Cyber Digest
A daily roundup of key cybersecurity developments across sectors
Executive Summary
Top Stories: ShinyHunters' exploitation of an Oracle PeopleSoft flaw has reached the FBI's own recruitment portal. In a memo obtained by the *New York Times*, senior FBI officials told staff they are "operating under the premise that the threat actor is also exfiltrating [personal information] of all F.B.I. employees"; the FBIJobs.gov portal remained offline on Monday and the bureau has not confirmed the scope, type or volume of data involved. Google's Mandiant reported that the group had restarted exploitation of CVE-2026-35273 and adapted to published defensive guidance, striking organisations that had applied the workaround but never installed the June patch, and planting web shells on dozens of systems worldwide. Dutch police arrested a suspected member of the group in Amsterdam. Elsewhere, Japan's Times Car confirmed that approximately 6.6 million current and former member accounts were exposed after an intrusion detected in early September, and a New Mexico jury found Meta liable for nearly 44 million violations of the state's Unfair Practices Act in a verdict that could cost the company billions. The Citrix NetScaler zero-days remain the live operational story: CISA has given US federal agencies until Wednesday to patch CVE-2026-88771 and CVE-2026-88772, and ASD's ACSC issued a Critical alert on 28 September.
ASD's ACSC issued a Critical alert on 28 September for the Citrix NetScaler vulnerabilities (CVE-2026-88771, CVE-2026-88772), stating that it "understands that at least 2 of these vulnerabilities ... have been under active exploitation globally prior to a patch becoming available", while noting it has not yet received reports of confirmed exploitation in Australia. The alert is addressed to small and medium business, large organisations and government, and directs operators to the vendor bulletin (CTX697096) and to device logging review. Australian organisations running customer-managed NetScaler ADC or Gateway appliances on the affected 14.1 and 13.1 builds carry the same exposure that CISA has ordered US federal agencies to remediate by Wednesday, and NetScaler appliances sit at the perimeter as remote-access and application-delivery gateways, so a successful compromise yields a foothold inside the network without requiring an endpoint to be breached first. ACSC also published new guidance on 28 September — an advisory, "Protect your organisations' AI services", covering the securing of accounts, credentials and connected systems to reduce the risk of unauthorised AI use, disruption and data exposure — following its High alert of 24 September on the risks of AI misalignment to Australian organisations. The Medicare portal incident continues to generate regulatory machinery: a formal AI review is now under way alongside the Prime Minister's task force and the parliamentary inquiry.
The week's dominant pattern is a sequential run at edge infrastructure. Across 22–29 September the corpus's two largest categories were zero-day and vulnerability stories and breach or leak disclosures, and the spine of the week is a queue of internet-facing appliances falling in order: Zyxel GS1900 switches added to KEV on 22 September, Check Point management and gateway flaws on 23–24 September, the Kiteworks shutdown advisory on 26 September, and Citrix NetScaler on 27–28 September. The transferable lesson from the pair of campaigns running today is the same in both: actors are optimising against mitigations rather than against products. Mandiant found ShinyHunters deliberately targeting PeopleSoft deployments that had implemented workarounds but never patched, and Citrix NetScaler exploitation arrived before any fix existed, leaving operators with no mitigation to apply at all. "We applied the mitigation" is a materially weaker control position than it is usually presented as, and it decays silently the moment the mitigation is the only thing standing between an attacker and an unpatched appliance. Agentic AI now appears on both sides of the ledger: Australia's Medicare portal task force and its new AI review on the defensive and regulatory side, JADEPUFFER/Storm-3168 and Carbonato on the adversarial side. Exposure rather than intrusion also remains a dominant disclosure path. Most consequential for the week ahead is that ShinyHunters has moved from exploitation into open conflict with law enforcement — defacing rival Clop's leak site and mounting a public campaign against the FBI even as Dutch police arrested one of its suspected members — a posture that tends to produce more disclosure, not less.
