Weekly recap: Week of 28 September to 4 October 2026
Review the week's tracked stories, vulnerability changes, and unverified leak-site claims for the dates shown.
309 stories tracked from Monday to Sunday, Coordinated Universal Time (UTC): September 28 to October 04, 2026; -61 vs prior week; 6 Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) additions from Monday to Sunday, UTC: September 28 to October 04, 2026; 327 ransomware leak-site claims observed in tracked feeds (unverified) from Monday to Sunday, UTC: September 28 to October 04, 2026
Monday to Sunday, UTC. Permalink label: 2026-W40.
The 309 stories above are counted by publisher date (first-seen date where it is missing or unusable), and only for stories that have a summary and a why-it-matters line and are not thin or editorially excluded. The daily archive counts by the day the tracker first saw each story and does not require a summary or a why-it-matters line: its 7 day pages for these 7 days list 509 stories. The two figures use different dates and rules, so they are not expected to match.
Most covered
- vulnerabilities7 sourcesApple Patches CoreGraphics Flaw Possibly Exploited in Targeted AttacksSource ↗
Apple patched CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics affecting iOS, iPadOS, and macOS, that could enable arbitrary code execution through maliciously crafted files. The flaw carries a CVSS score of 8.8 and appears on the Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in targeted attacks.
Grouped: similar headlines.
- vulnerabilities4 sourcesUnauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570Source ↗
Microsoft Threat Intelligence documented active exploitation of CVE-2026-73570, an unauthenticated command-injection flaw in Zimbra Collaboration Suite affecting internet-facing mail servers with the optional SNMP package installed. Attackers deployed web shells, reverse shells, and credential-stealing implants to extract authentication material, mailbox data, and service secrets from compromised environments across multiple sectors and regions. The attack chain included privilege escalation via PAM manipulation, lateral movement through SSH trust relationships, and attempted exfiltration using cloud storage tools.
Grouped: the same Common Vulnerabilities and Exposures (CVE) record (CVE-2026-73570) and the same name (ZIMBRA COLLABORATION SUITE).
- vulnerabilities4 sourcesDutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters InvestigationSource ↗
Dutch authorities arrested 23-year-old Pepijn van der Stap in mid-September on suspicion of aiding the ShinyHunters hacking group; van der Stap had previously been convicted in 2023 for data thefts and extortions under the hacker alias Umbreon and was released from prison in December 2025. Following his arrest, ShinyHunters escalated operations, exploiting CVE-2026-35273 in Oracle PeopleSoft to breach the FBI's job application site and steal personal data on over 5,000 officials, including Social Security numbers and sensitive medical files, and also targeted the ransomware group Cl0p. Evidence suggests a younger hacker known as Rey, who leads a merged group called ScatteredLapsussHunters, has taken control of ShinyHunters and may have framed van der Stap for the FBI breach by embedding the Umbreon Pokemon character in the defacement message.
Grouped: similar headlines.
- vulnerabilities3 sourcesSwarming Against Citrix 0-Day ExploitationSource ↗
On September 24, 2026, a threat actor at IP address 149.104.78.141 attempted to exploit a zero-day vulnerability in Citrix NetScaler Gateway before public disclosure. GreyNoise detected the malicious behavior through behavioral analysis despite the absence of CVE-specific signatures at that time.
Grouped: similar headlines.
- vulnerabilities3 sourcesNetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)Source ↗
Citrix NetScaler ADC and Gateway deployments face escalating exploitation of CVE-2026-88771, a remote code execution vulnerability affecting unpatched devices with default configurations. Mass attacks have intensified following the public release of a root-cause analysis and proof-of-concept exploit, shifting from targeted zero-day attacks to widespread opportunistic compromise.
Grouped: the same Common Vulnerabilities and Exposures (CVE) record (CVE-2026-88771) and the same name (CITRIX NETSCALER ADC).
- vulnerabilities2 sourcesAttackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOTSource ↗
Unknown threat actors exploited a newly patched Citrix NetScaler ADC and NetScaler Gateway vulnerability to gain root access on appliances throughout September 2026. Mandiant and Google Threat Intelligence observed the activity deploying WHIPSHOT and SLAPSHOT malware, targeting government, financial services, technology, education, and legal and professional organizations in North America and Europe.
Grouped: the same names (GOOGLE THREAT INTELLIGENCE GROUP, NORTH AMERICA).
- vulnerabilities2 sourcesNCSC-2026-0398 [1.00] [M/H] Vulnerability fixed in Fortinet FortiMailSource ↗
Fortinet released a patch for CVE-2026-104286, a critical vulnerability in FortiMail caused by path traversal and insufficient NULL-byte neutralization that allows unauthenticated attackers to write arbitrary files via crafted HTTP or HTTPS requests. The flaw affects FortiMail versions 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.1 with Identity Based Encryption (IBE) enabled, and is being actively exploited in the wild. Fortinet published indicators of compromise to help organizations investigate potential abuse and detect forensic evidence of compromise.
