This cybersecurity weekly report covers one of the more consequential seven day stretches of the quarter. A $351.6 million crypto exchange breach. Two unpatched Citrix NetScaler zero-days under active exploitation with no vendor fix in sight. A wave of new CISA Known Exploited Vulnerabilities additions touching WSO2, Adobe Commerce, Microsoft SharePoint, and MikroTik RouterOS.
There’s a lot of cybersecurity news this week worth slowing down for, especially at the network edge, and the cybersecurity threats this week ranged from crypto exchange backend compromises to AI agents turned against their own users.
Underneath those headlines sits a quieter but arguably more instructive story. A set of Salesforce Agentforce flaws showed how prompt injection can turn a trusted AI agent into a data exfiltration channel, and Cisco Talos documented the first publicly known malware sample that lets a panel of large language models vote on its next move. This edition of our weekly cybersecurity news coverage arrives amid a genuinely unusual stretch for edge infrastructure specifically.
Drawing on CyberInfos’ internal threat tracking framework, this week’s global threat posture sits at Level 3 (Elevated). That’s not driven by any single incident so much as by the sheer number of internet facing edge devices, NetScaler, Roundcube, SharePoint, now sitting in active exploitation windows at the same time.
Major Incidents in Cybersecurity News This Week
Among the cybersecurity incidents this week, three stood out for scale, novelty, or the pattern they represent.
1. Bitget – Cryptocurrency Exchange

Bitget detected unauthorized transfers from its hot and warm wallets at 18:31 UTC on September 24. By the time the exchange’s security team got it fully contained, roughly $351.6 million had moved out across seven blockchains. An internal wallet infrastructure component was compromised; spoofed transaction data was then fed into the exchange’s own approval process, so funds left as if the payouts were routine.
Cold storage was reportedly untouched. CEO Gracy Chen said the exchange’s $464 million plus User Protection Fund would cover the loss. Blockchain forensics firm TRM Labs tagged exploiter addresses and traced funds across BNB Chain, THORChain, the XRP Ledger, and Bitcoin. Bitget itself called North Korean involvement “very likely,” based on IP addresses linked to VPN services associated with a North Korean hacking group. Withdrawals remain paused. Deposits and trading continue. [Read More]
ANALYST INSIGHT: This isn’t a stolen key incident. It’s a backend authorization compromise, and that’s a materially different threat model. Exchanges that only monitor for anomalous signing keys will miss an attacker who has learned to forge legitimate looking transfer requests inside the approval pipeline itself.
2. Citrix NetScaler ADC and Gateway: Unpatched Zero-Days
Security firm watchTowr disclosed on September 26 that two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances, both allowing remote code execution, are being actively exploited in the wild. Citrix has yet to confirm the flaws or publish a fix.
These are distinct from CVE-2026-19490, the authentication bypass Citrix patched on August 19 and CISA added to its KEV catalog on September 9.
Some administrators have simply taken appliances offline rather than wait, given that NetScaler devices sit at the network edge handling VPN, load balancing, and authentication. Here’s the harder problem: because exploitation reportedly preceded any fix, installing a patch once one is available won’t tell an operator whether an attacker already got in. Citrix communications and patches are expected early in the week of September 28. [Read more]
3. Salesforce Agentforce: “SalesBleed”
Zenity Labs disclosed three vulnerabilities in Salesforce’s Agentforce AI platform on September 24, collectively named SalesBleed. Together they could allow a single untrusted lead to hijack trusted Agentforce agents, silently exfiltrate sensitive CRM data, and turn an enterprise agent into a vehicle for phishing attacks.
The attack chain began at a public Web to Lead form. Malicious instructions injected into a submitted lead would sit dormant until an employee asked an Agentforce agent to interact with that record, at which point the agent quietly executed the hidden instructions.
A third flaw let attackers weaponize an Agentforce agent connected to Slack, distributing phishing messages under the agent’s own trusted identity. Salesforce fixed the Trusted URLs bypasses within roughly two weeks of disclosure, and Zenity found no evidence of in the wild exploitation before the patch shipped. [Read more]
Together, these three incidents capture the full range of cybersecurity threats this week: financial, infrastructure, and AI agent based.
ANALYST INSIGHT: All three share a thread. Attackers are targeting the trust boundary around automated systems, whether that’s an exchange’s transfer approval pipeline, an edge appliance’s authentication layer, or an AI agent’s data handling permissions, rather than brute forcing their way in from outside. Expect more of this in the coming months as agentic AI deployments keep outpacing the guardrails meant to contain them.

New Vulnerabilities & Patches
CISA added four actively exploited flaws to its KEV catalog within about 48 hours this week, alongside a fifth high severity webmail bug still awaiting formal KEV listing. Taken together, these five vulnerabilities are the most concrete cybersecurity threats this week for internet facing infrastructure.
[CVE] CVE-2026-5430 | WSO2 | API Manager, Control Plane, Traffic Manager, Universal Gateway | CVSS: 9.8 to 10.0 | Exploited: Yes
An authentication bypass caused by improper verification of JWT signatures, allowing an attacker to use an unsupported signing algorithm to gain unauthorized access and potentially take over accounts. watchTowr said it captured forged JWT tokens targeting the flaw on September 13 and reproduced the vulnerability despite the lack of public technical details at the time.
[PATCH] