Security Digest 035, audio
Listen to the audio version of this digest, voiced by Brian.
This Week in Brief
Issue 035 covers weeks 39 and 40, 24 through 30 September, picking up where issue 034 left off on 23 September. A few items below happened shortly before the window and are carried in because they moved during it; the text says so each time. Four stories define the week. Citrix disclosed two critical NetScaler zero-days that attackers had been using for weeks, and Norway’s NSM warned the same day. Dutch police announced an arrest connected to ShinyHunters, though the group denies the man is a member and nothing public ties him to the FBI breach it claims. Microsoft published the anatomy of an Azure wipe that took about seven minutes and was stopped only where resource locks were in place. And the Storting’s open Epstein hearing began on 30 September with eleven current and former ministers called to appear.
The EU’s AI Act did not reach its high-risk milestone on 2 August as first scheduled. A digital omnibus regulation changed that, and it is covered under Regulatory.
Security
Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) were exploited for weeks before the patch
Citrix disclosed two critical NetScaler ADC and Gateway vulnerabilities on 27 September in an eight-vulnerability bulletin, CTX697096. CVE-2026-88771, CVSS 9.5, is an unauthenticated remote code execution flaw caused by an input-validation error, affecting default configurations. CVE-2026-88772, also CVSS 9.5, is a DTLS memory overflow in VPN servers with DTLS enabled by default. Affected versions are ADC and Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23. Both were exploited as zero-days. Google’s Threat Intelligence Group says the CVE-2026-88772 campaign has run since at least early September, eSentire places exploitation of CVE-2026-88771 in early September too, and Rapid7 saw its earliest attempts on 20 September. A web shell reported in the campaign sits at /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver, has no .php extension and runs as PHP. Cybernews, citing ShadowServer, counts more than 20,000 exposed servers. CISA added both CVEs to its Known Exploited Vulnerabilities catalogue the same day, with a federal civilian deadline of 30 September. NSM published its own advisory on 27 September, “Aktivt utnyttelse av kritiske sårbarheter i Citrix NetScaler”, confirming active exploitation. It is NSM’s second NetScaler advisory in about five weeks; the 20 August alert covered different CVEs.
Operational read: patching closes the hole and does nothing about a shell already planted. Anything internet-facing that ran an affected build since early September should be handled as a possible compromise. Preserve logs and a disk image before the patch or a reboot, hunt for the web shell path above, then rotate credentials that passed through the appliance and revoke active sessions.
ShinyHunters, PeopleSoft and a Dutch arrest
Attackers exploiting CVE-2026-35273, CVSS 9.8, in Oracle PeopleSoft bypass web application firewalls by URL-encoding the path /PSEMHUB/ as /%50SEMHUB/: the WAF inspects the literal path while WebLogic decodes and routes it anyway. Google and Mandiant attribute the campaign to UNC6240, which drops JSP web shells and a C++ backdoor named SIDEEYE through a trojanized installer, per The Hacker News and SecurityWeek.
Separately, ShinyHunters claims to have breached the FBI’s applicant portal, FBIJobs.gov. The FBI acknowledged a cybersecurity incident on 23 September, and the New York Times reported on 28 September on an internal FBI email about it. The data types usually listed, which include names, addresses, badge numbers and medical fitness records, are the group’s claims as relayed by the BBC, and the FBI has not confirmed scope. On 29 September Dutch police announced that a 24-year-old man from Amsterdam had been arrested on 15 September on suspicion of involvement with ShinyHunters. Nothing public ties him to the FBI claim, the group denies that he is a member, and he is in 90-day detention; police also allege a murder plot, which is an allegation and not a finding.
Operational read: PeopleSoft shops should not file this under the Oracle EBS and Clop story from earlier issues. It is a separate WAF-bypass technique that will work anywhere a WAF and its application server disagree on URL decoding, so check decode order as well as patch level.
On 25 September Microsoft published its analysis of Storm-3168, tracked alongside the JADEPUFFER campaign. Using two compromised service principals, the actor attempted to delete more than 100 Azure storage accounts and most deletions succeeded, along with a Key Vault, a Function App and an App Service plan, in about seven minutes. Azure resource locks and deletion protection stopped several. Microsoft found no ransom note and has not established that an AI agent controlled the deletions, though Sysdig describes JADEPUFFER as AI-driven. The credentials had leaked on a public GitHub repository.
Australia’s Senate AI inquiry invited the chief executives of OpenAI and Anthropic to a 1 October hearing on an AI-agent breach of Australian government systems, which happened on 18 June and was announced on 24 September. Both declined on 28 September, per the Guardian and Reuters. OpenAI has pointed to an existing $1 billion fund for defensive work. Separately, the group LASST sued OpenAI on 29 September over a July incident in which its agents chained eight to nine zero-days in Artifactory, per Axios.
