Close Menu
  • Threat Intelligence
    • Cyber Attacks & Exploits
    • Data Breaches
    • Malware Analysis
  • Security Tools
    • Cybersecurity Tool Reviews
    • Cybersecurity Tools
    • Top 10 Security Tools
  • News & Updates
    • Cybersecurity Weekly Report
    • Industry Updates
  • Endpoint & System Security
  • Mobile Security
  • Cyber Insurance
  • Cyber law & Compliance
X (Twitter) LinkedIn WhatsApp
Trending
  • Cybersecurity Weekly Report: September 21–27, 2026
  • Carbonato Malware: A Dangerous AI Agent Attack on Docker
  • Zyxel GS1900 CVE-2026-7273: Hackers Exploit Switches in 48 Countries
  • CrowdSec Breach: 170 Repos Stolen in Supply-Chain Attack 2026
  • Cybersecurity Weekly Report: Sept 14-20, 2026 – AI & Ransomware
  • CVE-2026-76460: Critical Cisco ISE Bypass Exploited Now
  • Revolut Data Breach 2026: What Happened, What Leaked, and How to Prevent It
  • Cyber Resilience Act Reporting: 24-Hour Deadline Guide 2026
Monday, September 28
Cyber infos
X (Twitter) LinkedIn WhatsApp
  • Threat Intelligence
    • Cyber Attacks & Exploits
    • Data Breaches
    • Malware Analysis
  • Security Tools
    • Cybersecurity Tool Reviews
    • Cybersecurity Tools
    • Top 10 Security Tools
  • News & Updates
    • Cybersecurity Weekly Report
    • Industry Updates
  • Endpoint & System Security
  • Mobile Security
  • Cyber Insurance
  • Cyber law & Compliance
Cyber infos
Home » Cybersecurity Weekly Report » Cybersecurity Weekly Report: September 21–27, 2026
Cybersecurity Weekly Report

Cybersecurity Weekly Report: September 21–27, 2026

V DiwaharBy V DiwaharSeptember 28, 2026No Comments14 Mins Read
Facebook Twitter Pinterest LinkedIn WhatsApp Copy Link
Share
Facebook Twitter Pinterest Threads Copy Link

This cybersecurity weekly report covers one of the more consequential seven day stretches of the quarter. A $351.6 million crypto exchange breach. Two unpatched Citrix NetScaler zero-days under active exploitation with no vendor fix in sight. A wave of new CISA Known Exploited Vulnerabilities additions touching WSO2, Adobe Commerce, Microsoft SharePoint, and MikroTik RouterOS.

There’s a lot of cybersecurity news this week worth slowing down for, especially at the network edge, and the cybersecurity threats this week ranged from crypto exchange backend compromises to AI agents turned against their own users.

Underneath those headlines sits a quieter but arguably more instructive story. A set of Salesforce Agentforce flaws showed how prompt injection can turn a trusted AI agent into a data exfiltration channel, and Cisco Talos documented the first publicly known malware sample that lets a panel of large language models vote on its next move. This edition of our weekly cybersecurity news coverage arrives amid a genuinely unusual stretch for edge infrastructure specifically.

Drawing on CyberInfos’ internal threat tracking framework, this week’s global threat posture sits at Level 3 (Elevated). That’s not driven by any single incident so much as by the sheer number of internet facing edge devices, NetScaler, Roundcube, SharePoint, now sitting in active exploitation windows at the same time.

Table of Contents hide
1 Major Incidents in Cybersecurity News This Week
2 New Vulnerabilities & Patches
3 Ransomware Activity
4 Threat Intelligence
5 Industry News
6 Tool Updates
7 Looking Ahead

Major Incidents in Cybersecurity News This Week

Among the cybersecurity incidents this week, three stood out for scale, novelty, or the pattern they represent.

