Day Lila

Cybersecurity · Monday, 28 September 2026

01 Briefing what happened

Attackers used two holes in Citrix's NetScaler boxes before any fix existed. Citrix has now disclosed eight flaws

Cybersecurity 30 sources

Firms were told privately on Saturday to switch off their NetScalers, the boxes that handle logging in from outside. On Sunday Citrix disclosed eight flaws, and CISA said two are being used in attacks.

2 of 8

new NetScaler flaws that CISA says attackers are already using

Each of the two, on its own, lets an attacker run their own code on the box. [3]

13.1

the older NetScaler version whose regular updates ended on 15 September

As of Sunday morning, Citrix had not said whether it would get a fix. [2]

The lead story — what happened

  • Attackers used two holes in Citrix's NetScaler boxes before any fix existed, the security firm watchTowr said on Saturday 26 September. [2][1]
  • NetScaler boxes sit at the edge of a company's network. They check who is logging in and let staff reach work systems from outside. [2]
  • The same day, administrators wrote on Reddit that their IT suppliers had phoned to tell them to switch their NetScalers off at once, without giving details. [1][2]
  • Others said police, emergency response teams and national cyber agencies had been contacting organisations too. [1]
  • A private notice from the Netherlands' National Cyber Security Centre, copied online, said each hole on its own lets an attacker run their own code on the box. [1]
  • The notice said Citrix found the holes while investigating break-ins at its customers, and that several customers around the world had been hit. [1]
  • Before Citrix spoke, watchTowr had named no victim and shown no evidence. Some administrators took their boxes offline rather than wait. [2]
  • On Sunday CISA, the US cyber-defence agency, said Citrix had disclosed eight new flaws in NetScaler. [3]
  • CISA put two of them on its list of flaws used in real attacks, and said attackers are using them around the world. [3]
  • CISA asks owners to look for signs of a break-in before they update, because updating can wipe the traces an investigator needs. [3]
  • Under a CISA directive, US federal agencies have rules on when they must check for a break-in before fixing a flaw on that list. [4]
  • Citrix has published signs of a break-in to look for, in its NetScaler Console product and in a security bulletin. [3]
  • These are not the NetScaler flaws Citrix fixed on 19 August. CISA listed one of those as under attack on 9 September. [2][1]
  • The Dutch notice warned that attacks could grow once Citrix publishes its fixes and the details. [1]
Private phone calls came first, then a public warning, then Citrix's own list of flaws and the US agency's alert.

Who is involved

  • Citrix

    the company that makes NetScaler, owned by Cloud Software Group; the Dutch notice says it found the holes while investigating customers' break-ins

  • watchTowr

    a security firm; it warned in public on Saturday and said Citrix's fixes were expected early this week

  • CISA

    the US cyber-defence agency; it listed two of the eight flaws as used in real attacks

  • Dutch National Cyber Security Centre

    the Netherlands' national cyber-defence team; copies of a private notice from it were shared online, and it would not confirm the notice

How it unfolded

  1. 19 Aug Citrix fixes earlier NetScaler flaws [2]
  2. 9 Sep CISA lists one of those as under attack [1][2]
  3. 15 Sep NetScaler 13.1 stops getting regular updates [2]
  4. 26 Sep suppliers tell firms to switch off, and watchTowr warns [1][2]
  5. 27 Sep Citrix discloses eight flaws, and CISA says two are being used [3]

Where this points

Watch whether Citrix's fixes reach the older 13.1 version, and whether attacks grow once the details are public, as the Dutch notice warned. [2][1]

What is pushing on the whole day

The bar and the word are our reading of how hard each one is pushing today. The arrow is where it is heading. The evidence is in the stories below.

