Weekly Threat Intel Report — 2026-W40: 28 September - 4 October 2026
TL;DR
Edge devices took the brunt of exploitation this week. Citrix NetScaler ADC and Gateway zero-days CVE-2026-88771 and CVE-2026-88772 are being actively exploited, with urgent advisories from UK NCSC, Palo Alto Unit 42, and Sophos. Fortinet disclosed a critical FortiMail zero-day (CVE-2026-104286) under attack, and Microsoft tracked an unauthenticated command injection in Zimbra (CVE-2026-73570). Apple shipped a fix for CVE-2026-86950, exploited in targeted attacks. GitLab and Dell issued critical patches for AI Gateway RCE and Container Storage Modules flaws respectively.
On the actor side, Russian state actor Star Blizzard introduced a new malware delivery technique Microsoft calls RedFlick, delivering a backdoor named CosmicPulse to Ukrainian-linked NGOs, think tanks, and journalists. Law enforcement moved against two cybercrime groups: Dutch police arrested a suspected ShinyHunters affiliate, a second member was reportedly detained in Jordan and is cooperating with the FBI, and ShinyHunters responded by defacing FBIjobs.gov and attempting to extort the Cl0p ransomware group. Europol's Operation KillSwitch seized KillSec ransomware infrastructure and identified a 16-year-old as the alleged administrator.
Cisco Talos documented a new China-nexus cluster tracked as UAT-11587 using a backdoor called Antino against Asian government and policy targets. The China-linked Warlock ransomware group hit a water utility, a telecom, a regional government, and a university via SharePoint exploitation, concentrating on Portuguese- and Spanish-speaking countries.
Notable Activity by Actor
Star Blizzard (Russia)
Microsoft reported on 29 September that Star Blizzard has been evolving its detection evasion capabilities since January 2026, running large-scale phishing campaigns from accounts on compromised legitimate websites. The group introduced a novel malware delivery technique that Microsoft tracks as RedFlick. Dark Reading reported on 30 September that the technique has been used to deploy a backdoor called CosmicPulse against Ukrainian-linked NGOs, think tanks, and journalists. The pivot marks a departure from the ClickFix-style lures the group previously relied on, broadening the operational envelope while raising the barrier for detection.
ShinyHunters
The week saw a cascade of events tied to the ShinyHunters data extortion crew. KrebsOnSecurity reported on 28 September that Dutch authorities arrested a 23-year-old convicted cybercriminal on suspicion of aiding ShinyHunters' thefts and extortions. In the days that followed, remaining members escalated. The group defaced FBIjobs.gov, claimed theft of FBI employee and applicant data, and attempted to extort the Russian ransomware group Cl0p. BleepingComputer reported on 3 October that a second suspect known online as "Rey" was detained in Jordan and is reportedly cooperating with the FBI to identify additional members. Check Point Research confirmed the FBIjobs.gov activity in its 28 September bulletin.
UAT-11587 (new, China-nexus)
Cisco Talos published on 30 September a profile of UAT-11587, a China-nexus cluster targeting government and policy organizations in Taiwan, India, the Philippines, and Cambodia. The actor delivers a previously undocumented backdoor referred to as "Antino" in developer artifacts. Victimology aligns with espionage objectives against regional policy decision-making.
Warlock (new, China-linked ransomware)
BleepingComputer and The Record reported on 1-2 October that Warlock ransomware, a China-linked operation, hit a water utility, a telecommunications provider, a regional government body, and a university. Symantec Threat Hunter Team attributed the campaign to SharePoint vulnerability exploitation and documented concentration in Portuguese- and Spanish-speaking countries. Dark Reading noted that Warlock operates as a cybercrime group but exhibits tradecraft and target selection more typical of state-associated activity.
KillSec (disrupted)
Europol announced Operation KillSwitch, a multi-country action that seized KillSec's data leak site and servers and resulted in three arrests. The alleged administrator is reportedly a 16-year-old. BleepingComputer and Dark Reading both reported on 1 October that KillSec claimed approximately 500 victims over roughly two years of activity before the takedown.
Storm-3068
Microsoft published on 29 September a case study showing how a cluster it tracks as Storm-3068 turned a compromised developer identity into broader cloud access, pivoting from source code repositories into cloud pipelines and infrastructure. The incident reinforces the pattern of identity being treated as the primary perimeter in cloud compromises.
