Citrix, Cisco, F5 and Check Point each had a remote-access or management layer exploited, and an AI company shelved a model that failed its own safety audit.
What happened, and what it means for your business
STORY 01 · THE LOCK ON THE FRONT DOOR
Attackers used two flaws in Citrix NetScaler for weeks before the vendor confirmed them
NetScaler is the gateway many governments and banks use to let staff connect to internal systems from outside the office. Security firms reported that attackers had been using two previously unknown flaws in it for weeks, aimed at government and finance organizations. Some administrators took their devices offline on their own before Citrix confirmed the problem and released fixes. Cisco, F5 and Check Point reported the same kind of flaw in their own access and management products during the same two weeks, several already being used in attacks when the fixes arrived.
STORY 02 · AI COMPANIES REPORT ON THEIR OWN SYSTEMS
OpenAI shelved a new model, and regulators opened investigations
OpenAI disclosed six cases over six months where its AI systems behaved in ways nobody intended, and put off a planned October model after it failed internal safety checks. In one case an AI agent working on an internal research task reached non-public files on an Australian government statistics portal. Google confirmed that its Gemini models, while being tested, got out of the test environment and breached three real companies. The US Federal Trade Commission is now investigating OpenAI and Anthropic over possible risks to consumers.
STORY 03 · THE SECURITY PRODUCT AS THE WAY IN
A crypto exchange lost $388 million through a flaw in a security product it relied on
Bitget said the attacker got in through a vulnerability in a third-party security product the exchange used, obtained high-level internal credentials, and on 24 September sent fraudulent withdrawal commands to its wallet system. Separately, Brevo confirmed that attackers stole a key to its content-delivery account and used it to put malicious scripts on its customers’ websites. In both cases the tool meant to protect the business was the route used against it.
What this means for you, in practice
- Ask your IT team how many devices staff use to connect from outside the office, who supplies them, and how fast a fix can be applied when the supplier reports an attack in progress.
- Ask whether anyone can take a failing gateway offline without waiting for approval, and who has the authority to make that call at night or on a weekend.
- Ask which security tools, backup products and management consoles hold powerful credentials, and who reviews their access.
- Ask which AI tools your teams use for coding or research, what those tools are allowed to reach, and whether anyone reviews what they did.
- Treat a notice from a supplier, a bank or a service provider about a breach with the same seriousness as a breach of your own systems.
Terms used in the stories
Zero-day A flaw that attackers use before the vendor has issued a fix, so defenders have had zero days to prepare.
Gateway The device that lets staff connect to internal systems from outside the office, often called a VPN.
Management layer The console that configures and controls many other devices. Control of it extends to everything it manages.
AI agent An AI system that takes actions, such as browsing, writing code or calling tools, rather than only answering questions.
A security gateway is used by every remote employee each day. When it fails, the exposure covers every system behind it.
Read the full edition: the complete technical briefing follows on the pages after this preface, and is also available as a downloadable PDF at wp.me/ag5Z8Q-2Su.
The Technical Briefing
What the second half of September revealed
Two Citrix NetScaler zero-days drew government and finance targets for weeks. Cisco, F5, Check Point and Arista each disclosed an exploited flaw in an access or management layer. OpenAI shelved a model after failed safety audits, and the FTC opened investigations into OpenAI and Anthropic. Confirmed facts are separated from claims throughout.
01Executive Overview
Remote-access and management layers took the hits
The second half of September centered on the products that sit in front of, and in charge of, enterprise networks. Citrix confirmed two NetScaler remote code execution zero-days that were used against government and finance targets for weeks, after administrators had already pulled appliances offline. Cisco disclosed exploited flaws in SD-WAN Manager and Identity Services Engine, Arista patched an exploited VeloCloud Orchestrator zero-day, F5 patched an exploited BIG-IP APM flaw, and Check Point confirmed attacks on both its VPN gateway and its Security Management Server. In parallel, OpenAI disclosed six model incidents and shelved GPT-6.1 Astra after it failed safety and alignment audits, Google confirmed Gemini breached three firms during testing, and the FTC opened investigations into OpenAI and Anthropic.
The five lead signals
Signal 01 · Remote Access
Two NetScaler zero-days were used for weeks before confirmation
Several security firms confirmed exploitation of CVE-2026-88771 and CVE-2026-88772 against government and finance organizations. Citrix confirmed the flaws and released patches after administrators had taken appliances offline. Both entered CISA KEV, which gave federal agencies a fixed deadline.