Incident Map
Government 1 story
ShinyHunters' PeopleSoft Exploitation Reached the FBI's Own Portal, and Mandiant Found It Targeting Unpatched Workarounds
The FBI is treating the compromise of its FBIJobs.gov recruitment portal as a breach affecting its own workforce: in a memo obtained by the *New York Times*, senior officials told staff they are "operating under the premise that the threat actor is also exfiltrating [personal information] of all F.B.I. employees". ShinyHunters claims it stole data on almost every agent and job applicant, and samples the group shared with journalists contain agents' personal contact details, family-member information, office and duty assignments and, in some cases, personnel specialties. The intake portal remained offline on Monday and the bureau has not confirmed the type or volume of data involved or attributed the intrusion. Google's Mandiant published a blog on Friday about CVE-2026-35273, an Oracle PeopleSoft flaw disclosed in June that it first reported as a zero-day exploited between 27 May and 9 June against academic institutions, and warned the group had restarted exploitation and "adapted to published defensive guidance, targeting organizations that implemented [workarounds] but did not patch the vulnerability", deploying web shells on dozens of systems across higher education, technology, IT services, healthcare, agriculture, transportation and government. Dutch police confirmed an arrest in the investigation; Krebs on Security identified the suspect as a 23-year-old convicted Dutch cybercriminal.
Defence 1 story
NeedyMantis: a Selectively Deployed Post-Compromise Framework Aimed at Telecoms, Universities and Government Contractors
Microsoft Threat Intelligence disclosed NeedyMantis, a modular post-compromise malware family observed in a limited number of targeted intrusions affecting telecommunications organisations, universities, medical nonprofits, intergovernmental organisations and government contractors. It was found while pivoting from indicators in Kaspersky's DAEMON Tools supply-chain investigation, whose official signed installers carried malicious code from 8 April 2026 until the developer replaced them on 5 May; Microsoft tracks that activity as Storm-3069, assesses it originates from China without attributing it to a Chinese nation-state actor, and says NeedyMantis may be used by more than one operator. The framework combines several loaders written in C++ and x64 shellcode, a custom encrypted archive format, a custom executable file format and modular components, and has been seen masquerading as Microsoft Office, Broadcom, Intel and NVIDIA DLL components. Microsoft stresses the link to DAEMON Tools is narrower than it first appears: it has not observed NeedyMantis itself delivered through a supply chain, only that supply-chain access is one route to the point where the malware is installed. The victimology and limited deployment indicate selective rather than broad use. Users of the affected installers should move to DAEMON Tools 12.6.0.2445 or later.
Global (Macro) 3 stories
A 16-Year-Old Researcher Posed as Titan's Administrator and Reached 17.3 Trillion Rows of Microsoft Analytics Data
A flaw in Titan, an internal Microsoft analytics service, meant it did not verify the signature on login tokens. The researcher, who publishes as Faav, found Titan's web interface was reachable only over a Microsoft VPN, but a separate, publicly documented API endpoint accepted raw SQL. Iterating on a token from his own external Entra test tenant, he walked past tenant, audience and application-allowlist errors to a user lookup; because the token's payload could change while its signature stayed identical, he inferred signature verification was absent and sent a token with the algorithm set to "none" and an empty signature. Setting the `upn` claim to "admin" matched it to user ID 1, which held the Admin role, granting administrator access and the ability to run SQL against 17 connected databases. Its platform metadata database held roughly 25,000 account and email entries, 17,990 employee email records and 15,001 employee organisation records including job titles, departments and hierarchy; he also pulled two single-row samples from Bing analytics containing search, identifier and location fields. Faav reported the flaw to the Microsoft Security Response Center on 5 September, the endpoint was locked down on 9 September and he received a $5,000 bounty on 17 September. He described the 17.3 trillion figure as a storage estimate from database metadata that likely includes historical, duplicated and derived data, and said he did not touch customer data or PII.
Apple Patched a CoreGraphics Out-of-Bounds Write It Says May Have Been Used Against Specific Individuals
Apple released iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 to fix CVE-2026-86950, an out-of-bounds write in the CoreGraphics component that can lead to arbitrary code execution when processing a maliciously crafted file, addressed with improved bounds checking. Apple said it "is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27", and credited Meta Product Security with discovering and reporting the flaw — but offered no detail on how many individuals were targeted, whether any attempts succeeded, or when exploitation began. The affected builds cover iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later and iPad mini 5th generation and later, plus Macs running Tahoe or Sequoia. The disclosure continues Apple's pattern of patching memory-safety flaws in core frameworks while attributing exploitation only to small, targeted campaigns: in February it fixed a dyld memory-corruption issue (CVE-2026-20700, CVSS 7.8) on the same basis.
