# This Week in Cybersecurity: Week 40

> Week 40: Citrix NetScaler flaws mass-exploited worldwide, an exploited Apple flaw patched for older iPhones, and attacks on Cisco SD-WAN and FortiMail.

By Marcus · October 4, 2026 · 16 min read · Weekly

Source: https://bluwarden.com/blog/this-week-in-cybersecurity-2026-w40

---

The biggest story of the week is not new code, it is an old pattern. Two critical flaws in Citrix NetScaler, the boxes that sit at the edge of tens of thousands of company networks and handle VPN logins, went from "exploited in targeted attacks" to mass exploitation by multiple unrelated groups within days. By midweek researchers were watching attackers plant web shells to sell the access on or recruit the devices into botnets. If your organisation runs NetScaler and has not patched since last Saturday, assume someone has already knocked.

Around it sat a crowded week for edge and email gear: an actively exploited authentication bypass in Cisco's SD-WAN manager, a FortiMail zero-day with no full patch yet, and Microsoft's detailed write-up of attackers emptying Zimbra mail servers. On the consumer side, Apple patched a flaw it says may have been used against specific people on older iOS versions, and a ChatGPT feature was turned into a malware delivery route. This roundup covers Monday 28 September to Sunday 4 October.

If you missed it, [last week's roundup](/blog/this-week-in-cybersecurity-2026-w39) covered the F5, Check Point and SharePoint attacks and the first days of the Bitget theft, which got its explanation this week.

## What to act on

### Update your iPhone, iPad or Mac if it is not on the latest version

Apple [patched CVE-2026-86950](https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html) on 28 September, a memory flaw in CoreGraphics, the part of iOS and macOS that draws images and renders PDFs. A booby-trapped file can trigger it. Apple says it is aware of a report that the bug may have been used in an "extremely sophisticated attack against specific targeted individuals" running versions of iOS before iOS 27. CISA added it to its list of exploited flaws the next day.

The fixes are iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. Apple does not list iOS 27 as affected.

Two days later, researchers [published the first public proof of concept](https://thehackernews.com/2026/10/apple-coregraphics-poc-emerges-as.html): a PDF with a crafted embedded font that crashes unpatched iPhones and Macs. That is a crash, not a working takeover, and turning it into one is separate work. But a public trigger shortens the road for everyone else. There is also circumstantial evidence pointing at WhatsApp as a possible delivery route - Meta found the flaw, and WhatsApp's attachment scanner quietly gained new checks for suspicious PDF fonts - though nobody has confirmed that path and Meta has not commented.

**Do this:** Settings, General, Software Update. If your device can run iOS 27, the newest release is the cleaner fix; if it cannot, install 26.7.1. Our [iPhone security guide](/blog/ios-standard-security-hardening) covers turning on automatic updates so the next one lands without you. If you believe you are a likely target of state-level spyware - journalists, activists, people in politics - Lockdown Mode is worth turning on, though Apple has not said whether it would have blocked this specific attack.

### The fake "ChatGPT" that tells you to paste a command

Huntress [found attackers abusing ChatGPT's Custom GPT feature](https://thehackernews.com/2026/09/attackers-abuse-chatgpt-custom-gpts-to.html), the option that lets anyone publish a tailored version of ChatGPT on the real chatgpt.com site. The chain started with a paid Google ad for searches like "chatgpt". That led to a Custom GPT called "Plus 5.6", which answered any prompt with a fake "Service Availability Notice" pushing users to a "backup domain" on Google Sites. There, a fake Cloudflare check told visitors to copy and run a PowerShell command. That command installed a remote access trojan that can watch the screen, record the microphone and camera, and run anything the attacker sends. At least 40 people were infected.

This is the ClickFix trick again, wrapped in a trusted brand and hosted on trusted domains. Every link in the chain looked legitimate because every link was on a legitimate site.

**Do this:** one rule covers it. No real website, CAPTCHA, or "verification" ever needs you to paste a command into PowerShell, Terminal or the Run box. If a page asks, close it. And go to chatgpt.com by typing it, not through a sponsored search result.

## The week's biggest

### Citrix NetScaler: two 9.5 flaws, now in mass exploitation

Citrix confirmed on 27 September that two flaws in NetScaler ADC and NetScaler Gateway were being exploited, and CISA [added both to its exploited list](https://thehackernews.com/2026/09/cisa-says-attackers-are-exploiting-two.html) the same day. CVE-2026-88771 lets an unauthenticated attacker run commands and affects every deployment on a vulnerable version. CVE-2026-88772 is a memory flaw in how NetScaler handles DTLS, the UDP flavour of encryption used for VPN traffic, and it needs DTLS enabled - which it is by default on VPN servers. Both score 9.5.

The first flaw is almost comically simple once explained. Researchers at watchTowr found that NetScaler writes attacker-supplied text into its logs, and a crash-reporting script later feeds those log lines into a shell command. So an attacker sends a login request with a command hidden in the username, and the box eventually runs it as root.

Fixed builds are 14.1-73.37 and 13.1-64.23 and later, with matching FIPS releases. Unit 42 counted more than 50,000 internet-exposed NetScaler instances potentially vulnerable to both flaws as of 27 September.

Then it escalated. Mandiant and Google's threat intelligence team [reported targeted intrusions](https://thehackernews.com/2026/09/attackers-exploit-netscaler-flaw-for.html) at dozens of organisations in government, finance, tech, education and legal services across North America and Europe, using two new tools: a PHP web shell that hides commands in ordinary HTTP headers, and a Python tunnel that lets the attacker reach the internal network through the compromised box. GreyNoise said that what started as reconnaissance had become "mass exploitation across a multitude of independent actors" by 30 September, aimed largely at botnet recruitment and access brokering.

The important part for defenders: patching closes the door, it does not evict anyone already inside. Citrix's own guidance for a suspected compromise is to isolate the device, rebuild it, rotate every local password and key, and investigate everything the appliance connected to. This is the textbook case for why we keep saying [edge devices are where company security actually breaks](/blog/what-actually-breaks-company-security-2026): they face the internet, they hold credentials, and no endpoint protection runs on them.

**Who's exposed:** any organisation running NetScaler ADC or Gateway as its remote-access front door - common in mid-size and large companies, councils and universities. If you only connect to a work VPN, this is your IT team's problem; if you suddenly get a forced password reset from work this month, this may be why.

### Cisco SD-WAN Manager: admin access with no login

Cisco said on 30 September that attackers are [exploiting CVE-2026-76504](https://thehackernews.com/2026/09/cisco-warns-of-attackers-exploiting.html) (CVSS 9.8) in Catalyst SD-WAN Manager, the console companies use to run their Cisco wide-area networks. A request with one character of a login path URL-encoded slips past an authentication rule and lands the attacker on the Manager's API as the admin user. No credentials needed, and there is no workaround - only fixed releases, starting at 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1.

Two details matter. First, a Manager patched for the May or June SD-WAN flaws still needs this update, because those fixes are older. Second, the advisory does not say whether upgrading removes an attacker who already got in, and Cisco's earlier SD-WAN advisories said it would not. Cisco suggests checking the service-proxy and vmanage-server logs for odd `j_security_check` requests and collecting an admin-tech file before upgrading. This is the eighth Cisco SD-WAN flaw added to CISA's exploited list this year.

**Who's exposed:** enterprises with an on-premises SD-WAN Manager reachable from the internet. Cisco's managed cloud customers are already fixed. Nobody at home is affected.

### FortiMail zero-day, with patches still "upcoming"

CISA [added CVE-2026-104286](https://thehackernews.com/2026/10/critical-fortimail-zero-day-flaw.html) (CVSS 9.8) in Fortinet's FortiMail email security gateway to its exploited list on 1 October. A path traversal lets an unauthenticated attacker write arbitrary files to the system with a crafted web request, which in practice means planting their own code. Fortinet confirms exploitation in the wild.

The uncomfortable bit: Fortinet's advisory lists the fixed versions for the 8.0, 7.6 and 7.4 branches (8.0.2, 7.6.7, 7.4.9) as "upcoming", and tells 7.2 users to move to 7.4. Until those land, the workarounds are to disable the IBE (identity-based encryption) feature and take the management interface off the internet. Fortinet has published two attacker IP addresses and a list of planted files, including a modified `ld.so.preload`, which admins should check for now rather than after patching.

**Who's exposed:** organisations that filter their email through a FortiMail appliance. You will not have one at home, but your bank, employer or council might, and email gateways see every message.

### Zimbra mail servers emptied through one email

Microsoft published a [detailed account of attacks on Zimbra](https://thehackernews.com/2026/09/attackers-exploit-zimbra-flaw-to-deploy.html) using CVE-2026-73570 (CVSS 8.9). The flaw is not new - Zimbra patched it in version 10.1.20 in July, and CERT Polska flagged exploitation in August - but the write-up shows what the attackers did once inside, and it is thorough. A specially crafted email to an exposed server, no login and no click, runs commands as the Zimbra service account when the optional SNMP package is installed and SNMP notifications are on.

From there, attackers dropped multiple web shells for redundancy, gave themselves passwordless root, pulled Zimbra's central authentication secrets (including the keys behind its two-factor login), spread across clustered servers, dumped the mailbox database, and tried to ship mailbox backups out to Azure storage. Notably, Microsoft saw the exploitation in the window between the patch release and public disclosure, which is a reminder that attackers read changelogs too.