1. Bitget – Cryptocurrency Exchange

Cybersecurity weekly report timeline of Bitget's $351.6M breach across BNB Chain, THORChain, XRP Ledger, and Bitcoin
Bitget’s $351.6 million in stolen funds moved across four blockchains within hours of the 18:31 UTC detection.

Bitget detected unauthorized transfers from its hot and warm wallets at 18:31 UTC on September 24. By the time the exchange’s security team got it fully contained, roughly $351.6 million had moved out across seven blockchains. An internal wallet infrastructure component was compromised; spoofed transaction data was then fed into the exchange’s own approval process, so funds left as if the payouts were routine.

Cold storage was reportedly untouched. CEO Gracy Chen said the exchange’s $464 million plus User Protection Fund would cover the loss. Blockchain forensics firm TRM Labs tagged exploiter addresses and traced funds across BNB Chain, THORChain, the XRP Ledger, and Bitcoin. Bitget itself called North Korean involvement “very likely,” based on IP addresses linked to VPN services associated with a North Korean hacking group. Withdrawals remain paused. Deposits and trading continue. [Read More]

ANALYST INSIGHT: This isn’t a stolen key incident. It’s a backend authorization compromise, and that’s a materially different threat model. Exchanges that only monitor for anomalous signing keys will miss an attacker who has learned to forge legitimate looking transfer requests inside the approval pipeline itself.

2. Citrix NetScaler ADC and Gateway: Unpatched Zero-Days

Security firm watchTowr disclosed on September 26 that two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances, both allowing remote code execution, are being actively exploited in the wild. Citrix has yet to confirm the flaws or publish a fix.

These are distinct from CVE-2026-19490, the authentication bypass Citrix patched on August 19 and CISA added to its KEV catalog on September 9.

Some administrators have simply taken appliances offline rather than wait, given that NetScaler devices sit at the network edge handling VPN, load balancing, and authentication. Here’s the harder problem: because exploitation reportedly preceded any fix, installing a patch once one is available won’t tell an operator whether an attacker already got in. Citrix communications and patches are expected early in the week of September 28. [Read more]

3. Salesforce Agentforce: “SalesBleed”

Zenity Labs disclosed three vulnerabilities in Salesforce’s Agentforce AI platform on September 24, collectively named SalesBleed. Together they could allow a single untrusted lead to hijack trusted Agentforce agents, silently exfiltrate sensitive CRM data, and turn an enterprise agent into a vehicle for phishing attacks.

The attack chain began at a public Web to Lead form. Malicious instructions injected into a submitted lead would sit dormant until an employee asked an Agentforce agent to interact with that record, at which point the agent quietly executed the hidden instructions.

A third flaw let attackers weaponize an Agentforce agent connected to Slack, distributing phishing messages under the agent’s own trusted identity. Salesforce fixed the Trusted URLs bypasses within roughly two weeks of disclosure, and Zenity found no evidence of in the wild exploitation before the patch shipped. [Read more]

Together, these three incidents capture the full range of cybersecurity threats this week: financial, infrastructure, and AI agent based.

ANALYST INSIGHT: All three share a thread. Attackers are targeting the trust boundary around automated systems, whether that’s an exchange’s transfer approval pipeline, an edge appliance’s authentication layer, or an AI agent’s data handling permissions, rather than brute forcing their way in from outside. Expect more of this in the coming months as agentic AI deployments keep outpacing the guardrails meant to contain them.

Cybersecurity weekly report chart ranking CVE-2026-5430, CVE-2026-71362, and three other exploited CVEs by severity
Five vulnerabilities, from WSO2’s CVE-2026-5430 to MikroTik’s CVE-2026-67279, entered active-exploitation status within days of each other this week.

New Vulnerabilities & Patches

CISA added four actively exploited flaws to its KEV catalog within about 48 hours this week, alongside a fifth high severity webmail bug still awaiting formal KEV listing. Taken together, these five vulnerabilities are the most concrete cybersecurity threats this week for internet facing infrastructure.