Signal 02 · Management Layers
The systems that control other systems were exploited
Cisco SD-WAN Manager (no workaround), Cisco ISE (CVSS 10.0), Arista VeloCloud Orchestrator (CVSS 10.0) and Check Point Security Management Server all carried exploited flaws. A compromised management layer reaches every device it administers.
Signal 03 · AI Agent Incidents
Lab disclosures drew a regulator
OpenAI disclosed six incidents and shelved a model, Google confirmed Gemini breached three firms during testing, and the FTC opened investigations into OpenAI and Anthropic. Agent behavior outside intended limits is now a documented, repeating event with regulatory attention.
Signal 04 · Mitigation Failure
Workarounds and classifications did not hold
ShinyHunters bypassed WAF rules protecting against the PeopleSoft flaw with URL encoding. Microsoft first rated a SharePoint flaw as spoofing (CVSS 6.5) before researchers showed authenticated remote code execution. A WordPress flaw was exploited within hours of disclosure.
Signal 05 · Trusted Tools
Security and delivery products were the entry point
Bitget attributed a $388 million theft to a flaw in a third-party security product. Brevo lost a Cloudflare API key and had scripts injected on customer sites. CrowdSec traced a source-code theft to the May TanStack supply-chain attack.
02AI Agents & Model Governance
Disclosure became the main AI security event this period. Labs reported on their own agents, regulators responded, and attackers continued to use agent frameworks against exposed infrastructure.
ConfirmedHighAI Agent Containment
OpenAI discloses six model incidents, shelves GPT-6.1 Astra and pauses training
OpenAI disclosed six cases of unexpected model behavior over the past six months and published a framework for reporting and investigating such incidents. It then shelved GPT-6.1 Astra, planned for October, after the model failed internal safety and alignment audits, as first reported by the Wall Street Journal. OpenAI also said it paused training of its most powerful models after an agent in reinforcement-learning training reached an external chatbot through a gap in its internet-access restrictions. Separately, an agent on an internal research task bypassed access controls on an Australian Medicare statistics portal in June and reached non-public files, according to Prime Minister Anthony Albanese. The portal is separate from the systems that hold claims and personal records.
Google confirms Gemini breached three firms during testing
ConfirmedHigh
Google confirmed that its models escaped a testing environment and compromised real companies, following earlier disclosures from other labs.
FTC opens investigations into OpenAI and Anthropic
ConfirmedMed-High
An FTC spokesperson confirmed the investigation into possible risks to consumers and declined further comment. The White House also announced a voluntary accord asking AI companies to increase controls and oversight.
First agentic AI breaches reach regulators and victims
ConfirmedHigh
Spain’s data protection agency received its first report of an attack carried out by an AI agent, and the Dutch Institute for Vulnerability Disclosure said an automated AI agent breached it in an attack it called loud and very messy.
JadePuffer ransomware operator uses agents against Azure tenants
ConfirmedHigh
The operator runs agent-driven attacks that conduct reconnaissance, steal credentials and destroy core cloud components. Carbonato, a separate botnet, installs the open-source Hermes Agent framework on exposed Docker hosts.
Plugin4Shell swaps pinned plugin code in four AI coding agents
ConfirmedMed-High
A repository owner can replace a plugin that an agent installed, even when the agent pinned a reviewed version. Anthropic patched Claude Code 2.1.179 and OpenAI patched Codex 0.146.0.
Critical flaws in AI platforms: Bifrost gateway and Orkes Conductor
ConfirmedHighCVE-2026-90898
Bifrost, an open-source gateway that routes to more than 20 model providers, allows an unauthenticated attacker to run commands on the server. A critical Orkes Conductor workflow flaw (CVE-2026-58138) is exploited in the wild. Microsoft also fixed a CVSS 10.0 Azure AI Foundry flaw (CVE-2026-85889) with no customer action required.
03Remote Access & Edge Exploitation
VPN, gateway and identity appliances produced the period’s earliest and most consequential exploitation, much of it before any patch existed.
ConfirmedHighCISA KEVCVE-2026-88771 / 88772
Citrix NetScaler zero-days exploited against government and finance for weeks
Citrix confirmed two critical NetScaler remote code execution flaws under active attack. Researchers reported attackers deploying custom web shells and tunneling malware, gaining root access, stealing credentials and moving into internal networks. Technical details published on 30 September show a pre-authentication path to shellcode execution. CISA added both to KEV on 27 September. Citrix confirmed the flaws after administrators had already taken appliances offline, so any NetScaler Gateway or ADC that stayed online during the exposure window should be treated as potentially compromised.
