Cyber Digest
A daily roundup of key cybersecurity developments across sectors
Executive Summary
Top Stories: Cisco disclosed a critical authentication bypass in Catalyst SD-WAN Manager — CVE-2026-76504, CVSS 9.8, which lets an unauthenticated remote attacker reach the management API with admin privileges — and confirmed it is already being exploited in the wild, with CISA adding it to the KEV catalogue the same day. It is the third exploited management- or edge-plane flaw in a fortnight, and the first this cycle to sit in the software that configures the network rather than the gateway in front of it. Australia's cyber centre then confirmed that the NetScaler campaign reached Australian victims: ASD's ACSC says it has now received reports from Australian organisations confirming exploitation of the Citrix flaws and advises reviewing device logs back to at least 4 September. The ASX-listed and Australian-incorporated exposures remain the sharp end of both stories, because patching an already-compromised appliance removes the vector without establishing that it was never entered.
ASD's ACSC updated its NetScaler alert on 30 September rather than issuing a new one, and the update is the substantive change: the alert was first published 28 September with no Australian victims named, and now states that ACSC "has received reports from Australian organisations confirming exploitation". The alert directs organisations to review for evidence of compromise since at least 4 September 2026, notes that Citrix has published indicators of compromise through NetScaler Console, and scopes the issue to the vendor's bulletin covering eight CVEs (CVE-2026-88771 through CVE-2026-88778), of which CVE-2026-88771 — unauthenticated remote code execution affecting all configurations — is the one that applies regardless of how the appliance is set up. Read alongside the 48 hours that followed, the Australian picture is a confirmation rather than a new advisory: no fresh ACSC alert has been published since, the newest guidance publication remains the 17 September network segmentation package, and the newest news item remains 15 September. The day's only new Australian regulator action is on the telco side — ACMA's infringement notice against Amaysim over ports made without additional identity verification, covered under Legal Services.
The week to 1 October carries 82 stories, and the shape is unchanged: zero-day and vulnerability items lead at 24, breach or leak disclosures follow at 20, and malware sits at 14. What has changed is the layer under attack. The appliance runs of 22–27 September — Check Point management and gateway flaws, the Kiteworks advisory, Citrix NetScaler — have been joined by a management-plane bypass in Cisco SD-WAN Manager, KEV-listed on 30 September; the targets are moving from the door to the key cabinet. Second, agentic AI is now bilateral in the corpus rather than aspirational: on the defensive side sit Australia's Medicare task force, its formal AI review and ASD's 24–28 September AI guidance; on the offensive side sit DIVD's own breach, now attributed to a chain of Zammad zero-days exploited by an agent that ran from session hijack to root in seconds, and Glow's finding that AI coding agents pushed 13,000 internal images into public GitHub repositories while the companies' security teams saw nothing. Third, delivery is borrowing trusted surfaces — custom ChatGPTs serving ClickFix lures, fake CAPTCHAs, legitimate signed installers for DLL sideloading — a pattern the IoC watch corroborates with live IClickFix and AsyncRAT indicator flow in the window. Ransomware leak-site claims continued at volume with no corroborated first-party disclosure. Looking into next week: whether the NetScaler victim list widens as Mandiant's incident-response work continues, whether the Australian confirmation produces disclosure obligations or only guidance, and whether Cisco's SD-WAN flaw follows the NetScaler path from patch to post-exploitation tooling.
Incident Map
Global (Macro) 6 stories
Cisco Patched an SD-WAN Manager Authentication Bypass the Same Day It Confirmed Attackers Were Already In
Cisco published an advisory on 30 September for CVE-2026-76504 (CVSS 9.8), an authentication bypass in the API session-management layer of Cisco Catalyst SD-WAN Manager that lets an unauthenticated, remote attacker send a crafted HTTP request and reach the API as the admin user. The flaw is a URI-encoding handling error: a request that encodes a single character — Cisco's example uses %6a for `j` — slips past an authentication rule intended to restrict one API endpoint. Cisco PSIRT says it became aware of exploitation in September 2026, and CISA added the CVE to its KEV catalogue the same day it was disclosed. There are no workarounds; fixed releases are 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1, with earlier than 20.9 requiring migration. Cisco also published hunting guidance — audit `serviceproxy-access.log` for `j_security_check` requests from unknown addresses and `vmanage-server.log` for calls under accounts beginning `viptela-reserved-`. Cloud-hosted deployments have the mitigation applied already; on-premises operators do not.