Holes used before a fix High↑

Citrix's two NetScaler holes were used before any fix existed. [2] Check Point says attackers used a flaw in its firewall management software from 23 July, before it was fixed. [9] Attack code is public for a D-Link router flaw that has no fix. [22]

Quick fixes that did not hold Building↑

ShinyHunters got past firewall rules that PeopleSoft owners had used instead of Oracle's update. [8] Two GitHub tools switched off in May came back on with their old harmful code still inside. [10][11]

AI inside attack tools Building↑

ClosedQuorum, new Windows malware, lets AI models vote on its next move. [23] The CARBONATO botnet puts an AI agent on each machine it takes over. [24] Exposed documentation suggests RemControl's makers used an AI assistant told it was building a quiz app. [24]

US government checks falling short Building→

A watchdog found 88 of 102 US civilian agencies missed a cloud security deadline set by CISA. [15] US agencies bought phone-search software from a company that hid its Russian owners, prosecutors say. [5][7] CISA's election plan came out 40 days before the vote, and election officials say that is too late. [14]

The rest of the day

22 more stories on this beat.

Each with its own sources. None of these is a link to the story above.

  1. 02

    Phone-search firm hid Russian owners, US says

    US prosecutors have charged Lee Reiber, chief executive of Oxygen Forensics, and Oleg Davydov, its chief technology officer, with conspiracy to commit wire fraud. [7][5] Oxygen, based in Virginia, sells software that pulls data off phones for investigators, and US agencies including the Secret Service bought it. [7][5] Prosecutors say five Russians secretly owned it through a Cyprus company, and its software was written in Russia. [5][7] Reiber was arrested in Idaho on Sunday 20 September, and Davydov at London's Heathrow Airport. [7][5]

    Why it matters — Russia's FSB security service bought the same software under another name from a company run by Davydov, prosecutors say. [7][5] US officials say they would not have bought it had they known who owned it, and prosecutors do not claim it contained harmful code. [6][7]

  2. 03

    ShinyHunters steps round PeopleSoft blocks

    ShinyHunters, an extortion gang, is attacking servers running Oracle's PeopleSoft software again, Google's Mandiant team says. [8] Oracle fixed the hole in June, but some owners only blocked one web address, /PSEMHUB/, with a firewall rule. [8] The gang now writes the P as %50, a code that means the same letter. [8] The firewall rule sees no match, and Oracle's server reads the code as P and passes the request on. [8]

    Why it matters — Google says the gang has planted web shells, hidden back doors, on dozens of systems at universities, health-care groups, transport firms and government bodies. [8] The gang told BleepingComputer it used this trick against the FBI's jobs website. [8]

  3. 04

    Check Point flaws used in attacks

    Check Point, a cybersecurity company, has confirmed that attackers are using a flaw in the part of its Security Gateway that handles VPN connections, the secure links staff use from outside. [9] It says a second flaw, in its management web service, has been used as a zero-day, meaning before any fix existed, since 23 July. [9] Attacks on the first flaw began on 12 September, from VPNs and proxies that hide where they come from. [9]

    Why it matters — The Dutch National Cyber Security Centre had warned on 10 September that attacks were expected soon, and CISA gave US federal agencies until 25 September to fix both. [9] Check Point's fix is a LivePatch update or a newer hotfix, and it tells owners who cannot update to limit who can reach the VPN. [9]

  4. 05

    Poisoned GitHub tools came back for nine days

    Two GitHub Actions, small tools that run by themselves inside programmers' projects, were poisoned on 18 May in an attack called Mini Shai-Hulud. [11][10] GitHub's security team then removed them. [10] On 16 September they became available again without being cleaned, so their version labels still pointed at the harmful code, which steals passwords and keys. [11][10] Projects that called them by version label ran that code again until GitHub had switched them off by 25 September. [10]

    The tools came back without being cleaned, and projects that used them ran the May code again for nine days.

    Why it matters — Socket, a security firm, says about 15,000 projects on GitHub depend on one of the two tools, though not all of them ran the bad code. [10] Projects that named an exact version of the code, instead of a label that can be moved, were not affected. [11]

  5. 06

    US election plan arrives 40 days out

    CISA, the US cyber-defence agency, published its 2026 Election Infrastructure Security Plan on Thursday 24 September, 40 days before the 3 November midterm elections. [14][13] It warns that rules for certifying voting systems can stop makers releasing fixes, and stop officials installing them quickly. [12] It says hackers have tried to break into voter registration systems in all 50 US states and succeeded in at least 20 over the last decade. [12][13]

