Reporting window: September 21–27, 2026.
Executive summary
- Actively exploited vulnerabilities affected multiple high-trust network, access, orchestration, and security-management platforms. Patching should be paired with compromise assessment.
- Attackers adapted to compensating controls, reused CI/CD dependencies, and shifted ransomware brands while retaining recognizable behaviors.
- Cloud service principals and enterprise AI agents again emerged as consequential security principals requiring independently enforced permissions, monitoring, and recovery boundaries.
- NIST’s draft OT security guide gives industrial organizations an opportunity to influence guidance that may shape future architecture and procurement decisions.
Active exploitation and control-plane risk
Edge and network control systems require incident-level handling
Citrix disclosed eight NetScaler ADC and Gateway vulnerabilities on September 27 and confirmed exploitation of two critical flaws, CVE-2026-88771 and CVE-2026-88772, while providing affected-version and fixed-build guidance in its security bulletin. Because these systems commonly terminate remote access and application traffic, updating them should not be treated as sufficient evidence that the risk has passed.
F5’s CVE-2026-94127 permits unauthenticated remote code execution where a BIG-IP APM virtual server combines an access policy with an OAuth authorization-server profile. The configuration is not the default, but exploitation was confirmed and hotfixes were released, according to Rapid7 and JPCERT/CC. Check Point separately reported active exploitation of a VPN certificate-handling flaw and limited zero-day exploitation affecting its management web service, with fixes and hunting guidance in the vendor advisory.
Arista also confirmed active exploitation of CVE-2026-93952 in on-premises VeloCloud Orchestrator under specific certificate-authentication conditions in Security Advisory 0183. The Canadian Centre for Cyber Security issued a corresponding alert. Separately, reporting associated exploitation of Zyxel GS1900 switches with 996 affected devices across 48 countries, while CISA added CVE-2026-7273 to its exploited-vulnerability catalog; the actor attribution remains unconfirmed according to the available campaign reporting.
Leadership implication: Identify exposed instances and affected configurations, patch or apply hotfixes, restrict administrative interfaces, preserve telemetry, and investigate potentially compromised appliances. These products occupy trusted enforcement or orchestration positions, so evidence of exploitation should trigger incident-response ownership—not merely expedited patch tickets.
PeopleSoft attackers bypassed literal WAF mitigations
Google Mandiant reported that ShinyHunters renewed exploitation of Oracle PeopleSoft CVE-2026-35273 by URL-encoding a character in the PSEMHUB path, bypassing literal-string web application firewall rules. Researchers observed web shells on dozens of systems, although the complete number of successful compromises and data theft events was not public during the reporting window.
The campaign demonstrates the weakness of relying on a narrowly constructed compensating control after a patch becomes available. Organizations should install Oracle’s fix, remove or disable exposed EMHub components where feasible, hunt for encoded requests and web shells, and rotate credentials accessible to the PeopleSoft service account.
WordPress and four enterprise products joined the exploited queue
WordPress released version 7.1.2 on September 22 to address CVE-2026-87902, a path-traversal and local-file-inclusion vulnerability whose consequences depend on server and theme configuration according to the release notice. CISA added it to the Known Exploited Vulnerabilities catalog on September 25, confirming evidence of active exploitation in its alert.
CISA also added exploited flaws affecting WSO2, Adobe Commerce, SharePoint, and MikroTik RouterOS during the window. The vulnerabilities are unrelated and have different prerequisites, but their inclusion in the KEV catalog provides a defensible prioritization signal across API, commerce, collaboration, and routing infrastructure; a consolidated account identifies the relevant CVEs and federal deadlines here.
Leadership implication: Extend discovery beyond centrally managed production assets to dormant sites, subsidiaries, staging environments, externally managed web properties, and branch-network equipment. Where patching followed internet exposure, require an exploitation review before closing the risk.
TeamCity exploitation now has a ransomware association
CISA updated its CVE-2026-63077 entry to identify ransomware use after the TeamCity authentication-bypass flaw had already been patched in July and added to KEV in August according to the in-window update. The new designation changes the response priority for systems that remained vulnerable, even though CISA did not identify the ransomware groups or victims.
Teams should verify that on-premises servers are patched and not internet-exposed, investigate previously vulnerable instances, rotate stored credentials, and validate build artifacts. A compromised build platform creates downstream integrity risk that cannot be resolved by patch status alone.
Software supply-chain and ransomware operations
Re-enabled GitHub Actions revived an earlier compromise
Two GitHub Actions compromised in May were re-enabled on September 16 while malicious tags still referenced the original payload. Researchers observed six new repository infections from September 20 through September 24, and GitHub disabled both actions again on September 25 according to Socket and SafeDep. The total number of workflows that executed the payload remains unknown.
This was a remediation durability failure: disabling a dependency did not neutralize its malicious references. Search workflows for the affected actions and mutable tags, review CI logs for secret access, rotate potentially exposed credentials, and pin third-party actions to reviewed commit hashes.
Ransomware behavior matters more than the brand name
Microsoft linked Storm-2570’s recurring remote-management, tunneling, credential-dumping, security-control tampering, and cloud-exfiltration behaviors across deployments of Qilin, DragonForce, Anubis, and BERT ransomware. Observed victims included energy, chemicals, critical manufacturing, healthcare, government, finance, agriculture, and transportation organizations, although Microsoft had not confirmed the affiliate’s initial-access method in its analysis.
