Touchpoint Weekly Threat Roundup

Edge-Device Zero-Days, Ransomware Takedowns and Shrinking Patch Windows

TSTouchpoint Security·October 4, 2026·Covers Sep 28 – Oct 4, 2026

This was a week dominated by exploited flaws in internet-facing infrastructure. Citrix NetScaler, Fortinet FortiMail and Cisco SD-WAN Manager zero-days were all confirmed as exploited, and one FortiMail fix has yet to ship. Ransomware and extortion groups kept up the pressure on critical infrastructure and government, even as law enforcement dismantled KillSec and moved against ShinyHunters. Research from Google and Microsoft shows why speed now matters most: the window between disclosure and exploitation is shrinking toward hours.

Top story of the week The Citrix NetScaler zero-days went from quiet state-sponsored exploitation to mass attacks against about 42,000 exposed appliances, so patching must be paired with a compromise assessment.

The week at a glance

Click any row to jump to that story.

Date Category Item
Oct 3 Law enforcement Suspected ShinyHunters member reportedly detained in Jordan, cooperating with the FBI
Oct 2 Breach/ransomware DTU breach affects up to 200,000 people
Oct 1 Vulnerability FortiMail CVE-2026-104286 exploited; fixes still pending
Oct 1 Breach/ransomware Warlock ransomware breaches critical infrastructure via SharePoint
Oct 1 Law enforcement KillSec ransomware dismantled; three arrests across Europe
Oct 1 Vulnerability Critical Dell CSM and GitLab AI Gateway fixes
Oct 1 Research Microsoft Digital Defense Report: weaponization in under 24 hours
Oct 1 Research AI agent breach of DIVD; agents probe government sites
Oct 1 Threat actor TA419 phishing targets US AI policy experts
Sep 30 Vulnerability Cisco Catalyst SD-WAN Manager CVE-2026-76504 exploited
Sep 30 Breach/ransomware OpenInfra Europe Artifactory compromise disclosed
Sep 30 Research Google GTIG: exploited vulnerabilities and AI-found RCEs rising
Sep 30 Policy MI5 espionage alert on MSS-funded academic research
Sep 29 Breach/ransomware Pentagon DMDC breach of about 3 million records reported
Sep 29 Vulnerability Mandiant details state-linked NetScaler exploitation; mass attacks follow
Sep 28 Vulnerability Apple patches exploited Core Graphics zero-day

Vulnerabilities and patches

Citrix NetScaler zero-days move from targeted to mass exploitation (CVE-2026-88771, CVE-2026-88772)

What happened. Citrix's bulletin CTX697096, published September 27, fixes eight NetScaler ADC and Gateway vulnerabilities (CVE-2026-88771 through CVE-2026-88778). Two of them, CVE-2026-88771 and CVE-2026-88772, are unauthenticated remote code execution flaws that Citrix confirms have been exploited; CISA added both to its KEV catalog the same day. On September 29, Mandiant and Google Threat Intelligence Group reported that CVE-2026-88772 had been exploited since early September against government, financial services, technology, education and legal organizations in North America and Europe. Attackers deployed a PHP web shell (WHIPSHOT) and a Python tunneller (SLAPSHOT) for persistence and internal access. Mandiant's CTO attributed the initial intrusions to suspected state-sponsored actors. After a public proof of concept appeared, opportunistic exploitation began within minutes.

Who is affected. NetScaler ADC and Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23, plus the 14.1-FIPS and 13.1-FIPS/NDcPP builds before 14.1-73.37 and 13.1-37.279. CVE-2026-88771 affects default configurations; CVE-2026-88772 requires DTLS, which is on by default for VPN virtual servers. Citrix rates both CVSS 9.5 (v4.0). The other six flaws (CVSS 7.0–9.3) are not reported as exploited but are fixed by the same updates. Censys counted roughly 42,000 internet-facing NetScaler hosts.

What to do. Upgrade to 14.1-73.37 or 13.1-64.23 or later now. If you cannot patch immediately, Mandiant recommends disabling DTLS on internet-facing Gateway virtual servers or blocking inbound UDP/443 upstream. Because exploitation predates disclosure, snapshot appliances with memory before rebooting, and hunt with Mandiant's published commands and YARA rules (unexpected PHP handlers in httpd.conf, /tmp/.uxdport, a SUID /bin/sh). After patching, end all admin, Gateway and VPN sessions, then rotate appliance, LDAP/RADIUS and API credentials and reissue TLS certificates. Patching alone does not remove an attacker who is already in.

FortiMail zero-day exploited before fixes ship (CVE-2026-104286)

What happened. On October 1, Fortinet disclosed that a CVSS 9.8 path traversal flaw in FortiMail is being exploited in the wild. It lets unauthenticated attackers write arbitrary files through the Identity-Based Encryption (IBE) feature. Advisory FG-IR-26-175 lists fixes in 8.0.2, 7.6.7 and 7.4.9 as "upcoming"; the 7.2 branch will not be fixed. CISA added it to its Known Exploited Vulnerabilities (KEV) catalog on October 1 with a three-day federal deadline. As of October 4, the fixed builds were still listed as upcoming.

What to do. Disable IBE if you do not use it. Otherwise, restrict webmail to trusted networks and block POST requests to /ibe containing ../ at a web application firewall. Hunt for the IP addresses and log indicators in the advisory, and upgrade as soon as fixed builds are available.

Cisco Catalyst SD-WAN Manager authentication bypass exploited (CVE-2026-76504)

What happened. Cisco published an advisory on September 30 for a CVSS 9.8 API authentication bypass in Catalyst SD-WAN Manager. Mishandled URI encoding lets an unauthenticated attacker reach the API with admin privileges. Cisco found exploitation through a support case in September, and CISA gave federal agencies until October 3 to remediate. It is the latest in a run of exploited SD-WAN flaws this year.

What to do. No workaround exists. Upgrade to 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 or 26.2.1; releases before 20.9 must migrate. Remove management interfaces from the internet, and review the service-proxy and vManage server logs for j_security_check requests from unexpected sources.

Apple patches Core Graphics zero-day used in targeted attacks (CVE-2026-86950)

What happened. Apple released iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 on September 28 to fix an out-of-bounds write in Core Graphics. A maliciously crafted file can trigger code execution. Apple says the flaw may have been exploited in an extremely sophisticated attack against specific individuals. Meta Product Security reported it, and CISA added it to the KEV catalog on September 29.

What to do. Enforce the updates through MDM, prioritizing executives, administrators and staff who travel or handle sensitive negotiations. Consider Lockdown Mode for those most at risk.

Critical fixes for Dell Container Storage Modules and GitLab AI Gateway

Dell's DSA-2026-448 fixes six critical flaws in Container Storage Modules, the software that connects Dell enterprise storage to Kubernetes. Two missing-authentication bugs are rated CVSS 10.0 (CVE-2026-63688, CVE-2026-63692), and the others include hard-coded credentials and a hard-coded JWT secret. Upgrade to CSM 1.18.0 and rotate CSM Authorization secrets. GitLab fixed CVE-2026-90970 (CVSS 9.9), a sandbox escape in self-hosted AI Gateway that any user with Duo Agent Platform access could use to run commands. Fixed versions are 19.2.4, 19.3.2 and 19.4.1. Neither flaw is reported as exploited.

Breaches, ransomware and supply chain

Warlock ransomware hits critical infrastructure through old SharePoint flaws

What happened. Symantec and Carbon Black reported on October 1 that the Warlock ransomware operation recently hit a water utility, a telecommunications provider, a regional government body and a university. Symantec attributes the activity to a China-nexus group it calls Longlegs, which Microsoft tracks as Storm-2603. The recent victims are in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America.

Technical context. Initial access came through the "ToolShell" SharePoint vulnerabilities (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771), which were patched in July 2025. The attackers harvested ASP.NET machine keys, used a vulnerable K7 driver (CVE-2025-1055) to disable endpoint protection, persisted through Visual Studio Code tunnels and pushed ransomware through SYSVOL and Group Policy. In one case, nine days passed between first access and encryption.

What to do. Verify that on-premises SharePoint is fully patched, and rotate machine keys on any server that was ever exposed while unpatched. Enable Microsoft's vulnerable driver blocklist, and hunt for unexpected VS Code tunnels and SYSVOL changes.

OpenInfra Europe Artifactory breach puts downloaded packages in doubt

What happened. OpenInfra Europe disclosed that attackers compromised its self-hosted JFrog Artifactory instance (artifactory.nordix.org). They exploited an authentication bypass, CVE-2026-82329, which had been disclosed on August 28 and was added to CISA's KEV catalog on September 2, and gained admin access. The intrusion began around August 31 but went unnoticed until September 15. The full impact is still undetermined.

What to do. If your pipelines pulled artifacts from that repository between August 28 and September 15, stop using them, remove them and treat them as compromised. More broadly, patch self-hosted artifact repositories with the same urgency as perimeter devices. They are a direct route into the software supply chain.

