Daily Digest

Citrix Zero-Days Exploited, Ransomware Hits Record High, Maritime Cyber Risk

September 28, 2026
7 articles (5 new, 2 updated)
21 min read

Summary

Critical Vulnerabilities Under Active Exploitation:

  • Citrix Patches Two Critical NetScaler Zero-Days Under Active Attack: Citrix has released emergency patches for eight vulnerabilities in its NetScaler ADC and Gateway appliances, including two critical zero-days (CVE-2026-88771 and CVE-2026-88772) confirmed to be under active global exploitation. These flaws allow for unauthenticated remote code execution, potentially leading to webshell deployment and network compromise. CISA has added these to its KEV catalog, mandating immediate patching and investigation for federal agencies.

Evolving Ransomware and Threat Actor Activity:

  • [UPDATE] ShinyHunters Hijacks Clop Ransomware Site in Inter-Gang Feud: ShinyHunters compromised the Clop ransomware gang's data leak site by exploiting CVE-2026-42608, an unpatched path traversal vulnerability in Grav CMS. This allowed for unauthenticated file uploads, leading to site defacement and alleged theft of source code and private keys, highlighting Clop's operational security issues.
  • [UPDATE] Ransomware Attacks Reached a Record High in August 2026: August 2026 saw a record surge in ransomware attacks, with the Qilin group targeting the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF). The report also introduces the Aurora RaaS group, which has been active since April 2026, typically exploiting VPN vulnerabilities and using stolen credentials for initial access.
  • [NEW] New 'Altair' Ransomware Employs Double-Extortion Tactics: A new ransomware strain named 'Altair' has been identified, targeting Windows systems with a double-extortion model. It encrypts files, exfiltrates data, and leaves an HTML ransom note with a 72-hour deadline before threatening to leak stolen information. Altair uses WMI for stealthy reconnaissance and execution.

Industry-Specific Risks and Incidents:

  • [NEW] Pentagon Reveals Breach; Kiteworks Halts Systems on Threat Intel: Two significant third-party risk incidents have emerged. The U.S. Department of Defense disclosed a data breach from October 2025 affecting the Defense Manpower Data Center (DMDC) via a third-party provider. Separately, Kiteworks advised a customer-wide system shutdown on September 25 due to credible federal threat intelligence, later patching a critical flaw affecting a small percentage of customers.
  • [NEW] 87% of Maritime Firms Hit by Cyberattacks in Past Year: Report: A Honeywell report indicates a severe lack of cybersecurity maturity in the maritime industry, with 87% of surveyed organizations experiencing at least one significant OT cyber incident in the past year. Critical gaps include low OT asset inventory completeness and integration into SOCs, leading to substantial downtime and potential financial losses.

Law Enforcement and Criminal Activity:

  • [NEW] Ex-US Soldier 'kiberphant0m' Jailed for Hacking Telecom Giants: Cameron John Wagenius, a former U.S. Army soldier operating as 'kiberphant0m', has been sentenced to 70 months in prison for a large-scale hacking and extortion campaign. He targeted at least 10 organizations, including major telecom firms, stole customer data partly via Snowflake exploits, and attempted to extort over $1 million. He also attempted to sell data to a foreign intelligence service.

Filter by Category

New Articles (5)

Updated Articles (2)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.