Grouped: similar headlines and the same Common Vulnerabilities and Exposures (CVE) record (CVE-2026-104286).
- vulnerabilitiesCitrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode ExecutionSource ↗
Researchers have disclosed technical details of CVE-2026-88772, a critical memory overflow vulnerability in Citrix NetScaler ADC and Gateway's Datagram Transport Layer Security (DTLS) protocol handling. The flaw, with a CVSS score of 9.5, is under active exploitation and affects pre-authentication code paths that can lead to remote code execution (RCE).
- vulnerabilities28th September – Threat Intelligence ReportSource ↗
A threat intelligence bulletin reported multiple significant incidents during the week of September 28, 2026, including breaches at FBIjobs.gov, Astrana Health, Bitget cryptocurrency exchange, and Ludwig Maximilian University. Active exploitation of critical vulnerabilities in Check Point products (CVE-2026-85102 and CVE-2026-93616), F5 BIG-IP (CVE-2026-94127), and WordPress (CVE-2026-87902) posed remote code execution risks. Threat researchers identified campaigns leveraging artificial intelligence (AI) agents for automated retail attacks, ransomware affiliates operating across multiple ecosystems, and Azure-targeted destructive operations by compromised service principals.
- vulnerabilitiesWeek in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedSource ↗
A 16-year-old researcher disclosed a flaw in Microsoft's Titan analytics service that exposed access to 17 trillion rows of data, including employee records and Bing search analytics. Citrix patched eight critical and high-severity vulnerabilities in NetScaler, including two remote code execution zero-days (CVE-2026-88771, CVE-2026-88772) that were exploited globally for weeks.
Most active ransomware groups (leak-site claims, unverified)
| The Gentlemen | 69 claims | +43 vs prior week |
|---|---|---|
| Storm | 23 claims | +15 vs prior week |
| Qilin | 14 claims | -3 vs prior week |
| Safepay | 12 claims | +12 vs prior week |
| Imnotavillian | 11 claims | +11 vs prior week |
| INC Ransom | 10 claims | +2 vs prior week |
| Lamashtu | 10 claims | +10 vs prior week |
| Akira | 9 claims | 0 vs prior week |
| KryBit | 9 claims | +6 vs prior week |
| Brain Cipher | 8 claims | +7 vs prior week |
Leak-site claim data is unverified: RansomLook (CC BY 4.0), with ransomware.live as a failover, credited and linked as its terms require (Source: Ransomware.live).
Takedowns and arrests
- Pair Sentenced for Roles in Business Email Fraud SchemeSentencing · Guilty Plea · U.S. Department of Justice
ABINGDON, Va. – Two individuals who conspired with others to execute a business email compromise scheme that stole more than $1.5 million from victims throughout the United States were recently sentenced in U.S. District Court in Abingdon. Shelton, 57, of Wytheville, Virginia, and Olivia Oxley, 36, of Brooklyn, New York, both pleaded guilty in July last year to conspiracy to commit bank and wire fraud. For her role in the conspiracy, Oxley was sentenced to one year and one day of imprisonment followed by three years of supervised release. Shelton was sentenced to 300 hours of community service
- Spain Arrests Teen Suspected of Running KillSec RansomwareArrest · Seizure · HealthcareInfoSecurity
Spanish police arrested a 16-year-old suspected of operating the KillSec ransomware group and seized its servers and leak site. U.S. prosecutors simultaneously charged a Dutch national with assisting the group in extorting victims, including a Puerto Rico company.
- Iranian accused of hacking American universities extradited from MontenegroExtradition · The Record
An Iranian national facing U.S. charges related to breaches at American universities was transferred from Montenegro to face prosecution. The alleged attacks targeted academic institutions and resulted in theft of research data and proprietary information.
- Police dismantle KillSec ransomware gang allegedly led by 16-year-oldArrest · Disruption · BleepingComputer
An international law enforcement operation called Operation KillSwitch disrupted the KillSec ransomware gang by taking down its data leak site and infrastructure, resulting in three arrests. Investigators identified a 16-year-old as the group's alleged leader.
- Europol reports cyber enforcement: seizureSeizure · Europol
- Flushing, NY Man Pleads Guilty in Transnational Fraud Scheme Targeting Elderly VictimsGuilty Plea · U.S. Department of Justice
PROVIDENCE – Xuehai Sun, 38, of Flushing, New York, has pleaded guilty in federal court in Rhode Island, to conspiracy to commit wire fraud for his role in an elaborate transnational fraud scheme that targeted elderly victims across the United States and Canada.
