CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
Citrix confirmed worldwide exploitation of two critical NetScaler RCE zero-days, while Microsoft reported active attacks against SharePoint Server CVE-2026-65660. Operation Master also exploited GlobalProtect CVE-2026-0257 to create VPN sessions without valid credentials, steal data and support large-scale payment fraud.
About 22,000 NetScaler systems were reported internet-exposed, and attacks against Japanese systems were observed beginning September 24. Citrix has released updates for affected ADC and Gateway appliances; administrators should patch immediately and investigate whether attackers gained access before remediation.
ShinyHunters reportedly bypassed temporary mitigations on Oracle PeopleSoft systems, and a reported WhatsApp zero-click chain silently linked attacker devices to iOS accounts for impersonation and wire-transfer fraud. Official fixes and post-remediation compromise checks warrant priority over temporary workarounds.
Editorial: Recommended Actions
01
PRIORITY
Patch Citrix NetScaler ADC and Gateway appliances immediately, prioritizing internet-exposed systems, and investigate for compromise that predates remediation. Attackers are exploiting two critical remote-code-execution flaws worldwide, with about 22,000 NetScaler systems reportedly exposed; affected releases include ADC and Gateway versions before 13.1-64.23 and 14.1-73.37.
02
PRIORITY
Apply Microsoft's fix for SharePoint Server CVE-2026-65660 and examine supported SharePoint Server 2016, 2019, and Subscription Edition systems for webshells or other compromise. Microsoft has reliable evidence of active exploitation, public proof-of-concept code is reported, and observed attacks attempted to install webshell backdoors; CISA added the flaw to its KEV catalog with a September 28 federal remediation deadline.
03
PRIORITY
Investigate Palo Alto Networks GlobalProtect gateways for exploitation of CVE-2026-0257, unauthorized VPN sessions and subsequent data theft. Operation Master used the flaw to establish sessions without valid credentials, compromised seven gateways in four countries, deployed AdaptixC2 against at least two Windows server identities and exfiltrated some records through structured DNS requests; businesses serving Brazilian customers and energy-sector organizations face documented exposure.
04
PRIORITY
Upgrade Roundcube Webmail to 1.6.16 or 1.7.1 wherever the virtuser_query plugin is enabled, and prioritize installations running 1.6.x before 1.6.16 or 1.7.x before 1.7.1. CVE-2026-48842 permits unauthenticated SQL injection in configurations using that plugin and is reportedly being exploited in the wild.
05
PRIORITY
Install Oracle's official PeopleSoft fix rather than relying on temporary mitigations, then assess exposed environments for unauthorized access and theft of payroll, banking, employee or personnel records. ShinyHunters reportedly renewed attacks after bypassing temporary mitigations where the official fix was absent, affecting government, healthcare, higher education and automotive organizations worldwide.
ROUNDTABLE
Expert Panel Discussion
12 AI experts analyzed this briefing across 3 turns of structured debate
12Agents18Messages32mDuration
→
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_