- Vulnerable U
- Posts
- 🎓️ Vulnerable U | #188
🎓️ Vulnerable U | #188
Major Citrix vuln and exploitation, ShinyHunters member arrested, Massive list of new Linux Kernel CVEs, and much more!
Read Time: 8 minutes

Brought to you by:
Howdy friends!
Exciting news! I got asked to be the opening keynote for SecTor (Blackhat Canada) at their AI Summit. Going to be easily my largest keynote and I’m very excited to return to SecTor. I spoke there a few times over a decade ago - for you long time friends you’ll remember my days on the Liquidmatrix Security Digest as the lone American amongst a bunch of Canucks. It is always a good time and Toronto is easily a Top 5 city for me so all around will be fun. Be sure to say hey if you’re around SecTor!
ICYMI
🖊️ Something I wrote: Security teams know how to do security, that isn’t the hard part of the job
🎧️ Something I heard: The Low Down where we talk about the illusion of privacy in AI
🎤 Something I said: Check me out on this webinar coming up here soon all about threat hunting!
🔖 Something I read: The scoreboard watching the Yankees beat the Red Sox in the playoffs. Better than a World Series to me.
Vulnerable News

NetScaler admins found out about this one from a Reddit thread and watchTowr's warnings on X the weekend before Citrix said a word. By the time the bulletin landed September 27, two pre-auth RCE zero-days in NetScaler ADC and Gateway (CVE-2026-88771 and CVE-2026-88772) had been exploited for most of the month, and Dutch and Danish government agencies had already yanked their boxes offline. watchTowr has since turned the DTLS bug into root-level shellcode execution, and DTLS is on by default for VPN virtual servers.
Google's Mandiant team found custom webshells tunneling into internal networks at government, finance and legal orgs, and Kevin Beaumont is tracking 100+ victims, each with its own webshell you can't scan for from the outside. Quoting him, he thinks "it's espionage." The IR vendors have been publishing victim-specific webshell names and attacker IPs in their writeups, which maps out exactly who got popped.
Patching leaves already-planted webshells right where they are, and Beaumont's scanning had fewer than 10% of boxes patched as of the 29th, with public PoCs now feeding spray-and-pray exploitation. If your NetScaler was internet-facing and unpatched in September, treat it as compromised. Mandiant says preserve logs and a memory snapshot and hunt before upgrading, since the upgrade can wipe your evidence. Then patch to 14.1-73.37 or the newest 13.1 build (Citrix flagged a reboot loop in the first 13.1 fix), and 12.1 and 13.0 are EOL with no fix at all. If you find anything, Citrix says stand up a fresh instance, and rotate everything that box touched: admin creds, LDAP bind accounts, certs and keys. PitScaler is a running tracker of advisories and IOCs if you're in the thick of it. (read more here, here, here and here)
Legacy SCA and SAST scanners match patterns and bury engineers in noise. That's why we built Maze Code: AI agents that understand your code and dependencies.
AI agents investigate every finding with context from your code and cloud, close false positives, and catch business logic flaws other tools miss. Then they help you fix what's left, right in your IDE or coding agent.
Finally, inbox zero for your code and cloud vulnerabilities is possible.
*Sponsored

"Several." Debian's latest kernel advisory for stable (trixie) opens with a CVE list that runs well over a thousand IDs. Then it sums all of them up in one sentence: privilege escalation, denial of service or information leaks, please upgrade. That's the whole advisory. Part of this is just how kernel CVEs work now. Since the kernel team became its own CVE issuer in 2024, nearly every bug fix gets an ID, and plenty of them will never be reachable in your environment.
Nobody is going to triage these one by one, and that's kind of the point. Last week we covered researchers arguing containers aren't a real security boundary anymore because there are so many kernel CVEs nowadays. (read more here and here)

Dutch police arrested a 24-year-old on September 15 as part of their ShinyHunters investigation. Krebs identified him as Pepijn van der Stap, who served prison time for data theft and extortion under the handle "Umbreon" and got out last December. Krebs had interviewed him on September 9, when he was pitching himself as reformed and working an offensive security job. I also got a few DMs from his former coworkers at security consulting shops.
The timeline is funny here though, the arrest actually happened BEFORE the FBI hack, but they just announced it this week. The defacement on the FBI site featured giant Umbreon ASCII art, which Krebs's sources read as a rival now running the group trying to pin the hack on the guy in custody.
On September 29, Dutch police said he is also suspected of ordering two murders abroad. The FBI called him an alleged leader tied to more than 140 hacked orgs and $70 million in extortion payments, and Assistant Director Brett Leatherman told the remaining members to reach out "while the choice is still yours." ShinyHunters started out promising the arrested member a defense lawyer and calling the Dutch police "useless." Now it tells 404 Media it will never publish the FBI data, because the whole thing was a marketing campaign. Its leak site says operations are unaffected and victims should keep negotiating. (read more here, here and here)

The open-weight models caught up like we knew they would. Anthropic's Frontier Red Team tested Zhipu AI's GLM-5.3 and found it builds working end-to-end exploits at close to the rate of Claude Mythos Preview, the model Anthropic kept behind a limited-access program five months ago. In about a day, a researcher used it to find several 0-days in a major browser's JavaScript engine and chain them into a webpage that reads files off the visitor's machine. I’m in some group texts and people are having lots of luck with similar vuln research using GLM.
The smaller Flash version turned a public Chrome CVE into a reliable exploit chain in eight hours, for $20.40 at Zhipu's API prices. The guardrails apparently are more of a suggestion. A fake red-team cover story gets it to engage 64% of the time, prefilling its reasoning gets 92%, and stripping refusals out of the weights gets 100%. People already published versions with the refusals stripped out within days of release.
Consider the source a little: Anthropic sells the safeguarded alternative, and the post closes on a pitch to get Claude into more defenders' hands. But NIST's CAISI reached the same capability conclusion on its own, calling GLM-5.3 the most cyber-capable open-weight model yet and putting it about four months behind the US frontier. Tie that into to the Zimbra story below. The time between a fix landing and someone weaponizing it is now roughly a workday and twenty bucks, and your patch SLAs should reflect that. (read more)
Security teams need visibility across every log source, but storing it all in a SIEM gets expensive fast. Scanner CEO Cliff Crosland calls the solution federated indexing: read each log once, at the source, and build a compact index at around 15% of the raw volume. Learn how it works and how it enables search and detection across all of your telemetry. (read more)
*Sponsored
Inc columnist Jason Aten installed Meta's new Muse agent on his Mac and says he explicitly declined access to his messages. Then he got a push notification suggesting a column based on a text conversation he'd just had with his podcast co-host. When he asked how it knew, Muse said it only saw incoming notification banners. Aten then found it had been syncing his local Messages database. Meta's Andy Stone says the Messages integration is opt-in and needs both Full Disk Access and the Messages connector turned on. David Singleton walked through three permission gates, including macOS's own, and said the agent just gave a wrong explanation of itself.
So which is it? If Meta's version is right, a permission got granted somewhere in onboarding that a privacy-obsessed tech journalist didn't register, and that's still a design problem. An agent's explanation of its own access is just more generated text, so treat it with zero authority. (read more here and here)
Edge devices, wtf is going on? Same week as Citrix, Cisco says attackers are exploiting a zero-day in Catalyst SD-WAN Manager, the box that runs your whole SD-WAN fabric. CVE-2026-76504 (CVSS 9.8) lets an unauthenticated attacker get past a login check with one crafted request and then drive the Manager's API as admin, which on a default setup can do everything. Cisco found it while working a support case and hasn't said who, since when, or how many customers got hit. By the way, this is the eighth Cisco SD-WAN bug added to CISA's KEV catalog this year...
