By security practitioners, for security practitioners novacoast federal | Apex Program | novacoast | about innovate
By security practitioners, for security practitioners

Top 10 Cybersecurity News (October 05, 2026): Citrix NetScaler Zero-Day Hits Government, Finance Orgs, Apple Patches Exploited CoreGraphics Zero-Day, and More

WEEKLY TOP TEN: September 28, 2026, 16:00 GMT

  1. Citrix NetScaler Zero-Day Hits Government, Finance Orgs

    Mandiant and Google Threat Intelligence Group report that attackers have exploited CVE-2026-88772, a Citrix NetScaler ADC and Gateway zero-day, since at least early September. Likely victims include government, financial services, technology, education, and legal and professional services organizations across North America and Europe. The exploit arrives over DTLS on UDP/443, bypasses authentication, and crashes the packet processing engine to gain root access. Attackers then planted the WHIPSHOT PHP web shell and the SLAPSHOT Python tunneler to reach internal networks and steal credentials. Citrix has issued fixed builds, and responders recommend patching, rotating appliance credentials, and hunting for altered httpd.conf files.
  2. Fortinet Warns Of FortiMail Zero-Day Exploited In Attacks

    Fortinet disclosed CVE-2026-104286 on October 1, a critical unauthenticated path traversal flaw in FortiMail that attackers are actively exploiting to write arbitrary files and execute code on email security gateways. Affected releases include FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. CISA added the bug to its KEV catalog the same day and gave federal agencies until October 4 to remediate. Because FortiMail sits at the email perimeter and inspects inbound traffic, a compromised appliance can expose message flows and serve as a network foothold. Any instance with management interfaces reachable from untrusted networks should be patched and triaged for compromise.
  3. Cyberattack Hits South Africa’s Air Traffic Operator

    South Africa’s state-owned Air Traffic and Navigation Services (ATNS), which manages roughly 10% of the world’s airspace, discovered ransomware-linked malware in operational technology environments supporting weather services. Preliminary findings pointed to tooling commonly seen in the early stages of ransomware attacks, along with signs of data exfiltration to external IP addresses in China. ATNS believes its technical team contained the intrusion and is seeking outside forensics firms to investigate. The probe covers Port Elizabeth Airport and possibly East London Airport, plus Maputo International Airport in Mozambique for possible insider data theft. The incident highlights mounting ransomware pressure on aviation and transportation critical infrastructure.
  4. Warlock Ransomware Hits Water, Telecom Via SharePoint

    Symantec reports that the China-based Warlock ransomware operator, tracked as Storm-2603 and Longlegs, continues exploiting Microsoft SharePoint flaws against critical infrastructure. Over the past two months, the group hit at least four organizations in Spanish- and Portuguese-speaking countries: a water utility, a telecommunications provider, a regional government body, and a university. In one intrusion, it disabled security software on at least 40 systems and deployed Warlock on 33. The operator chains ToolShell and newer SharePoint bugs, steals ASP.NET machine keys, abuses Visual Studio Code tunnels for covert access, and stages ransomware in SYSVOL to encrypt domain-wide. Unpatched on-premises SharePoint remains a viable entry point.
  5. AI-Driven Attack Breaches DIVD Via Zammad Zero-Days

    The Dutch Institute for Vulnerability Disclosure (DIVD) says an AI-driven attack breached its network by chaining two zero-day vulnerabilities in the open-source Zammad helpdesk platform. The attacking agent hijacked sessions through CVE-2026-102489, achieved remote code execution as the Zammad service user, then escalated to root via CVE-2026-102490 within seconds before moving to other services. CISA added both flaws to its KEV catalog on October 2 with an October 5 federal deadline. Zammad says the session flaw affects only unsupported 6.5 and earlier releases and recommends upgrading to 7.2.0. Organizations running self-hosted ticketing systems should inventory instances and hunt for root-level compromise.
  6. Apple Patches Exploited CoreGraphics Zero-Day

    Apple released iOS and macOS updates fixing CVE-2026-86950, a zero-day in its CoreGraphics framework that Meta’s product security team reported after spotting it in a highly sophisticated attack against specific targeted individuals. Apple has shared few technical details, but CISA has since added the flaw to its KEV catalog. A public proof-of-concept exploit has also been released, which sharply raises the risk of broader abuse beyond the original targeted operation and should be treated as a triage signal. Organizations should push the latest iOS and macOS releases through mobile device management immediately, prioritizing executives, administrators, and other high-value users who attract mercenary spyware operators.
  7. CISA Warns Of Critical Pre-Auth Flaw In MikroTik RouterOS

    CISA warned of CVE-2026-84411, a critical pre-authentication integer underflow in MikroTik RouterOS web-management HTTP request handling. A single crafted request can give an unauthenticated attacker root-level code execution or crash the device. RouterOS versions earlier than 7.24 are affected, and administrators should move to 7.24.5 or later; MikroTik shipped the fix roughly two weeks before the advisory without publishing its own bulletin. No exploitation has been reported, but about 3.5 million RouterOS devices are exposed online and botnet operators routinely target them. The bug is separate from the MikroTrick SSH chain exploited in September. Restrict management interfaces to trusted networks.
  8. WatchGuard Fixes Critical Fireware OS Root Code Flaw

    WatchGuard released Fireware OS updates addressing 15 vulnerabilities, led by CVE-2026-86131, a critical 9.2-rated code injection flaw in BOVPN over TLS client configuration handling. An attacker who controls the remote VPN server a Firebox connects to can execute arbitrary commands as root, with no user interaction or prior privileges required. Fixes ship in Fireware OS 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21. The batch also includes 13 high-severity bugs, among them a SAML authorization flaw granting unauthorized Mobile VPN with SSL access and a DHCP fingerprinting buffer overflow. WatchGuard reports no exploitation, but perimeter firewalls are prime targets. Prioritize appliances using BOVPN over TLS.
  9. Star Blizzard Adopts RedFlick To Push CosmicPulse Backdoor

    Microsoft reports that the FSB-linked Russian actor Star Blizzard has shifted from narrowly targeted spear phishing to large-scale campaigns using a new delivery technique called RedFlick, which deploys the CosmicPulse backdoor after a single user interaction. Since January, the group has run at least 13 campaigns impersonating think tanks and events such as Chatham House and IISS roundtables, affecting more than 100 organizations, primarily in the US and UK. Targets include Ukrainian institutions, NGOs, governments, and financial organizations supporting Ukraine. RedFlick uses MSI installers to create scheduled tasks posing as network components, and the actor now sends phishing from accounts on compromised websites.
  10. Chinese Spies Spoof Anthropic Exec In AI Policy Phishing

    Proofpoint attributes a credential phishing operation to China-aligned TA419, which impersonated a senior Anthropic employee, a former White House Office of Science and Technology Policy official, and a prominent economist to target AI policy experts at US universities, think tanks, and law firms. Lures invited recipients to join a fake AI policy advisory committee or contribute to a Senate report on AI export controls. Recipients who replied received shortened links leading to an attacker-in-the-middle page that steals Microsoft 365 credentials and session cookies using Evilginx and a Browser-in-the-Browser overlay. Proofpoint recommends phishing-resistant authentication such as passkeys for staff working on sensitive policy topics.

Our Threat Operations and Intelligence team compiles a daily digest of the most recent online cybersecurity risks. The previous 10 stories were determined to be most significant during the course of the week, ranked by highest risk, and using multiple sources when available.

Previous Post

Top Conversations to Define Innovate Cybersecurity Summit Scottsdale 2026

Innovate uses cookies to give you the best online experience. If you continue to use this site, you agree to the use of cookies. Please see our privacy policy for details.