ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
Board › Daily Briefing › 28 Sept 2026

ITSECURITY.GURU

Daily Briefing

Today's outlook

Actively exploited Citrix ADC flaws top the day; ShinyHunters run a new Oracle PeopleSoft campaign as the FBI's job sites stay offline

Good morning. Patch Citrix ADC first. CISA's Known Exploited Vulnerabilities catalog lists CVE-2026-88771 (CVSS 9.8, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and CVE-2026-88772 (CVSS 8.1) as known to be exploited. Citrix's advisory lists Citrix ADC 13.1 as affected up to the fix in 13.1-64.23. The same advisory (CTX697096) covers CVE-2026-88775, CVE-2026-88776 and CVE-2026-88777 — each CVSS 9.8 and not on the KEV catalog — with the same affected range and fix. Move to 13.1-64.23 per Citrix's advisory and apply any interim mitigation it names; CISA directs affected asset owners to follow BOD 26-04 patching guidance or discontinue the product where mitigations are unavailable.

ShinyHunters is exploiting a bug in Oracle PeopleSoft. The Record reported that Mandiant warns the group is using workarounds for the flaw in a new campaign. Help Net Security reported the FBI's applicant portals at apply.fbijobs.gov and fbijobs.gov/special-agents remain offline following what it describes as successful compromises by ShinyHunters via a PeopleSoft zero-day. If you run PeopleSoft, treat it as exposed and hunt for compromise. On the enforcement side, Krebs on Security reported Dutch authorities arrested a 23-year-old convicted cybercriminal on suspicion of aiding ShinyHunters, and that remaining members escalated their attacks in the days after; BleepingComputer reported Dutch police confirmed a 24-year-old Amsterdam man was arrested this month in the same investigation.

WordPress users should update. CISA's catalog lists CVE-2026-87902 (CVSS 8.1) as known to be exploited; the WordPress advisory lists versions from earliest up to the fix in 4.7.37 as affected. Move to 4.7.37.

Microsoft flagged two threats. The Register reported Microsoft warns that JadePuffer hijacked Azure identities and used them to destroy cloud resources, characterising it as agentic ransomware. The Hacker News reported Microsoft's technical analysis of NeedyMantis, a malware family used to maintain long-term access after a breach, seen in a small number of targeted intrusions at telecommunications organisations, universities, medical nonprofits and intergovernmental organisations.

Apple released updates for an out-of-bounds write in CoreGraphics affecting older versions of iOS, iPadOS and macOS; The Hacker News reported Apple said it "may have been exploited in targeted attacks." Update older Apple devices.

Also reported Monday: The Hacker News reported Bitget said an attacker exploited a flaw in a third-party security product to obtain high-level internal credentials and steal about $388 million. BleepingComputer reported researchers found more than 16,000 misconfigured Supabase databases exposing tables with personally identifiable information, passwords or authentication tokens — audit your Supabase access rules. BleepingComputer also reported Keio Corporation confirmed a ransomware attack disrupted business systems, and that Times Car confirmed a breach affecting approximately 6.6 million user accounts.

Zoom out: Two of the day's threats — JadePuffer's Azure identity abuse and the NeedyMantis malware — were disclosed by Microsoft.

Vulnerability in focus

CVE-2026-88772 — Citrix. CVSS 8.1 CISA lists it as known to be exploited.

Affected: citrix-adc.

What to do: Follow the vendor advisory for the fixed release and any interim mitigation.

What we're tracking

  • BleepingComputer: Japan's Keio confirms ransomware attack disrupted business systems Read it
  • The Register: JadePuffer crims hijacked Azure identities and used them to blow up cloud resources Read it
  • The Record: ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns Read it
  • The Hacker News: Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks Read it

Sources

Summarized from the linked reports and the advisory record by the desk. Verify against the original sources before citing.

All briefings →