There's no workaround, so patch. But, before you upgrade, pull the diagnostic bundle Cisco asks for and look for logins from IPs you don't recognize, because Cisco's earlier SD-WAN advisories said an update alone won't evict someone who's already in. Until you can patch, lock the Manager down to known hosts. Cisco's own hardening guide says it should never face the internet in the first place. (read more here and here)
A mail server is close enough to an edge device for this week's theme. Microsoft Threat Intelligence tracked exploitation of CVE-2026-73570 in Zimbra Collaboration Suite. It's unauthenticated and zero-click: a single crafted email gets a shell as the Zimbra service account, as long as the optional SNMP package is installed and notifications are turned on. The timeline is the interesting part. Zimbra quietly shipped the fix on July 20, public disclosure came August 13, and Microsoft watched scanners probing the exact injection point in the weeks between. Somebody diffed that patch.
After getting in, attackers dropped webshells on every mailbox node, got root by abusing Zimbra's own sudo-allowed helpers, stole the keys Zimbra uses to sign login sessions (which means they can forge a login as any user), and staged entire mail stores for exfil to Azure blob storage.
Patch to Zimbra 10.1.20 or later. If you can't yet, uninstall the SNMP package or turn off notifications. If you ran with SNMP enabled any time since July, assume the worst: rotate the preauth and session-signing keys plus the service credentials, and hunt every node for stray JSP files, since Microsoft saw redundant shells planted across clusters. Silent fixes are only silent to defenders. (read more)
Rounding out edge device week apparently, CISA put out an advisory for CVE-2026-84411, a pre-auth bug in RouterOS's web management interface where one crafted request gets you root code execution or crashes the router. MikroTik hasn't published its own advisory yet, so the version guidance is a bit muddy: CISA says everything below 7.24 is affected and also points to 7.23 as the fix.
MikroTik boxes are botnet catnip, and attackers were chaining two other RouterOS bugs to hijack routers just weeks ago. Update to the current stable or long-term release, and get the web management interface off the internet, which you've definitely already done, right? (read more)
The people whose whole job is warning you about exposed vulnerable systems just got popped by an AI agent. On September 21, an attacker's agent hit the Dutch Institute for Vulnerability Disclosure, the volunteer group that scans the internet and tells owners when they're exposed. It chained two zero-days in Zammad, the open source helpdesk DIVD runs, to hijack sessions, run code and get root, then moved into other services to read and pull data. DIVD says the whole sequence took seconds. It called the attack loud and very messy, and the agent left behind explanations of its own decisions, which is how DIVD reconstructed the attack. Network segmentation kept it from going deeper. DIVD also says this is unrelated to its former volunteer in the ShinyHunters story.
The AI-agent read comes from DIVD's own logs, and it hasn't said who ran it or what was taken. If you run Zammad, DIVD says upgrade to version 7 or take it offline. Zammad hadn't published its own advisory as of Thursday morning, and at least one outlet reports the root escalation bug has no fix in any version yet. If yours is internet-facing, take the offline option seriously. (read more here and here)
Last week the FBI, this week the Pentagon's personnel office. The Defense Manpower Data Center, which holds more than 60 million DoD personnel records, is notifying people that a small number of unauthorized users got in through a vulnerability in one of its file-sharing systems. They had access from October 2025 until someone noticed on July 16, 2026. That's about nine months. A defense official puts the count at 2.76 million living people plus 294,000 deceased. The stolen data includes unencrypted SSNs, names, birth dates, contact info, race, and military personnel details, including what jobs people held.
DMDC hasn't named the product, the bug, or who was inside, and officials say there's no evidence of misuse yet. A dataset of millions of service members and what they do is a counterintelligence problem, same as the FBI one. Twelve months of credit monitoring does very little about a foreign service knowing who holds which job. (read more here and here)
How'd I do this edition?It's hard doing this in a vacuum. Screaming into a void. Feedback is incredibly valuable to make sure I'm making a newsletter you love getting every week. |
Parting Thoughts:
Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. Community is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you.
Stay safe, Matt Johansen
@mattjay