**Who's exposed:** organisations running self-hosted Zimbra with the optional zimbra-snmp package installed and SNMP notifications on. If you are on 10.1.20 or later and still had SNMP open beforehand, rotate the Zimbra secrets anyway.

### Bitget's $387.5 million theft came through its security vendor

Last week Bitget said suspected North Korean attackers had drained its hot and warm wallets. This week it [explained how](https://thehackernews.com/2026/10/bitget-confirms-third-party-zero-day.html), and revised the figure to $387.5 million. The way in was a zero-day in a third-party security product the exchange used. Investigators at SlowMist traced the first malicious activity back to 31 August, more than three weeks before the money moved. Mandiant found the attackers compromised two security appliances, planted a web shell on one, then used it to push malicious packages onto Bitget's production wallet server. A custom tool, built around Bitget's own withdrawal logic, did the actual stealing.

Bitget has not named the vendor, which means other customers of the same product cannot yet check whether they are next. That is the part worth watching.

**Who's exposed:** Bitget customers' balances are reported as intact and cold wallets untouched. The wider lesson lands on any organisation that trusts its security appliances implicitly - the product meant to protect the network was the path through it.

### France's tax agency lost 600,000 records to stolen passwords

France's cybersecurity agency ANSSI published its [report on the DGFIP tax data theft](https://thehackernews.com/2026/09/french-tax-data-theft-using-stolen.html), and it is a blunt document. An attacker used several dozen staff passwords, probably harvested by infostealer malware on staff's personal computers, to log into two internal portals that asked for nothing but a password. Over June and July they scraped data on a little over 350,000 individuals (tax ID, contact details, family situation, reference income, withholding rate) and over 250,000 businesses. A separate route through a land surveyor's compromised computer reached land-registry data on nearly 435,000 households. Nobody noticed for seven weeks, until the attacker bragged on a forum.

The ministry originally blamed "the sophistication of the attack". ANSSI says it was not sophisticated at all. The security team did catch some stolen accounts and reset their passwords, but a password reset did not end the attacker's open session on a portal nobody was monitoring, and data kept flowing for 16 more hours. ANSSI's fixes read like a checklist: kill every session on a password reset, use phishing-resistant MFA everywhere (a code sent to an email inbox the same password opens does not count), set limits on how much data one account can pull, and keep personal devices away from work systems. Our [guide to passkeys and MFA](/blog/password-best-practices-2026) explains why the password-only portal was the whole problem.

**Who's exposed:** if you file taxes in France, the DGFIP says your online account and password were not compromised, but expect convincing tax-themed phishing that quotes your real details. Treat any message about a refund or "regularisation" as suspect and go to impots.gouv.fr directly.

### AI coding agents posted 13,000 private screenshots in public

Security firm Glow [found more than 13,000 internal images](https://thehackernews.com/2026/09/ai-coding-agents-exposed-13000-internal.html) from developers at over 300 organisations sitting in public GitHub repositories, including customer billing records, a treasury and settlement console at a financial firm, and screens of unreleased features. The cause was mundane. Developers asked AI coding agents to show screenshots of their changes for code review; GitHub's command-line tool could not attach images until 1 September; so the agents improvised by creating a public repository under the developer's personal account and posting the images there. At one company the workaround spread from agent to agent as a saved skill, and over a thousand screenshots went public.

Because the repositories sat on personal accounts, company security teams never saw them. Glow's advice is to check the public repos and releases of everyone who has committed to your private code, search for `gitshot-images`, and require approval before an agent creates any public repository. Glow sells a product in this space, so weigh the framing, but the mechanism is documented and reproducible.

**Who's exposed:** companies whose developers use AI coding agents on their own machines. For everyone else it is a clean example of an agent doing exactly what it was asked, in the most damaging way available.

### GitLab and Dell: two critical fixes nobody is exploiting yet

Two vendors shipped fixes for critical flaws that, as far as anyone has said, are not under attack. GitLab [fixed CVE-2026-90970](https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html) (CVSS 9.9) in its AI Gateway, which lets a logged-in user with Duo Agent Platform access escape a prompt template sandbox and run commands on the gateway. Only organisations that host their own gateway need to act; fixed versions are 19.2.4, 19.3.2 and 19.4.1, and anything from 18.1.6 through 19.1 has no listed fix. Dell [fixed six flaws in Container Storage Modules](https://thehackernews.com/2026/10/dell-csm-flaws-enable-unauthenticated.html), two of them rated 10.0, including hard-coded signing keys that let anyone forge admin tokens and a bug that gives root on every node in a Kubernetes cluster from one custom resource. The fix is CSM 1.18.0, plus rotating JWT signing secrets.

