Cyber Briefing, Sep 28: Citrix NetScaler CVEs exploited, SharePoint flaw weaponized

Graphic representing cybersecurity news, featuring a shield with a lock, a laptop, various icons including envelopes and a magnifying glass, set against a digital background.

11 stories · 5 sources · 3 critical · 2 high · ~12 min read

Coverage: Last 72 hours

Today’s Highlights

Widespread exploitation of Citrix NetScaler ADC/Gateway and Microsoft SharePoint vulnerabilities demonstrates the urgent risk to exposed edge infrastructure and collaboration platforms. Attackers are also evolving by abusing service principals for destructive actions in cloud environments, and new attack techniques against AI and legacy cryptography are raising the stakes for defenders. These themes demand action on patching, credential and privilege auditing, and reassessment of technical and policy controls across business-critical systems, with Citrix NetScaler, SharePoint, and Oracle PeopleSoft among the highest priorities.

Table of Contents

  1. Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability
  2. DC Health Agency Exposes 400,000 Beneficiary Records
  3. CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
  4. Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug
  5. Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
  6. JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

Critical   High   Medium   Low

Top Stories


Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability

Source: SecurityWeek | Published: Sep 28 | Risk: HIGH | Impacted: Kiteworks customers, Organizations exchanging confidential data via managed file transfer | Topics: Vulnerability / Threat Intel

What happened: The company says the measure was precautionary and that it has no evidence of Kiteworks or customer systems being compromised. The post Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability appeared first on SecurityWeek.

Why it matters: Precautionary shutdowns of secure file transfer platforms due to advanced vulnerabilities can disrupt critical business processes and put sensitive content at risk until full mitigation is confirmed.

How it works: Kiteworks provides managed file transfer and secure forms services for sensitive business communication. Vulnerabilities in advanced forms functionality can allow unauthorized access or manipulation of sensitive content stored or routed through the service.

Practitioner Perspective

Kiteworks users are facing operational outages due to a yet-unfixed advanced forms vulnerability. Even though active exploitation has not been confirmed, adversaries specifically target secure file transfer and content collaboration platforms for high-value data. Relying on downtime alone is not a viable defense: defenders must segment exposed infrastructure, review forms/workflow configurations, and monitor for signs of attempted access or unexplained activity. The key point is this: extended downtime creates friction for business, but the risk of data leak or lateral movement in file transfer environments justifies aggressive action.

Recommended Actions

  • Follow vendor guidance for immediate Kiteworks server shutdown as a precautionary measure
  • Review advanced forms and workflow configurations for signs of past or ongoing compromise

DC Health Agency Exposes 400,000 Beneficiary Records

Source: SecurityWeek | Published: Sep 28 | Risk: MEDIUM | Impacted: State health agencies, Medicaid administrators, Public web reporting platforms | Topics: Vulnerability / Threat Intel

What happened: The District of Columbia Department of Health Care Finance (DHCF) notified nearly 400,000 Medicaid and DC Healthcare Alliance beneficiaries that their personal information was potentially exposed due to a data breach. The incident occurred when two reports on DHCF’s website, intended to display summary information, inadvertently contained underlying personal data accessible to unauthorized users between 2023 and July 2026. The exposed information included Medicaid IDs, provider names, dates of birth, race, gender, ethnicity, and ward, but did not include Social Security numbers, names, or financial information. DHCF stated that it has no reason to believe anyone misused the information but advised affected individuals to remain vigilant against identity theft and fraud attempts.

Why it matters: Incidents where sensitive attributes are unintentionally exposed through public resources can trigger regulatory scrutiny, legal response, and reputational damage, even if classic identifiers like names or SSNs are not included. Downstream, this enables targeted phishing and social engineering against affected populations.

How it works: Web reporting tools often export summary or aggregated data, but underlying exported files or hidden report fields can inadvertently include direct identifiers or sensitive attributes if misconfigured or insufficiently redacted.

Practitioner Perspective

Health sector defenders must treat every public reporting or analytics interface as a potential data leak vector, not just obvious database exports. The fact that summary reports revealed granular PII highlights a persistent control gap between what the business intends to expose and actual content. Teams should re-audit report generation workflows and validate with test users, including using web scraping techniques, what is truly rendered to anonymous visitors. Assume motivated adversaries seek fringe PII combinations to conduct phishing or influence operations. Attackers will weaponize even partial identity elements if they inform targeting or social engineering.

