Weekly recap: Week of 21 to 27 September 2026
Review the week's tracked stories, vulnerability changes, and unverified leak-site claims for the dates shown.
370 stories tracked from Monday to Sunday, Coordinated Universal Time (UTC): September 21 to September 27, 2026; +31 vs prior week; 12 Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) additions from Monday to Sunday, UTC: September 21 to September 27, 2026; 305 ransomware leak-site claims observed in tracked feeds (unverified) from Monday to Sunday, UTC: September 21 to September 27, 2026
Monday to Sunday, UTC. Permalink label: 2026-W39.
- vulnerabilities5 sourcesWarning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active ExploitationSource ↗
Two unpatched remote code execution zero-days in Citrix NetScaler ADC and NetScaler Gateway are actively being exploited. Citrix has not acknowledged the flaws or released patches. Some operators have disabled affected appliances to mitigate risk.
Grouped: the same names (CITRIX NETSCALER ADC, NETSCALER ADC, NETSCALER GATEWAY).
- vulnerabilities4 sourcesCISA Adds One Known Exploited Vulnerability to CatalogSource ↗
CISA added CVE-2026-7273, a stack-based buffer overflow in Zyxel GS1900 Series Switches, to its Known Exploited Vulnerabilities Catalog based on active exploitation evidence. The vulnerability poses significant risk because successful exploitation grants total control of affected devices. Federal agencies must prioritize patching this and other high-risk catalog vulnerabilities under Binding Operational Directive 26-04.
Grouped: the same Common Vulnerabilities and Exposures (CVE) record (CVE-2026-7273) and the same name (KNOWN EXPLOITED VULNERABILITIES).
- threat intel3 sourcesShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoftSource ↗
Mandiant and Google Threat Intelligence Group identified a renewed mass exploitation campaign by UNC6240 (ShinyHunters) targeting Oracle PeopleSoft using CVE-2026-35273, a critical vulnerability with CVSS 9.8. The threat actor modified its exploit to bypass web application firewall rules by URL-encoding the vulnerable PSEMHUB endpoint path, then deployed web shells, trojanized backdoors, and tunneling toolkits across dozens of systems globally spanning higher education, technology, healthcare, and government sectors. Post-exploitation activity included credential theft, lateral movement, and data exfiltration, with evidence suggesting preparations for extortion.
Grouped: the same Common Vulnerabilities and Exposures (CVE) record (CVE-2026-35273) and the same name (ORACLE PEOPLESOFT).
- vulnerabilities2 sourcesMind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day ExploitsSource ↗
A Chinese advanced persistent threat (APT) group tracked as UTA0565 deployed chained zero-day vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and Windows (CVE-2026-85880) through spoofed websites impersonating legitimate media organizations and nonprofits. The actor sent phishing emails to Asian government entities and other targets, directing them to fake sites that delivered a previously undocumented malware family called CLEANGULP with capabilities including command execution, file transfer, and persistence through scheduled tasks. This represents a third distinct Chinese APT leveraging the same exploit chain, suggesting the toolkit has been shared across multiple threat actors within the Chinese cyberattack community.
Grouped: the same Common Vulnerabilities and Exposures (CVE) record (CVE-2026-85046) and the same names (AMERICAN PROGRESS, CHINA DIGITAL TIMES).
- vulnerabilities2 sourcesNCSC-2026-0394 [1.00] [H/H] Kwetsbaarheden verholpen in NetScaler ADC en NetScaler GatewaySource ↗
Citrix released patches for eight vulnerabilities in NetScaler ADC and NetScaler Gateway, with three marked critical: CVE-2026-88771 (CVSS 9.5, unauthenticated remote code execution via input validation), CVE-2026-88772 (CVSS 9.5, memory overflow enabling remote code execution or denial of service when DTLS is enabled), and CVE-2026-88773 (CVSS 9.3, HTTP request smuggling). The remaining five vulnerabilities (CVE-2026-88774 through CVE-2026-88778) range from CVSS 7.0 to 8.8 and involve policy bypass, memory overflow, and TCP sequence number predictability, with exploitation of the two critical flaws already observed in the wild.
