Forum Discussion
Tenable Security Intel Brief: NetScaler zero-day warnings arrived before patches
Welcome to this week's Tenable Security Intel Brief, a curated summary of the top stories in cybersecurity by Tenable's Research Special Operations (RSO) team.
This week, Citrix fixed two NetScaler zero-days on September 27, after private warnings had already told some admins to switch their appliances off. Google traced CVE-2026-88772 attacks to at least early September. Thanks to our Vulnerability Detection team for working through the weekend to get customers coverage for these flaws.
The brief also covers ShinyHunters' FBI data claims, open-source AI agents breaking into online retailers, and a North Korean Terraform lure.
Private NetScaler zero-day warnings arrived before Citrix's advisory →
Brief: Citrix fixed two NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, on September 27, after private warnings had already told some admins to switch their appliances off. Google traced CVE-2026-88772 attacks to at least early September.
Intel: On September 25, admins posted on Reddit that IT suppliers were telling them to take NetScalers offline, while the Netherlands' National Cyber Security Centre (NCSC-NL) reportedly circulated a private alert. Citrix confirmed exploitation on September 27, and CISA added both flaws to its Known Exploited Vulnerabilities (KEV) catalog. Google says organizations in government, finance, education, and legal and professional services in North America and Europe were likely hit. On September 28, watchTowr released a proof-of-concept exploit for CVE-2026-88771 and Defused reported its mass exploitation.
Why it matters: Mandiant found attackers moving from compromised appliances into some victims' internal networks. CISA warns updates "may result in loss of forensic visibility," and NCSC-NL's public alert wants memory and logs secured first. Where attackers got into appliances before the fix, the upgrade may wipe the evidence of their activity.
Reuters finds FBI intelligence roles in data ShinyHunters says it took →
Brief: Reuters verified details for more than 22 people in a 5,000-line spreadsheet ShinyHunters says it stole from the FBI, and found the file lists staff in China-related and human intelligence (HUMINT) roles.
Intel: ShinyHunters claims it broke into FBIjobs.gov through Oracle PeopleSoft, then moved to FBI servers hosted in AWS GovCloud and took 2 TB to 3 TB. It told BleepingComputer it used a trick Mandiant documented for getting past firewall rules that block CVE-2026-35273, a PeopleSoft flaw patched in June, though it still claims a new zero-day as well. The FBI says "the point of breach is still undetermined," but a Justice Department notice to lawmakers says the affected system holds Social Security numbers.
Why it matters: In May, the FBI warned that ShinyHunters "may falsely claim" to hold sensitive data. ShinyHunters says it hit the FBI to answer that, and did it for "future corporate partners," which The Register reads as extortion victims. ShinyHunters is playing to the next company deciding whether the group is bluffing.
Card thieves use open-source AI agents to break into online shops →
Brief: Gambit Security recovered a financially motivated attacker's staging server and found three AI tools running nearly every step of break-ins at online retailers since July 2026.
Intel: Strix, an open-source tool for AI penetration testing, hunted for flaws, and Cairn attacked targets for hours chasing a goal such as remote control of a server or admin access. Hermes, an open-source AI agent, ran the campaign on 1,951 short Chinese prompts over 260 sessions, such as "get into the web backend." September 10 to 15 alone saw 105 attack projects and at least 27 companies "compromised to varying degrees," per Gambit. Two companies lost over 600,000 unexpired card details.
Why it matters: The attacker's own cost review averages $25.46 per completed scan, and Gambit's verdict is that "the economics no longer filters anyone out." That price also buys damage: at one bicycle retailer, the agent's cleanup deleted 180 database tables, including backup copies the shop's IT staff had created.
North Korean hackers hide a backdoor route in a Terraform lock file →
Brief: SentinelOne found macOS backdoors from TraderTraitor, a North Korean state-sponsored group, on a DevOps engineer's MacBook at an India-based IT services provider with no cryptocurrency ties.
Intel: The group, also tracked as UNC4899, PUKCHONG and Jade Sleet, sends job seekers fake interview projects on GitHub. The repos carry a tampered .terraform.lock.hcl, the file that records which plugin versions Terraform (a tool companies use to set up cloud infrastructure from code) installs. It points to lookalike domains like registry.hashicorp-aws[.]com, and when the developer runs the project's setup command, Terraform fetches and runs the attackers' code. The backdoors also appeared in the $292 million KelpDAO theft; how they reached this laptop is unknown.
Why it matters: A lock file lets Terraform reject a download that doesn't match what was recorded. In these interview repos, the attacker wrote the lock file. The check that worked was human. One candidate removed the lookalike plugin and left a note, possibly taking it for a security test.
Stat of the week: 1,073
The number of ransomware attacks in August, the highest monthly total of 2026 so far and up 12% from July, with Qilin taking the top spot from The Gentlemen, according to NCC Group.
Tenable's RSO serves as Tenable's Forward Logistics Element in the threat landscape, providing customers with the analyses and contextualized exposure intelligence required to manage risks to critical business assets. With over 150 years of collective expertise, this hand-picked group of world-class security researchers is united with one mission: to cut through the noise and deliver critical intelligence about the most dangerous cyber threats emerging right now.