    Why it matters — Election officials told AP the help came too late after the Trump administration cut CISA's election work, and Minnesota expects to pay about $250,000 for private testing. [14] The plan says the Homeland Security department has consistently supported CISA's services, which many election officials say is not true. [14]

  6. 07

    Most US agencies missed a cloud deadline

    The inspector general of the US Homeland Security department, its internal watchdog, published a report on Wednesday 23 September. [15] It found 88 of 102 US civilian agencies had not put in place all the cloud security settings CISA ordered by June 2025. [15] By February 2026, 78 still had not. [15] The missing settings included blocking old login methods and requiring a second check at login. [15]

    US civilian agencies, out of 102, that had not put in all of CISA's required cloud settings.

    Why it matters — The watchdog says CISA lacks the power to make agencies follow its orders, which leaves their cloud systems open to attacks that could be prevented. [15] CISA did not respond to the report. [15]

  7. 08

    Cloudflare customers could read others' leftovers

    A flaw in Cloudflare Containers, a service that runs customers' programs on shared servers, let one paying customer read data other customers had left behind. [16][17] Oren Yomtov of the security firm Accomplish reported it on 4 September. [16] Shared disk space was not wiped before it was handed to the next customer. [16] The researchers found leftover material, including databases, browser profiles and files holding logins, on 18 of 24 tries. [16][17]

    Why it matters — Cloudflare finished fixing it on 19 September, says customers need do nothing, and found no sign anyone else used the method in the records it kept. [16][17] It has not said how long the unsafe setting was in place. [16]

  8. 09

    One link could hand over a WordPress site

    Elementor, a WordPress add-on for building web pages that is active on 10 million sites, had a flaw that let one link create an administrator account for an attacker. [18] The link works when a logged-in administrator opens it, from an email, a chat message or a comment. [19] Elementor skipped a safety check whenever a certain phrase appeared anywhere in the web address, and whoever writes the link can add that phrase. [19] Only versions 4.3.0 and 4.3.1 are affected. [18]

    Why it matters — Patchstack, a security firm, reported it on 22 September, and Elementor fixed it two days later in version 4.3.2. [18] The two affected versions are installed on up to 2 million sites. [18]

  9. 10

    Labcorp pays $2.3m over a collector's breach

    Labcorp, a large medical testing company, will pay a $2.3 million fine and change how it guards data, 44 US state attorneys general announced on Thursday 24 September. [20] It settles their case over a 2019 breach that exposed 10.2 million Labcorp customers. [20] That breach began at the American Medical Collection Agency, a debt collector Labcorp used, where 27.5 million people were affected in total. [20]

    Why it matters — Labcorp must now write security rules into its contracts with suppliers and get regular audits from debt collectors. [20] The collector itself was ordered in 2021 to pay a $21 million fine, which was suspended because it went bankrupt. [20]

  10. 11

    WSO2 and Adobe shop flaws now attacked

    CISA added two critical flaws to its list of ones used in real attacks, BleepingComputer reported on 25 September. [21] One is in products from WSO2, an enterprise software maker with nearly 1,000 customers in banking, government, telecoms and logistics. [21] It accepts login tokens signed in a way it should reject, and was first disclosed in May. [21] The other is in Adobe Commerce and Magento, online shop software, and needs no account to use. [21]

    Why it matters — US federal agencies had until Sunday 27 September to fix both. [21] The security firm watchTowr saw attempts on WSO2 on 13 September, and Sansec, which protects online shops, saw the Adobe flaw used in real attacks. [21]

  11. 12

    No fix yet for a D-Link router hole

    D-Link has warned of a flaw rated at the maximum severity in its older DIR-822A Wi-Fi routers. [22] Someone on the same local network can send the router crafted messages that could crash it or let them run their own code, with no password. [22] The researcher who found it has published attack code, and D-Link has no fix yet. [22] A second flaw in the same router, also with public attack code, is still being investigated. [22]

    Why it matters — D-Link tells owners to keep the routers off the open internet and limit who can manage them. [22] Attackers often add D-Link devices to botnets, networks of hijacked machines used to flood websites with traffic. [22]