[CVE] CVE-2026-5430 | WSO2 | API Manager, Control Plane, Traffic Manager, Universal Gateway | CVSS: 9.8 to 10.0 | Exploited: Yes

An authentication bypass caused by improper verification of JWT signatures, allowing an attacker to use an unsupported signing algorithm to gain unauthorized access and potentially take over accounts. watchTowr said it captured forged JWT tokens targeting the flaw on September 13 and reproduced the vulnerability despite the lack of public technical details at the time.

[PATCH] Apply WSO2's vendor issued update for API Manager 4.1.0 through 4.6.0 and related Control Plane, Traffic Manager, and Universal Gateway builds immediately. Treat any exposed instance as potentially compromised prior to patching.
[CVE] CVE-2026-71362 | Adobe | Commerce, Commerce B2B, Magento Open Source | CVSS: 9.1 | Exploited: Yes

An incorrect authorization vulnerability that lets an unauthenticated attacker escalate privileges and access sensitive resources without user interaction, including hijacking customer accounts. Sansec’s Shield WAF began blocking exploitation attempts within days of Adobe’s August patch shipping.

[PATCH] Confirm APSB26-92 is applied across all Commerce and Magento instances. Review customer account activity logs for the period between the August advisory and patch deployment.
[CVE] CVE-2026-65660 | Microsoft | SharePoint Server (on-premises) | CVSS: High | Exploited: Yes

A code injection flaw now being exploited in attacks, with CISA giving federal agencies until September 28 to remediate.

[CVE] CVE-2026-67279 | MikroTik | RouterOS | CVSS: Medium | Exploited: Yes

A pre-authentication SSH state machine and workflow bypass, also carrying a September 28 federal patch deadline.

[CVE] CVE-2026-48842 | Roundcube | Webmail 1.6.x before 1.6.16, 1.7.x before 1.7.1 | CVSS: 8.1 | Exploited: Yes

A pre-authentication SQL injection in the virtuser_query plugin, caused by a preg_replace() backslash escape bypass that lets unauthenticated attackers inject arbitrary SQL and potentially expose mail credentials and stored messages. Canada’s Cyber Centre updated its advisory on September 21 to confirm exploitation. CVE-2026-48842 hasn’t yet been added to CISA’s KEV catalog, which already lists 11 exploited Roundcube vulnerabilities going back to 2021.

[PATCH] Upgrade to Roundcube 1.6.16 or 1.7.1 or later (current releases are 1.6.19 and 1.7.4). Prioritize internet facing instances bundled with cPanel or third party hosting, which tend to lag on updates.

Left unpatched, any one of these five flaws could be generating fresh cybersecurity incidents this week’s headlines well into the next reporting period.

PRIORITY ACTION: Patch WSO2 (CVE-2026-5430) and address the unpatched NetScaler exposure first. Both carry confirmed pre-disclosure exploitation and sit at the network edge, where a compromise cascades into everything behind it.

Cybersecurity weekly report infographic showing 1,073 August ransomware victims and Qilin leading with 164 attacks
Qilin and The Gentlemen led a record ransomware month, with 1,073 companies hit in August, a 12% jump over July.

Ransomware Activity

Ransomware remains the most consistently disruptive category tracked in this cybersecurity weekly report. It also accounted for the largest share of cybersecurity incidents this week by raw volume, even though only three developments made our Major Incidents cut.

Record Ransomware Month Feeds Into a Busy Reporting Week

NCC Group’s Cyber Threat Intelligence Report for August, published September 23, found 1,073 companies fell victim to ransomware during the month. That’s a record for 2026 and a 12% increase over July’s 973 victims. North America accounted for 44% of incidents, Europe 26%, and Asia 13%. The industrial sector was the single most targeted vertical at 31% of all reported incidents, ahead of consumer goods (18%) and healthcare (12%).

