one participant, but the ShinyHunters name, existing access methods and leak-site infrastructure continued to be used.
Bitget now says its $388 million loss originated with a flaw in a third-party security product that exposed internal credentials, which were then used to send fraudulent withdrawal commands. That provides a more specific account of the compromise than the multi-chain transaction tracing reported last week. Citrix's NetScaler flaws also spent several days under attack before public disclosure: GreyNoise recorded exploitation attempts against a NetScaler Gateway on 24 September, three days before Citrix published its advisory. CISA's Wednesday patching deadline for federal agencies followed after exploitation was already underway.
Microsoft's NeedyMantis and JadePuffer research describe different ways attackers operated after gaining access. NeedyMantis, linked to Storm-3069, uses DLL sideloading against applications including Poedit and TightVNC, placing malicious components in normal software directories. JadePuffer's Storm-3168 operation used stolen Azure service principals and spent roughly 18 hours collecting credentials and deleting resources within a compromised tenant.
Highlights of the Day
CISA Orders Federal Agencies to Patch Exploited Citrix NetScaler Flaws
CISA added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities Catalogue, confirming active exploitation of both critical Citrix NetScaler ADC and Gateway flaws. CVE-2026-88771 allows unauthenticated remote code execution on any deployment, while CVE-2026-88772 is a memory overflow affecting DTLS configurations enabled by default on VPN virtual servers. Under Binding Operational Directive 26-04, federal civilian agencies must prioritise remediation of catalogued flaws that grant total control after exploitation.
Ex-US Soldier Sentenced to 70 Months for Telecom Hacking Spree
Former US Army soldier Cameron Wagenius, known as "kiberphant0m", was sentenced to 70 months in prison and ordered to pay nearly $295,000 in restitution for hacking and extorting telecommunications companies between April 2023 and December 2024. Using a self-built tool called SSH Brute, he and co-conspirators breached at least 10 organisations, stealing call and text records tied to the 2024 Snowflake data theft affecting AT&T. Prosecutors said Wagenius sold stolen data on cybercrime forums and attempted to sell information to a foreign intelligence service.
Keio Railway Confirms Ransomware Attack Disrupting Group Systems
Keio Corporation confirmed early on 26 September 2026 that a ransomware attack had disrupted systems at its group servers, affecting sales systems at some subsidiaries. The company has reported the incident to police and is investigating the attack's entry route and scope with external specialists, with no confirmed data leak so far. Train operations remain unaffected, and Keio has cut network connections to prevent further damage while the investigation continues.
Dutch Police Arrest Suspect Linked to ShinyHunters Extortion Group
Dutch police arrested Pepijn van der Stap, a 24-year-old previously convicted cybercriminal, on suspicion of aiding data thefts and extortions by ShinyHunters. Days after his detention, remaining ShinyHunters members escalated activity, claiming a breach of an FBI job application site that exposed Social Security numbers and personal data on more than 5,000 officials, and separately extorting the Cl0p ransomware group. Sources said the FBI breach exploited Oracle PeopleSoft flaw CVE-2026-35273, and that leadership of ShinyHunters has shifted to a teenager linked to the ScatteredLapsussHunters collective.
Microsoft Details NeedyMantis Post-Compromise Malware Linked to China
Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware family active since at least October 2025 and deployed after attackers already have access to a target environment. The malware, linked to threat actor Storm-3069 and the DAEMON Tools supply chain compromise, sideloads malicious DLLs disguised as legitimate software components from tools including Poedit and TightVNC. It has been observed against telecommunications firms, universities, intergovernmental organisations, medical nonprofits and government contractors, communicating with its command server over an encrypted WebSockets protocol.
ShinyHunters Breached FBI Jobs Portal by Bypassing Firewall Fix
ShinyHunters accessed the FBI's apply.fbijobs.gov site by exploiting Oracle PeopleSoft flaw CVE-2026-35273, bypassing firewall rules that organisations relied on instead of Oracle's June patch through a single-character substitution in the web request. The group claims to have moved into FBI-managed storage on Amazon's government cloud and taken 2 to 3 terabytes of data, though the FBI has confirmed only that it is investigating. Unlike previous ShinyHunters campaigns based on stolen credentials, this breach used no password, and the group is demanding the FBI retract a prior advisory rather than seeking a ransom payment.
Daily Coverage