Recommended Actions

  • Perform periodic data inventory scans on all public-facing reporting interfaces on DHCF and similar platforms
  • Implement automated bleed-through checks to validate that summary reports don’t expose underlying PII fields

Exploits & CVEs


CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

Source: The Hacker News | Published: Sep 28 | Risk: CRITICAL | Impacted: Organizations with perimeter NetScaler ADC/Gateway appliances, Users of Citrix remote access infrastructure, Network and IT operations with legacy Citrix deployments | Topics: Vulnerability / Cloud

What happened: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerabilities are listed below – CVE-2026-88771 (CVSS score: 9.5) – An improper input validation vulnerability that could allow an unauthenticated attacker to

Why it matters: Active exploitation of critical Citrix NetScaler vulnerabilities means that attackers can break perimeter defenses globally, potentially compromising VPN credentials and enabling mass access to corporate environments.

How it works: Citrix NetScaler ADC and Gateway are edge appliances supporting VPN and application access. CVE-2026-88771 (CVSS 9.5) and CVE-2026-88772 are remote input validation vulnerabilities allowing attackers to run code and bypass perimeter controls if left unpatched.

Affected / Fix: Patches released; CISA mandates patching

Practitioner Perspective

CISA’s addition of CVE-2026-88771 and CVE-2026-88772 to the KEV catalog is a signal: defenders should operate under breach until all externally accessible NetScaler hosts are fully patched and scrutinized. These flaws enable unauthenticated compromise and are being exploited worldwide, making delay unacceptable. Timelines for remediation should shrink from days to hours in high-risk sectors. Monitor for anomalous authentication, lateral movement, and web shell deployment. The risk window remains open for any lagging patch cycle.

Recommended Actions

  • Patch all Citrix NetScaler ADC and Gateway appliances against CVE-2026-88771 and CVE-2026-88772 immediately
  • Check for indicators of compromise (e.g., web shells, new accounts) on all interfaces exposed pre-patching

Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug

Source: SecurityWeek | Published: Sep 28 | Risk: CRITICAL | Impacted: Enterprise IT environments using NetScaler, Remote workers accessing via Citrix Gateway, Managed service providers supporting Citrix appliances | Topics: Vulnerability / Exploit

What happened: Citrix has released patches for the critical NetScaler vulnerabilities tracked as CVE-2026-88771 and CVE-2026-88772. The post Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug appeared first on SecurityWeek.

Why it matters: Unpatched Citrix NetScaler ADC and Gateway instances are now primary targets for attackers exploiting zero-days to gain footholds in enterprise networks, resulting in supply-chain and ransomware risk for organizations relying on these appliances for remote access.

How it works: Citrix NetScaler ADC and Gateway appliances deliver load balancing and remote access for corporate infrastructure. These two zero-day vulnerabilities allow unauthenticated attackers to exploit input validation bugs, bypassing upstream controls to run code or pivot into internal networks.

Affected / Fix: Patches released for affected NetScaler appliances

Practitioner Perspective

With confirmed exploitation of CVE-2026-88771 and CVE-2026-88772, defenders must treat all exposed NetScaler edge devices as already compromised unless full patching and forensic review are complete. These appliances often serve as primary ingress to internal networks, so compromise can enable lateral movement and credential theft. Security teams must not assume web application firewall layering is an effective compensating control, these flaws are being actively bypassed. Immediate update and post-exploit analysis are mandatory. Expect follow-on attacks targeting downstream resources if these zero-days are left unresolved.

Recommended Actions

  • Deploy patches for CVE-2026-88771 and CVE-2026-88772 on all Citrix NetScaler ADC and Gateway appliances
  • Perform retrospective forensic analysis of exposed NetScaler devices for signs of exploitation or credential extraction

Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

Source: SecurityWeek | Published: Sep 27 | Risk: CRITICAL | Impacted: Microsoft SharePoint Server operators, Large enterprise intranets, Federal and regulated sector SharePoint users | Topics: Vulnerability / Exploit

What happened: CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28. The post Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks appeared first on SecurityWeek.

Why it matters: Rapid weaponization of a new SharePoint vulnerability gives attackers direct access to internal collaboration data, exposing sensitive files and potentially enabling lateral movement or impersonation attacks in targeted organizations.

How it works: Microsoft SharePoint is a collaboration and document management platform widely used within enterprises. CVE-2026-65660 (CVSS not provided) is a vulnerability now under active attack, leveraging weaknesses in SharePoint’s web-accessible protocols to access or manipulate organizational content.