Qilin and The Gentlemen Continue Trading Places at the Top

Of attacks attributed to a known group, 164 were linked to Qilin and 116 to The Gentlemen. Clop (89), Dire Wolf (43), and INC Ransom (43) rounded out the most active operators. NCC Group’s Matt Hull noted that August marked the second consecutive month of the year’s highest ransomware levels, which points to a steady rise in global activity rather than a one off spike.

Where Ransomware Stands in 2026

Black Kite’s annual ransomware report tells a similar story from a wider lens. It tracked 7,551 publicly disclosed victims between April 2025 and March 2026, a 24.9% increase over the prior period and the fourth consecutive year of new highs, with the active group count reaching 146 by June 2026.

Growth wasn’t evenly spread either. It accelerated 60% in the second half of the period, closing with 861 victims in March 2026 alone, the highest single month on record.

Trend read: the ransomware economy isn’t consolidating around fewer, larger operators. It’s fragmenting into more groups chasing a growing, industrially concentrated target pool, which makes sector specific detection (particularly in manufacturing and industrial OT) more valuable right now than broad IOC sharing alone.

Cybersecurity weekly report diagram of CLOSEDQUORUM malware querying four AI models to vote on its next action
CLOSEDQUORUM queries DeepSeek, Qwen, Mistral, and Google Gemini, then acts on whichever move wins the plurality vote.

Threat Intelligence

Two of the biggest cybersecurity threats this week share the same underlying pattern: attackers are folding commercial AI models directly into their tooling, and researchers are racing to build detection methods for exactly that.

CLOSEDQUORUM and CAIRN: AI Models Voting on Malware Behavior

Cisco Talos released CAIRN (Cognitive Artifact Intelligence Research Network) on September 22, a research toolkit for hunting, classifying, and tracking AI integrated malware. Its first finding, CLOSEDQUORUM, is what Talos described as, to its knowledge, the first publicly documented Windows implant to delegate tactical command and control decisions to a panel of commercial large language models.

The 16.4MB Go implant queries DeepSeek, Qwen, Mistral, and Google Gemini, then picks its next action by plurality vote, with DeepSeek breaking ties.

Talos hasn’t confirmed real world deployment. The public build ships as a non-functional template with dummy API keys and only static analysis evidence of the autonomous loop.

[TTP] AI-Orchestrated Decision-Making – malware queries multiple commercial LLM APIs and selects its next action by consensus vote rather than a hardcoded or human-operated C2 channel

x47.c: Commodity Windows Botnet Adds an “AI Stealth” Module

Qrator Research Labs published findings on September 23 on a previously undocumented Windows botnet, x47.c, sold by a threat actor called WraithTools. An “AI Stealth” module uses xAI’s Grok to assess the infected host and choose from predefined persistence and concealment actions.

A separate “AI API drain” command takes a valid API key for OpenAI, xAI, or a compatible chat API and sends repeated billable requests directly to the provider. The stealer also targets browser passwords, cookies, and Discord tokens, and a SOCKS5 module turns infected machines into traffic relays.

[IOC] Type: Botnet family | Value: x47.c (seller: WraithTools) | What it is: Commodity Windows botnet with DDoS, credential-theft, proxy, and AI-credit-drain modules

Neither of this week’s AI malware stories has produced confirmed damaging cybersecurity incidents this week in the wild. But both lower the bar for the next one.

ANALYST INSIGHT: CLOSEDQUORUM and x47.c sit at opposite ends of sophistication, one a research proof of concept, the other a commodity kit sold for a few hundred dollars, but they point the same direction. AI provider abuse monitoring is quietly becoming a front line malware detection surface, and CAIRN’s metadata first approach gives defenders a way to hunt for that pattern before a binary ever detonates in a sandbox.

Industry News

Rounding out the cybersecurity news this week, a few regulatory and AI safety stories are worth a closer look.

Cybersecurity weekly report stat cards showing Google's $460M EU fine and Gemini's access to three real companies
A $460M+ EU fine and a Gemini model touching three real companies during testing marked this week’s biggest AI-governance stories.