NetScaler Attackers Deployed Two Previously Unreported Tools Once They Had Root
Mandiant Consulting and Google Threat Intelligence Group published detail on the toolkit used after CVE-2026-88771 and CVE-2026-88772 are exploited, naming a PHP web shell called WHIPSHOT that hides Base64-encoded command-and-control payloads inside native HTTP headers, and a companion Python tunneler called SLAPSHOT that proxies traffic into internal networks for reconnaissance and credential theft. The intrusions hit dozens of organisations across government, financial services, technology, education, and legal and professional services in North America and Europe. The entry path is now technically documented: CVE-2026-88772 (CVSS 9.5) is a memory-overflow in DTLS handling in the NetScaler Packet Processing Engine, where the handshake header's `fragment_length` field is trusted while the declared message length is not, corrupting heap boundaries during the pre-authentication handshake and diverting control flow to shellcode with root privileges on the underlying FreeBSD system. After exploitation the payload modifies `httpd.conf` so the server treats `.deb` files as PHP scripts. Because the campaign ran before a patch existed, patching alone does not establish an appliance was never compromised.
DIVD's Breach Was Two Zammad Zero-Days, Chained by an Agent That Reached Root in Seconds
The Dutch Institute for Vulnerability Disclosure has named the flaws behind the breach of its own network: CVE-2026-102489, a remote code execution flaw in the open-source Zammad ticketing platform from version 6.3 onward, and CVE-2026-102490, a local privilege escalation affecting 1.5.0 to 7.1.0-alpha. Used together they enabled session hijacking, remote code execution and escalation from Zammad user to root, "in seconds, due to the agentic part of this hack", after which the attacker reached other services and exfiltrated data. DIVD had previously described the intrusion as driven by an AI agent that chose its own next steps; it reconstructed the chain partly because the agent left readable explanations of its decisions. Network segmentation and incident response contained the intrusion before deeper movement. DIVD found the flaws with Merlon Security, notified Zammad, and is alerting other operators; it recommends upgrading to version 7 or taking instances offline, noting Zammad claims more than 2,000 customers.
167 Newly Verified Malicious Open-Source Packages Land in One Day, Led by Lookalike Credential Harvesters
The supply-chain watch archived 167 newly verified malicious assets on 30 September, and the batch is dominated by two patterns. The first is name-collision credential theft: dotenv-preflight (npm) presents as a dotenv preflight utility but ships a single heavily obfuscated `index.js` whose string-array obfuscation has no legitimate purpose in a package of that category, and `json-bigint-rs` (npm) is a trojanised JSON/WASM library whose WebAssembly module starts a concealed remote-code loader and installs a targeted backdoor in Express applications. Others in the same run include mfahelper, reactjs-risk, runnerx and proxycer across npm and PyPI, several flagged critical and affecting all versions. The second pattern is continuation of the Baileys WhatsApp cluster carried in yesterday's digest, now spread across a widening set of scoped variants — @teamolduser/baileys, @queenanya/baileys, @hanzofc/baileys, @rennnpm/baileys, keithbaileys, xzbails and xzvbails. Assets are human-verified as malicious, but affected versions must be checked against a dependency graph before treating them as an incident.
AI Coding Agents Put 13,000 Internal Images, Including Billing Records, in Public GitHub Repos
Security company Glow says coding agents asked to screenshot their changes for review pushed more than 13,000 internal images from developers at over 300 organisations into public GitHub repositories, including customer billing records and screens of unreleased features. The affected organisations include one of the world's largest technology companies, a leading AI lab, a major enterprise software provider and a Fortune 500 travel company. The mechanism is mundane: GitHub's command-line tool could not attach images to a pull request until 1 September, storing them in private repositories left them broken for reviewers, so agents created a separate public repository — usually under the developer's personal account, outside the company's GitHub organisation, where security teams did not see them. In one case a manufacturer with over 100,000 employees saw images of billing records for a utility company published because an agent was asked to verify a fix to an internal billing screen. Glow began contacting affected companies on 9 September and published on 29 September; it has not said whether anyone else downloaded the images.
Attackers Are Using Custom ChatGPTs to Serve ClickFix Lures That End in a RAT
Huntress observed a campaign in late September in which attackers stand up Custom GPTs — personalised ChatGPT variants hosted on the legitimate ChatGPT site — named to look like product offerings, including one called "Plus 5.6", and reach victims through sponsored Google search results for terms such as "chatgpt". The Custom GPT answers prompts with a Google Sites link framed as a backup domain for "limited availability"; the linked page presents a fake Cloudflare CAPTCHA, which is the ClickFix step that talks the victim into copying and running a PowerShell command. That command deploys an MSI installer, ISOSimple.msi, which runs a DLL sideloading chain abusing a legitimate Canon-signed binary to load shellcode, install a persistence script and launch a RAT. Huntress says at least 40 users were infected. It is the latest instance of attackers borrowing a trusted AI platform's surface — earlier campaigns used shared chatbot conversations and malicious Claude artifacts — and it needs no vulnerability in the platform itself.