Affected / Fix: CISA mandates immediate patching of all affected SharePoint servers

Practitioner Perspective

SharePoint is often broadly accessible and trusted internally, so new exploits like CVE-2026-65660 are magnets for mass scanning and automated attacks. Exploited weaknesses may allow adversaries to extract sensitive project documents and search for credentials or pivot to other internal assets. Delayed patching means any externally accessible SharePoint instance is a likely candidate for compromise, particularly in organizations subject to CISA directives. Treat this vulnerability as a high-confidence gateway for data loss and follow-on attacks. The key action: patch must be prioritized above all other IT maintenance actions this week.

Recommended Actions

  • Deploy patches for CVE-2026-65660 to all Microsoft SharePoint servers, prioritizing instances with external exposure
  • Search for indicators of compromise, such as anomalous user activity or access to restricted SharePoint sites, since initial public exploit

Emerging Signals


JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

Source: The Hacker News | Published: Sep 28 | Risk: HIGH | Impacted: Azure tenants using service principals, Cloud automation and DevOps teams, Organizations with limited privilege separation in cloud IAM | Topics: Vulnerability / Cloud

What happened: The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor’s tradecraft. The attack took place in early June 2026 over a period of about 18 hours. “The destructive operations

Why it matters: The abuse of Azure service principals for destructive operations creates a new category of cloud risk: attackers can persist and cause operational outages even when privileged user accounts are locked down.

How it works: Service principals in Microsoft Azure are non-human identities granting limited (or sometimes excessive) privileges to automation or application code. Compromising these identities allows attackers to operate inside the cloud platform, even executing destructive actions, outside traditional user account controls.

Practitioner Perspective

Cloud environments built on Azure AD often under-prioritize auditing of non-human identities like service principals. The JADEPUFFER group’s evolution, using these service principals to delete resources, means that attackers now target automation credentials as a path to maximum impact. Defenders must treat automation identities with at least the same vigilance as key administrative accounts, right down to subscription-scoped privileges. This episode should prompt a wholesale re-evaluation of how cloud automation and managed identities are monitored, rotated, and, crucially, limited in scope. Assume attackers have mapped cloud IAM to find any privilege delta between human and service principal accounts.

Recommended Actions

  • Audit Azure Active Directory for service principals with broad permissions or resource-delete privileges
  • Monitor Microsoft Storm-3168 and JADEPUFFER TTPs to detect destructive patterns in cloud activity logs

Also Today

Defensive Actions

  • Patch Citrix NetScaler ADC and Gateway appliances against CVE-2026-88771 (CVSS 9.5) and CVE-2026-88772 immediately.
  • Patch all Microsoft SharePoint servers to remediate CVE-2026-65660 and investigate for any signs of compromise since public disclosure.
  • Inventory and restrict permissions of all Azure service principals, particularly those with delete or administration privileges.
  • Monitor for indicators of compromise on all Citrix and SharePoint edge appliances, and reissue VPN credentials if exploit activity is detected.
  • Review data exposure controls and automated bleed-through checks for public web reporting interfaces.
  • Enforce least-privilege on third-party app API access and regularly review OAuth and API permissions for privacy compliance.
  • Follow vendor instructions to shut down Kiteworks servers until vulnerabilities are mitigated, and monitor for related suspicious activity.
  • Hunt for web shell persistence and out-of-band activity on Oracle PeopleSoft, regardless of WAF status, and apply patches for CVE-2026-35273.

What We’re Watching

  • Broader exploitation and potential malware deployment via CVE-2026-88771 and CVE-2026-88772 in Citrix NetScaler across all regions; continued monitoring for new TTPs.
  • Emergent exploitation of Microsoft SharePoint CVE-2026-65660 and public release of automated exploit chains.
  • Follow-on attacks leveraging ShinyHunters’ established web shells in Oracle PeopleSoft environments, bypassing common defenses.
  • New offensive tradecraft from groups like JADEPUFFER (Storm-3168) targeting cloud automation identities and service principals.
  • Policy and technical fallout from high-profile AI abuses, including OpenAI re-training suspension and new containment architectures from Nvidia.

Found this briefing useful? Follow the blog to get the next one as soon as it is published, and pass it along to a colleague who owns patching.



Categories: Cybersecurity Blog, Cybersecurity News

Tags: , , , , , , ,

Leave a Reply

Discover more from TECHMANIACS.com

Subscribe now to keep reading and get access to the full archive.

Continue reading