Threat Brief — 2026-09-28 — Citrix zero-days under exploit deadline
Two actively exploited Citrix NetScaler zero-days now carry a federal remediation deadline. A novel cross-ecosystem worm simultaneously targeting npm and PyPI represents a new supply-chain attack pattern. Reuters has confirmed the authenticity of leaked FBI employee files, and Belgium's national research network disclosed a two-month email interception breach.
Top items
- CISA orders federal agencies to patch Citrix NetScaler zero-days by Wednesday. Two critical NetScaler vulnerabilities are under active exploitation; CISA has issued a binding directive with a mid-week remediation deadline. This is a developing story first reported 2026-09-27 by The Hacker News covering unpatched Citrix NetScaler RCE zero-days; the new development is the formal CISA order with a specific deadline. (src: BleepingComputer)
- Cross-ecosystem worm simultaneously hijacks npm and PyPI packages. A single malicious worm propagates across both npm and PyPI registries, activating on code execution rather than package installation — a departure from typical dependency-confusion or typosquatting patterns. This is a new story first reported today. (src: SecurityLab)
- Reuters confirms authenticity of leaked FBI employee files including medical and psychiatric records. Leaked files range from ECGs to psychiatric evaluations, confirming the sensitivity of data exfiltrated in the breach attributed to ShinyHunters via a PeopleSoft zero-day. The intrusion vector into the bureau's HR infrastructure remains unidentified. This is a developing story first reported 2026-09-22 by BleepingComputer; the new development is Reuters independently confirming file authenticity and revealing the scope of sensitive personal data. (src: SecurityLab)
- Belgian national research network Belnet disclosed two-month email interception. Attackers silently copied all incoming email at Belnet for approximately two months, exfiltrating data through a previously unknown vulnerability that was discovered during investigation. This is a new story first reported today. (src: SecurityLab)
- Roskomnadzor instructs operators to check MikroTik routers amid six actively exploited RouterOS vulnerabilities. Russia's telecommunications regulator has directed ISPs to audit MikroTik routers in their networks and at customer premises, citing six fresh vulnerabilities in RouterOS that are already being exploited. This is a developing story first reported 2026-09-04 by SecurityLab; the new development is the formal regulatory directive to operators encompassing both ISP infrastructure and subscriber devices. (src: Xakep)
- OpenAI agents accidentally uploaded user-provided images to third-party sites. AI agents exposed user images to external services, with the full scale only becoming apparent after retrospective log review. This is a developing story first reported 2026-09-26 by BleepingComputer; it has not been previously featured in this brief. (src: SecurityLab)
- Bitget resumes Bitcoin withdrawals after suspected North Korean $387.5M heist. The exchange has restored Bitcoin withdrawal functionality after suspending operations following the breach attributed to North Korean actors. This is a developing story first reported 2026-09-25 by SecurityLab; the new development is the resumption of withdrawals, indicating partial operational recovery. (src: BleepingComputer)
Themes
Active exploitation pressure is mounting across edge infrastructure. Citrix NetScaler zero-days under active attack with a federal deadline, six exploited MikroTik RouterOS flaws prompting regulatory action, and a two-month Belnet email interception all point to persistent targeting of perimeter and network-layer systems.
AI agent data leakage persists as an emergent risk. The OpenAI agent image-leak disclosure adds to a growing pattern of AI assistants inadvertently exposing user data to third parties, reinforcing that agentic AI systems remain an under-controlled attack surface.
Supply-chain worms are evolving beyond single ecosystems. The npm/PyPI cross-ecosystem worm demonstrates that attackers are building propagation mechanisms that transcend individual package registries, potentially complicating traditional per-ecosystem monitoring.
