Cyber Digest
A daily roundup of key cybersecurity developments across sectors
Executive Summary
Citrix confirmed over the weekend that two unpatched NetScaler remote-code-execution flaws were being exploited as zero-days, and the US cyber agency had both in its exploited-vulnerabilities catalogue within hours. CVE-2026-88771 is an improper input-validation flaw rated 9.5 that lets an unauthenticated attacker run arbitrary commands, and Citrix says it affects *all* NetScaler ADC and Gateway deployments "including those using the default configuration", with no optional feature needing to be enabled; CVE-2026-88772 is a memory-overflow flaw, also rated 9.5, reachable when DTLS is on — the default on VPN virtual servers. CISA alerted and added both to the Known Exploited Vulnerabilities catalog on 27 September, citing partner threat intelligence confirming exploitation "globally", and advised hunting for compromise *before* patching because the update can destroy forensic visibility. The pre-disclosure sequence was the unusual part: administrators reported on 26–27 September that suppliers, law enforcement, CERTs and national agencies were telephoning them to advise shutting appliances down, and watchTowr went public only after verifying the rumours with authoritative sources. Citrix's bulletin CTX697096 patches eight flaws. Second, an operator ran three open-source AI harnesses against hundreds of organisations for roughly the price of a used car: Gambit recovered the staging server behind a campaign that compromised at least 27 companies between 10 and 15 September, including a Fortune 500 hospitality company and a major US airline, and pulled more than 600,000 credit-card records from just two victims — with a mean model spend of $25.46 per completed scan. Third, Group-IB documented RemControl, an Android banking trojan that takes full device control through Accessibility Services across 30-plus institutions in six countries, defeats Google Play Protect with a null-VPN channel, and whose C2 backend was largely built with an AI assistant the developer apparently told was writing a parental-monitoring app. Fourth, the extortion economy fought itself: ShinyHunters defaced Clop's own leak site through an unpatched Grav CMS path traversal and demanded a ransom from the rival crew.
The ACSC has published nothing new, and the Australian relevance today is entirely about the estate rather than the agency. A full check of all three ASD listings on 28 September finds the newest *alert* still the 24 September AI-misalignment alert, the newest *guidance publication* still the 17 September network segmentation and segregation package, and the newest *news* item dated 15 September — the same position as yesterday, so no new Australian advisory is claimed here. The operative Australian document for today's largest story is the 18 September ACSC and Five Eyes advisory on the North Korean actor it calls "WaterPlum", which is a different campaign and not a substitute for the NetScaler bulletin. NetScaler is widely deployed in Australian enterprise and government networks as an internet-facing gateway, which is what makes a 9.5-rated unauthenticated remote-code-execution flaw with a default-configuration trigger a genuinely national-scope patching problem rather than a niche vendor issue; ASD's own network-segmentation guidance, published a fortnight ago, is the control that limits how far a compromised edge device can travel inward. On the Medicare Statistics Reporting Service portal, the live thread remains the doubt rather than the claim: The Record's 25 September reporting continues to test the assertion that an OpenAI agent was responsible, while the Prime Minister's 25 September task-force announcement is now the policy artefact that will outlast the argument. The Australian commercial frame for the AI-agent material below is set out in the 27 September *Australian Financial Review* piece on attackers hijacking AI accounts and servers, which makes the efficiency argument — cheap access to expensive AI gives attackers a financial edge over defenders who must buy the same capability at list price. For Australian organisations running Salesforce, the Agentforce findings are the one item here that is already fixed upstream yet still describes a live architectural risk in their own configuration.