Bitget’s CEO and the analytics firms Elliptic and TRM link the 24 September hot-wallet compromise, revised from $351.6 million to $387.5 million, to North Korean actors, while Mandiant and SlowMist are still investigating. Stolen stablecoins were swapped for ETH within minutes to dodge freezes; Circle froze about $318,000 on 25 September, a figure later reported near $1.1 million.
Apple shipped iOS and iPadOS 26.7.1 on 28 September fixing CVE-2026-86950, a CoreGraphics flaw reported by Meta’s security team and used in what Apple called extremely sophisticated attacks against specific individuals. SlowMist’s CISO says a variant may be linked to cryptocurrency-wallet theft.
MedImpact, a US pharmacy-benefit manager, mailed breach notifications on 25 September, about eleven months after it detected a Qilin ransomware intrusion on 18 October 2025; it has not disclosed how many people are affected. Singapore’s Simba disclosed on 25 September that 23,549 customers’ IC numbers and birth dates were exposed. Japan’s Times Car and Park24 disclosed on 28 September that 6.6 million accounts, including driver’s-licence images, were exposed.
Norway and the Nordics
Carried in: Stortinget went dark on 14 September
Russian hackers claimed a DDoS that took the Norwegian Parliament’s website offline on 14 September. The same day, Tõnis Saar, director of NATO’s Cooperative Cyber Defence Centre of Excellence in Tallinn, told Aftenposten “we are at war”. Both sit before this window and are carried because the political fallout ran through it. Saar’s remark is one interview and should be read as a warning and not as a finding.
Operational read: a parliament’s website going dark is low-consequence on its own. Expect the same pressure on other Norwegian public-sector domains through the autumn, and check DDoS mitigation and log retention on government-adjacent infrastructure now.
Denmark’s intelligence service assessed on 24 September a low but growing risk of limited Russian strikes on NATO states bordering Russia. Carried in from 14 and 15 September: Denmark summoned Russia’s ambassador and Prime Minister Mette Frederiksen called Russia’s pattern increasingly aggressive. Finnish and Swedish jets jointly intercepted Russian aircraft over the Gulf of Finland on 25 September, the first such joint intercept between the two.
Carried in from 10 September: Reuters reported continued Russian probing around Svalbard, including suspected surveillance of undersea cables.
Nkom announced on 24 September a notice of decision (varsel om vedtak) that six former BankID issuers, Bankenes ID-tjeneste, Danske Bank, DNB Bank, Eika Gruppen, Nordea and SpareBank 1, had not met the requirements for the high security level, because code tokens were sent without physical identity verification. It is a notice and not a final decision. Stø, which now issues BankID, is not covered, and Nkom says BankID users see no consequence.
Metavision, the system Northern Norway’s hospitals use for medication and vitals documentation, has been disrupted since 21 September. UNN says no mis-medication was confirmed but could not rule it out, and Altaposten reported that nothing pointed to a cyberattack.
A routine Telenor network update on 29 September left about 20,000 customers, all on iPhone or iPad, with “Ingen tjeneste”. Telenor told them to order a free eSIM in the Mitt Telenor app, or collect a physical SIM in a store, per VG and TV2.
Regulatory and Policy
The EU AI Act timetable changed. Regulation (EU) 2026/1744, the digital omnibus on AI, was published on 24 July and entered into force on 27 July. It moves the Annex III high-risk obligations to 2 December 2027 and the Annex I product-embedded obligations to 2 August 2028. Article 50 transparency obligations apply from 2 August, with a grace period to 2 December 2026 for marking by systems already on the market. For anyone who planned around 2 August, the high-risk deadline is more than a year later.
Norway’s NVE gave Nscale a notice of coercive fines (varsel om tvangsmulkt) for starting construction of its Narvik data centre at Kvandal without the legally required analysis of excess-heat use. NVE wants the analysis by 15 November. Nscale says it has been in dialogue with NVE and questions the notice, per NRK and Aftenposten. Separately, the Financial Times reported that ByteDance has access to 2,304 Nvidia B200 chips through Nscale, a route that sits in a gap in the export rules and does not break sanctions. NVE’s notice has no connection to that reporting.
Forbrukertilsynet, the Consumer Authority, fined influencers Sara Emilie Tandberg NOK 500,000 and Tonje Frigstad NOK 120,000 for undisclosed advertising, after an inspection of 28 influencers; Tandberg appealed within the deadline and Frigstad after it, per NRK and Nettavisen. The authority points to its existing ceiling of NOK 25 million, or 4 percent of annual turnover, for repeat or significant violations. The cases involve products shown in personal everyday settings with no clear marking.
Scams and Consumer Protection
Five men in their 20s were sentenced on 29 September to between 2 years 9 months and 6 years 10 months for 180 serious frauds and about 100,000 attempts, per TV2, NRK and Aftenposten. They texted people while impersonating the police, the Tax Administration and Altinn, linking to fake sites that harvested ID numbers and passwords, and then phoned victims. Most victims were elderly and lived in Østlandet; the value of completed and attempted fraud exceeded NOK 60 million. Police describe a network of about 100 people with spammers, callers and money launderers, and call it probably the largest digital mass-fraud case tried in Norway.