Grouped: the same names (CITRIX NETSCALER ADC, CITRIX NETSCALER GATEWAY, REMOTE CODE EXECUTION).
- vulnerabilities2 sourcesAL26-023 - Vulnerability Impacting Microsoft SharePoint Server - CVE-2026-65660Source ↗
The Canadian Centre for Cyber Security has issued an alert regarding active exploitation of CVE-2026-65660, a code injection vulnerability in Microsoft SharePoint Server that allows authenticated attackers to execute arbitrary code and, when chained with other vulnerabilities, enables unauthenticated remote code execution on servers configured for anonymous access. The vulnerability affects SharePoint Enterprise Server 2016, Server 2019, and Subscription Edition, with fixed versions available for each. The centre recommends upgrading affected instances, restricting internet exposure, implementing multifactor authentication (MFA) for administrators, enabling antimalware scanning, and monitoring for indicators of compromise including unusual administrative activity and web shell deployment.
Grouped: similar headlines and the same Common Vulnerabilities and Exposures (CVE) record (CVE-2026-65660).
- vulnerabilitiesChinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP MalwareSource ↗
Chinese threat actor UTA0565 exploited a chain of vulnerabilities in Google Chrome and Microsoft Windows as zero-days in early September 2026 to deploy CLEANGULP malware via fake websites. The attack leveraged CVE-2026-85046 and CVE-2026-87491 in Chrome together with CVE-2026-85880 in Windows Advanced Local Procedure Call (ALPC) to achieve code execution.
- vulnerabilitiesIs This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)Source ↗
F5 BIG-IP contains a heap buffer overflow in the Authorization header processing of its OAuth flow that allows unauthenticated remote code execution. The vulnerability (CVE-2026-94127, CVSS 9.3) results from missing bounds checking on the Authorization header size before copying it to a 0x4100-byte heap buffer; exploitation causes a crash that can be leveraged to overwrite heap metadata and hijack function pointers. The flaw affects BIG-IP APM versions 21.1.0, 17.5.0-17.5.1, and 17.1.0-17.1.3, with patches available as of September 22.
- threat intel21st September – Threat Intelligence ReportSource ↗
A weekly threat intelligence roundup covering government and supply chain breaches, active exploitation of critical vulnerabilities in Cisco and Check Point products, and multiple campaigns from state-aligned and cybercriminal groups targeting government, technology, and financial sectors. Artificial intelligence (AI) threats include new attack techniques like BragJack against AI-enabled browsers and the discovery of Luciferus, an uncensored AI service for malware creation. Major patch releases from Oracle, Cisco, ISC, and Check Point address hundreds of flaws, including actively exploited remote code execution vulnerabilities.
- ot icsSiemens SIPLUS and SIMATIC ProductsSource ↗
Siemens released security advisories for CVE-2026-31431, a Linux kernel vulnerability affecting numerous SIPLUS and SIMATIC product lines including runtime environments, human machine interface panels, and industrial edge devices. The vulnerability enables incorrect resource transfer between security spheres with a CVSS score of 7.8, and Siemens has released patched versions for most affected products while providing mitigation guidance for others.
| Killsec3 | 46 claims | +46 vs prior week |
| The Gentlemen | 26 claims | -34 vs prior week |
| Metaencryptor | 25 claims | +20 vs prior week |
| Clop | 23 claims | +23 vs prior week |
| Qilin | 17 claims | -14 vs prior week |
| Akira | 9 claims | -1 vs prior week |
| INC Ransom | 8 claims | -3 vs prior week |
| Silentransomgroup | 8 claims | +7 vs prior week |
| Storm | 8 claims | -3 vs prior week |
| Termite | 8 claims | +8 vs prior week |
Leak-site claim data is unverified: RansomLook (CC BY 4.0).
- U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon ExtortionsSentencing · KrebsOnSecurity
A U.S. Army soldier stationed in South Korea, Cameron John Wagenius, was sentenced to 70 months in federal prison for hacking telecommunications companies and stealing call and text metadata for over 100 million AT&T customers. Working under the alias Kiberphant0m, Wagenius and co-conspirators exploited exposed Snowflake credentials lacking multifactor authentication (MFA) to access multiple telecom firms, then publicly extorted them for payment. Despite the scale of stolen data, his extortion efforts netted only approximately $1,500, though he also claimed access to national security secrets and presidential call logs.
- Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companiesSentencing · CyberScoop
Cameron John Wagenius, a former Army soldier, was sentenced to 70 months in prison for leading a years-long cybercrime campaign that compromised over 165 Snowflake customer environments and targeted major companies including AT&T, Ticketmaster, Advance Auto Parts, and Santander. Working with co-conspirators Connor Moucka and John Erin Binns, Wagenius stole billions of sensitive records and obtained more than $2.5 million in extortion payments while on active duty at Fort Cavazos in Texas. He pleaded guilty in July 2025 to multiple counts and was ordered to pay approximately $295,000 in restitution.
- Kiteworks urges customers to shut down their servers amid ‘imminent’ threat of cyberattackTakedown · TechCrunch Security
Kiteworks, a platform for secure data transfer over the internet, instructed customers to shut down their servers after receiving a credible threat notification from law enforcement regarding an imminent cyberattack. The company took the precautionary step to protect customer infrastructure from the anticipated threat.
- Cyberattack hits Welsh police force, may have affected staff dataDisruption · The Record
Dyfed-Powys Police in Wales experienced a cyberattack that disrupted non-emergency systems and potentially exposed staff data. The force confirmed the incident but did not disclose technical details or the scope of affected records.
- Woodbridge predator sentenced to 40 years in prison for sexually exploiting more than 40 minor girlsSentencing · U.S. Department of Justice
Malachi Morgan Thomas, 24, of Woodbridge, was sentenced yesterday to 40 years in prison for sexually exploiting more than 40 minor girls.
- U.S. Attorney’s Office Filed 114 Border-Related Cases This Week · U.S. Department of Justice
SAN DIEGO – Federal prosecutors in the Southern District of California filed 114 border-related cases this week, including charges of bringing in aliens for financial gain, reentering the U.S. after deportation, and importation of controlled substances. The U.S. Attorney’s Office for the Southern District of California is the fourth-busiest federal district, largely due to a high volume of border-related crimes. This district, encompassing San Diego and Imperial counties, shares a 140-mile border with Mexico. It includes the San Ysidro Port of Entry, the world’s busiest land border crossing, c
- Rydox cybercriminal marketplace operator pleads guilty following co-conspirator brothers’s deportationGuilty Plea · The Record
Ardit Kutleshi, 28, pleaded guilty after extradition from Kosovo for operating Rydox, a cybercriminal marketplace where stolen personal information, unauthorized device access, and fraud tools were bought and sold. He and his older brother face charges related to the illicit platform.
- Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ allegesArrest · CyberScoop
The Justice Department announced the arrest of two leaders of Oxygen Forensics, a phone-hacking company that concealed Russian ownership while securing millions of dollars in contracts from the U.S. Defense Department, Department of Homeland Security, and other agencies. CEO Lee Reiber of Boise, Idaho, was arrested at his home, and Russian national Oleg Davydov was arrested in London; both face wire fraud conspiracy charges. The company installed Reiber as a front after 2022 sanctions on Russia, falsely representing itself as U.S.-owned to government clients who stated they would not have awarded contracts had they known the truth.
- Kosovar National Pleads Guilty to Operating Cybercrime Marketplace Offering Tools and Products to CybercriminalsGuilty Plea · U.S. Department of Justice
Ardit Kutleshi, 28, a Kosovar national, pleaded guilty to charges related to his creation and operation of Rydox, an illicit website and marketplace for cybercriminals to buy, sell and trade stolen personal information, and to access devices and other tools for carrying out cybercrime and fraud.