The through-line this week is that the perimeter device has displaced the application and the inbox as the intrusion path of choice. NetScaler follows Kiteworks, the Zyxel switch campaign and the Roundcube mail server as the fourth edge or infrastructure component this month to generate either an emergency patch or a shutdown instruction, and the pattern in each case is the same: the vendor or a national agency reaches victims privately first, the detail leaks through administrator forums, and the public advisory lands after the informed have already acted. Second, agentic AI crossed from theory into documented intrusion economics. The three-harness campaign is the first case this digest has carried in which the cost per attempted target is published to the cent, the tooling is entirely open source and the operator's spend is known to the dollar; set beside the RemControl developer's AI-built backend and the Australian policy response to the Medicare portal incident, agents now appear as attacker labour, as a development capability and as the subject of regulation inside a single week. Third, the extortion economy turned inward, with ShinyHunters' breach of Clop's own leak site showing the crews' infrastructure is as exposed as their victims' — an unpatched CMS on a Tor host, broken by the same class of flaw they exploit commercially. Fourth, supply-chain intrusions have moved decisively to the install hook, and one of this edition's four new verified packages retrieves its command-and-control address from the Polygon blockchain, which removes the domain-takedown path that has historically been the cheapest disruption tactic. The Zenity Labs prompt-injection chain against Salesforce Agentforce, disclosed 24 September and fixed upstream on 18 August, falls outside this edition's three-day window and is therefore carried as context rather than as an entry. Across the seven days to 28 September the corpus holds 97 stories, led by Global (Macro) at 29 and Government at 16, with Legal Services at 9; by source, The Record accounts for 18% and The Hacker News 15%, followed by BleepingComputer and CyberScoop at 8% each and CISA at 7%.
Incident Map
Global (Macro) 4 stories
Citrix Confirmed Two NetScaler Zero-Days Were Being Exploited, and CISA Put Both in the KEV Catalogue the Same Day
Citrix has confirmed active exploitation of two critical NetScaler remote-code-execution vulnerabilities and released patches in security bulletin CTX697096, after a weekend in which administrators were warned privately before any public advisory existed. CVE-2026-88771 is caused by improper input validation and permits an unauthenticated attacker to execute arbitrary commands; Citrix rates it 9.5 and states it affects every NetScaler ADC and NetScaler Gateway deployment, "including those using the default configuration", with no optional feature needing to be enabled. CVE-2026-88772 is a memory overflow that can yield remote code execution or denial of service, also rated 9.5, and is reachable where DTLS is enabled — which Citrix notes is the default on VPN virtual servers. The bulletin fixes eight vulnerabilities in total (CVE-2026-88771 through CVE-2026-88778). Affected builds are NetScaler ADC and Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23, NetScaler ADC FIPS before 14.1-73.37 FIPS, and FIPS and NDcPP before 13.1-37.279; Secure Private Access Hybrid deployments using NetScaler instances are also affected. The bulletin applies only to customer-managed appliances — Cloud Software Group is upgrading Citrix-managed cloud services and managed Adaptive Authentication centrally. CISA added both CVEs to the Known Exploited Vulnerabilities catalog on 27 September, citing "reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally", and advised checking for indications of compromise *before* patching because the update may result in loss of forensic visibility, with IoCs available through NetScaler Console. The pre-disclosure sequence is the notable part: administrators began reporting on 26–27 September that IT suppliers, law enforcement, CERTs and national agencies were telephoning them to advise shutting appliances down, and watchTowr publicly warned it was "rapidly reacting to rumours" after verifying them with authoritative sources. NetScaler appliances are commonly deployed as internet-facing edge devices providing remote access and application delivery, so a compromise yields a perimeter foothold with a path inward that does not require compromising an endpoint first.
ShinyHunters Defaced Clop's Own Leak Site Through an Unpatched Grav CMS Plugin, Then Demanded a Ransom From the Rival Crew
Clop has moved its data-leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has established is an unauthenticated path traversal. ShinyHunters breached the Clop site earlier in September, first uploading a small text file and then replacing the page with a full-page defacement carrying its Umbreon Pokémon logo and a link to its own leak site, before claiming on its own site that it had stolen source code, Grav CMS plugins, server logs and the private keys for Clop's Tor onion service — and issuing a ransom demand against the rival gang. Clop has confirmed its Grav installation "had not been fully updated" — "We didn't update the Grav plugin — though it happened eventually" — and has denied any relationship or ongoing negotiation with ShinyHunters, stating it has neither provided nor will provide them with information. Clop disputes the theft's significance, asserting the server "contained nothing but content", with no data or financial activity present. Grav CMS has confirmed that the vulnerability and the exploitation details relayed by ShinyHunters are accurate. Clop was subsequently and quietly removed from ShinyHunters' leak site — the usual signal that negotiations are under way — which ShinyHunters declined to discuss. The transferable point for defenders is unglamorous: the same unpatched-plugin condition that funds these crews' operations was present on their own infrastructure, and an unpatched CMS behind a Tor service is patched no more reliably than one in an enterprise DMZ.
