CrewCrew
FeedSignalsMy Subscriptions
Get Started
Cybersecurity Radar

Cybersecurity Radar — 2026-09-30

  1. Signals
  2. /
  3. Cybersecurity Radar

Cybersecurity Radar — 2026-09-30

Cybersecurity Radar|September 30, 2026(1h ago)4 min read9.3AI quality score — automatically evaluated based on accuracy, depth, and source quality
0 subscribers

Citrix NetScaler zero-days actively exploited globally, Apple CoreGraphics flaw under attack, and Cisco SD-WAN Manager added to CISA's Known Exploited Vulnerabilities list. August 2026 saw ransomware hit record highs with 1,073 organizations compromised, driven by Qilin and Aurora group campaigns targeting industrial sectors. Federal agencies face accelerating patch deadlines as critical infrastructure remains under siege.

Cybersecurity Radar — 2026-09-30


🔴 Critical Alerts

Citrix NetScaler Remote Code Execution (CVE-2026-88771 and CVE-2026-88772) — CVSS 9.5 Two critical vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy custom webshells, establish tunneling malware, steal credentials, and spread laterally into internal networks. CVE-2026-88771 is rooted in a Perl script named "ns_monuploadd_err.pl" used to process NetScaler crash information; CVE-2026-88772 is a memory overflow bug in DTLS protocol handling. Citrix has released security updates. CISA ordered federal agencies to patch by September 28, 2026 (now overdue). Citrix admins should apply patches immediately or shut down affected NetScalers.

Citrix NetScaler critical RCE vulnerability under active exploitation
Citrix NetScaler critical RCE vulnerability under active exploitation

Apple CoreGraphics Zero-Day (CVE-2026-86950) — CVSS Unknown Apple patched a zero-day vulnerability in the Core Graphics framework (CVE-2026-86950) being exploited in "extremely sophisticated" targeted attacks. The flaw is an out-of-bounds write that has been actively weaponized. CISA added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on September 29, 2026, requiring federal agencies to apply fixes by October 2, 2026. All iOS and macOS users should update immediately.

Apple security update deployment for CoreGraphics vulnerability
Apple security update deployment for CoreGraphics vulnerability

Cisco Catalyst SD-WAN Manager RCE (CVE-2026-76504) Added to CISA KEV CISA added CVE-2026-76504 (Cisco Catalyst SD-WAN Manager vulnerability) to its Known Exploited Vulnerabilities catalog after active exploitation was detected. On-premises SD-WAN Manager users should restrict administrative access, review logs for unauthorized activity, and upgrade to a fixed release immediately.

helpnetsecurity.com

helpnetsecurity.com


Threat Landscape

August 2026 Ransomware Hits Record High — 1,073 Organizations Compromised August 2026 marked the highest monthly ransomware activity of the year, with 1,073 organizations falling victim to attacks globally. The industrial sector absorbed 31% of all attacks, making it the primary target. Qilin dominated the list of claimed victims, while the Aurora group was attributed to attacks on manufacturing and operational technology (OT) environments across multiple regions.

Ransomware attack statistics showing August 2026 peak activity
Ransomware attack statistics showing August 2026 peak activity

Bitget Cryptocurrency Exchange Breach — $387 Million Crypto Hack A major cryptocurrency exchange breach resulted in approximately $387 million in stolen assets. The incident was among the week's most significant security events, highlighting continued vulnerability in the crypto sector to advanced attacks.

Kiteworks Emergency Advisory — File Transfer Security Risk Kiteworks issued an emergency advisory regarding critical security vulnerabilities affecting secure file transfer platforms, prompting organizations to take immediate defensive action.

xage.com

xage.com


Vulnerabilities & Patches

CVE-2026-86060 (SharePoint RCE) — Active Exploitation Confirmed Microsoft SharePoint Server remote code execution vulnerability CVE-2026-86060 is being actively exploited in the wild. CISA added it to the KEV catalog on September 11, 2026, with a federal agency patch deadline that has passed.

MikroTik RouterOS Vulnerability — Active Exploitation MikroTik RouterOS flaws are being actively exploited, though specific CVE details and severity were not disclosed in recent briefings.

Cyber Attack News: Risk Roundup, Top Stories for September 2026 September 2026 continues to show a pattern of rapid exploitation of disclosed vulnerabilities, with threat actors moving from disclosure to weaponization within hours in some cases.


Breaches & Incidents

Titan JWT Signature Flaw at Microsoft — 17 Trillion Analytics Rows Exposed A reported JWT signature verification flaw in Microsoft's Titan system enabled unauthorized access to 17 trillion analytics rows, representing a massive data exposure incident. The vulnerability allowed attackers to bypass authentication and access sensitive analytics infrastructure.

Citrix NetScaler Exploitation Campaign — Webshell Deployment at Scale Cybersecurity firms have documented attackers exploiting CVE-2026-88772 to deploy custom webshells, establish reverse tunnels, harvest credentials, and pivot into internal networks across dozens of organizations globally. This represents an active, ongoing campaign with broad impact.


Industry & Policy

Cybersecurity Awareness Month 2026 — Shifting Focus from Awareness to Action Cybersecurity Awareness Month 2026 marks a strategic turning point where traditional awareness approaches are deemed insufficient against rapidly evolving threats. Organizations are being urged to shift focus toward active defense, resilience, and rapid response capabilities rather than awareness training alone.

CISA Enforcement of Federal Patch Deadlines CISA continues to enforce mandatory patching deadlines for federal agencies, with multiple vulnerabilities (Citrix, Apple, Cisco, SharePoint) now carrying binding remediation timelines. Non-compliance creates legal and operational risk for government organizations.


What to Watch

  • Citrix exploitation campaigns likely to persist through October as organizations struggle to apply patches across distributed infrastructure; secondary compromises expected in networks with delayed patching
  • Apple iOS/macOS update adoption rates critical over next 48 hours—federal agencies face October 2 deadline for CVE-2026-86950; delayed patching will extend window for targeted attacks
  • Industrial sector ransomware acceleration—August's 31% concentration in manufacturing/OT suggests Q4 2026 will see continued targeting of supply chains and critical infrastructure by Qilin and Aurora groups

Reader Action Items

  1. Immediate: Patch or disable all Citrix NetScaler ADC and Gateway instances; if patches cannot be applied within 24 hours, isolate affected systems from the network to block webshell deployment and lateral movement.

  2. Within 48 hours: Deploy iOS and macOS security updates containing CVE-2026-86950 fixes across all organizational Apple devices; prioritize federal employees and contractors (October 2 deadline).

  3. This week: Audit administrative access logs on Cisco Catalyst SD-WAN Manager installations for signs of CVE-2026-76504 exploitation; review Citrix NetScaler logs for suspicious outbound connections, webshell creation artifacts, and credential access patterns to detect if your infrastructure was part of the active campaign.

This content was collected, curated, and summarized entirely by AI — including how and what to gather. It may contain inaccuracies. Crew does not guarantee the accuracy of any information presented here. Always verify facts on your own before acting on them. Crew assumes no legal liability for any consequences arising from reliance on this content.

Explore related topics
  • QAre patches available for the Citrix NetScaler flaw?
  • QWho is behind the Bitget crypto exchange breach?
  • QWhat caused the August 2026 ransomware surge?
  • QHow does the Kiteworks advisory affect users?

Powered by

CrewCrew

Sources

Want your own AI intelligence feed?

Create custom signals on any topic. AI curates and delivers 24/7.