ITsecurity Daily
Daily Briefing
Actively exploited Citrix ADC flaws top the day; ShinyHunters run a new Oracle PeopleSoft campaign as the FBI's job sites stay offline
Good morning. Patch Citrix ADC first. CISA's Known Exploited Vulnerabilities catalog lists CVE-2026-88771 (CVSS 9.8, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and CVE-2026-88772 (CVSS 8.1) as known to be exploited. Citrix's advisory lists Citrix ADC 13.1 as affected up to the fix in 13.1-64.23. The same advisory (CTX697096) covers CVE-2026-88775, CVE-2026-88776 and CVE-2026-88777 — each CVSS 9.8 and not on the KEV catalog — with the same affected range and fix. Move to 13.1-64.23 per Citrix's advisory and apply any interim mitigation it names; CISA directs affected asset owners to follow BOD 26-04 patching guidance or discontinue the product where mitigations are unavailable.
ShinyHunters is exploiting a bug in Oracle PeopleSoft. The Record reported that Mandiant warns the group is using workarounds for the flaw in a new campaign. Help Net Security reported the FBI's applicant portals at apply.fbijobs.gov and fbijobs.gov/special-agents remain offline following what it describes as successful compromises by ShinyHunters via a PeopleSoft zero-day. If you run PeopleSoft, treat it as exposed and hunt for compromise. On the enforcement side, Krebs on Security reported Dutch authorities arrested a 23-year-old convicted cybercriminal on suspicion of aiding ShinyHunters, and that remaining members escalated their attacks in the days after; BleepingComputer reported Dutch police confirmed a 24-year-old Amsterdam man was arrested this month in the same investigation.
WordPress users should update. CISA's catalog lists CVE-2026-87902 (CVSS 8.1) as known to be exploited; the WordPress advisory lists versions from earliest up to the fix in 4.7.37 as affected. Move to 4.7.37.
Zoom out: Two of the day's threats — JadePuffer's Azure identity abuse and the NeedyMantis malware — were disclosed by Microsoft.
Vulnerability in focus
CVE-2026-88772 — Citrix. CVSS 8.1 CISA lists it as known to be exploited.
Affected: citrix-adc.
What to do: Follow the vendor advisory for the fixed release and any interim mitigation.
Elsewhere
- The Hacker News: OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot Read it
- The Hacker News: OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions Read it
- The Hacker News: Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials Read it
- Help Net Security: GitHub’s AI agent found 24 Android app vulnerabilities Read it
- SecurityWeek: Apple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’ Read it
- Help Net Security: Hottest cybersecurity open-source tools of the month: September 2026 Read it
- Help Net Security: Cybersecurity jobs available right now: September 29, 2026 Read it
- The Register: OpenAI’s dirty deeds Down Under included security bypass attempts, using exposed keys, source code siphon Read it
- The Hacker News: Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks Read it
- BleepingComputer: Dutch police confirm arrest in ShinyHunters hacking investigation Read it
- The Record: ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns Read it
- BleepingComputer: Misconfigured Supabase apps expose data in over 16,000 databases Read it
Sources
- Japan's Keio confirms ransomware attack disrupted business systems BleepingComputer
- JadePuffer crims hijacked Azure identities and used them to blow up cloud resources The Register
- ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns The Record
- Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks The Hacker News
- Call for Presentations Open for 2026 CISO Forum Virtual Summit SecurityWeek
- Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation Krebs on Security
- FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day Help Net Security
- New Attack Against RSA Schneier on Security
- Times Car confirms data breach affecting 6.6 million user accounts BleepingComputer
- Dutch police confirm arrest in ShinyHunters hacking investigation BleepingComputer
- Misconfigured Supabase apps expose data in over 16,000 databases BleepingComputer
- Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks The Hacker News
- IAM for AI agents: A Practical Enterprise Framework The Hacker News
- Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M The Hacker News
Share this issue
Facebook · X · Reddit · LinkedIn · WhatsApp · Email · Bluesky
Every briefing is on the site, with the advisory record behind it. All briefings