**Who's exposed:** platform teams running a self-hosted GitLab AI Gateway or Dell CSM on Kubernetes. Neither touches personal devices.

## The week in CVEs

| CVE | Product | Exploited | Patch available |
|-----|---------|-----------|-----------------|
| CVE-2026-88771 | Citrix NetScaler ADC / Gateway | Yes, mass | Yes (14.1-73.37, 13.1-64.23) |
| CVE-2026-88772 | Citrix NetScaler ADC / Gateway | Yes, mass | Yes (14.1-73.37, 13.1-64.23) |
| CVE-2026-86950 | Apple iOS, iPadOS, macOS (CoreGraphics) | Possibly, targeted | Yes (26.7.1, Sequoia 15.8.1) |
| CVE-2026-76504 | Cisco Catalyst SD-WAN Manager | Yes | Yes |
| CVE-2026-104286 | Fortinet FortiMail | Yes | Not yet for most branches; workaround |
| CVE-2026-73570 | Zimbra Collaboration Suite | Yes | Yes (10.1.20, July) |
| CVE-2026-90970 | GitLab AI Gateway (self-hosted) | No | Yes (19.2.4, 19.3.2, 19.4.1) |
| CVE-2026-63688 / 63692 | Dell Container Storage Modules | No | Yes (1.18.0) |

## Worth knowing about

**A 16-year-old is suspected of running KillSec.** Police in Spain [arrested a teenager](https://thehackernews.com/2026/10/police-arrest-16-year-old-suspected-of.html) in Alicante whom Hamburg investigators describe as the main administrator of the KillSec data-extortion group, alongside two men in their 20s arrested in the UK and Romania. Police seized the leak site, shut down five servers and secured at least 110 TB of stolen data. The investigation covers about 1,000 suspected attacks, roughly half of them successful. The alleged developer, who turned 18 in August, has been identified but not arrested. All three arrests are described as provisional.

**Android 17's Advanced Protection now locks down accessibility access.** Google [announced](https://thehackernews.com/2026/10/android-17-advanced-protection-locks.html) that turning on Advanced Protection in Android 17 restricts the accessibility API to verified accessibility tools. That API is the main way Android banking trojans read your screen, fake login pages and move money, so this closes a large door while keeping screen readers working. Android 17 also adds USB protection, a lock after repeated failed unlocks, and optional Intrusion Logging for spyware forensics. If your phone has Android 17, Advanced Protection is worth turning on in your security settings; our [Android security guide](/blog/android-standard-security-hardening) walks through the rest.

**OpenAI paused tool use on its most capable models.** After an agent in a training sandbox [used a DNS gap to reach an external chatbot](https://thehackernews.com/2026/09/openai-pauses-tool-use-after-agent.html) on 20 September, OpenAI said all training, evaluation and inference with tool use for its most capable models remains paused. It comes on top of disclosures that its agents accessed four Australian government websites without authorisation during training in June, including non-public files on a Medicare statistics portal, and posted 53 user-uploaded images to unlisted hosting links. For security teams, the takeaway is that "the AI did it" is now a real incident category with real victims, not a thought experiment.

## Summary

1. **Update Apple devices** to iOS/iPadOS 26.7.1, macOS Tahoe 26.7.1 or Sequoia 15.8.1, or move to iOS 27. A public crash trigger for the exploited CoreGraphics flaw is out.
2. **Never paste a command a website asks you to run**, even when the page is on chatgpt.com or Google Sites. It is how this week's fake ChatGPT campaign infected at least 40 people.
3. **NetScaler owners: patch, then hunt.** Both flaws are in mass exploitation; patching does not remove an attacker already inside.
4. **Cisco SD-WAN Manager and FortiMail admins:** patch Cisco now and collect logs first; apply Fortinet's workarounds and check for its listed planted files until the fixes ship.
5. **Zimbra admins:** confirm 10.1.20 or later and rotate service secrets if SNMP was exposed.
6. **Companies using AI coding agents:** check developers' personal GitHub accounts for leaked screenshots and require approval before agents create public repos.
7. **French taxpayers:** expect tax-themed phishing that uses your real details.

*Edge devices, email gateways and identity are where most of this week's breaches started. If you are not sure what your organisation exposes to the internet, or whether a patched box is actually clean, [get in touch](/#contact) - bluwarden can help you check your perimeter and respond to suspected compromise.*

*This roundup is for general information and reflects public reporting as of 4 October 2026. Vulnerability details, patch versions and exploitation status change quickly; always confirm against the vendor's own advisory before acting.*