- Dutch National Indicted and Arrested for Unauthorized Computer Access ConspiracyArrest · Indictment · U.S. Department of Justice
SAN JUAN, Puerto Rico – On September 16, 2026, a federal grand jury in the District of Puerto Rico returned an indictment charging a Dutch national who resides in the United Kingdom with conspiracy to intentionally access a computer without authorization for financial gain, intentionally causing damage without authorization to a protected computer, and intentionally transmitting a threat to obtain information from a protected computer without authorization with the intent to extort. The Dutch national named in the indictment, Fouad Eltibrizi (a/k/a Archduke), was arrested on September 30, 2026
- Eurojust reports cyber enforcement: arrest, takedown (2026-10-01)Arrest · Takedown · Eurojust
- US sanctions 10 over ATM malware scheme tied to Tren de AraguaSanction · The Record
The US Treasury Department's Office of Foreign Assets Control (OFAC) imposed sanctions on ten individuals and associated companies linked to Tren de Aragua, a Venezuelan criminal organization involved in ATM malware schemes. The action targets the money laundering infrastructure used to process proceeds from dozens of compromised automated teller machines.
- Former US Air Force members sent to prison over BEC attacksSentencing · BleepingComputer
Two former United States Air Force members received combined sentences of 189 months in federal prison for conducting business email compromise (BEC) scams and phishing campaigns over multiple years. The individuals coordinated a sustained effort targeting victims through fraudulent email schemes.
- Alleged ShinyHunters leader arrested in the NetherlandsArrest · CyberScoop
Dutch National Police arrested a 24-year-old man in Amsterdam on September 29, 2026, identified as Pepjin van der Stap, alleged leader of ShinyHunters cybercrime group. ShinyHunters has breached over 140 organizations and extorted at least $70 million since 2025, with recent attacks targeting cloud platforms, healthcare, education, and major technology vendors. Evidence recovered from van der Stap's laptop reportedly includes details of alleged murders he ordered, and the FBI is actively pursuing additional leads against group members.
- Delaware Men Sentenced for Cyber Intrusion Scheme Targeting Victims in the Southern District of IowaSentencing · U.S. Department of Justice
DES MOINES, Iowa –Two Delaware men were sentenced on September 25, 2026, to a combined 189 months in federal prison for their roles in an international cyber intrusion scheme.
6 more qualifying actions on the full feed.
CISA KEV additions
- CVE-2026-104286Fortinet FortiMaildue
- CVE-2026-88779Citrix NetScalerdue
- CVE-2026-76504Cisco Catalyst SD-WAN Managerdue
- CVE-2026-102489Zammad GmbH Zammaddue
- CVE-2026-86950Apple Multiple Productsdue
- CVE-2026-102490Zammad GmbH Zammaddue
Vulnerabilities on the move, to (the 7 days before this recap was generated)
- CVE-2026-63077JetBrains TeamCityEPSS exploit likelihood up 80 percentage points (0.90 now)
- CVE-2026-19490Citrix NetScalerEPSS exploit likelihood up 16 percentage points (0.23 now)
- CVE-2026-104286Fortinet FortiMailAdded to CISA KEV 2026-10-01; Added to VulnCheck KEV 2026-10-01; Added to ENISA EUVD 2026-10-01; Exploitation active since 2026-10-01
- CVE-2026-88779Citrix NetScalerAdded to CISA KEV 2026-10-04; Added to VulnCheck KEV 2026-10-04; Added to ENISA EUVD 2026-10-02; Exploitation active since 2026-10-04
- CVE-2024-49766palletsprojects werkzeugAdded to VulnCheck KEV 2026-09-30
Ransomware leak-site claims (20 of 327 shown, unverified)
- claimCenter State EngineeringUnverified claim. Claimed by The Gentlemen.
- claimCenter State EngineeringUnverified claim. Claimed by The Gentlemen.
- claimAwareUnverified claim. Claimed by The Gentlemen.
- claimWOOSHIN SAFETY SYSTEMS CO LTDUnverified claim. Claimed by The Gentlemen.
- claimZelhamUnverified claim. Claimed by The Gentlemen.
- claimHospital de la Santa Creu i Sant PauUnverified claim. Claimed by The Gentlemen.
- claimRotamacUnverified claim. Claimed by The Gentlemen.
- claimMandurah State Emergency ServiceUnverified claim. Claimed by The Gentlemen.
- claimNipigon District Memorial HospitalUnverified claim. Claimed by Storm.
- claimStates IndustriesUnverified claim. Claimed by Storm.
- claimAllied Machine & EngineeringUnverified claim. Claimed by Storm.
- claimStep By StepUnverified claim. Claimed by Storm.
- claimStates IndustriesUnverified claim. Claimed by Storm.
- claimAllied Machine & EngineeringUnverified claim. Claimed by Storm.
- claimStep By StepUnverified claim. Claimed by Storm.
- claimWest County Health CentersUnverified claim. Claimed by Storm.
- claimUnident GroupUnverified claim. Claimed by Qilin.
- claimChadwick SwitchboardsUnverified claim. Claimed by Qilin.
- claimEmserUnverified claim. Claimed by Qilin.
- claimCotesmaUnverified claim. Claimed by Qilin.
Ransomware claim data is unverified: RansomLook (CC BY 4.0), with ransomware.live as a failover, credited and linked as its terms require (Source: Ransomware.live).