  12. 13

    Malware lets AI models vote on its next move

    Cisco Talos, a security research team, has found ClosedQuorum, Windows malware that asks up to four AI models what to do next on an infected computer. [23][24] DeepSeek, Qwen, Mistral and Gemini vote between stealing passwords, hiding inside other programs or staying on the machine. [23] When the vote is tied, DeepSeek's answer wins. [23] The stolen data goes to the operators through Discord, a chat app. [23]

    Why it matters — Talos has not seen it used in real attacks, and the copy it studied held placeholder keys. [23][24] It says handing these choices to AI lets an attack run at any hour with no person involved. [23]

  13. 14

    Fake TV app hides a banking trojan

    Group-IB, a security company, has found RemControl, Android malware rented out to criminals and spread through fake Google Play pages for TVTap, a TV-streaming app. [25][24] Once given special access, it lays fake login screens over banking apps and lets its operator control the phone remotely. [25] It targets customers of more than 30 banks in Western Europe, the Middle East and Canada. [24]

    Why it matters — It also stops Google Play Protect, Android's built-in malware check, from checking it against known malware. [25] Group-IB suspects a link to the Medusa banking trojan. [25]

  14. 15

    Mac stealer hides orders in iCloud calendars

    Kaspersky's researchers say a new version of MacSync, malware that steals passwords and crypto wallets from Macs, gets its orders from public iCloud calendar events. [26] Commands hidden in an event's description are downloaded and run, and they fetch the next part of the malware. [26] It has been spread through a fake crypto wallet called Toria, promoted on social media, and through apps offered as free or cracked. [26]

    Why it matters — A new part of it poses as Finder, the Mac's file manager, and can swap an installed Ledger crypto wallet app for the attacker's version. [26] Kaspersky could not work out what one of its commands does. [26]

  15. 16

    Attack code out for a WordPress theme flaw

    The security firm pwn.ai, which found the Click2Shell flaw in WordPress, software for building and running websites, has published full attack code for it. [27][28] A crafted link opened by a logged-in administrator makes the site install a theme from WordPress's own catalogue without asking. [27] pwn.ai says more than 40 themes in that catalogue can then run the attacker's code, even while switched off. [28]

    Why it matters — The fix is in WordPress 7.1.1, and WordPress paid pwn.ai $300, its largest bug reward. [28] A site set to block file changes cannot be made to install the theme. [27]

  16. 17

    Clop moves its leak site after the hack

    Clop, a ransomware gang, has moved its leak site, where it posts victims' stolen files, to a new address on the Tor network. [29] It confirmed its old server was broken into and defaced earlier this month by ShinyHunters, an extortion gang. [29] BleepingComputer learned the way in was an unfixed flaw in Grav, the website software Clop used, that needed no login. [29]

    Why it matters — Clop denied any link to ShinyHunters and said it has given it nothing. [29] ShinyHunters says it took Clop's code, server logs and keys, and has threatened to publish them unless Clop pays. [29]

  17. 18

    US agencies warn about hired control-system firms

    CISA and the FBI have warned operators of essential services about the outside firms they hire to set up industrial control systems. [30] They describe foreign hackers who got into a US industrial automation company in March and April 2025, whose customers included power utilities and transport firms. [30] The hackers packed nine archive files with network drawings, device settings and customer details. [30] Separately, NIST, publisher of the Cybersecurity Framework 2.0, released a draft update of its security guide for these systems. [30]

    Why it matters — The agencies say such firms should get only the access they need, and contracts should say where data is kept and how remote access works. [30] NIST's guide now covers water systems, food and farming, freight rail and ships, and comments are open until 30 November. [30]

  18. 19

    Stolen logins reach US water utilities

    SpyCloud, which studies stolen identity data, looked at data taken by password-stealing malware and linked to 10,000 US water and wastewater utilities and their suppliers. [24] It found stolen data at 1,787 of them, and logins for control or remote-access systems at 258. [24] One infected computer at a metering supplier held saved logins for about 167 utilities' metering websites. [24]

