Don’t do SECURITY. Do business SECURELY.

Threat and vulnerability round-up: week ending 4 October 2026

Citrix patches another exploited NetScaler flaw, FortiMail and Zammad zero-days are in KEV, and Star Blizzard and Warlock ransomware campaigns hit UK and European targets.

Our weekly round-up of significant threats and actively exploited vulnerabilities. It is awareness content, not a monitored threat intelligence service: always check vendor advisories against your own environment.

This week at a glance

Citrix NetScaler is under attack again: a new SAML flaw was exploited before Citrix’s advisory on Sunday, and Mandiant has described how attackers used last week’s NetScaler zero-days to plant web shells. Fortinet FortiMail and the Zammad helpdesk platform also had flaws exploited before fixes were widely available. Among campaigns, Russia’s Star Blizzard is phishing policy and events staff in the UK and Europe, Warlock ransomware is breaking into critical infrastructure through unpatched SharePoint, and European police dismantled the KillSec ransomware operation.

Actively exploited vulnerabilities

Citrix NetScaler ADC and Gateway (CVE-2026-88779)

Citrix fixed a memory overflow in NetScaler’s SAML authentication on Sunday 4 October (bulletin CTX697174, CVSS 8.7). It affects appliances configured with SAML for Gateway or AAA. NetScaler administrators and researcher Kevin Beaumont reported attacks from Thursday 1 October, before the advisory, and watchTowr has reproduced the flaw. Citrix describes it as a denial of service issue, but researchers are examining whether it allows code execution. CISA added it to its Known Exploited Vulnerabilities (KEV) catalogue on 4 October. Fix: upgrade to NetScaler ADC and Gateway 14.1-73.41 or 13.1-64.28 (14.1-73.41 FIPS, or 13.1-37.282 for NDcPP builds), then check for signs of compromise.

Source: BleepingComputer

Fortinet FortiMail (CVE-2026-104286)

As covered in our urgent alert on 2 October, a path traversal flaw in FortiMail’s Identity Based Encryption (IBE) feature lets an unauthenticated attacker write files and take over the appliance (CVSS 9.8). Fortinet’s advisory of 1 October confirmed exploitation, CISA added it to KEV the same day, and Fortinet has published indicators of compromise, including two attacker IP addresses. Fix: upgrade to FortiMail 8.0.2, 7.6.7, or 7.4.9 or later (7.2 users should move to a supported branch); until you can, disable IBE, restrict webmail and management access to trusted networks, and check for the published indicators.

Source: Fortinet PSIRT advisory FG-IR-26-175

Zammad helpdesk (CVE-2026-102489, CVE-2026-102490)

The Dutch Institute for Vulnerability Disclosure (DIVD) revealed that an automated attacker, which it describes as AI-driven, breached its network in the Netherlands on 21 September by chaining two previously unknown flaws in its self-hosted Zammad ticketing system: a session flaw that leads to remote code execution (CVE-2026-102489) and a local privilege escalation to root (CVE-2026-102490). CISA added both to KEV on 2 October. Versions 6.3.0 to 6.5.4 are exploitable. Zammad says it cannot yet verify the privilege escalation claim. Fix: upgrade self-hosted Zammad to 7.2.0 or later (or take it offline), run DIVD’s log-check script, and treat any internet-exposed 6.x instance as possibly compromised.

Source: DIVD case DIVD-2026-00015

Notable threats and campaigns

Star Blizzard phishes policy and events staff

Microsoft reports that the Russian state group Star Blizzard has added larger-scale phishing to its usual targeted approach. Fake event invitations, including lures imitating Chatham House and IISS events, deliver password-protected archives containing a virtual disk and a disguised shortcut. A technique Microsoft calls RedFlick then uses scheduled tasks to install the NOROBOT downloader and a Python backdoor. Targets include governments, diplomats, think tanks, NGOs, universities, and media, especially those supporting Ukraine, in Ukraine, the United States, the United Kingdom, and other European countries. Block VHDX and LNK files at the email gateway, warn policy and events staff about unexpected invitations with password-protected attachments, and use phishing-resistant MFA.

Source: Microsoft Threat Intelligence

Warlock ransomware enters critical infrastructure through SharePoint

Symantec reports that the Warlock ransomware group (also tracked as Storm-2603) breached a water utility, a telecoms provider, a regional government body, and a university through unpatched on-premises SharePoint servers, using the 2025 “ToolShell” flaws. It then disabled security tools with a vulnerable driver, moved through Active Directory, and staged ransomware. Victims were in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. Patch or retire on-premises SharePoint, hunt for web shells, and turn on Microsoft’s vulnerable driver blocklist.

