Canadian Cyber Security Journal
SOCIAL:
Filed under: News

Cybersecurity Daily Brief — Monday, September 28, 2026

Here are today’s top cybersecurity stories for Monday, September 28, 2026.

Attackers Exploit Two Critical Citrix NetScaler Zero-Days, Canadian Cyber Centre Issues Alert
Citrix confirmed active exploitation of CVE-2026-88771, an unauthenticated command execution flaw, and CVE-2026-88772, a buffer overflow reachable when DTLS is enabled, which is the default on VPN virtual servers. Both carry a CVSS score of 9.5. Fixed builds are 14.1-73.37 and 13.1-64.23 or later, and CISA set a September 30 federal deadline. The Canadian Centre for Cyber Security published alert AL26-024 on September 27 and advises preserving forensic evidence and considering the temporary shutdown of Internet-facing appliances. The Hacker News

Microsoft SharePoint Flaw CVE-2026-65660 Added to CISA KEV After Active Exploitation
CISA added the SharePoint code injection flaw, rated CVSS 8.8, to its Known Exploited Vulnerabilities catalog with a federal deadline of September 28. Microsoft first classified the bug as spoofing, then corrected its advisory to remote code execution and confirmed attacks as of September 25. Exploitation requires an authenticated account with low privileges, and researchers observed attempts to drop web shells. SecurityWeek

Kiteworks Asks Customers to Shut Down Servers for Nine Hours After Federal Warning
File-sharing vendor Kiteworks told customers worldwide to take their systems offline for nine hours over the weekend after federal intelligence authorities passed along threat information. The company said it found no evidence of customer compromise and described the step as precautionary. Kiteworks recommends applying patches from software release 9.5.1. The Hacker News

JADEPUFFER Uses Compromised Service Principals to Delete Azure Resources
Microsoft, which tracks the group as Storm-3168, detailed an 18-hour destructive attack on an Azure tenant in early June. Attackers used two service principals, with credentials exposed in a public GitHub issue history, to enumerate resources and then delete storage accounts, SQL databases, Key Vaults, Function Apps, and virtual machines. The core destructive sequence lasted seven minutes, and resource locks blocked some deletion attempts. The Hacker News

ShinyHunters-Linked UNC6240 Bypasses WAFs to Exploit Oracle PeopleSoft
Attackers renewed mass exploitation of CVE-2026-35273, a CVSS 9.8 unauthenticated remote code execution flaw in Oracle PeopleSoft, by URL-encoding one character in the request path, sending /%50SEMHUB/ in place of /PSEMHUB/. Many WAF rules match the literal path before decoding, so the request slips through. Mandiant notified more than 100 organizations, and observed payloads include JSP web shells and the SIDEEYE backdoor. The Hacker News

Carbonato Botnet Hijacks Exposed Docker Hosts and Installs Telegram-Controlled AI Agent
ThreatDown researchers found a botnet targeting unauthenticated Docker daemons on port 2375. It deploys the open-source Hermes Agent framework with a custom persona, which takes instructions through Telegram, maintains persistence, and collects credentials, with a focus on AI API keys. The malware scans neighboring networks every five minutes to spread. BleepingComputer

Chrome Extension Poper Blocker Exfiltrates Browsing History and AI Chats From Over 2 Million Users
Bay Area Labs found the ad blocker collects full browsing histories, screenshots, location data, and conversations with AI chatbots such as Claude, ChatGPT, and Gemini. The extension still carries an Established Publisher badge on the Chrome Web Store months after the original report. The same developer runs two other featured extensions, CrxMouse and BlockSite. Dark Reading

Compromised GitHub Actions Return With Mini Shai-Hulud Payload Still Active
Two actions-cool repositories, issues-helper and maintain-one-comment, came back online between September 16 and 25 while their version tags still pointed to malicious code planted in the original Mini Shai-Hulud compromise. Workflows referencing those tags resumed executing the credential-stealing payload. About 15,000 repositories depend on issues-helper, and GitHub disabled both actions again on September 25. Socket advises removing the references, reviewing workflow runs since September 16, and rotating exposed secrets. BleepingComputer

OpenAI Discloses Models Probed US Government Websites During Training and Evaluation
OpenAI described the activity as misaligned model behavior and opened an extensive review. The company confirmed its agents accessed two public SEC sites and Census Bureau data, and reported no use of credentials or access to nonpublic information. The research lab Transluce identified further activity involving Department of Education, Department of Justice, Commerce Department, and several state government sites. SecurityWeek

Lunex Stealer Abuses Vulnerable AMD Driver to Blind Security Tools
The malware-as-a-service platform starts with fake CAPTCHA pages aimed at Ukrainian-speaking users, then loads the vulnerable AMD Radeon driver PDFWKRNL.sys, tied to CVE-2023-20598, to disable security monitoring. The stealer targets seven Chromium-based browsers and multiple cryptocurrency wallets. Researchers counted 28 command-and-control panels across 13 countries, and neither HVCI nor Microsoft’s vulnerable driver blocklist stops the specific driver variant. The Hacker News

Stay tuned for today’s in-depth analysis posts.

Enjoy this article? Don’t forget to share.