Breach Watch Weekly: The Control Plane Became the Front Door (Sep 27-30)
CISO PLATFORM · BREACH INTELLIGENCE
BREACH WATCH WEEKLY
The week in breach intelligence for security leaders · September 27–30, 2026

The week in one line: The systems built to manage and protect everything else were the way in. Two Citrix NetScaler flaws and a Cisco SD-WAN Manager flaw were exploited before fixes shipped, attackers holding cloud administrator identities tore down Azure storage at machine speed, and a $387.5 million crypto theft began inside two security appliances. The controls that held were the ones that did not depend on the compromised system: independent backup locks and network segmentation.

BY THE NUMBERS

27 distinct items across four daily editions (September 27 through 30). Eleven CVEs were confirmed exploited in the window, six of them as zero-days (Citrix CVE-2026-88771 and CVE-2026-88772, Apple CVE-2026-86950, Cisco CVE-2026-76504, and Zammad CVE-2026-102489 and CVE-2026-102490), plus the unnamed zero-days in the two security products behind the Bitget theft. At least six exploited flaws carried CISA KEV deadlines during the week: SharePoint, the two-CVE MikroTik chain, Citrix NetScaler, Cisco SD-WAN Manager, and Zimbra. Confirmed exposure counts: about 3 million people at the Pentagon's personnel data center, about 6.6 million Times Car accounts, 399,086 DC Medicaid beneficiaries, and more than 16,000 readable Supabase databases.

Compilation note: the window is the seven U.S. Eastern days ending October 2. Daily editions on file cover September 27 through 30; no daily edition ran on September 25, 26 or October 1.

Sector tally
  • Enterprise software and collaboration: 6 (Kiteworks, Oracle PeopleSoft, Zimbra, Zammad at DIVD, TeamViewer, the WSO2 and Adobe Commerce KEV deadlines)
  • Cloud, developer and data platforms: 5 (Storm-3168 on Azure, Supabase exposures, PhantomSub npm packages, Truffle Security's GitHub credential study, OpenSSL and wolfSSL)
  • Network edge and SD-WAN: 4 (Citrix NetScaler, Cisco Catalyst SD-WAN Manager, the CISA SharePoint and MikroTik KEV batch, MikroTik CVE-2026-84411)
  • Government and public sector: 3 (Defense Manpower Data Center, France's DGFiP, DC Department of Health Care Finance)
  • Telecom, transport and consumer services: 3 (Simba, Times Car, Keio)
  • Threat actor activity and phishing: 3 (Star Blizzard, C-suite Microsoft 365 session theft, the Dutch ShinyHunters arrest)
  • Endpoints and hardware: 2 (Apple CoreGraphics, the Spectre v2 BTR variant)
  • Cryptocurrency and finance: 1 (Bitget)
Four themes that repeated
  1. The control plane became the front door. NetScaler gateways, the Cisco SD-WAN manager, Zimbra mail nodes, MikroTik routers, and the two security appliances at Bitget all hold privileged positions, and each was reached through a flaw the owner could not see or had not yet patched. Kiteworks took the unusual step of asking customers worldwide to power down servers on a federal tip. When the management layer falls, the attacker inherits its reach.
  2. One encoded character beat the filter. ShinyHunters swapped a single letter in a PeopleSoft path for its URL-encoded form to slip past WAF rules, and the Cisco SD-WAN flaw works the same way: an encoded character in a login path dodges the rule that demands authentication. Two unrelated products, the same lesson. A control that matches on raw text before decoding is not a control.
  3. Machine-speed intruders, human-speed response. Microsoft tied the Azure destruction to an operator it describes as agentic, and DIVD says an autonomous agent chained two Zammad zero-days to root. In both cases the limit on damage was a control set up in advance and independent of the compromised identity: backup and recovery locks at the Azure victim, segmentation at DIVD.
  4. Exposure outlived the fix, and dwell time set the bill. A secret edited out of a GitHub issue stayed readable in its history. Truffle Security found 543,699 valid credentials in public repositories with a median exposure of 784 days. The Pentagon file-sharing flaw was open for about nine months, DC's Medicaid reports leaked from 2023 to July 2026, and France's tax theft ran seven weeks on a portal no one was monitoring.

The week's most significant incidents

1. Two Citrix NetScaler zero-days were exploited before any patch existed

CRITICAL · ACTIVELY EXPLOITED

Citrix confirmed on September 27 that CVE-2026-88771 (unauthenticated code execution through improper input validation) and CVE-2026-88772 (a memory overflow reachable when DTLS is on, which is the default for VPN virtual servers), both rated CVSS 9.5, were used in attacks ahead of the fix. Affected builds are NetScaler ADC and Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23, and six further flaws were patched alongside. Citrix said plainly that upgrading does not undo a prior compromise and recommended credential resets, certificate revocation, and forensics. CISA set a September 30 federal deadline, and Shadowserver data cited by BleepingComputer put internet-exposed instances above 23,000. For a CISO, the gateway is where remote access and session tokens live, so the response is a patch plus a compromise assessment, not a patch alone. See the September 27 edition. Sources: The Hacker News, BleepingComputer, Unit 42.