- Kosovar National Pleads Guilty to Operating Cybercrime Marketplace Offering Tools and Products to CybercriminalsSentencing · Guilty Plea · U.S. Department of Justice
PITTSBURGH, Pa. - Ardit Kutleshi, 28, a Kosovar national, has pleaded guilty to charges related to his creation and operation of Rydox, an illicit website and marketplace for cybercriminals to buy, sell, and trade stolen personal information, and to access devices and other tools for carrying out cybercrime and fraud. “Cybercriminals Ardit Kutleshi and his brother Jetmir—who pleaded guilty and was sentenced in December 2025 prior to his deportation back to Kosovo—operated the Rydox marketplace for their own gain, making hundreds of thousands of dollars from the marketplace where cyber criminal
- Phone Hacking Software Firm Hid Russian Ownership, Say FedsArrest · HealthcareInfoSecurity
U.S. and British law enforcement arrested the chief executive officer and chief technology officer of Oxygen Forensics, a provider of phone hacking software, on charges of concealing Russian ownership of the company. The firm's products have been widely used by law enforcement digital forensic examiners, and its Russian connections were previously known within that community.
- Texan Scattered Spider Member Receives 45-Month SentenceGuilty Plea · HealthcareInfoSecurity
Ahmed Elbadawy, a member of the cybercrime group Scattered Spider, pleaded guilty to wire fraud and identity theft charges. He received a 45-month federal prison sentence and must forfeit $18 million in cryptocurrency seized from his involvement in dozens of attacks.
7 more qualifying actions on the full feed.
- CVE-2026-94127F5 BIG-IP APMdue
- CVE-2026-88772Citrix NetScalerdue
- CVE-2026-88771Citrix NetScalerdue
- CVE-2026-71362Adobe Commerce and Magento due
- CVE-2026-93616Check Point Multiple Productsdue
- CVE-2026-87902WordPress Coredue
- CVE-2026-7273Zyxel GS1900 Series Switchesdue
- CVE-2026-93952Arista VeloCloud Orchestratordue
- CVE-2026-85102Check Point Multiple Productsdue
- CVE-2026-5430WSO2 Multiple Productsdue
- CVE-2023-48365Qlik SenseEPSS exploit likelihood up 23 percentage points (0.47 now)
- CVE-2026-76461Cisco Secure Email GatewayEPSS exploit likelihood up 26 percentage points (0.28 now)
- CVE-2024-57728SimpleHelp SimpleHelpEPSS exploit likelihood up 58 percentage points (0.65 now)
- CVE-2026-94127F5 BIG-IP APMAdded to CISA KEV 2026-09-22; Added to VulnCheck KEV 2026-09-22; Added to ENISA EUVD 2026-09-22; Exploitation active since 2026-09-22
- CVE-2018-2894Oracle WebLogic ServerEPSS exploit likelihood up 26 percentage points (0.50 now)
- claim(unnamed victim)Unverified claim. Claimed by Killsec3.
- claim(unnamed victim)Unverified claim. Claimed by Killsec3.
- claim(unnamed victim)Unverified claim. Claimed by Killsec3.
- claim(unnamed victim)Unverified claim. Claimed by Killsec3.
- claim(unnamed victim)Unverified claim. Claimed by Killsec3.
- claimgofile.ioUnverified claim. Claimed by Killsec3.
- claimgofile.ioUnverified claim. Claimed by Killsec3.
- claim(unnamed victim)Unverified claim. Claimed by Killsec3.
- claimLigue se GrupoUnverified claim. Claimed by The Gentlemen.
- claimCharles KeithUnverified claim. Claimed by The Gentlemen.
- claimENKEI*******Unverified claim. Claimed by The Gentlemen.
- claimFTAPI SoftwareUnverified claim. Claimed by The Gentlemen.
- claimFTAPI SoftwareUnverified claim. Claimed by The Gentlemen.
- claimENKEI*******Unverified claim. Claimed by The Gentlemen.
- claimCharles KeithUnverified claim. Claimed by The Gentlemen.
- claimLigue se GrupoUnverified claim. Claimed by The Gentlemen.
- claimCorona CorporationUnverified claim. Claimed by Metaencryptor.
- claimFactoryFiveUnverified claim. Claimed by Metaencryptor.
- claimAquamar IncUnverified claim. Claimed by Metaencryptor.
- claimAstemo, Ltd.Unverified claim. Claimed by Metaencryptor.
Ransomware claim data is unverified: RansomLook (CC BY 4.0), with ransomware.live as a voluntarily credited failover.