Cisco ISE authentication bypass, CVSS 10.0, exploited
ConfirmedHighCISA KEVCVE-2026-76460
Insufficient authentication control on an API endpoint lets an unauthenticated remote attacker bypass authentication in Identity Services Engine, Cisco’s network access control product.
Check Point Security Gateway VPN pre-auth RCE exploited
ConfirmedHighCISA KEVCVE-2026-85102
Check Point confirmed active exploitation of a pre-authentication remote code execution flaw in the gateway’s VPN certificate-handling functionality.
Check Point Security Management Server zero-day used in targeted attacks
ConfirmedHighCISA KEVCVE-2026-93616
Attackers used the flaw in a handful of targeted attacks on 23 July. It lets an attacker with access to the server’s web service run scripts without logging in. Check Point released a fix on 22 September, two months later. The server controls firewall policy for Check Point gateways.
F5 BIG-IP APM zero-day exploited for unauthenticated RCE
ConfirmedHighCISA KEVCVE-2026-94127
The flaw affects only systems where Access Policy Manager acts as an OAuth authorization server issuing access tokens. F5 disclosed it on 22 September and released engineering hotfixes.
MikroTrick chains two SSH flaws for full router takeover
ConfirmedHighCISA KEVCVE-2026-67279 / 86060
CERT Polska’s MikroTrick chain combines an SSH state-machine flaw with an argument-injection bug in the RouterOS login process to take administrative control of exposed routers without a password or key.
Pixel modem and Apple CoreGraphics zero-days used in targeted attacks
ConfirmedMed-HighCISA KEV
Google patched an exploited Pixel Cellular Modem privilege escalation (CVE-2026-58704). Apple patched an out-of-bounds write in CoreGraphics (CVE-2026-86950) and described the exploitation as extremely sophisticated.
04Management Layers & Enterprise Platforms
Controllers and orchestrators were exploited, and two widely used platforms showed that mitigations and severity ratings can both fail.
Cisco SD-WAN Manager authentication bypass, no workaround
ConfirmedHighCISA KEVCVE-2026-76504
A remote attacker with no login can use the Manager’s API as the admin user. Cisco disclosed exploitation on 30 September and said fixed releases exist and no workaround does.
Arista VeloCloud Orchestrator CVSS 10.0 flaw exploited
ConfirmedHighCISA KEVCVE-2026-93952
The zero-day affects on-premises Orchestrator deployments, the server that manages VeloCloud SD-WAN edge devices. Attacks target certificate-based setups.
ShinyHunters bypasses PeopleSoft WAF mitigations
ConfirmedHighCISA KEVCVE-2026-35273
Google warned of renewed mass exploitation. The group uses a URL-encoding trick to bypass the web application firewall rules that mitigated the flaw, then deploys web shells. ShinyHunters also claimed an FBI breach tied to the PeopleSoft zero-day, which remains a claim.
SharePoint flaw rated spoofing is authenticated RCE
ConfirmedHighCISA KEVCVE-2026-65660
Microsoft initially classified the flaw as spoofing with a CVSS score of 6.5. Technical details from Viettel Cyber Security show authenticated remote code execution on SharePoint 2016, 2019 and Subscription Edition. CISA added it to KEV with a 28 September deadline.
Zimbra command injection exploited for web shells
ConfirmedHighCISA KEVCVE-2026-73570
Microsoft researchers found attackers using an unauthenticated OS command injection (CVSS 8.9) to deploy web shells and reach mailbox data and authentication secrets.
Zyxel, Veeam and TeamCity exploitation continues
ConfirmedHighCISA KEVCVE-2026-7273
Zyxel switch and Veeam flaws are under active exploitation with command and SYSTEM access. CISA warned that ransomware gangs now exploit a critical JetBrains TeamCity flaw patched in July.
Infrastructure and embedded platforms
Unbound DNSSEC validator heap overflow, every release before 1.26.1
ConfirmedHighCVE-2026-81642
NLnet Labs warned that an attacker who controls a malicious DNS zone can trigger remote code execution in the resolver.
FatPipe VPN appliances on end-of-life firmware
ConfirmedHighCVE-2026-90822 / 90823
CISA flagged an OS command injection and a stack buffer overflow in firmware that no longer receives updates.
Ubuntu container escape has a public exploit and no patch
ConfirmedMed-HighCVE-2026-80521
Exploit code is public for a flaw that lets a container user reach root on the host.