Epstein
Presumption of innocence applies to every individual named below. Hearing, testimony and document-release items are procedural facts, not findings of wrongdoing.
The Storting’s control and constitutional committee opened its public hearing on 30 September, continuing on 1 October, on control and culture in the foreign service, with eleven current and former foreign and development ministers called, per Stortinget and TV2. Thorbjørn Jagland is not among those called. Børge Brende, who resigned as head of the World Economic Forum on 26 February after the document release, is among them as a former foreign minister, per Dagbladet.
Finansavisen reported on 24 September that Elden Advokatfirma holds two mortgages of NOK 1 million each, registered on 27 February and 7 April, in Terje Rød-Larsen’s half-share of the Frogner apartment, securing fee claims. That is a civil financial arrangement and has no bearing on any criminal question. Økokrim found boxes of Oslo Process documents in the storage room used by Rød-Larsen and Mona Juul on 9 February, and the National Archives collected five more boxes in March, per Nettavisen and NRK. The Foreign Ministry now wants to release further Oslo documents, per Aftenposten and Dagens Næringsliv.
Conflicts
ArcelorMittal suspended operations at its Kryvyi Rih plant indefinitely on 25 September, after four direct missile strikes in five weeks that killed five workers, the latest on 21 September. Putin signed a decree on 28 September raising the active military to 1,550,500, an increase of 15,500 and the fourth such decree this year. Zelensky warned that Russia is preparing to deploy 10,000 more North Korean troops, a Ukrainian claim not independently confirmed.
Trump rejected Iran’s proposal to reopen the Strait of Hormuz within seven days on 26 September, per Al Jazeera. Brent rose more than 3 percent to near $108 a barrel on 28 September.
In Ethiopia, the TPLF and six allied factions formed the Ethiopian Peoples’ Forces Alliance for Survival. Government forces say they recaptured Alamata on 28 September, and the military chief accused Eritrea, Sudan and Egypt of backing the rebels, a claim made without public evidence.
By the Numbers
| Figure | Context |
|---|---|
| 9.5 | CVSS score for both new Citrix NetScaler CVEs |
| 20,000+ | NetScaler servers exposed, per ShadowServer figures via Cybernews |
| 9.8 | CVSS score, Oracle PeopleSoft CVE-2026-35273 |
| $387.5M | Revised Bitget loss; North Korean link alleged, investigation ongoing |
| 100+ | Azure storage accounts targeted by Storm-3168 in about seven minutes |
| 90 days | Detention ordered for the Dutch ShinyHunters suspect |
| 6.6M | Accounts exposed in the Times Car and Park24 breach, Japan |
| 23,549 | Simba customers affected, Singapore |
| 2 x NOK 1M | Elden mortgages in Rød-Larsen’s half-share of the apartment |
| NOK 500k / 120k | Forbrukertilsynet’s two influencer fines |
| 180 / ~100,000 | Completed and attempted frauds in the Østlandet SMS conviction |
| 11 | Current and former ministers called to the Storting Epstein hearing |
What to Do This Week
- Patch NetScaler ADC and Gateway to 14.1-73.37 or 13.1-64.23 or later, but treat patching as the second step. If an affected build was internet-facing at any point since early September, preserve logs and a disk image first, hunt for the web shell path above, rotate credentials that passed through the appliance, and revoke active sessions.
- Running Oracle PeopleSoft: check WAF decode-order handling against the /%50SEMHUB/ bypass, not just patch level for CVE-2026-35273.
- Audit Azure service-principal credentials, remove any that have ever touched a public repository, and confirm resource locks and deletion protection on critical storage accounts and Key Vaults, including backup and Site Recovery locks.
- Update iOS and iPadOS to 26.7.1 for the CoreGraphics fix, particularly on devices that hold crypto wallets.
- Nkom’s notice names six former BankID issuers. No user action is required, and BankID through Stø is unaffected.
- MedImpact plan members should watch for the delayed notification and read it for which data categories were affected before deciding on a credit freeze.
- Treat any text or call claiming to be from the police, the Tax Administration or Altinn, especially one with a link, as fraud. Open the service yourself and do not use the link.
Sources cited in the text above: SecurityWeek, The Hacker News, Cybernews, NSM, Google Threat Intelligence Group, Rapid7, eSentire, Mandiant, Microsoft, Sysdig, the New York Times, the BBC, the Guardian, Reuters, Axios, Al Jazeera, Aftenposten, VG, NRK, TV2, Nettavisen, Dagbladet, Dagens Næringsliv, Finansavisen, Altaposten, Stortinget, Nkom, NVE and the Financial Times. Single-source and contested claims are marked in the text. Presumption of innocence applies throughout the Epstein coverage. Compiled for FTRCRP under the editorial responsibility of Thomas A. Kleppestø.
Issue 035, weeks 39 and 40, 1 October 2026