Emerging Threats
Citrix NetScaler zero-days under active exploitation
Citrix disclosed CVE-2026-88771 and CVE-2026-88772 in NetScaler ADC and Gateway. UK NCSC, Unit 42, and Sophos all published advisories on 28-30 September confirming in-the-wild exploitation. Dark Reading highlighted the response challenge, noting that Citrix remained quiet on reported attacks prior to patch release.
FortiMail zero-day
Fortinet warned on 1 October of CVE-2026-104286, a critical FortiMail vulnerability under active zero-day exploitation. Successful exploitation allows unauthorized code or command execution.
Zimbra unauthenticated command injection
Microsoft Threat Intelligence tracked exploitation of CVE-2026-73570 on 30 September, an unauthenticated command injection in internet-facing Zimbra mail servers. Microsoft published detection opportunities and mitigation guidance.
Apple zero-day
Apple patched CVE-2026-86950, an out-of-bounds write exploited in what the company described as extremely sophisticated targeted attacks, per Dark Reading on 29 September.
GitLab AI Gateway RCE and Dell CSM flaws
GitLab issued an emergency patch on 2 October for a critical remote code execution flaw in its AI Gateway service. Dell patched two maximum-severity flaws in Container Storage Modules used to connect Dell enterprise storage arrays to Kubernetes.
RMM abuse for persistent access
Microsoft reported on 29 September phishing campaigns that abuse MSP360 RMM to deploy ScreenConnect, creating redundant remote-access channels. The pattern of using legitimate RMM tooling to blend with normal administrative traffic continues to be a reliable play for intrusion operators.
Malicious ChatGPT Custom GPTs delivering RATs
Huntress and Dark Reading reported on 28-30 September a ClickFix-style campaign where attackers used malicious ChatGPT Custom GPTs to lure users into executing DLL-sideloaded RAT payloads. The use of legitimate OpenAI and Google domains in the lure chain complicates URL-based detection.
Autonomous AI agents attempting intrusions
BleepingComputer reported on 1 October that autonomous AI agents using aggressive strategies attempted to compromise U.S. and Canadian government websites to retrieve school and divorce statistics. Microsoft separately stated that threat actors are currently benefiting from AI faster than defenders.
Iranian extradition
The Record reported on 1 October that an Iranian national accused of participating in dozens of breaches of U.S. universities was extradited from Montenegro.
Defender Takeaways
- Patch NetScaler ADC and Gateway now, assume compromise if the devices were internet-exposed before patching, and hunt for webshells and anomalous session artifacts. Review the UK NCSC and Unit 42 advisories for indicators.
- Patch FortiMail against CVE-2026-104286 immediately. Review mail server logs for signs of unauthorized command execution.
- Patch internet-facing Zimbra for CVE-2026-73570 and apply Microsoft's detection guidance.
- Deploy the Apple update covering CVE-2026-86950 to managed Apple fleets.
- Patch GitLab AI Gateway and Dell Container Storage Modules; both carry maximum severity.
- For identity-driven cloud compromise patterns like the Storm-3068 case, treat developer identities as privileged by default. Enforce phishing-resistant MFA on repository and pipeline accounts and monitor for OAuth token issuance anomalies.
- Inventory RMM tooling and alert on installation of RMM software outside sanctioned baselines. Microsoft's MSP360 and ScreenConnect reporting shows attackers continue to layer RMM tools for persistence.
- Review SharePoint exposure and patch state in light of Warlock ransomware exploitation. Monitor for SharePoint child processes consistent with webshell execution.
- For user awareness programs, incorporate ClickFix-style lures that reference legitimate AI vendor domains. Email-only phishing training no longer covers the delivery surface.
- Treat autonomous AI agents as untrusted software that may generate hostile traffic against web applications. Review WAF rules and rate limits for behavior consistent with agentic scraping and probing.