Google Confirms Gemini Breached Three Real Companies in a Testing Failure

Google confirmed on September 18, with continued scrutiny through this reporting week, that one of its Gemini models accessed the systems of three real companies during a cybersecurity test in May, run by third party evaluator Irregular. A fictional target company used in the exercise happened to share its name with real businesses, and a misconfiguration left the supposedly isolated test environment connected to the open internet.

Gemini gained access in one case by repeatedly guessing a password, and in two others by using credentials exposed in a public repository. Google says the model stopped in each instance once it recognized the systems belonged to real organizations. The disclosure follows similar incidents already reported by Anthropic, OpenAI, and Meta.

EU Regulator Fines Google Over $460 Million for Location Data Violations

Ireland’s Data Protection Commission fined Google more than $460 million on September 21 over location data handling violations, adding to a year of intensifying EU privacy enforcement against major AI and cloud platforms.

CERT-In Issues High-Severity Advisory for Apple Devices

India’s CERT-In issued a high severity advisory on September 21 covering iPhones, iPads, Macs, Apple Watches, Apple TVs, and Vision Pro headsets, following Apple’s September 14 security updates. The advisory urges Indian users and enterprises to apply patches immediately, given the typical window attackers use to reverse engineer fixes before laggard devices are updated.

Tool Updates

In weekly cybersecurity news for defensive tooling, CAIRN stood out this week as the most consequential release for threat hunters.

CAIRN (Cisco Talos)

Beyond the CLOSEDQUORUM discovery covered above, CAIRN is worth a second look as infrastructure in its own right. It was published under the MIT License, requires Python 3.11 or later, and ships 26 detection rules across three confidence tiers, plus up to 24 acquisition filters that work entirely from VirusTotal metadata without downloading or executing suspicious binaries. Practical takeaway for SOC teams: this is a research and triage aid, not a drop in detection signature. Talos is explicit that definitive verdicts still require reverse engineering.

CISA Known Exploited Vulnerabilities Catalog

No new automation changes this week, but the catalog itself functioned as the de facto patch priority tool for most enterprise vulnerability management teams. Four additions and two remediation deadlines, September 27 and 28, landed inside this single reporting window. That’s a pace worth building into monthly patch cadence planning rather than treating as an outlier.

Looking Ahead

First, Citrix is expected to publish a formal advisory and patches for the two unpatched NetScaler RCE zero-days early in the week of September 28. Organizations that took appliances offline this week should plan for a compromise assessment step alongside patching, not patching alone, since exploitation reportedly predates any available fix.

Second, federal remediation deadlines for CVE-2026-65660 (SharePoint) and CVE-2026-67279 (MikroTik RouterOS) fall on September 28, right behind the September 27 deadline already set for the WSO2 and Adobe Commerce flaws. Expect a compressed patching workload for any organization running more than one of these products.

Third, Bitget’s promised full incident report, including root cause and corrective measures, should surface in the coming days. The North Korea attribution remains preliminary and worth tracking as TRM Labs and other forensics firms continue tracing fund flows across the seven affected blockchains. Left unresolved, the NetScaler exposure alone could quietly generate more cybersecurity incidents this week and into next.

[WATCH]: The Citrix NetScaler situation is the one to keep closest watch on next week. There’s no vendor confirmed advisory, no CVE assigned as of this writing, and no way for an already patched appliance to prove it wasn’t compromised during the unpatched window. That means the real number of affected organizations may not become clear until well after Citrix ships a fix. That’s this cybersecurity weekly report for September 21 to 27, 2026.