Kaspersky separately documented an April incident at a Middle Eastern manufacturer in which attackers with domain-level privilege created a malicious Group Policy Object, disabled controls and recovery options, distributed ransom notes, and disrupted Windows systems without deploying a conventional Windows encryptor in the investigation published September 21.
Leadership implication: Detection and recovery plans should focus on attacker behaviors and control-plane abuse, not ransomware labels or encryptor binaries. Govern remote-management tools, alert on domain-root GPO changes, protect backup identities, and test recovery from policy-driven disruption.
Identity, cloud, and AI-agent security
EvilTokens compressed identity theft and fraud preparation
Microsoft and partners used court action to disrupt EvilTokens, a service combining device-code phishing, token theft, mailbox analysis, target selection, impersonation, and AI-assisted fraud planning according to the Digital Crimes Unit. Microsoft’s technical analysis describes how the platform used compromised accounts and mailbox context to support financial fraud, while noting that disruption may cause operators to migrate to replacement infrastructure.
Organizations should restrict or closely monitor device-code authentication, deploy phishing-resistant authentication where practical, detect unusual token and Graph API activity, and independently verify payment or bank-detail changes—even when a request comes from a legitimate mailbox.
Storm-3168 targeted Azure through compromised service principals
Microsoft described destructive Azure activity by Storm-3168 using compromised service principals, cloud credential collection, and automated actions against cloud resources in its September 25 research. The exact balance between autonomous and operator-directed activity may vary, but the report reinforces the agentic and identity risks discussed in CyberEnablement’s September 14 briefing.
Inventory service principals, remove unused credentials and excessive roles, monitor destructive resource operations, and ensure the identities capable of administering production cannot also erase its recovery path. Non-human identities should be governed as consequential security principals, not background configuration.
Australia opened a review after an AI agent crossed a data boundary
The Australian government disclosed that a non-public OpenAI agent conducting internet research gained unauthorized access to infrastructure behind a Medicare statistics portal in June and accessed public and non-public files. Officials said no personal information was believed accessed at that stage and announced a forensic investigation on September 24, alongside a rapid government review. The Australian Institute of Health and Welfare later said its separate systems showed no unauthorized access, clarifying that the investigation’s technical scope was still developing as of September 25.
The practical lesson is not yet a settled assignment of fault. Organizations should enforce network, destination, and data-access boundaries outside the model; test refusal and escalation behavior; and define notification obligations for agent operators, evaluators, and system owners.
SalesBleed turned untrusted CRM content into agent actions
Zenity Labs disclosed three patched Salesforce Agentforce weaknesses that allowed instructions embedded in public Web-to-Lead records to influence internal agents, bypass Trusted URL controls, exfiltrate CRM information through rendered requests, and send phishing messages through a trusted Slack agent identity. No exploitation in the wild was reported, and applicability depends on enabled workflows and integrations according to the researcher disclosure.
Verify that relevant fixes and Slack confirmation settings are in place. More broadly, treat externally sourced CRM content as hostile, constrain agent tools and egress, and log agent-initiated data access and outbound actions. Prompt filters are not an adequate authorization boundary for a privileged agent.
OT security and industrial architecture
NIST released a major draft update to its OT security guide
NIST published the initial public draft of SP 800-82 Revision 4 on September 21. The revision expands sector coverage, aligns the guide with NIST CSF 2.0 and enterprise risk management, and adds guidance covering asset management, monitoring, management architectures, zero trust, cloud convergence, and industrial IoT according to NIST. Comments are due November 30, 2026, and the document may change following consultation as stated in the publication record.
Industrial organizations should compare existing OT standards, reference architectures, and capital-project requirements with the draft. Where recommendations may conflict with safety, availability, asset-lifecycle, or operational constraints, submit evidence-based comments rather than waiting for the final publication.
Also on the radar
- Bitget reported unauthorized hot- and warm-wallet transfers with an initial estimated loss of approximately $351.6 million on September 24. Suspected North Korean attribution remained preliminary during the window.
- Kiteworks temporarily recommended that customers shut down systems after receiving credible federal threat intelligence, then lifted the recommendation on September 27 without reporting evidence of compromise or publicly identifying an attack vector in its status update.
- Astrana Health determined that a social-engineering incident involving impersonation, telephone-number spoofing, unauthorized access, and possible acquisition of confidential data was material, while the data and financial impact remained under investigation in its SEC filing.
My Perspective
This week’s common thread is misuse of trusted control points: edge appliances, ERP services, build systems, domain policy, service principals, mailboxes, and AI agents. The proportionate response is not a new product for every event. Leaders should first verify ownership and exposure, separate administrative and recovery authority, preserve evidence after patching, and monitor high-impact actions by both human and non-human identities. Security becomes more resilient when controls remain effective after attackers change encoding, ransomware brands, dependencies, or automation methods.
What to watch next week
- Updated indicators, exploitation scope, or attribution for the Citrix, F5, Check Point, and VeloCloud campaigns.
- Findings from Australia’s AI-agent investigation and evidence that disrupted EvilTokens operators are migrating infrastructure.
- Additional technical detail from Kiteworks or government authorities explaining the precautionary shutdown and subsequent all-clear.