Pentagon personnel agency breach exposes data of about 3 million people

What happened. The Defense Manpower Data Center (DMDC), the Pentagon's personnel data agency, is notifying about 3.06 million current and former service members, dependents and deceased individuals that their data was stolen. Attackers exploited a vulnerability in a DMDC file-sharing system and reached a server holding unencrypted personal data, including Social Security numbers, dates of birth, contact details and military occupational specialty. The access began in October 2025 and was not discovered until July 16, 2026. No group has claimed responsibility, and the DoD says it has no indication of misuse.

What to do. Keep sensitive personal data off file-sharing servers or encrypt it at rest, and monitor file-transfer platforms for unusual access and bulk downloads. This intrusion went unnoticed for roughly nine months. Organizations whose employees or customers include service members should expect related phishing.

Threat actors, law enforcement and policy

KillSec ransomware dismantled; suspected 16-year-old operator arrested

What happened. Eurojust announced on October 1 that an international operation dismantled the KillSec ransomware and extortion group, which it links to nearly 1,000 attacks worldwide since 2024. Authorities from nine countries, including the US, coordinated three arrests and eight house searches. Among those arrested is a 16-year-old suspected of being the main operator. Investigators seized five servers, the group's domains and at least 110 TB of stolen data.

Why it matters. KillSec relied on poorly secured access points, especially misconfigured cloud storage, rather than sophisticated exploits. That is a reminder that basic exposure management prevents a large share of extortion cases.

ShinyHunters under pressure: FBI breach claim, two arrests and a cooperating suspect

What happened. ShinyHunters claimed to have breached FBI recruitment systems through an Oracle PeopleSoft flaw, and the FBI's job portals were taken offline. The FBI confirmed it is investigating but has not confirmed data theft. Google Threat Intelligence Group reported on September 25 that the group (tracked as UNC6240) has renewed mass exploitation of CVE-2026-35273. This is a deserialization flaw in PeopleSoft Environment Management Hub (PSEMHUB) that Oracle patched in a June 10 Security Alert. The attackers evade WAF rules by URL-encoding one character of the path (/%50SEMHUB/). Separately, Reuters reported that a suspected member known as "Rey" was detained in Jordan this week and is helping the FBI identify associates, following another arrest in the Netherlands in September.

What to do. Apply Oracle's CVE-2026-35273 fix, and remove or block external access to PSEMHUB if you don't need it; GTIG warns that WAF rules alone are not enough. Search web logs for /PSEMHUB/ and percent-encoded variants. Look for unexpected JSP files or shells spawned by WebLogic, and rotate database and Integration Broker credentials on any exposed system. ShinyHunters also relies on help-desk social engineering, so require phishing-resistant MFA for administrators.

Research and reports

Google and Microsoft: exploitation is getting faster, and AI is a factor

Two major reports this week point the same way. Google Threat Intelligence Group's September 30 analysis found that monthly CVE disclosures roughly doubled in 2026, from 5,045 in January to 10,740 in August. It also found that 141 vulnerabilities were exploited in the first eight months of 2026, compared with 127 in all of 2025. Half of the AI-discovered vulnerabilities GTIG examined led to remote code execution, against 26% of others. In one case, a flaw found by an AI agent (BeyondTrust CVE-2026-1731) was weaponized four days after disclosure. Microsoft's 2026 Digital Defense Report, released the same week, says the median time from vulnerability discovery to weaponization has fallen well below 24 hours, and that attackers currently hold the early advantage in using AI.

What to do. Monthly patch cycles are no longer adequate for internet-facing systems. Keep a separate, faster track for edge devices and anything listed in CISA's KEV catalog, measured in hours or days rather than weeks.

Autonomous AI agents seen probing and breaching real targets

The Dutch Institute for Vulnerability Disclosure (DIVD) reported that an agentic AI attack breached it on September 21–22 through two zero-days in the Zammad helpdesk system. CVE-2026-102489 is a session hijack leading to remote code execution, and CVE-2026-102490 escalates privileges to root. DIVD says network segmentation kept the attacker from its most sensitive systems. Volunteer email addresses and possibly contact details were exposed. Zammad says CVE-2026-102489 affects only 6.5 and older (both out of support) and is fixed in 7.2.0. It is still awaiting technical details on CVE-2026-102490.

Separately, the nonprofit research lab Transluce documented autonomous agents sending SQL injection probes to US and Canadian government websites; officials found no evidence of compromise.

What to do. If you run Zammad, upgrade to 7.2.0, move any 6.x instances off the internet, and watch Zammad's GitHub advisories for a CVE-2026-102490 fix. More broadly, expect high-volume, automated probing of public web applications, and make sure rate limiting, web application firewall rules and input validation are in place.

Also notable this week

DTU breach (Denmark) The Technical University of Denmark disclosed on October 2 that attackers used compromised user profiles to access its identity and access management system. They downloaded data on up to 200,000 current and former users, including national ID (CPR) numbers and next-of-kin details. Identity systems need phishing-resistant MFA and alerts on bulk exports.
Frontline Education breach The K-12 software provider said a third-party product vulnerability exposed school district employees' Social Security numbers and addresses. Districts have until October 16 to decide who sends notifications.
Fakturownia (Poland) An attacker gained server access to the invoicing platform, which has more than 600,000 business users. Exposed data includes password hashes, bank details and integration tokens. Customers should rotate passwords and API tokens and watch for invoice fraud.
Vicksburg, Mississippi ransomware A ransomware attack forced the city to shut down its systems and disrupted utility payments; emergency services continued. It is a reminder that municipalities need manual fallbacks.
TA419 targets AI policy experts Proofpoint reported that this China-aligned group impersonates prominent policy figures to lure AI policy experts. It then steals Microsoft 365 credentials and session cookies through an adversary-in-the-middle kit that defeats standard MFA. Phishing-resistant authentication is the answer.
Antino backdoor Cisco Talos detailed a China-nexus campaign (UAT-11587) against government and policy organizations across Asia. Its Rust backdoor uses Outlook and OneDrive through the Microsoft Graph API for command and control. Watch for unusual Graph API activity from non-browser processes.
MI5 espionage alert MI5 warned that the China General Technology Research Institute funds research to improve China's Ministry of State Security espionage capabilities, and that more than 100 UK-linked academics have contributed. Research organizations should vet funders against the alert.
Microsoft Titan flaw A 16-year-old researcher showed that Microsoft's internal Titan analytics service accepted unsigned JWTs, exposing employee records and Bing analytics data. Microsoft fixed it on September 9. Every service should reject unsigned tokens.
Iranian hacker extradited Amir Barati, one of 17 alleged IRGC-linked Mabna Institute hackers charged in New York, was extradited from Montenegro. The group is accused of stealing data from hundreds of universities.
Microsoft's X account hijacked Attackers briefly took over Microsoft's official X account to promote a cryptocurrency token. Corporate social accounts need passkeys, a protected recovery email and a short admin list.

Touchpoint's Take

Three threads ran through this week. First, the edge remains the front line. Gateways, mail filters and SD-WAN controllers are exposed by design, highly privileged and often poorly monitored, which is why they keep appearing as zero-day targets. For these systems, "patched" and "clean" are different states. The NetScaler and FortiMail cases both call for compromise assessment alongside remediation.

Second, old weaknesses still pay. Warlock entered through SharePoint flaws fixed more than a year ago, OpenInfra was breached through a vulnerability already in CISA's catalog, and KillSec thrived on misconfigured cloud storage. Disciplined asset inventory and patch verification still prevent more incidents than any single new control.

Third, the time available to act is shrinking. The Google and Microsoft data, along with the first well-documented autonomous AI intrusions, suggest exploitation timelines will keep compressing. Organizations should review whether their patching, detection and incident response processes can operate in hours for internet-facing assets.

If you would like help assessing your exposure to any of this week's issues, the Touchpoint Security team is available to talk.

What to watch next week

  • FortiMail fixed builds: 8.0.2, 7.6.7 and 7.4.9 were still listed as upcoming at the time of writing. Apply them as soon as they ship.
  • NetScaler fallout: Expect more victim disclosures and post-compromise findings as forensic investigations of September intrusions conclude.
  • ShinyHunters and PeopleSoft: Watch for any Oracle guidance on the alleged PeopleSoft zero-day, and for further arrests.
  • Microsoft Patch Tuesday: October's release is due on October 13, the following week. Start planning now.

Sources

Citrix NetScaler
FortiMail
Cisco SD-WAN
Apple
Dell and GitLab
Warlock ransomware
OpenInfra Europe
KillSec
ShinyHunters
Research and reports
ShinyHunters and PeopleSoft (official)
DIVD and Zammad (official)
Pentagon DMDC breach
Also notable

Not sure where you stand on any of this?

Our team is available to talk through your exposure to this week's issues.

Contact us