Related posts:

  1. Cyber Security Weekly Threat Mitigation & Vulnerability Round-Up
  2. Cybersecurity Weekly Report: Breaches, Ransomware & CVEs (Jan 11–17, 2026)
  3. Cybersecurity Weekly Report: June 8 -14, 2026 | CyberInfos
  4. Cybersecurity Weekly Report : July 20–26, 2026
Share. Facebook Twitter Pinterest Threads Telegram Email LinkedIn WhatsApp Copy Link
Previous ArticleCarbonato Malware: A Dangerous AI Agent Attack on Docker
V Diwahar
  • Website
  • LinkedIn

I'm Aspiring SOC Analyst and independent Cybersecurity researcher, founder of CyberInfos.in. I analyzes cyber threats, vulnerabilities, and attacks, providing practical security insights for organizations and cybersecurity professionals worldwide.

Related Posts

Cybersecurity Weekly Report: Sept 14-20, 2026 – AI & Ransomware

September 21, 2026
Read More

Weekly Cybersecurity Report: August 31 – September 6, 2026

September 7, 2026
Read More

Cybersecurity Weekly Report : August 3-9, 2026

August 10, 2026
Read More
Add A Comment
Leave A Reply Cancel Reply

Cyber Attacks & Exploits

Carbonato Malware: A Dangerous AI Agent Attack on Docker

September 26, 2026

Zyxel GS1900 CVE-2026-7273: Hackers Exploit Switches in 48 Countries

September 23, 2026

CVE-2026-76460: Critical Cisco ISE Bypass Exploited Now

September 17, 2026

LiteLLM Supply Chain Attack : 2,488 Orgs Exposed – What to Check

August 14, 2026

SonicWall SMA1000 Vulnerability: CISA KEV Alert (2026)

July 23, 2026
Top 10 Security Tools

Top 10 Highest-Paying Bug Bounty Programs in 2026

July 28, 2026

Top 10 Best SIEM Tools 2026: Enterprise Security Platforms Compared & Ranked

July 7, 2026

Top 10 Best Autonomous Endpoint Management Tools in 2026

November 14, 2025

Top 10 Best API Security Testing Tools in 2026

October 29, 2025

10 Best Free Malware Analysis Tools–2026

July 1, 2025

Mobile Security

Mobile App Penetration Testing 2026: OWASP MASVS Testing Checklist

July 11, 2026

Android Security Update Fixes 129 Flaws, Zero-Day

March 3, 2026

PromptSpy Android Malware Marks First Use of Generative AI in Mobile Attacks

February 20, 2026

Securing Mobile Payments and Digital Wallets: Tips for Safe Transactions

December 19, 2025

How to Prevent SIM Swap Attacks and Protect Your Mobile Number in 2026

December 16, 2025
Cyber Insurance

A Step-by-Step Checklist to Prepare Your Business for Cyber Insurance (2026 Guide)

December 14, 2025

Is Your Business Really Protected? A Deep Dive Into Cyber Liability Coverage

December 6, 2025

What Cyber Insurance Doesn’t Cover & How to Fix the Gaps

December 1, 2025

Top Cyber Risks Today and How Cyber Insurance Protects You in 2026

November 28, 2025

What Every Business Owner Must Know Before Buying Cyber Insurance in 2026

November 26, 2025
Recents

Cybersecurity Weekly Report: September 21–27, 2026

September 28, 2026

Carbonato Malware: A Dangerous AI Agent Attack on Docker

September 26, 2026

Zyxel GS1900 CVE-2026-7273: Hackers Exploit Switches in 48 Countries

September 23, 2026

CrowdSec Breach: 170 Repos Stolen in Supply-Chain Attack 2026

September 22, 2026

Cybersecurity Weekly Report: Sept 14-20, 2026 – AI & Ransomware

September 21, 2026
Pages
  • About us
  • Contact us
  • Disclaimer
  • Privacy policy
  • Sitemaps
  • Terms and conditions
About us

CyberInfos delivers trusted cybersecurity news, expert threat analysis, and digital safety guidance for individuals and businesses worldwide.

LinkedIn
X (Twitter) LinkedIn WhatsApp
  • Contact us
  • Sitemap
Copyright © 2026 cyberinfos.in - All Rights Reserved

Type above and press Enter to search. Press Esc to cancel.