THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

4 min read

AI-assisted briefingHow we put it together ↗

AT A GLANCE

  • Two NetScaler remote-code-execution flaws were exploited before disclosure; Rapid7 recommends emergency updates and compromise checks.
  • Mandiant reports that ShinyHunters bypassed string-based PeopleSoft WAF rules by encoding a character in the request path, targeting organizations that had not patched.
  • File-notification research found cross-account activity leaks; Linux’s mitigation covers only part of the exposure, and the reported Windows protection is disabled by default.
01

Citrix NetScaler flaws exploited as zero-days, CISA confirms global activity

Rapid7 reports that two critical NetScaler ADC and Gateway remote-code-execution vulnerabilities, CVE-2026-88771 and CVE-2026-88772, were exploited in the wild before Citrix disclosed them. CISA added both to its Known Exploited Vulnerabilities catalog; the first affects default configurations, while the second requires DTLS to be enabled. Rapid7 recommends emergency updates and checking vulnerable appliances for signs of compromise.

What changed The September 27 disclosure followed exploitation, rather than preceding it, so defenders received public notice after attacks had already begun.

Why it matters NetScaler operators cannot assume that avoiding optional features removes their exposure: CVE-2026-88771 permits remote code execution in vulnerable default deployments.

What to watch next Rapid7’s recommended next steps are emergency patching and investigation for existing compromise; installing an update alone does not answer whether an appliance was already breached.

Rapid7 ↗
02

ShinyHunters claim FBI portal breach as PeopleSoft flaw exploitation expands

The FBI’s job-applicant portals remain unavailable after ShinyHunters claimed it breached them and stole personal information; the FBI has said it is investigating the claim. Mandiant reports the group is again exploiting Oracle PeopleSoft vulnerability CVE-2026-35273, using URL encoding to bypass some WAF rules and targeting organizations across multiple sectors. The stolen-data claims, including the alleged scale and types of records, have not been independently verified in the report.

What changed The campaign shifted from an earlier exploit to a modified WAF-bypass technique and expanded its sector targeting.

Why it matters Organizations relying on string-based WAF rules instead of patching PeopleSoft may still expose the vulnerable endpoint despite believing it blocked.

What to watch next Whether the FBI portals were breached through a PeopleSoft zero-day remains an open question; the attackers’ claimed entry point is not confirmed.

HelpNet Security ↗
03

Microsoft fixes Titan token-signature flaw that exposed internal analytics access

A 16-year-old researcher, identified as Faav, reported that Microsoft’s internal Titan analytics service accepted login tokens without verifying their signatures, allowing him to obtain administrator access and query connected databases. He reported access to employee records and two Bing analytics samples, but said he did not access customer data or use the samples to identify people. Microsoft locked down the endpoint on September 9 and awarded a $5,000 bounty, according to the researcher’s account.

What changed Microsoft received the report on September 5 and locked down the endpoint on September 9, establishing a containment timeline rather than details of the underlying repair.

Why it matters For Microsoft staff represented in Titan, exposed organizational details could support more targeted social engineering; the researcher did not test that downstream use.

HelpNet Security ↗
04

Researchers find cross-account activity leaks through OS file notifications

Researchers at Graz University of Technology report that file-notification mechanisms can reveal activity across user accounts, including website visits on Windows and keystroke timing on Linux. They also found that a zero-permission Android app could observe certain files, including downloads, photos, screenshots and WhatsApp media; macOS showed less leakage in their tests. Linux shipped a partial mitigation in early 2026, while the researchers say Microsoft’s available Windows policy is disabled by default.

What changed Linux’s early-2026 patch closed the unreadable-device-file route, but left the broader filesystem exposure unresolved.

Why it matters On shared Windows machines, an unprivileged account could infer another user’s browsing activity, weakening the privacy boundary between accounts without needing administrator access.

What to watch next Whether Linux and Windows will adopt broader restrictions remains open; the researchers propose permission-aware Linux watches and an end to drive-wide Windows watches.

HelpNet Security ↗
05

GitHub Security Lab’s AI audit workflows uncover 24 Android app vulnerabilities

Researcher Kevin Stubbings used custom AI-driven taskflows to find and report more than 20 vulnerabilities in Android apps, including flaws in OsmAnd and the Wikipedia app. The reported issues could allow another app to alter OsmAnd settings and track map-tile requests, or let a lookalike Wikipedia link run JavaScript in the app’s WebView and access long-lived session cookies. Stubbings said the AI was less reliable at rating severity and impact, and that every finding still requires review by a mobile-security expert.

Why it matters Wikipedia app users could face account exposure beyond the app itself: the reported cookie theft would yield a session token usable across Wikimedia projects after one tapped link.

HelpNet Security ↗
06

NVIDIA introduces agent-safety platform with runtime controls and hardware monitoring

NVIDIA announced the Open Agent Safety Platform, combining OpenShell software that isolates agents and enforces access policies with Sentry, a watchdog in a reference design that monitors activity using separate hardware. NVIDIA says Sentry can quarantine and stop an agent that crosses its software boundary; it relies on supported hardware, while OpenShell is open source and can be extended to other computing platforms. The company says the platform is available through its developer resources and GitHub.

Why it matters Organizations seeking independent monitoring must account for a hardware dependency: Sentry’s placement outside the agent supports separate enforcement, but requires supported infrastructure.

HelpNet Security ↗
Cybersecurity — September 29, 2026 | Briefing24