CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
Attackers are exploiting CVE-2026-87902 across vulnerable WordPress installations, while ShinyHunters/UNC6240 is mass-exploiting Oracle PeopleSoft CVE-2026-35273 and deploying web shells and the SIDEEYE backdoor. Citrix has also confirmed worldwide exploitation of two NetScaler flaws that can enable remote code execution.
WordPress versions 4.7.0 through 7.1.1 are affected under relevant theme conditions. Attackers reportedly began probing on September 22, the day fixed releases became available; CISA added the flaw to its Known Exploited Vulnerabilities catalog and set a September 28 remediation deadline for federal civilian agencies.
Citrix says affected NetScaler and Secure Private Access Hybrid deployments should be upgraded immediately. Microsoft has confirmed exploitation and webshell-installation attempts against SharePoint, while ransomware operators are abusing TeamCity. In cryptocurrency infrastructure, Bitget attackers routed stolen assets through THORChain, which separately suffered a $10.7 million validator attack and a roughly five-week trading shutdown.
Editorial: Recommended Actions
01
PRIORITY
Update WordPress Core immediately to a fixed September 22, 2026 release and investigate affected sites for compromise. CVE-2026-87902 affects versions 4.7.0 through 7.1.1 under relevant theme conditions, enables remote file inclusion, and is actively exploited; attackers reportedly began probing on the day patches became available. Federal civilian agencies must remediate or discontinue affected software by September 28.
02
PRIORITY
Fully patch Oracle PeopleSoft systems for CVE-2026-35273 rather than relying on temporary firewall mitigations, then examine PeopleSoft servers for web shells and the SIDEEYE backdoor. ShinyHunters, tracked as UNC6240, is mass-exploiting insufficiently patched deployments and bypassing temporary mitigations; dozens of systems across multiple sectors were reportedly compromised, and more than 100 organizations were notified.
03
PRIORITY
Install Citrix’s security updates immediately on affected NetScaler ADC, Gateway, and Secure Private Access Hybrid deployments. CVE-2026-88771 and CVE-2026-88772 are being exploited worldwide, can enable remote code execution, and each carries a CVSS v4 score of 9.5. Both flaws were exploited before patches became available, making rapid upgrading essential even where earlier shutdown measures were used.
04
PRIORITY
Remediate Microsoft SharePoint against CVE-2026-65660 and inspect exposed deployments for web shells or other evidence of code execution. Microsoft confirmed active exploitation of this authenticated remote-code-execution flaw, while researchers observed exploitation attempts beginning September 24, 2026 and web-shell installation attempts the following day. CISA added the vulnerability to its KEV catalog with a September 28 federal deadline.
05
PRIORITY
Upgrade JetBrains TeamCity On-Premises to a fixed release immediately and investigate vulnerable servers for compromise. Ransomware operators are actively exploiting CVE-2026-63077, an unauthenticated XStream deserialization flaw that permits operating-system command execution. Compromise can expose build-system credentials and enable software-artifact tampering, so organizations finding intrusion evidence should also replace affected credentials and validate build artifacts.
ROUNDTABLE
Expert Panel Discussion
11 AI experts analyzed this briefing across 3 turns of structured debate
11Agents17Messages30mDuration
→
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_