Daily Digest

Citrix Zero-Days Under Attack; Ransomware Surges; DoD Fraud Risks

September 29, 2026
8 articles (6 new, 2 updated)
24 min read

Summary

Critical Vulnerabilities Under Active Exploitation:

  • [UPDATE] Citrix Patches Two Critical NetScaler Zero-Days Under Active Attack: CISA has mandated federal agencies patch critical Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) by September 30, 2026. CVE-2026-88771, affecting a Perl script, has low attack complexity and impacts default configurations. Over 50,000 NetScaler instances are potentially vulnerable.
  • [UPDATE] Ransomware Attacks Surge to 2026 High; Qilin Group Most Active: The Aurora ransomware group is now targeting hypervisors to encrypt virtual machines. Detection strategies include monitoring for encoded PowerShell, Active Directory reconnaissance tools, and unusual SMB/RDP traffic. Mitigation advice includes patching, MFA, and network segmentation.

New Threats and Advisories:

  • [NEW] Ransomware Attack on Japan's Keio Corp Disrupts Retail, Hotels: Japanese conglomerate Keio Corporation is experiencing a ransomware attack that began September 26, 2026, impacting payment and reservation systems for its hotel chains and retail stores. Core train services remain operational.
  • [NEW] SQL Injection Flaw in Medyc Software Leads to Polish Health Data Breach: Polish medical software provider Qbusoft suffered a data breach due to an SQL injection vulnerability in its Medyc platform between August 22-23, 2026, leading to the exfiltration of an encrypted database archive containing patient data.
  • [NEW] Astrana Health Data Breach Caused by Social Engineering Attack: Astrana Health reported a data breach resulting from a social engineering campaign where attackers impersonated staff and used phone number spoofing to gain unauthorized system access and exfiltrate private and confidential information.
  • [NEW] 19 Flaws in Industrial Gateway Grant Root Access to OT Networks: Nozomi Networks disclosed 19 vulnerabilities in the Pepperl+Fuchs IO-Link Master industrial gateway, including a critical authentication bypass (CVE-2026-27546), which can allow unauthenticated attackers to gain root access to OT networks.
  • [NEW] New 'OperTraitor' Tool Exposes Excessive RBAC Risks in Kubernetes: Palo Alto Networks' Unit 42 released OperTraitor, an LLM-powered tool to audit Kubernetes operator RBAC configurations. The tool revealed many operators have overly permissive privileges, creating supply chain weaknesses and potential backdoors.

Policy & Industry Notes:

  • [NEW] GAO: Poor Fraud Management Puts DoD IT Programs at Cyber Risk: A U.S. Government Accountability Office (GAO) report indicates the Department of Defense (DoD) has inadequate fraud risk management for IT programs, resulting in nearly $11 billion in fraud losses since 2017 and leaving critical systems vulnerable to cyberattacks.

Filter by Category

New Articles (6)

Updated Articles (2)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.