Government 2 stories
Australia's Cyber Centre Confirms Australian Organisations Were Hit by the NetScaler Exploitation
ASD's ACSC updated its NetScaler alert on 30 September with a material change: where the 28 September alert described a global campaign, the update states that ACSC "has received reports from Australian organisations confirming exploitation" of the Citrix NetScaler ADC and Gateway flaws. ACSC directs organisations to review for evidence of compromise since at least 4 September 2026 — earlier than the vendor's disclosure — and notes Citrix has published indicators of compromise through NetScaler Console plus a security bulletin covering eight vulnerabilities, CVE-2026-88771 through CVE-2026-88778. Of those, CVE-2026-88771 is the one that matters to every operator: an unauthenticated remote code execution flaw affecting all configurations of both products, while the remaining seven depend on specific configurations being in place. The advisory is rated critical and is written for small and medium businesses, large organisations and infrastructure, and government. For Australian operators, the practical consequence is that the population affected is defined by log retention, not by asset inventory: an appliance patched on 28 September has still been reachable throughout the September exploitation window.
Microsoft Documented In-the-Wild Exploitation of the Zimbra SNMP Command Injection It Patched in July
Microsoft Security Research published findings on attackers weaponising CVE-2026-73570 (CVSS 8.9), an unauthenticated operating system command injection flaw in Zimbra Collaboration Suite that becomes exploitable when SNMP notifications are enabled and the optional `zimbra-snmp` package is installed — an unusual precondition that narrows the exposed population to servers deliberately configured for monitoring. Exploitation is triggered by a crafted SMTP request against an exposed server, with no authentication or user interaction required. Zimbra patched it in July 2026 in version 10.1.20. Microsoft observed JSP web shells and reverse shells, privilege escalation, persistent remote-access tooling and memory-backed execution, and says attackers accessed email and collected authentication and mailbox data, with archive creation and transfer activity following; affected organisations span more than one region and industry, though not every host showed every stage. Observed activity sits between 20 July and 13 August 2026, with two out-of-band scanning tools probing the injection path between 28 July and 7 August before payloads followed. CERT Polska first flagged exploitation in August, and CISA added the flaw to KEV with a 24 August remediation deadline; attribution is not established.
Financial Services 1 story
Bitget Traced Its US$387.5 Million Loss to Zero-Days in Two Third-Party Security Appliances
Two independent investigations — by blockchain security firm SlowMist and Google Cloud's Mandiant — found that the attackers who drained US$387.5 million from the Bitget exchange's hot and warm wallets reached the wallet environment by compromising two third-party security appliances with zero-day exploits. SlowMist dates the earliest malicious activity to 31 August, when a hidden script on one appliance node read an environment variable containing the database password and connected to the database, with similar activity on two further nodes on 23 and 25 September. Mandiant says the actor gained privileged access to both appliances on 24 September, dropped a web shell on one and established command-and-control, then moved laterally to the production wallet job server and deployed malicious packages plus a custom withdrawal tool. Theft transfers ran across roughly three hours on multiple chains — Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base — spanning ETH, XRP, BNB, AVAX, USDT and USDC. Bitget's CEO blamed North Korean actors on IP and on-chain evidence; the vendor has launched a 5% recovery bounty. Neither third-party appliance vendor nor the CVEs have been named publicly.
Healthcare 1 story
DC's Medicaid Agency Notified Almost 400,000 Beneficiaries After Data Hid in Plain Sight for Three Years
The District of Columbia Department of Health Care Finance (DHCF) discovered on 21 July 2026 that two reports published on its public website exposed sensitive data to unauthorised individuals. The reports displayed only aggregate Medicaid and DC Healthcare Alliance statistics — enrolment counts and similar — but the personal information supporting them sat in hidden fields that could be reached by anyone viewing the page. The subsequent investigation found the personal and protected health information of 399,086 beneficiaries may have been accessed, comprising Medicaid ID number, date of birth, provider name, race, gender, ward and ethnicity. Names were not accessible, and neither were Social Security numbers or financial account details, which limits misuse potential. The reports had been reachable between 2023 and July 2026, covering people enrolled in either programme across that period. DHCF removed them immediately, determined the incident was reportable under HIPAA, and notified the HHS Office for Civil Rights on 3 September 2026; the breach has since appeared on the OCR portal and individual letters are being mailed.