Source: Symantec Threat Hunter Team

Mandiant details NetScaler web shell attacks

Mandiant says attackers have exploited the NetScaler zero-days in last week’s round-up (CVE-2026-88771 and CVE-2026-88772) since early September, planting a disguised PHP web shell (WHIPSHOT) and a Python tunnelling tool (SLAPSHOT) to scan internal networks and harvest credentials. Victims are in government, financial services, technology, education, and professional services in North America and Europe; reports name the United States, Germany, the Netherlands, the United Kingdom, and Switzerland. If you patched late, follow Mandiant’s hunting guidance, and if you find signs of compromise, rebuild the appliance and rotate credentials and certificates.

Source: Google Cloud (Mandiant)

Also reported this week

  • KillSec ransomware dismantled: a Europol and Eurojust-coordinated operation, with UK police taking part, led to arrests in Spain, server seizures, and the takedown of the KillSec leak site; the group is linked to almost 1,000 attacks worldwide, often through poorly secured cloud storage (The Record).
  • Disguised remote management tools: Microsoft warns that phishing lures such as meeting invites, software updates, and delivery notices install disguised MSP360 remote management software, with ScreenConnect as a backup channel, across many industries; allow only approved remote management tools (Microsoft).
  • Zimbra mail server attacks: Microsoft is tracking exploitation of CVE-2026-73570 (patched in July) to plant web shells, steal mailbox data, and send it to cloud storage; upgrade to 10.1.20 and disable zimbra-snmp notifications (Microsoft).
  • NeedyMantis backdoor: Microsoft details a modular backdoor used by the suspected China-based Storm-3069 against telecoms firms, universities, and intergovernmental organisations; the same actor was behind trojanised DAEMON Tools Lite installers earlier this year (Microsoft).
  • DirtyBlanket npm worm: nine typosquatted npm packages imitating Express and React install a Tor-based remote access trojan on Linux machines and spread using stolen SSH keys and package tokens (SafeDep).
  • RatHat Android banking trojan: spread by text message and malicious adverts, it steals banking logins and uses an AI model to rank victims by likely balance, aimed at users in Europe, Latin America, and South-East Asia (Cleafy).
  • CloudSyncD macOS backdoor: a fake Zoom installer drops a persistent backdoor that profiles the Mac and steals data; install Zoom only from official or managed sources (Jamf).
  • Self-healing WordPress backdoor: Sucuri found malware whose eight components reinstall each other within seconds, create hidden administrator accounts, and take commands through the Ethereum blockchain (Sucuri).
  • Carbonato botnet: takes over Docker hosts exposed without authentication on port 2375 and scans neighbouring networks; never expose the Docker API without TLS and authentication (The Hacker News).

Other patches worth knowing

  • Kiteworks Email Protection Gateway 9.4.1 fixes CVE-2026-54154, a maximum-severity unauthenticated code injection flaw, alongside more than 120 other fixes, following last week’s precautionary shutdown advice.
  • GitLab AI Gateway (self-hosted) 19.2.4, 19.3.2, and 19.4.1 fix CVE-2026-90970 (CVSS 9.9), which lets an authenticated user escape the prompt template sandbox and run commands.
  • Dell Container Storage Modules 1.18.0 fixes several critical flaws (DSA-2026-448), including CVE-2026-63688 and CVE-2026-63692 (CVSS 10.0); rotate JWT signing secrets after upgrading.

Practical steps to consider

  • Keep an inventory of internet-facing appliances such as VPNs, email gateways, and application delivery controllers, and patch actively exploited flaws within days, in line with ISO/IEC 27001 control A.8.8 and the Cyber Essentials 14-day rule for high and critical updates.
  • After patching an exploited edge device, check it for compromise: patching does not remove web shells, new accounts, or stolen credentials. Use published indicators as part of your threat intelligence process under control A.5.7.
  • Limit remote management tools and unknown software with application allow-listing, and give staff likely to be targeted, such as policy, events, and executive teams, phishing-resistant MFA.

This round-up is for general awareness only and is not a monitored threat intelligence service. If you would like help reviewing your vulnerability management or incident readiness, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with a link to our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights