CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (1 October 2026)

Published: Loading…

At a Glance

  • Suspected state-sponsored actors exploited Citrix NetScaler flaw CVE-2026-88772 since early September, compromising dozens of organisations across sectors.
  • Cisco confirmed active exploitation of CVE-2026-76504, a critical authentication bypass in Catalyst SD-WAN Manager granting admin-level API access.
  • Attackers exploited Zimbra flaw CVE-2026-73570 before its public disclosure, deploying web shells and harvesting mailbox and authentication data.
  • Bitget said the $387.5 million theft from its systems began with exploitation of a zero-day flaw in third-party security products.
  • The PolinRider malware loader, found in 35 GitHub repositories, reads command-server addresses from Ethereum mainnet transactions.
  • CISA warned of a critical pre-authentication remote code execution flaw in MikroTik RouterOS enabling denial-of-service conditions.

Editorial Analysis

Microsoft's Zimbra research adds another confirmed case this week of exploitation beginning well before public disclosure, following Citrix's NetScaler flaws and Bitget's third-party security product breach. CVE-2026-73570 was weaponised through a single crafted email targeting the SNMP notification path. Microsoft's timeline places exploitation between the 20 July fix and the 13 August disclosure, leaving a three-week period in which patched code existed but the vulnerability remained unannounced. Attackers used that window to deploy JSP web shells, modify Zimbra's PAM configuration for root access, and move laterally through the mail server's existing SSH trust between cluster nodes. Cisco's CVE-2026-76504 has a different entry point but affects the same type of centralised management infrastructure, with an authentication bypass providing admin-level control over the systems managed by Catalyst SD-WAN Manager. Cisco has shipped fixes but offers no workaround for organisations unable to patch immediately.

SafeDep's tracing of the PolinRider loader shows a supply-chain technique distinct from the token theft and typosquatting campaigns reported earlier this month. The operators embedded the loader into existing trusted repositories, including an attempted change submitted through a rejected pull request against the oxc-project build tool, and used forged commit metadata to make it resemble ordinary project history. The command infrastructure sits in Ethereum transactions rather than on a domain or IP address. Two operator wallets have been sending small transfers at intervals of roughly 51 minutes and 3.3 hours since June, with each recipient address encoding a current server location. Removing a malicious package does not remove that infrastructure, since the resolution mechanism continues to operate independently of any individual file, domain or hosting provider.

Highlights of the Day

New Exploit Variant Found in Citrix NetScaler Zero-Day Attacks

Sygnia identified an additional exploitation variant of Citrix NetScaler flaw CVE-2026-88771, which injects commands into appliance logs disguised as fabricated Packet Processing Engine failure messages. A legitimate maintenance script later parses the poisoned log entry and executes the embedded command as root, enabling configuration exposure, remote payload execution, or web shell deployment. The technique was observed in a field investigation before Citrix released fixed builds, with subsequent attacker activity reaching connected virtualisation and identity infrastructure.

Source: Sygnia

AI-Discovered Vulnerabilities More Likely to Enable Remote Code Execution

Google Threat Intelligence Group found that vulnerability disclosures doubled from 5,045 in January 2026 to 10,740 in August 2026, while in-the-wild exploitation rose from an average of 10.5 to 18 per month. AI-discovered vulnerabilities result in remote code execution 50% of the time, compared with 26% across the broader CVE ecosystem, and skew toward Medium and High risk ratings rather than low-severity findings. Exploited vulnerabilities concentrated in edge and security appliances, which represented 14% of exploitation activity, with over 65% of exploited edge flaws rated High or Critical.

Attackers Abuse ChatGPT Custom GPTs to Deliver Multi-Stage RAT

Huntress identified a campaign using a fake ChatGPT Custom GPT called "Plus 5.6" to direct victims to a ClickFix-style attack on Google Sites, triggering an eight-stage infection chain. The chain sideloads a malicious DLL into a legitimately signed Canon application, hides a loader inside a tampered WAV file, and unpacks a remote access trojan from a custom encrypted archive. The RAT can capture camera and microphone input, run remote desktop sessions, and communicate with its command server through DNS-over-HTTPS to Cloudflare and Google resolvers, with at least 40 incidents confirmed and a second campaign variant impersonating Stardock software already active.

Source: Huntress

Attackers Exploit Zimbra Mail Servers Before Public Flaw Disclosure

Microsoft tracked exploitation of CVE-2026-73570, an unauthenticated command injection flaw in Zimbra's SNMP notification path, beginning before its public disclosure on 13 August 2026. Attackers triggered the flaw with a crafted email to deploy JSP web shells, escalate privileges by manipulating Zimbra's PAM configuration, and move laterally across mail clusters using the server's own SSH identity. Observed activity included collection of authentication keys and mailbox data, with one case showing archived mail store content staged for transfer to cloud storage.

PolinRider Malware Hides Command Servers in Ethereum Transactions

SafeDep identified 35 GitHub repositories carrying the PolinRider loader, which reads Ethereum mainnet transactions from operator wallets to locate its command servers encoded in recipient addresses. The loader was discovered after a rejected pull request against the oxc-project build tool embedded the malware in 20 build and test scripts, using forged commit metadata to disguise its origin. Once run during a project build, the loader installs a Node.js and Python infostealer that collects environment secrets, browser passwords, cookies and cryptocurrency wallet data from 153 browser extensions.

Source: SafeDep

TerminalFix Campaign Uses Windows Terminal Lures to Deploy Python Tunnel

Sophos tracked a campaign called STAC4924 that uses TerminalFix, a ClickFix variant directing victims to paste commands into Windows Terminal rather than the Run dialog. The attack sideloads a malicious DLL called Lorem Ipsum Loader, which hides shellcode as English words and retrieves command servers from an attacker-controlled profile on the Letsdiskuss platform disguised as JPEG image traffic. A deployed Python runtime then runs a custom tunnelling implant that establishes an encrypted WebSocket connection, allowing attackers to relay traffic through the compromised host.

Source: Sophos

32 Browser Extensions Secretly Track Users via Remote Configuration

Akamai identified 32 malicious browser extensions on the Chrome Web Store and Microsoft Edge Add-ons Store, disguised as productivity tools and affecting over 6,150 users. The extensions share nearly identical code and retrieve attacker-controlled configuration files from a shared jsDelivr-hosted endpoint, allowing operators to alter behaviour and redirect traffic without publishing browser store updates. Korean-language code artifacts and a shared remote infrastructure tie the campaign, active since March 2025, to a single threat actor engaged in browsing surveillance and affiliate fraud.

Source: Akamai

Daily Coverage

Developments
Netscaler State-Actor ExploitationCisco Sd-Wan Zero-DayZimbra CVE-2026-73570Bitget Third-Party Breach
Vulnerabilities
CVE-2026-88772Adc (Critical)CVE-2026-76504Cisco Catalyst Sd-Wan Manager 18.3.6 (Critical)CVE-2026-88771Adc (Critical)CVE-2026-73570Collaboration (High)CVE-2026-86950Ios And Ipados (High)CVE-2026-82329Artifactory (Critical)CVE-2026-65669Sql Server Management Studio 22 22.0 (Critical)CVE-2026-89013Dolibarr 23.0.4 (High)CVE-2026-94545Satori >= 0.0.27, < 0.33.5 (Medium)CVE-2026-18145Fireware Os 2026.3 (High)
Threat Groups
Star BlizzardStar Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019. Star Blizzard campaigns align closely with Russian state interests and have included persistent phishing and credential theft against academic, defense, government, NGO, and think tank organizations in NATO countries, particularly the US and the UK.