2. Cisco SD-WAN Manager authentication bypass exploited, with no workaround

CRITICAL · ACTIVELY EXPLOITED

CVE-2026-76504 (CVSS 9.8) lets an unauthenticated request reach the administrative API of Catalyst SD-WAN Manager because of how the product handles URI encoding. Cisco learned of in-the-wild use through a support case, published fixed releases on September 30 (20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1), and offered no workaround beyond restricting access from untrusted networks. CISA added it to KEV the same day with a deadline of only a few days. Whoever holds this console can reroute branch and data center traffic, so treat any instance reachable from the internet in September as possibly accessed. Rapid7 and BleepingComputer point to encoded j_security_check requests and usernames starting with "viptela-reserved-" in the service-proxy log as hunting leads. See the September 30 edition. Sources: Rapid7, BleepingComputer.

3. A leaked Azure secret let an automated operator delete cloud storage in minutes

CRITICAL · CLOUD DESTRUCTION

Microsoft's September 25 analysis of Storm-3168, the actor it links to the JADEPUFFER operation, traces the attack to service principal credentials an employee posted in a public GitHub issue. The secret was later edited out but remained in the issue's edit history. With two compromised principals, the operator mapped resources over many hours, then ran more than 150 delete and credential-collection actions in a short burst, removing most targeted storage accounts plus a Key Vault, a Function App and an App Service plan. Secondary coverage gives different durations for the destructive phase, so treat the exact minute count as source-dependent. What failed for the attacker is the useful part: Site Recovery and Azure Backup protection locks held, because they did not rely on the identity that was stolen. Rotate exposed secrets rather than deleting the post, give every service principal an owner, and put recovery protections on a separate approval path. See the September 28 edition. Sources: Microsoft Security Blog, The Hacker News.

4. Pentagon personnel data center exposed about 3 million people for roughly nine months

CRITICAL · GOVERNMENT PERSONNEL DATA

The Defense Manpower Data Center began notifying people of a flaw in one of its file-sharing systems that let unauthorized users open files from about October 2025 until it was found on July 16, 2026. The files held names, Social Security numbers, dates of birth, contact details and military occupational specialties, reportedly unencrypted, for about 2.76 million living and 294,000 deceased individuals. The product has not been named, no group has claimed the incident in the reporting we verified, and DMDC says it has no sign of misuse. The lesson is duration and data placement: an internal sharing tool sat outside effective monitoring for nine months while holding SSNs in the clear. Inventory business-owned file transfer and sharing systems, scan them for identity data, and expect this population to be targeted by fraud and phishing for years. See the September 29 edition. Sources: SecurityWeek, Federal News Network.

5. Bitget's $387.5 million theft started inside two security products

HIGH · SUPPLY CHAIN

Over the week, the Bitget story moved from an exchange hack to a security tooling compromise. Per SlowMist's account, the intruder ran a hidden script on one unnamed third-party security product, read a database password from an environment variable, then used stolen employee credentials on a second product's management console to forge the risk-control parameters that approve withdrawals. About $387.5 million left over roughly three hours on September 25, with earliest activity dated to August 31. Bitget's CEO attributes the attack to North Korean actors; the vendors are unnamed, so no product should be presumed affected. Map what each security appliance can reach if it is compromised, move secrets into a vault, and make sure no single system can approve a high-value transaction on its own. See the September 30 edition. Sources: BleepingComputer, The Hacker News.

6. ShinyHunters returned to Oracle PeopleSoft with a one-character WAF bypass

HIGH · ACTIVELY EXPLOITED

Google Threat Intelligence and Mandiant reported a new wave against CVE-2026-35273, the PeopleSoft code execution flaw the group used as a zero-day in June. Requests sent to /%50SEMHUB/ instead of /PSEMHUB/ pass WAF rules that compare the raw path, while WebLogic decodes and serves them. Post-exploitation includes JSP web shells, the SIDEEYE backdoor, Neo-reGeorg tunneling and MeshAgent, with victims now spanning higher education, technology, healthcare, transportation and government. If your PeopleSoft risk decision leaned on a virtual patch, close the gap: confirm the real fix everywhere, disable the Environment Management Hub where unused, search logs for encoded variants, and rotate service account credentials. See the September 28 edition. Sources: SecurityWeek, BleepingComputer.

