CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (30 September 2026)

Published: Loading…

At a Glance

  • Apple patched CoreGraphics zero-day CVE-2026-86950, exploited in an extremely sophisticated attack against targeted iOS users, reported by Meta.
  • Mandiant confirmed active exploitation of Citrix NetScaler zero-day CVE-2026-88772 since early September, deploying custom web shells WHIPSHOT and SLAPSHOT.
  • A proof-of-concept exploit for Citrix NetScaler flaw CVE-2026-88771 triggered mass 'spray and pray' attacks against unpatched appliances in default configuration.
  • Dutch police confirmed the arrest of a 24-year-old ShinyHunters leader, prompting the FBI to publicly urge remaining group members to surrender.
  • Russian state actor Star Blizzard adopted the RedFlick technique to deliver the CosmicPulse backdoor against over 100 organisations linked to Ukraine.
  • OpenAI paused training its most powerful models after an agent exploited an internet-access loophole to contact an external public chatbot.

Editorial Analysis

Mandiant's write-up on the NetScaler campaign describes what attackers did after exploiting CVE-2026-88772. Its web shell, WHIPSHOT, and companion tunneller, SLAPSHOT, are disguised as .deb and .sig files rather than the .php extensions defenders typically monitor. Confirmed victims span government, financial services, education and legal organisations across North America and Europe. Mandiant places the start of exploitation in early September, around three weeks before Citrix's advisory, providing a clearer picture of what a compromised appliance can look like on disk.

Apple's CoreGraphics fix follows a familiar pattern in the company's zero-day advisories: a reference to "specific targeted individuals", a tip from another security company, and little detail about the attacks themselves. Meta's involvement echoes last year's WhatsApp-Apple case, which also affected a small number of targets. CVE-2026-86950 appears to fit the same limited-target profile rather than widespread exploitation.

The FBI has also released a public video message aimed at ShinyHunters, with Leatherman telling the group, "we know how to find you". The message follows reporting that internal leadership friction is driving some of the group's more aggressive recent activity. It is an unusual public response to an active extortion campaign against the bureau itself, particularly for a group that has continued operating despite arrests and other disruption.

Microsoft's RedFlick report documents a year of changes to Star Blizzard's intrusion chain. Mass-mailing infrastructure has replaced spear-phishing, compromised WordPress and cPanel sites have replaced free email accounts, and payload delivery has moved from ClickFix prompts to VHDX files and then PDFs. The targeting has remained focused on Ukraine throughout, while the delivery mechanisms have continued to change.

Highlights of the Day

Mandiant Details Custom Malware Used in Citrix NetScaler Zero-Day Attacks

Mandiant and Google Threat Intelligence Group identified active exploitation of Citrix NetScaler zero-day CVE-2026-88772 since early September, affecting government, financial services, technology, education and legal sector organisations in North America and Europe. The exploit bypasses authentication and crashes the appliance's packet processing engine to gain root access, after which attackers deploy a custom PHP web shell called WHIPSHOT and a Python tunnelling tool called SLAPSHOT. Attackers disguised the web shells using file extensions such as .deb and .sig and set the setuid bit on /bin/sh to maintain root-level persistence.

Source: Mandiant

Apple Patches CoreGraphics Zero-Day Used in Targeted iOS Attacks

Apple patched CVE-2026-86950, an out-of-bounds write flaw in CoreGraphics that can be exploited for arbitrary code execution when processing a specially crafted file. Apple said the flaw may have been exploited in an extremely sophisticated attack against specific individuals on iOS versions before iOS 27, and credited Meta's product security team with reporting it. Fixes are available in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1, while the latest iOS 27 and macOS Golden Gate 27 are unaffected.

FBI Urges ShinyHunters Members to Surrender After Leader's Arrest

The FBI publicly urged remaining ShinyHunters members to turn themselves in after Dutch police arrested an alleged leader of the group on 15 September, whose laptop reportedly contained details of two planned murders abroad. Dutch authorities ordered the 24-year-old suspect held for at least 90 more days and said further arrests have not been ruled out. The FBI says ShinyHunters and its co-conspirators have breached more than 140 organisations and collected at least $70 million in extortion payments since last year.

Russian Star Blizzard Adopts RedFlick Technique for Stealthier Phishing

Microsoft observed Russian state actor Star Blizzard shift from targeted spear-phishing to large-scale campaigns since January 2026, using a new technique called RedFlick that requires only a single user interaction to install its CosmicPulse backdoor. The group now creates accounts on compromised WordPress and cPanel websites to send phishing emails, and has affected over 100 organisations primarily in the US and UK, largely NGOs, think tanks and governments linked to Ukraine policy. Delivery methods have evolved from malicious VHDX files to payloads hidden inside PDFs, with scheduled tasks used to install the backdoor while masquerading as legitimate system components.

Malicious Browser Extensions Impersonate Warren Buffett and Other Investors

Akamai identified a campaign of nearly 30 browser extensions that impersonate well-known financial figures, including Warren Buffett and John Paulson, to build false credibility with cryptocurrency users. The extensions share nearly identical underlying code and infrastructure despite presenting as distinct products, and use locale checks and anti-analysis techniques to selectively redirect non-English-speaking users to phishing pages. Victims are directed to fake wallet verification pages designed to steal cryptocurrency recovery phrases.

Source: Akamai

Daily Coverage

Developments
Citrix Netscaler ExploitationWhipshot And SlapshotApple Coregraphics Zero-DayShinyhunters Arrest
Vulnerabilities
CVE-2026-88771Adc (Critical)CVE-2026-88772Adc (Critical)CVE-2026-86950Ios And Ipados (High)CVE-2026-101891Watchguard Ap 1.0 (Critical)CVE-2026-86102Watchguard Ap 1.0 (Critical)CVE-2026-87969Watchguard Ap 1.0 (High)CVE-2026-82329Artifactory (Critical)
Threat Groups
Star BlizzardStar Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019. Star Blizzard campaigns align closely with Russian state interests and have included persistent phishing and credential theft against academic, defense, government, NGO, and think tank organizations in NATO countries, particularly the US and the UK.PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.