    Why it matters — SpyCloud says these are possible ways in, not confirmed break-ins. [24] Most of the logins at the utilities themselves were for remote-control tools such as TeamViewer. [24]

  19. 20

    Shared relays hide AI users in China

    Researchers at Team Cymru found nearly 11,000 servers running Claude Relay Service or sub2api, open-source tools that let many people share AI accounts. [24] The AI companies see only the relay, not the real user or where they are. [24] In one group of relays hosted in the US, more than 4,000 internet addresses in China and Hong Kong connected to 304 relays that also reached OpenAI, Anthropic, xAI and Google. [24]

    Why it matters — Anthropic, OpenAI and Google exclude China and Hong Kong from their services, and the relays hide where users really are. [24]

  20. 21

    A botnet that hunts AI keys first

    Researchers at ThreatDown have described CARBONATO, a botnet that takes over computers running Docker, a tool for running programs, that were left open with no password. [24] It scans nearby networks every five minutes to spread. [24] On each machine it installs Hermes Agent, an open-source AI agent, and tells it to obey commands sent over Telegram and collect passwords, with AI keys ranked first. [24]

    Why it matters — The researchers found it through a storage site the operators left open. [24] Language, time zone and other clues point to operators in Costa Rica. [24]

  21. 22

    Ubuntu moves to weekly core updates

    Canonical is replacing the separate four-week and two-week update cycles for Ubuntu's kernel, the core of the system, with one two-week cycle. [24] Because the cycles overlap, a new core will be released every week. [24] Canonical also aims to offer workarounds or other guidance within 24 to 48 hours of a flaw going public. [24]

    Why it matters — It says the number of reported flaws has risen sharply, partly because AI tools now help find bugs. [24] The kernel's own developers also now give numbers to thousands of bugs themselves. [24]

  22. 23

    One message can crash a factory database

    Ridge Security found a flaw in TDengine, a database that stores readings from machines in industry, energy and utilities. [24] A stranger with no login can crash it with a single malformed message. [24] Versions 3.4.0.0 to 3.4.1.5 are affected, and version 3.4.1.6 fixes it. [24]

    Why it matters — The researchers only showed a crash, but they warn the memory damage behind it could allow more. [24]

02 Lesson why it matters

Attackers get past a filter by writing the same thing a different way

A filter checks how a request is spelled, so attackers spell the same request differently and the server still understands it.

The twist

A filter protects a server only if both read a request the same way. When they read it differently, an attacker can write a request that the filter lets through and the server obeys.

The picture

%50 is a code for the letter P. The firewall compares letters and finds no match. Oracle's server turns %50 into P and passes the request on.

How it works

  1. A filter is told to block one exact string of letters
  2. The server behind it turns codes back into letters
  3. The attacker writes the blocked letters in code
  4. The filter finds no match and lets it through
  5. The server decodes it and does what was asked

The same force, elsewhere today

Where this chain is also running, in today's other stories.

  • ShinyHunters steps round PeopleSoft blocks

    Firewalls were set to block the letters /PSEMHUB/, so the gang wrote the P as %50, and Oracle's server turned %50 back into P.

  • One link could hand over a WordPress site

    Elementor's check was skipped whenever a certain phrase was in the web address, and the person writing the link could put that phrase in it.

  • Attack code out for a WordPress theme flaw

    WordPress's theme service cut a value in the link down to a plain theme name, while the administrator's browser kept the original punctuation and acted on it.

Where you've seen this

Game chat filters

a filter that blocks a rude word misses it spelled with numbers or symbols, and other players still read the word

Spam filters

an email filter watching for the word free misses fr3e, and the reader still sees the same offer

School web blocks

a block on one web address misses the same page reached through a different address

The catch

Blocking more spellings does not end it. Google warned the gang could switch to other codes or mixed capital letters, and its Mandiant team urges owners to install Oracle's update instead, which closes the hole itself.

And the whole of it

Almost everyone sits behind filters like these, from a spam folder to a school's web block. The person relying on a filter cannot see how it reads a message. They also cannot see how the machine behind it will read the same message a moment later.