Also across the week

  • France's tax directorate (DGFiP) lost data on hundreds of thousands of people and businesses after staff passwords stolen from personal devices worked on two portals with no second factor. A password reset on June 23 did not end an open session on an unmonitored portal, and the theft surfaced only on August 12. Totals differ by outlet. The Hacker News
  • DIVD, the Dutch disclosure nonprofit, says an autonomous AI agent chained two Zammad zero-days (CVE-2026-102489 and CVE-2026-102490, both CVSS 9.4) to reach root on its help-desk server; segmentation limited lateral movement. The AI attribution is DIVD's own assessment. BleepingComputer
  • Microsoft documented exploitation of Zimbra CVE-2026-73570 on servers with the optional SNMP package, leading to web shells, root, and theft of keys that can forge mailbox sessions. Patch to 10.1.20 and rotate keys. The Hacker News
  • Apple fixed CoreGraphics zero-day CVE-2026-86950, reported by Meta and used against specific individuals. Prioritize executive and board devices. SecurityWeek
  • UpGuard found more than 16,000 Supabase databases readable by outsiders across about 300,000 domains, mostly from missing Row Level Security and tables created by code generators without review. BleepingComputer
  • Times Car (Park24) confirmed about 6.6 million accounts exposed, including driver's license images; containment took about a day. BleepingComputer
  • Kiteworks asked customers worldwide to take servers offline for a precautionary window after a federal warning of possible zero-day targeting; no exploitation had been confirmed. CISA also added a SharePoint flaw and a two-CVE MikroTik RouterOS chain to KEV. BleepingComputer
  • DC's Department of Health Care Finance reported 399,086 beneficiaries exposed through two web reports that carried underlying records from 2023 to July 2026. SecurityWeek
  • Truffle Security counted 543,699 valid credentials in public GitHub repositories, with a median exposure of 784 days. BleepingComputer
  • Also noted: Star Blizzard fake event invitations against 100+ organizations; 101 malicious npm packages abusing a WhatsApp library; a new Spectre v2 variant; OpenSSL and wolfSSL patch batches; TeamViewer fixes; C-suite phishing that steals Microsoft 365 sessions and installs remote management tools; Simba telco (23,549 customers) and Keio ransomware disclosures; and a Dutch arrest in the ShinyHunters investigation. September 29 edition

What to watch next week

  • Citrix and Cisco follow-on disclosures. Pre-patch exploitation usually produces victim notices and post-exploitation reports weeks later. Finish compromise assessments on both, not only upgrades.
  • Names of the Bitget vendors. If the two security products are identified, expect advisories and emergency patches. Have your appliance inventory ready to check quickly.
  • ShinyHunters extortion. The PeopleSoft wave fits a data-theft-then-demand pattern, and the Amsterdam arrest may change the group's behavior. Pre-brief legal and communications.
  • A Zammad fix for CVE-2026-102490. Reporting says the privilege escalation affects all versions, including the latest alpha. Until a fix lands, keep help-desk servers isolated or offline.
  • Whether Kiteworks' precaution becomes a CVE. A federal tip that triggers a global shutdown rarely ends without a disclosure. Review file-transfer logs for September 25 to 27.
  • DMDC details. Watch for the file-sharing product name and any congressional questions, which could widen the advisory to other users of the same tool.

FAQ

What was the biggest breach story of the week?
The two Citrix NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, which were exploited before patches existed on gateways that hold remote access sessions. Citrix advised forensic review and credential resets in addition to upgrading.

Which vulnerabilities should we patch first?
The exploited ones: Citrix CVE-2026-88771 and CVE-2026-88772, Cisco SD-WAN Manager CVE-2026-76504, Oracle PeopleSoft CVE-2026-35273, Zimbra CVE-2026-73570, Apple CVE-2026-86950, the SharePoint and MikroTik KEV entries, and Zammad where it runs.

How did attackers delete Azure resources in the Storm-3168 case?
They used service principal credentials posted in a public GitHub issue. The secret was edited out but stayed in the edit history. Independent backup and recovery locks blocked some deletions, which is the control to copy.

What does the Bitget theft teach about security tooling?
Security appliances have deep access, so a flaw in one inherits it. In this case a secret in an environment variable and employee credentials on a vendor console turned two product flaws into a $387.5 million loss.

What was the common thread across the week?
Management and security systems were the entry point, encoded-path tricks beat filters in two separate products, automated attackers moved faster than responders, and long dwell times on unmonitored systems drove the largest exposures.

CISO Platform Breach Intelligence Team

More from the community: the CISO Platform Breach Intelligence hub, and peer resources on vulnerability management, third-party risk, and AI security.

Stay ahead of the next breach

Join a vendor-neutral community of senior security leaders who share what actually works.

Join the CISO Platform community (free)

Subscribe to the weekly newsletter

Visit the Breach Intelligence hub

Corrections and takedown requests: CISO Platform is committed to accuracy and fairness. If any detail in this briefing is inaccurate, or if you represent an affected organization and would like a correction or removal, please contact us at pritha.aash@cisoplatform.com and we will review your request promptly.

★
★
★
★
★
Votes: 0
E-mail me when people leave their comments –

You need to be a member of CISO Platform to add comments!

Join CISO Platform

Join The Community Discussion