Three Newly Verified npm Packages Harvest Credentials From a Post-Install Hook, Two Aimed at Minecraft Accounts
OpenSourceMalware added three npm packages to its human-verified malicious-asset set on 28 September, each executing on `npm install` through a `postinstall` hook. fabric-asset-pipeline and fabric-render-bridge, both rated critical, present as Fabric render tooling but ship no rendering functionality: they read Minecraft launcher credential stores — `launcher_accounts.json` and `launcher_profiles.json` for the official launcher, plus PrismLauncher, MultiMC, TLauncher, Modrinth, PolyMC and GDLauncher — along with a session dump from the OS temp directory, extract access and refresh tokens, and POST them and the recovered username to a hardcoded Discord webhook, together with `os.hostname()`, `os.userInfo().username`, `os.platform()` and `os.release()`. chalk-figlet, rated high, instead decodes a hex-obfuscated URL to `http://104[.]234[.]65[.]75:700/setup.exe`, downloads a file named `RuntimeBroker.exe` over plain HTTP from a bare IP into the temp directory and executes it with a hidden window, gated on the npm lifecycle event. Google's OSV database carries advisory MAL-2026-17224 for fabric-asset-pipeline.
Financial Services 1 story
Bitget Named the Entry Point for Its $388 Million Loss: a Flaw in a Third-Party Security Product
Bitget says the attacker who took roughly $388 million from the exchange gained access through a vulnerability in a third-party security product the exchange used, exploiting it to obtain high-level internal credentials and then, on 24 September, using them to send fraudulent withdrawal commands to Bitget's wallet system. Transfers from hot and warm wallets must still be approved before they are signed; the stolen funds came from those wallets and cold storage was unaffected. This is the new material in the reporting: the exchange had said last week only that a critical backend system in its wallet infrastructure had been compromised and used to spoof transaction data and trigger its approval process, without explaining how the attacker got in. CEO Gracy Chen described the attack in a livestream on Monday, and Bitcoin withdrawals have restarted. The company has not named the third-party product, which matters because an unpatched vendor appliance or agent holding privileged wallet credentials is an exposure shared by every other customer of that product — and one Bitget's own controls could not see.
Healthcare 1 story
Poland's Medyc Breach Exposed Patient Data Through an SQL Injection, and the Regulator Has Ordered an Audit
Qbusoft, the developer of the Medyc medical records and practice management platform used by healthcare providers across Poland, was breached after an attacker exploited an SQL injection vulnerability in the application interface in late August, according to a notification issued by one of the affected providers. Medyc said on Friday that the attackers obtained names, national identification (PESEL) numbers, home addresses, phone numbers and email addresses. The company has not confirmed the theft of medical records, but the Addiction and Psychiatric Treatment Centre in Inowrocław said it was informed that Qbusoft had found evidence the attackers executed scripts targeting database tables containing medical information, making it "highly likely" that some records were taken. The centre said records covering patients treated in its day treatment unit between July 2024 and August 2026 were in scope, that an encrypted archive of a database was transferred outside Qbusoft's systems, and that the intrusion was detected overnight on 9 September. Qbusoft fixed the flaw on the day it was discovered, restricted database permissions and rotated credentials. Poland's data protection authority ordered an audit of the company, and Digital Affairs Minister Krzysztof Gawkowski criticised Qbusoft for not reporting initially to CERT Polska; the Central Bureau for Combating Cybercrime is investigating.
Legal Services 1 story
A New Mexico Jury Found Meta Deceived Consumers Nearly 44 Million Times, With Penalties That Reach Billions
A New Mexico jury found Facebook violated the state's Unfair Practices Act almost 44 million times by misleading consumers about its data privacy practices. Each violation carries up to $5,000 in civil penalties, leaving the final figure to a judge in the coming weeks; New Mexico is also pressing for court-ordered changes to Facebook's data practices. Jurors found the company told users they controlled how their information was shared and that it did not buy or sell users' private data, particularly with advertisers. They also held that its statements about hate speech and misinformation were "willfully deceptive" — including claims that it did not profit from either, that it deleted harmful misinformation, that it did not tolerate hate speech, and that it applied no special protections for particular groups or exceptions for politicians or newsworthiness. Separately, the jury found Facebook did not honour promises, made after the Cambridge Analytica scandal, to investigate apps that accessed significant amounts of user data, conduct forensic audits, stop working with developers who misused data and alert affected users. The verdict follows $942 million in New Mexico civil penalties in March and a $17 billion children's-online-safety settlement with California in August.