03 Truth what's really going on

What is really going on

This week attackers used holes in Citrix's NetScaler boxes and in Check Point's firewall software before fixes were out. [2][9] Organisations that used a stopgap instead of the fix were caught too: PeopleSoft owners who only blocked one web address were attacked again when ShinyHunters wrote that address a different way. [8]

Why it works on us — A chief executive in Idaho, an office in Virginia and signed forms saying no foreigner controlled the company made Oxygen look American, and US officials say they would not have bought its software had they known it was Russian-owned. [6][7]

Who gains

  • Whoever got into a NetScaler before the fix — Updating can wipe the traces an investigator needs, which is why CISA asks owners to check for a break-in first. [3]
  • ShinyHunters — Owners who blocked one web address instead of installing Oracle's fix were left open to the same address written in code. [8]
  • Private firms that test election systems — With CISA's tests unavailable, Minnesota's election office expects to pay about $250,000 for private testing. [14]
  • Cellebrite — Oxygen, its direct competitor, has had its website seized and its chief executive arrested. [7]
  • The 44 US states in the Labcorp case — They get a $2.3 million fine and a promise that Labcorp will require audits from the debt collectors it works with. [20]

Who pays

  • Organisations that switched their NetScalers off — They took down the box that handles logging in from outside, some after a phone call that gave no details. [1][2]
  • Programmers whose projects ran the two GitHub tools — Socket tells them to review every run since 16 September and change every secret those runs could reach. [10]
  • About 10.2 million Labcorp customers — Their data was exposed in 2019 through a debt collector Labcorp used, seven years before this settlement. [20]
  • Anti-war Russians — Access Now says the FSB used the same software to pull data off their phones and turn it into criminal charges. [7]
  • US civilian agencies still missing CISA's cloud settings — The watchdog says their cloud systems stay open to attacks that could be prevented. [15]

What nobody knows yet

Open questions from across today’s stories — ours included.

  • 01

    Who is behind the NetScaler attacks, and how many organisations they reached.

    watchTowr named no victim and showed no evidence, and the Dutch notice said it did not know whether the holes were being used widely. [2][1]

  • 02

    Whether Citrix's fixes cover the older NetScaler 13.1.

    Its regular updates ended on 15 September, and as of Sunday morning Citrix had not said whether it would get one. [2]

  • 03

    How many projects ran the poisoned GitHub tools between 16 and 25 September.

    About 15,000 projects depend on one of them, but Socket has not worked out how many used the movable label that pulled in the bad code. [10]

  • 04

    Why the two GitHub tools were switched back on without being cleaned.

    BleepingComputer says their maintainer re-enabled them, and neither report explains why. [10][11]

  • 05

    Whether ShinyHunters used a new PeopleSoft hole at the FBI.

    The gang says it used both the address trick and a new unknown flaw, and BleepingComputer could not check the claimed new flaw. [8]

  • 06

    Whether anyone besides the researchers read other customers' data in Cloudflare Containers.

    Cloudflare checked only the records it had kept, and did not say how far back they go or when the unsafe setting began. [16]

  • 07

    What Oxygen's software did inside US investigations.

    Prosecutors do not claim it held harmful code, while Access Now, a digital rights group, is asking more than 100 governments to investigate how it was used. [6][7]

  • 08

    How much federal help reaches US election offices before 3 November.

    The plan says Homeland Security has consistently supported CISA's election services, while secretaries of state told AP that tests CISA used to run were not available this year. [14]

  • 09

    Whether ClosedQuorum has been used against anyone.

    Cisco Talos has not confirmed any real attacks, and the copy it studied held placeholder keys. [23]

04 Hope carry this

Cloudflare fixed its leftover-data flaw 15 days after it was reported, and found no sign in its records that anyone besides the researchers and its own engineers had used it.

Also true today

  • Elementor released a fix two days after Patchstack reported the flaw that let one link create an administrator account on a WordPress site.
  • Oxygen Forensics' chief executive was arrested in Idaho and its technology chief at London's Heathrow Airport, and US authorities seized about 57 of the company's web domains.
  • Canonical will release a new Ubuntu core every week and aims to offer workarounds within 24 to 48 hours of a flaw going public.

Across the beats