Dev.to Security šŸ” Cybersecurity šŸ‘ 0 šŸ“– 4 min read

Daily Cybersecurity Intelligence - September 28, 2026

Daily cybersecurity intelligence digest from CyberNetSec.io - September 28, 2026 šŸ“Š 8 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories. 1. Citrix NetS

Daily cybersecurity intelligence digest from CyberNetSec.io - September 28, 2026

šŸ“Š 8 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.

1. Citrix NetScaler Zero-Days (CVE-2026-88771) Actively Exploited

Citrix has released emergency patches for eight vulnerabilities in its NetScaler ADC and Gateway appliances, with two critical zero-days, CVE-2026-88771 and CVE-2026-88772, confirmed to be under active global exploitation. The flaws allow for unauthenticated remote code execution, leading to potential webshell deployment and full network compromise. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, mandating immediate patching and compromise investigation for federal agencies. The attacks were reportedly underway for weeks prior to disclosure, with attackers gaining persistent access to internal networks. Organizations are urged to apply updates immediately and hunt for indicators of compromise, as patching alone does not remediate existing intrusions.

šŸ“– Read full report →

2. JADEPUFFER (Storm-3168) Conducts Destructive Azure Attack

Microsoft has detailed a sophisticated and destructive attack against a Microsoft Azure tenant by the AI-driven threat actor JADEPUFFER, also tracked as Storm-3168. The attack, which occurred in June 2026, involved the use of two compromised service principals. One was used for extensive reconnaissance over 16 hours, while the second executed a rapid, seven-minute destructive sequence, deleting over 100 Azure Storage accounts, an Azure Key Vault, and other critical resources. The operation, believed to be automated, aimed to cripple recovery by also targeting backups. This incident highlights the evolution of agentic AI attacks, capable of performing complex, high-speed operations in cloud environments, and underscores the critical importance of securing non-human identities like service principals.

šŸ“– Read full report →

3. August Ransomware Attacks Hit 2026 Record High, Qilin Leads

Global ransomware attacks surged to a 2026 peak in August, with 1,073 incidents reported by NCC Group, a 12% increase from July. The industrial sector was the most heavily targeted, accounting for 31% of all attacks. The Qilin ransomware group emerged as the most prolific actor, responsible for 15% of the total incidents, with 164 confirmed attacks. High-profile targets included the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives. North America remained the most affected region, experiencing 44% of the attacks. The report also highlights the activities of emerging groups like Aurora and the continued trend of data extortion, reinforcing the escalating threat of ransomware to critical sectors worldwide.

šŸ“– Read full report →

4. Former US Soldier Sentenced for Hacking and Extortion

Cameron John Wagenius, a 22-year-old former U.S. Army soldier, has been sentenced to 70 months in federal prison for a large-scale hacking and extortion campaign. Operating as 'kiberphant0m', Wagenius targeted at least 10 organizations, including major telecommunications firms like AT&T, while on active duty. He and his co-conspirators stole vast amounts of customer data, partly through attacks exploiting the Snowflake cloud platform, and attempted to extort over $1 million from victims. Wagenius also attempted to sell stolen data to a foreign intelligence service. He was ordered to pay nearly $295,000 in restitution for charges including conspiracy to commit wire fraud and aggravated identity theft.

šŸ“– Read full report →

5. Altair Ransomware Strain Discovered Targeting Windows

Security researchers at CYFIRMA have identified a new ransomware strain named 'Altair' that targets Windows systems. Altair follows a double-extortion model, encrypting files with an extension like '.altair19' and exfiltrating data before dropping an HTML ransom note. The note gives victims a 72-hour deadline to establish contact via email or Tor before the ransom amount increases and threatens to leak the stolen data. The malware uses Windows Management Instrumentation (WMI) for stealthy reconnaissance and execution. Researchers anticipate future versions will incorporate more advanced evasion techniques and target critical data like databases and backups.

šŸ“– Read full report →

6. Pentagon Breach & Kiteworks Proactive Shutdown

Two major third-party risk incidents emerged, highlighting supply chain vulnerabilities. The U.S. Department of Defense disclosed a significant data breach from October 2025 that affected the Defense Manpower Data Center (DMDC) through a third-party provider, compromising sensitive personnel data. Separately, secure file transfer company Kiteworks took the drastic step of advising a customer-wide shutdown on September 25 based on 'credible, imminent' federal threat intelligence. Kiteworks later confirmed the threat window passed without compromise and that they had discovered and patched a new critical flaw affecting less than 1% of customers during the shutdown.

šŸ“– Read full report →

7. Clop Leak Site Hacked Using Grav CMS Flaw CVE-2026-42608

The recent defacement of the Clop ransomware gang's data leak site was caused by an unpatched path traversal vulnerability in the Grav content management system (CMS), tracked as CVE-2026-42608. Rival group ShinyHunters exploited the flaw, which existed in the older 1.7 branch of Grav CMS that Clop was using. The vulnerability allowed unauthenticated file uploads, enabling ShinyHunters to gain access, deface the site, and allegedly steal server source code and private keys. The incident highlights poor operational security by a major cybercrime group and the importance of timely patching for all software, as Grav had already fixed the flaw in a newer version.

šŸ“– Read full report →

8. Honeywell Report: 87% of Maritime Orgs Hit By Cyberattacks

A new report from Honeywell reveals a severe lack of cybersecurity maturity in the maritime industry. A staggering 87% of surveyed maritime organizations reported experiencing at least one significant operational technology (OT) cyber incident in the past year. The report highlights critical gaps, with only 21% maintaining a complete OT asset inventory and just a third integrating OT into a security operations center (SOC). These incidents led to an average of 16.2 hours of downtime, with potential financial losses reaching $500,000 per hour in severe cases. The findings align with other reports showing industrial sectors, including maritime, are increasingly targeted by cybercriminals.

šŸ“– Read full report →

šŸ“Œ Subscribe to daily updates at CyberNetSec.io

All reports include detailed analysis, IOCs, mitigation strategies, and references.

šŸ“° Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.