Threat Brief — 2026-09-30: TeamViewer and OpenSSL Flaws Demand Urgent Patching
Executive Summary
Two patching priorities lead today: TeamViewer is urging customers to immediately fix high-severity vulnerabilities in its client and host software, and OpenSSL has patched a DTLS flaw that can leak unencrypted heap memory across a connection. Active exploitation of the patched Citrix NetScaler vulnerability continues to evolve, with Mandiant now attributing post-exploitation activity to new tooling called WHIPSHOT and SLAPSHOT. A US-focused C-suite phishing campaign stealing Microsoft 365 sessions and deploying RMM tools, plus the exposure of over 13,000 internal developer images on GitHub via AI coding agents, round out the day's most actionable findings.
Top Items
- TeamViewer urges immediate patching of severe client and host vulnerabilities. TeamViewer disclosed a set of high-severity flaws in both its client and host products and advised customers to patch "as soon as possible." No CVE identifiers or technical exploit details were provided in the public advisory. Remote access software is a high-value target because it typically runs on both endpoints and critical infrastructure. (src: BleepingComputer)
- OpenSSL fixes high-severity DTLS flaw that can leak heap memory unencrypted. A vulnerability in OpenSSL's DTLS handshake resend logic can expose unencrypted heap memory to the remote peer or crash the process. Fixes were released on September 29. Any service relying on OpenSSL for UDP-based TLS is potentially affected. (src: The Hacker News)
- Citrix NetScaler exploitation evolves: Mandiant attributes post-exploitation to WHIPSHOT and SLAPSHOT. Unknown actors continue exploiting a patched Citrix NetScaler ADC and Gateway flaw — first reported 2026-08-17 via CISA KEV — targeting organizations in North America and Europe. Mandiant Consulting now reports attackers achieving root-level access and deploying previously undescribed post-exploitation tooling. This is a developing story with active exploitation in the wild. (src: The Hacker News)
- US-focused C-suite phishing steals Microsoft 365 sessions and deploys RMM tools. ANY.RUN researchers traced a phishing campaign across 351 sandbox analyses, with 51% of submissions from the United States. Technology, manufacturing, government, and consulting sectors showed highest exposure. Attackers steal M365 session tokens and deploy legitimate remote management tools for persistent access. (src: The Hacker News)
- AI coding agents expose over 13,000 internal images including billing records on GitHub. Security firm Glow found that AI coding agents asked to share screenshots for code review uploaded internal company images to public GitHub repositories, exposing billing records and other sensitive artifacts from developers at multiple organizations. This highlights a data-exfiltration vector inherent in AI-assisted development workflows. (src: The Hacker News)
- Mozilla audit finds 76 Firefox vulnerabilities, nearly half classified as critical. Mozilla identified 76 vulnerabilities in Firefox, with approximately half rated critical. The findings underscore the browser as a primary attack surface for enterprise access, consistent with industry analysis noting that most breaches now begin in a browser session. (src: SecurityLab)
Themes
Browser and remote-access tooling as the dominant attack surface pair. Today's findings converge on two interlocking vectors: browsers (76 Firefox vulnerabilities, M365 session token theft via phishing) and remote-access tools (TeamViewer severe flaws, RMM deployment in phishing campaigns, NetScaler exploitation). The browser is the most likely initial-access point; remote-access tooling — whether legitimate RMM or exploited vendor software — is the persistence bridge.
AI-assisted workflows as an unintentional data-exfiltration channel. The exposure of 13,000 internal images via AI coding agents is the latest in a pattern of findings showing that agentic AI tools can bypass traditional data-loss controls when granted access to internal artifacts and external publishing capabilities.
