ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
Board › Newsletters › Past editions › ITsecurity Daily — Monday, 28 September 2026: Actively exploited Citrix ADC flaws top the day; ShinyHunters run a new Oracle PeopleSoft campaign as the FBI's job sites stay offline

ITSECURITY.GURU

ITsecurity Daily

Daily Briefing

Actively exploited Citrix ADC flaws top the day; ShinyHunters run a new Oracle PeopleSoft campaign as the FBI's job sites stay offline

Good morning. Patch Citrix ADC first. CISA's Known Exploited Vulnerabilities catalog lists CVE-2026-88771 (CVSS 9.8, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and CVE-2026-88772 (CVSS 8.1) as known to be exploited. Citrix's advisory lists Citrix ADC 13.1 as affected up to the fix in 13.1-64.23. The same advisory (CTX697096) covers CVE-2026-88775, CVE-2026-88776 and CVE-2026-88777 — each CVSS 9.8 and not on the KEV catalog — with the same affected range and fix. Move to 13.1-64.23 per Citrix's advisory and apply any interim mitigation it names; CISA directs affected asset owners to follow BOD 26-04 patching guidance or discontinue the product where mitigations are unavailable.

ShinyHunters is exploiting a bug in Oracle PeopleSoft. The Record reported that Mandiant warns the group is using workarounds for the flaw in a new campaign. Help Net Security reported the FBI's applicant portals at apply.fbijobs.gov and fbijobs.gov/special-agents remain offline following what it describes as successful compromises by ShinyHunters via a PeopleSoft zero-day. If you run PeopleSoft, treat it as exposed and hunt for compromise. On the enforcement side, Krebs on Security reported Dutch authorities arrested a 23-year-old convicted cybercriminal on suspicion of aiding ShinyHunters, and that remaining members escalated their attacks in the days after; BleepingComputer reported Dutch police confirmed a 24-year-old Amsterdam man was arrested this month in the same investigation.

WordPress users should update. CISA's catalog lists CVE-2026-87902 (CVSS 8.1) as known to be exploited; the WordPress advisory lists versions from earliest up to the fix in 4.7.37 as affected. Move to 4.7.37.

Read the full briefing →

Zoom out: Two of the day's threats — JadePuffer's Azure identity abuse and the NeedyMantis malware — were disclosed by Microsoft.

Vulnerability in focus

CVE-2026-88772 — Citrix. CVSS 8.1 CISA lists it as known to be exploited.

Affected: citrix-adc.

What to do: Follow the vendor advisory for the fixed release and any interim mitigation.

Elsewhere

  • The Hacker News: OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot Read it
  • The Hacker News: OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions Read it
  • The Hacker News: Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials Read it
  • Help Net Security: GitHub’s AI agent found 24 Android app vulnerabilities Read it
  • SecurityWeek: Apple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’ Read it
  • Help Net Security: Hottest cybersecurity open-source tools of the month: September 2026 Read it
  • Help Net Security: Cybersecurity jobs available right now: September 29, 2026 Read it
  • The Register: OpenAI’s dirty deeds Down Under included security bypass attempts, using exposed keys, source code siphon Read it
  • The Hacker News: Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks Read it
  • BleepingComputer: Dutch police confirm arrest in ShinyHunters hacking investigation Read it
  • The Record: ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns Read it
  • BleepingComputer: Misconfigured Supabase apps expose data in over 16,000 databases Read it

Sources

Every briefing is on the site, with the advisory record behind it. All briefings

You are receiving this because you subscribed at itsecurity.guru.

Headlines from other outlets belong to them; each one credits its outlet and leads to their own report.

All past editions · Get them by email