CISA ICS advisories: Eufy cleaners, Botslab dashcams and lwIP
ConfirmedMed-High
Advisories cover Eufy Omni robots (three critical CVEs), 14 CVEs in Botslab dashcams, and a critical lwIP MQTT client flaw (CVE-2026-87121).
05Web Platforms & Application Servers
Public-facing web software was attacked fastest, with one WordPress flaw exploited within hours of disclosure.
ConfirmedHighCISA KEVCVE-2026-87902
WordPress flaw exploited within hours of disclosure
Attackers began exploiting a CVSS 9.2 WordPress vulnerability shortly after it was disclosed. An unauthenticated attacker can cause page-template resolution to include a chosen readable local PHP file, which leads to remote code execution. A second WordPress issue, Comment2Shell (CVE-2026-93485), turns anonymous comment cross-site scripting into remote code execution through an administrator session.
WSO2 API Manager JWT bypass exploited with forged admin tokens
ConfirmedHighCISA KEVCVE-2026-5430
Attackers forge administrator tokens against WSO2 API Manager. CISA added it to KEV alongside an Adobe Commerce and Magento flaw.
Roundcube pre-auth SQL injection exploited
ConfirmedHighCVE-2026-48842
An actively exploited SQL injection in the Roundcube webmail server requires no authentication and puts mailbox data in scope.
Issabel Framework and Acronis cPanel plugin flaws exploited
ConfirmedHighCVE-2026-89026 / 87886
Attackers execute OS commands without authentication on Issabel PBX frameworks, and exploit the Acronis Backup plugin for cPanel and WHM in targeted attacks.
SolarWinds patches critical Observability and ARM flaws
ConfirmedHighCVE-2026-28324 / 28325
Two critical Observability Self-Hosted flaws can be exploited without authentication. A separate hard-coded key in Access Rights Manager (CVE-2026-28326) allows unauthenticated remote code execution.
D-Link DIR-822A zero-day has public exploit code and no patch
ConfirmedHighCVE-2026-86296
D-Link warned of a maximum-severity flaw in legacy routers. Public proof-of-concept code exists and no patch is available for the affected models.
Linux kernel: three flaws in KEV, plus an ARM64 KVM host-memory flaw
ConfirmedMed-HighCISA KEV
CISA flagged three exploited Linux kernel vulnerabilities (CVE-2025-39682 among them). A separate KVM flaw (CVE-2026-89775) lets ARM64 guests read and write host memory when nested virtualization is enabled.
06Breaches & Supply Chain
Large losses traced to a third-party product or a stolen key.
ConfirmedHighThird-Party Product
Bitget loses $388 million through a flaw in a third-party security product
Bitget said the attacker exploited a vulnerability in a security product the exchange used, obtained high-level internal credentials, and on 24 September sent fraudulent withdrawal commands to its wallet system. Earlier reporting attributed the theft to suspected North Korean actors with a figure of $351.6 million. Bitget’s own statement puts it at about $388 million, and attribution remains reported rather than confirmed.
Brevo loses a Cloudflare API key and serves ClickFix scripts
ConfirmedHigh
Attackers used the stolen key to inject malicious ClickFix scripts into Brevo’s websites and into JavaScript files embedded on customer sites. Reporting puts the exposure at about 100,000 websites.
CrowdSec confirms source code theft linked to the TanStack attack
ConfirmedHigh
CrowdSec traced the breach to the May 2026 TanStack supply-chain attack, which led to a copy of 170 private GitHub repositories.
Pentagon personnel agency breach affects 3 million people
ConfirmedHigh
The Defense Manpower Data Center maintains personnel records for the Department of Defense. Details of the access path have not been disclosed.
Times Car and Gyazo disclose large account breaches
ConfirmedHigh
Times Car confirmed about 6.6 million user accounts were compromised. Gyazo’s breach exposed 23.62 million user records and 490 million image metadata records.
Revolut breach alleged to have lasted five months
UnverifiedHigh
SecurityWeek reported that Revolut customer information was allegedly passed to hackers impersonating an Italian government agency, affecting 680 high-profile accounts with a $3 million ransom demand. This is an allegation pending company confirmation.
Malicious npm packages: 101 WhatsApp packages and a B-tree library
ConfirmedMed-High
101 npm packages added developers’ WhatsApp accounts to groups without consent. Another package, indexed-btree, hid its loader in runtime code and accumulated millions of downloads before removal.
07Nation-State & Threat Actors
Phishing-led state activity continued alongside enforcement and extortion-group action.
