> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> InfoSec News Nuggets – 09/30/2026

[SOURCE] AboutDFIR [AUTHOR: Mary] [DATE: 30/09/2026 10:42] [LANGUAGE: EN]
Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services Attackers have been exploiting a critical Citrix NetScaler ADC and Gateway flaw, CVE-2026-88772, since at least early September, weeks before Citrix disclosed it along with seven other CVEs on Sunday. Google Threat Intelligence Group and Mandiant say government, financial services, education, legal and professional services organizations across North America and Europe were likely hit, and the intruders deployed two never-before-seen tools: WHIPSHOT, a PHP web shell disguised as a Debian package that hides Base64-encoded commands in HTTP headers, and SLAPSHOT, a Python TCP tunneler used to proxy traffic into internal networks for reconnaissance and credential theft. No attribution has been made public, and experts are criticizing Citrix for the disclosure delay. Mandiant advises NetScaler customers to hunt for signs of compromise before patching, since patching alone may not remove an attacker already inside.   Pentagon Personnel Agency Data Breach Impacts 3 Million People The Defense Manpower Data Center, which maintains personnel records for the Department of Defense, has begun notifying people that unauthorized users had access to one of its file-sharing servers for roughly nine months. The agency says a vulnerability in the file-sharing system was discovered on July 16, 2026, and that between October 2025 and that date a small number of unauthorized users accessed files containing unencrypted personal information, including Social Security numbers, names, dates of birth, contact details, demographic data and military occupational specialties. A department official said the breach affects 2.76 million living and 294,000 deceased individuals. The notice does not name the affected product, no group has claimed the attack, and the agency says it has no indication so far that the data has been misused.   Japan’s Keio confirms ransomware attack disrupted business systems Keio Corporation, a major private Japanese railway operator that also runs 25 hotels, confirmed that a ransomware attack hit its group servers in the early hours of September 26 and forced it to shut down its network. The attack appears to have affected the hospitality side of the business rather than train operations, with local media reporting disruptions to payment systems and the Keio Plaza Hotel Tokyo warning of possible delays to customer services. The company has reported the incident to police and is investigating whether customer or partner data was accessed, and no ransomware group has claimed responsibility yet. Over the same weekend, Tokyo Metro disclosed a separate intrusion that exposed about 59,000 member email addresses, though it is unclear whether the two incidents are connected.   Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950) Apple has released iOS, iPadOS and macOS updates to fix CVE-2026-86950, an actively exploited out-of-bounds write flaw in the Core Graphics framework that could allow arbitrary code execution when a device processes a maliciously crafted file. Apple says it is aware of a report that the bug may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27, but gave no details on the attacks or targets. The flaw, reported by Meta Product Security, is fixed in iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. The newest iOS 27.0.1 and macOS Golden Gate 27.0.1 releases don’t appear to be affected, but all users are urged to update as soon as possible.   Dutch police arrest ShinyHunters hacker accused of planning two murders The FBI and Dutch law enforcement say they have arrested a 24-year-old Amsterdam man, described by the FBI as one of the alleged leaders of the ShinyHunters extortion gang, which authorities link to hacks of more than 140 organizations including Ticketmaster, AT&T and Pornhub. Dutch police say he was arrested on September 15 for participating in a criminal organization and has been remanded into custody for at least 90 days, and that information found on his laptop about two murders meant to take place abroad has led to a separate investigation into attempting to orchestrate those killings. Multiple outlets have named him as Pepijn van der Stap, a previously convicted hacker who worked as a security professional, while a ShinyHunters representative denied any association. The arrest follows the gang’s claimed breach of the FBI’s careers portal that exposed sensitive personal data of agents and applicants. The post InfoSec News Nuggets – 09/30/2026 appeared first on AboutDFIR - The Definitive Compendium Project.
[messages.read_original_source] →