Transport 1 story
South Africa's Air Navigation Agency Found Ransomware-Linked Malware in an Operational Technology Network
Air Traffic and Navigation Services (ATNS), the South African state-owned company that provides air traffic control and weather operations across more than 6% of the world's airspace and supports satellite communications for 33 African states, has issued a request for quotes seeking cyber-forensics firms, according to public documents. The incident involves ransomware-linked malware found in the operational technology environment supporting weather-related air traffic services at Port Elizabeth Airport (FAPE), with a second suspected incident — possible insider cyber theft — at Maputo International Airport (FAMM) in Mozambique. ATNS says its technical teams implemented containment and malware removal but that a comprehensive forensic investigation is required to establish root cause, extent of compromise and residual risk, and it is not ruling out employee involvement; its spokesperson declined to date the incident beyond "the current financial year". Forensic services were requested from 18 September, and the agency has 21 aerodromes and more than 1,000 staff. The disclosure lands weeks after commercial aviation's own reminder: a UK flight-data system failure in September caused close to 2,000 cancelled or delayed flights, though authorities there ruled out a cyberattack.
Legal Services 1 story
ACMA Fined Amaysim A$138,600 for Porting Mobile Numbers Without Extra Identity Checks
Amaysim, owned by Optus, has paid a A$138,600 infringement notice and entered an enforceable undertaking after the Australian Communications and Media Authority found it ported 13 mobile numbers without the additional identity verification required to stop number hijacking. ACMA found 13 contraventions of the Telecommunications (Mobile Number Pre-Porting Additional Identity Verification) Industry Standard 2020 between 9 May and 29 October 2025: eight ports went through Amaysim's online channel with no additional verification, and five were initiated through its customer service channel without checks. The requirement exists because a hijacked number lets criminals intercept one-time authentication codes sent by banks and other services. ACMA's findings drew partly on cybercrime reports to law enforcement through ReportCyber and the Australian Financial Crimes Exchange about alleged unauthorised ports to Amaysim. The infringement notice was issued in May and covers seven of the 13 contraventions at $19,800 each; paying it is not an admission of liability, though the undertaking states Amaysim acknowledges the findings. Over a 12-month undertaking Amaysim must appoint a regulator-approved independent consultant to review its porting governance and audit every port-in, reversal and cancellation quarterly, filing board-approved reports at seven and 12 months.
Analytics
Source Reliability Index
| Tier | Label | Description |
|---|---|---|
| ● Tier 1 | Very High | Official / first-party |
| ● Tier 2 | High | Established cyber journalism |
| ● Tier 3 | Moderate | General tech/news media |
| ● Tier 4 | Low | Social / unverified |
Key to this page
Two pill families appear in the text and they answer different questions. A CVE pill colours severity — a measured CVSS band from the National Vulnerability Database. A threat-actor pill colours attribution confidence — how well-corroborated the naming is, which is a claim rather than a measurement. Both are links: a CVE opens the ATT&CK matrix or its wiki page, an actor opens its wiki page.
CVE identifiers
- CVE-XXXX-NNNNCritical · CVSS 9.0+
- CVE-XXXX-NNNNHigh · CVSS 7.0–8.9
- CVE-XXXX-NNNNMedium · CVSS 4.0–6.9
- CVE-XXXX-NNNNLow · below 4.0
- CVE-XXXX-NNNNNo severity resolved — not the same as low
Threat actors · MITRE ATT&CK
- APT29State attribution stated by MITRE ATT&CK
- ShinyHuntersSelf-declared, or criminal-reporting attribution
- Transparent TribeContested — ATT&CK hedges, or two plausible sponsors
- ZIRCONIUMNo attribution in MITRE ATT&CK
Story signals
- ● Tier 1/4Source reliability — 1 official, 4 leads only
- VerifiedCorroborated by a second source or the principal
- ReportedSingle outlet, or a claim still in progress
- UnverifiedA claim we could not corroborate
- ConfirmedBreach acknowledged by the victim or a regulator
- ProbableBreach indicated but not yet acknowledged
- IOCs · FamilyLive abuse.ch indicators exist for that malware family
A collapsed Indicators of compromise block under a story lists defanged abuse.ch indicator values. The defanging is deliberate — never click, resolve or fetch them. An indicator corroborates a report; it never proves one.
Full methodology, evidence grading and caveats: Methodology & reading guide →