Retail & Entertainment & Sport 1 story
An Ad Blocker With Two Million Users Was Exfiltrating Data, Researchers Say, Complete With Google's Approval
Bay Area Labs has identified Poper Blocker, a Chrome Web Store extension presenting as an ad blocker, as spyware that exfiltrates sensitive information — and one carrying every signal of legitimacy a user could check. It displays a "Featured" badge, its developer holds Google's "Established Publisher" status, it has a 4.8 out of 5 rating from more than 81,000 reviewers, and it claims over two million active users. The researchers say millions of people have installed infostealers disguised as ad-blocking extensions, in part because Google's own storefront provides the seals of approval those campaigns rely on. The practical point is that nothing visible to a shopper on the listing page distinguishes the extension from a legitimate one, so store vetting and enforcement — not user judgement — are the controls that matter here; the finding also sits on the same surface as earlier waves of fake AI-assistant extensions on the same store. Browser extensions should be treated as privileged software with access to every page a user visits, and reviewed accordingly rather than installed on the strength of a rating.
Transport 1 story
Japan's Times Car Confirmed 6.6 Million Member Accounts Were Exposed in a September Intrusion
Times Car, the Japanese car-sharing service operated by Times Mobility under the Park24 Group, has confirmed that approximately 6.6 million current and former member accounts were compromised. The company disclosed the incident on 25 September, saying a third party had accessed its systems at the beginning of the month and that it blocked the unauthorised access on 26 September; it confirmed the data theft in an update on 28 September. Exposed fields include full name, physical address, date of birth, telephone number, email address, driver's licence information and identity-verification document images such as photographs of licences, account passwords and linked service IDs, plus department names for corporate account members. Times Car says passwords were stored in a form that cannot be restored and that credit card information was unaffected; there is currently no evidence the stolen data has been distributed online. The company is conducting a forensic investigation with an external expert and will notify affected members in stages, and its services continue to operate normally. Times Car claims four million active members, 84,000 vehicles and 29,000 stations across all 47 Japanese prefectures.
Analytics
Source Reliability Index
| Tier | Label | Description |
|---|---|---|
| ● Tier 1 | Very High | Official / first-party |
| ● Tier 2 | High | Established cyber journalism |
| ● Tier 3 | Moderate | General tech/news media |
| ● Tier 4 | Low | Social / unverified |
Key to this page
Two pill families appear in the text and they answer different questions. A CVE pill colours severity — a measured CVSS band from the National Vulnerability Database. A threat-actor pill colours attribution confidence — how well-corroborated the naming is, which is a claim rather than a measurement. Both are links: a CVE opens the ATT&CK matrix or its wiki page, an actor opens its wiki page.
CVE identifiers
- CVE-XXXX-NNNNCritical · CVSS 9.0+
- CVE-XXXX-NNNNHigh · CVSS 7.0–8.9
- CVE-XXXX-NNNNMedium · CVSS 4.0–6.9
- CVE-XXXX-NNNNLow · below 4.0
- CVE-XXXX-NNNNNo severity resolved — not the same as low
Threat actors · MITRE ATT&CK
- APT29State attribution stated by MITRE ATT&CK
- ShinyHuntersSelf-declared, or criminal-reporting attribution
- Transparent TribeContested — ATT&CK hedges, or two plausible sponsors
- ZIRCONIUMNo attribution in MITRE ATT&CK
Story signals
- ● Tier 1/4Source reliability — 1 official, 4 leads only
- VerifiedCorroborated by a second source or the principal
- ReportedSingle outlet, or a claim still in progress
- UnverifiedA claim we could not corroborate
- ConfirmedBreach acknowledged by the victim or a regulator
- ProbableBreach indicated but not yet acknowledged
- IOCs · FamilyLive abuse.ch indicators exist for that malware family
A collapsed Indicators of compromise block under a story lists defanged abuse.ch indicator values. The defanging is deliberate — never click, resolve or fetch them. An indicator corroborates a report; it never proves one.
Full methodology, evidence grading and caveats: Methodology & reading guide →