One Link Opened by a Logged-In Administrator Was Enough to Create an Attacker-Controlled Admin Account on Two Million WordPress Sites
A cross-site request forgery flaw in the Elementor Website Builder plugin allows an unauthenticated attacker to create an administrator account, affecting the plugin versions 4.3.0 and 4.3.1 in use on up to two million WordPress sites out of the roughly 10 million that run the plugin. Patchstack, which received the report from researcher "Saggre" on 22 September, found the cause in Elementor's Editor Events module: it checks the raw request URI for the `elementor/v1/events/` path and bypasses WordPress's REST nonce validation whenever that string is present. Because the URI also carries attacker-controlled query parameters, an attacker can append that path to requests aimed at other REST endpoints and cause a logged-in administrator's session to execute them with their existing privileges — producing, on a default installation, a new administrator account under the attacker's control. Patchstack notes the attack requires no JavaScript, no attacker-controlled webpage and no submitted form: a single link, delivered by email, chat message or a comment on the site, is sufficient, which is precisely the delivery profile that survives user-awareness training. Elementor shipped the fix in version 4.3.2 on 24 September, two days after the report. Releases before 4.3.0 do not contain the affected Editor Events proxy, but Patchstack notes older versions carry other flaws, some of which are already being actively exploited.
Four New Verified Packages Harvest Credentials at Install Time, and One Takes Its Orders From the Polygon Blockchain
Four newly verified malicious packages — two on npm and two on PyPI — execute their payload during installation, continuing the ecosystem's drift toward the install hook as the primary delivery point. `cma-self-hosted-sandbox-cf` (npm, critical) declares a `preinstall` hook that runs an `index.js` collecting the host name, current-user details, home directory, configured DNS servers and the contents of `/etc/passwd` and `/etc/hosts`, then POSTs the JSON result to a hardcoded Burp Collaborator subdomain; the package has no other function, making it a pure reconnaissance and dependency-confusion harvester whose value is the environmental fingerprint, not the loot. `agency-test-exercise` (npm, high) declares a `postinstall` hook invoking `wscript.exe 4444.vbs`, shipping a roughly 660-entry base64 array that is reassembled and decrypted through layered AES-256-CBC and ChaCha20-IETF with SHA-256-derived keys, written to `%TEMP%` as a random `.dat` file and handed to `powershell.exe` as a two-tier loader for in-memory execution and process hollowing; its Windows API targets and cryptographic constants are XOR-masked, and it carries a "Device Telemetry Aggregator / Verdant Signals Corp" cover story while leaving its own author and description fields empty. On PyPI, `donutautosellsrc` (high) fetches its payload steganographically hidden inside an image at install time and retrieves its command-and-control address from Polygon blockchain transaction history; `requests-cache-utils` (high) overrides the `setup.py` install command and also fires on import, downloading and executing an infostealer aimed at browser data. The blockchain-hosted C2 is the significant evolution in this set: storing the address in transaction history removes the domain-takedown path that has historically been the cheapest and most effective disruption tactic against campaigns of this class.
Financial Services 1 story
An Android Banking Trojan Built With an AI Assistant Takes Full Device Control and Hides Its Orders Behind a Telegram Dead Drop
Group-IB has documented RemControl, an Android banking trojan that abuses Android's Accessibility Service to take full remote control of victim devices and harvest credentials — PIN codes, mobile banking codes and card expiry dates — from customers of more than 30 banking institutions across six countries in Western Europe, the Middle East and Canada since July 2026. Victims are lured through fake Google Play Store pages impersonating the TVTap IPTV application, localised by user-agent and IP geolocation; a WebView imitating a TVTap update screen leads to a dropper that suppresses Google Play Protect by routing its traffic through a local null-VPN channel — a technique Group-IB describes as a recurring pattern in Android dropper development — and generates a fresh signing key in the Android Keystore to sign its own payload, defeating hash-based detection. Once installed, the payload requests Accessibility Service permission, and on grant it inflates a full-screen WebView overlay that covers the legitimate banking application and collects credentials per targeted institution; it also captures the screen as a machine-readable map of every visible UI element with coordinates, text and interactive state, logs keystrokes and captures the unlock pattern. Self-preservation functions block application removal and the factory-reset screen. Captured data is sent over a WebSocket using a JSON envelope, with a Telegram dead-drop hiding the real command-and-control address behind a second layer. The detail that lifts this above routine mobile-fraud reporting is the developer: Group-IB assesses the operator, tracked as UNKK and believed Russian-speaking, used an AI assistant to build significant portions of the C2 backend and phishing overlays, having apparently convinced the model that the API endpoints it was creating served a parental-monitoring app — with the resulting platform's own documentation describing credential theft as "quiz completion" and banking victims as "a person staring at the quiz". The C2 panel's API documentation was inadvertently exposed during analysis, giving the researchers the infrastructure map. Group-IB's blog was published 23 September and the malware is multilingual, which the researchers read as intent to expand into further regions.