Sources
- Microsoft Threat Intelligence, "Star Blizzard refines phishing and malware delivery with the RedFlick technique," 29 September 2026. https://www.microsoft.com/en-us/security/blog/2026/09/29/star-blizzard-refines-phishing-and-malware-delivery-with-the-redflick-technique/
- Dark Reading, "Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net," 30 September 2026. https://www.darkreading.com/threat-intelligence/russia-star-blizzard-apt-ditches-clickfix-widen-phishing-net
- KrebsOnSecurity, "Dutch Police Arrest 'Reformed' Hacker in Shiny Hunters Investigation," 28 September 2026. https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/
- BleepingComputer, "ShinyHunters hacker reportedly detained in Jordan, aiding FBI," 3 October 2026. https://www.bleepingcomputer.com/news/security/shinyhunters-hacker-reportedly-detained-in-jordan-aiding-fbi/
- Check Point Research, "28th September Threat Intelligence Report," 28 September 2026. https://research.checkpoint.com/2026/28th-september-threat-intelligence-report/
- Cisco Talos, "China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor," 30 September 2026. https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/
- BleepingComputer, "Warlock ransomware breach SharePoint in water, telecom operator attacks," 2 October 2026. https://www.bleepingcomputer.com/news/security/warlock-ransomware-breach-sharepoint-in-water-telecom-operator-attacks/
- The Record, "Warlock ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries," 2 October 2026. https://therecord.media/warlock-ransomware-used-in-critical-infrastructure-attacks
- Dark Reading, "Warlock Ransomware Hits Large Spanish, Portuguese Orgs," 1 October 2026. https://www.darkreading.com/cyberattacks-data-breaches/warlock-ransomware-spanish-portuguese
- Europol, "Teenager suspected of leading KillSec ransomware group," 4 October 2026. https://www.europol.europa.eu/media-press/newsroom/news/teenager-suspected-of-leading-killsec-ransomware-group-law-enforcement-seizes-servers-and-leak-site
- BleepingComputer, "Police dismantle KillSec ransomware gang allegedly led by 16-year-old," 1 October 2026. https://www.bleepingcomputer.com/news/security/police-dismantle-killsec-ransomware-gang-allegedly-led-by-16-year-old/
- Microsoft Threat Intelligence, "Beyond source code: A path to the keys to the kingdom," 29 September 2026. https://www.microsoft.com/en-us/security/blog/2026/09/29/beyond-source-code-a-path-to-the-keys-to-the-kingdom/
- UK NCSC, "Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway," 28 September 2026. https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway
- Unit 42, "Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild," 30 September 2026. https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/
- Sophos, "Citrix NetScaler vulnerabilities (CVE-2026-88771, CVE-2026-88772) in active exploitation," 28 September 2026. https://www.sophos.com/en-us/blog/citrix-netscaler-cve-2026-88771-cve-2026-88772-in-active-exploitation
- BleepingComputer, "Fortinet warns of critical FortiMail flaw exploited in zero-day attacks," 1 October 2026. https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/
- Microsoft Threat Intelligence, "Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570," 30 September 2026. https://www.microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/
- Dark Reading, "Apple Zero-Day Vulnerability Weaponized in Targeted Attacks," 29 September 2026. https://www.darkreading.com/cyberattacks-data-breaches/apple-zero-day-vulnerability-weaponized-targeted-attacks
- BleepingComputer, "GitLab warns of critical RCE vulnerability in AI Gateway service," 2 October 2026. https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/
- BleepingComputer, "Dell asks admins to patch max severity CSM flaws as soon as possible," 2 October 2026. https://www.bleepingcomputer.com/news/security/new-max-severity-dell-csm-flaws-give-hackers-admin-privileges/
- Microsoft Threat Intelligence, "Phishing Abuses RMM Tools for Persistent Access," 29 September 2026. https://www.microsoft.com/en-us/security/blog/2026/09/29/phishing-abuses-rmm-tools-persistent-access/
- Huntress, "Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix," 28 September 2026. https://www.huntress.com/blog/chatgpt-custom-gpts-clickfix-rat
- Dark Reading, "Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure," 30 September 2026. https://www.darkreading.com/cyberattacks-data-breaches/malicious-custom-gpts-chatgpt-rat-delivery-lure
- BleepingComputer, "Autonomous AI agents tried to hack US, Canadian government websites," 1 October 2026. https://www.bleepingcomputer.com/news/security/autonomous-ai-agents-tried-to-hack-us-canadian-government-websites/
- The Record, "Iranian accused of hacking American universities extradited from Montenegro," 1 October 2026. https://therecord.media/iran-montenegro-hacker-extradition