Nation-state & espionage activity
Star Blizzard (Russia) Microsoft reported fake event invitations delivering the RedFlick backdoor to more than 100 organizations since January, mostly in the US and UK, tied to Ukraine. The group moved away from ClickFix to widen its phishing.
UTA0565 (China-linked) Used a chained Chrome and Windows zero-day exploit through fake websites on 3 and 4 September to deliver CLEANGULP malware.
FamousSparrow (China-aligned) Deployed the SparroWocky backdoor across Latin America in an espionage campaign focused on US political topics.
Jade Sleet (North Korea-linked) Linked to a breach of an Indian IT provider using the FLATROOF and ROOFDECK backdoors.
Criminal activity & enforcement
WaterPlum (North Korea) The US, Japan, Germany and Australia published a joint report, and Japan dismantled its first North Korean laptop farm. Reporting counts about 30,000 infected devices.
ShinyHunters Bypassed PeopleSoft WAF rules, claimed an FBI breach and reportedly took over the Clop leak site. The FBI claim has not been confirmed.
Handala (Iran-linked) Tied to the HEAVYGRAM Telegram-controlled backdoor that can steal passwords.
Ryuk enforcement A US court sentenced an Armenian man for Ryuk ransomware attacks, and a Ryuk member received 24 months in prison.
08Signals & Patterns
Five patterns define the second half of September
The access layer is attacked before it is patched NetScaler, Check Point, F5, Cisco ISE and VeloCloud were all exploited as zero-days or on disclosure. Emergency patch lanes for remote-access products need to exist before the advisory arrives.
Management layers carry the widest reach SD-WAN Manager, VeloCloud Orchestrator, ISE and Check Point’s Security Management Server each administer other devices. Compromise at that layer extends to everything it controls.
Mitigations and severity labels need independent testing A URL-encoding trick defeated the PeopleSoft WAF rules, and a flaw rated as spoofing proved to be remote code execution. Compensating controls and vendor ratings both need verification.
AI incidents now move from lab disclosure to regulatory action OpenAI reported six incidents, Google confirmed three breached firms, and the FTC opened investigations. Organizations running agents need their own incident framework before a regulator asks.
Trusted vendor tools are the entry point for the largest losses Bitget’s security product, Brevo’s Cloudflare key and CrowdSec’s TanStack dependency each opened the path. Third-party access to credentials and keys deserves the same review as the organization’s own accounts.
09Defender Actions
Eight actions for the period ahead
Treat NetScaler appliances online during the exposure window as suspect Review web shells, tunnels and credential use on any NetScaler that stayed up while the zero-days were exploited, and rotate credentials that passed through it.
Pre-authorize taking remote-access devices offline Name who can disconnect a VPN or gateway appliance without a change ticket when a vendor reports exploitation.
Inventory every management layer List SD-WAN managers, orchestrators, identity services and firewall management servers, and restrict their interfaces to administrative networks.
Test WAF and compensating controls independently Verify that mitigations hold against encoding and path variations before relying on them to defer a patch.
Reassess vendor severity ratings when exploit details publish Re-evaluate any flaw whose rating changes after technical details appear, as with the SharePoint spoofing label.
Set an AI agent incident process Define what counts as an agent incident, who reviews logs and who notifies regulators, following the framework OpenAI published.
Review third-party credentials and keys Audit API keys held by security, content-delivery and backup vendors, and rotate any that vendors cannot account for.
Keep confirmed facts separate from claims Hold ShinyHunters’ FBI claim and the Revolut allegation apart from confirmed incidents until the organizations confirm them.
10Closing Note
Administrators took their NetScaler appliances offline before Citrix confirmed that anything was wrong.
That sequence, with customers detecting a problem ahead of the vendor, appeared across the period. Check Point’s management server flaw was used in July and fixed in late September. Bitget lost $388 million through a security product it trusted. OpenAI found, and then disclosed, agent behavior it had not intended.
The practical response is to make the decision to disconnect a device an ordinary, pre-authorized one, to know which management layers control the rest of the estate, and to keep a record of what your AI agents and your vendors can reach. Each of those can be set up before the next advisory.
The full technical edition, with severity tags, CVEs and defender actions, is available as a downloadable PDF at wp.me/ag5Z8Q-2Su.
About The Signal Watchtower
Published by Elytra Security. Signal-only intelligence across security, privacy and AI. Confirmed facts kept rigorously separate from claims and attacker assertions.
Authored by Venkat Mangudi · Founder & CEO, Elytra Security
Integrity. Trust. Clarity.
An ISO/IEC 27001:2022 Certified Company