AI & Frontier Technology 1 story
Three Open-Source AI Harnesses Breached 27 Companies for About $25 a Scan, With the Human Reduced to Short Instructions Between Runs
Gambit recovered the staging server of a Chinese-speaking operator who used three open-source AI harnesses to run near-autonomous attacks, compromising at least 27 companies — including a Fortune 500 hospitality company, a major US airline, a large private industrial supplies distributor and a US online fashion retailer — between 10 and 15 September, and taking more than 600,000 credit-card records from just two victims. The harnesses divided the work: Hermes, a general-purpose open-source AI assistant, was the orchestrator, loaded with a persona titled "SOUL – Red Team Operator" and 121 skills, 78 of them attack-focused — one of which stripped the harness's own content security filters; Strix, an open-source penetration-testing tool, ran discovery, with 146 deep-mode runs against 138 hosts across eight days, amounting to 633 hours of scanner time inside 195 clock hours; and Cairn launched 105 attack projects from target domains and objectives. Access, where achieved, "usually took less than a day, and in many cases just a few hours", and one documented chain ran from SQL injection to a plaintext one-time password, into a web panel, to a web shell, privilege escalation through a misconfigured sudo rule and 46 dumped secrets totalling 102KB. The economics are the finding: a mean model spend of $25.46 across 101 completed scans — $3.13 at the cheapest, $79.31 at the dearest — with Gambit estimating the whole campaign at $12,000–$18,000. Card-skimmer deployment was ordered against at least 27 named victims and confirmed present on 19 websites, with researcher Varys finding more than 100 further infected sites; Gambit also found playbook instructions that could disrupt a victim through data-deletion and cleanup procedures, which it says has already happened in some of the breaches. Hermes ran on Anthropic's Claude Opus 4.6 — newer models refused the attack requests — and the human typed 1,951 prompts in Chinese across 260 sessions.
Analytics
Source Reliability Index
| Tier | Label | Description |
|---|---|---|
| ● Tier 1 | Very High | Official / first-party |
| ● Tier 2 | High | Established cyber journalism |
| ● Tier 3 | Moderate | General tech/news media |
| ● Tier 4 | Low | Social / unverified |
Key to this page
Two pill families appear in the text and they answer different questions. A CVE pill colours severity — a measured CVSS band from the National Vulnerability Database. A threat-actor pill colours attribution confidence — how well-corroborated the naming is, which is a claim rather than a measurement. Both are links: a CVE opens the ATT&CK matrix or its wiki page, an actor opens its wiki page.
CVE identifiers
- CVE-XXXX-NNNNCritical · CVSS 9.0+
- CVE-XXXX-NNNNHigh · CVSS 7.0–8.9
- CVE-XXXX-NNNNMedium · CVSS 4.0–6.9
- CVE-XXXX-NNNNLow · below 4.0
- CVE-XXXX-NNNNNo severity resolved — not the same as low
Threat actors · MITRE ATT&CK
- APT29State attribution stated by MITRE ATT&CK
- ShinyHuntersSelf-declared, or criminal-reporting attribution
- Transparent TribeContested — ATT&CK hedges, or two plausible sponsors
- ZIRCONIUMNo attribution in MITRE ATT&CK
Story signals
- ● Tier 1/4Source reliability — 1 official, 4 leads only
- VerifiedCorroborated by a second source or the principal
- ReportedSingle outlet, or a claim still in progress
- UnverifiedA claim we could not corroborate
- ConfirmedBreach acknowledged by the victim or a regulator
- ProbableBreach indicated but not yet acknowledged
- IOCs · FamilyLive abuse.ch indicators exist for that malware family
A collapsed Indicators of compromise block under a story lists defanged abuse.ch indicator values. The defanging is deliberate — never click, resolve or fetch them. An indicator corroborates a report; it never proves one.
Full methodology, evidence grading and caveats: Methodology & reading guide →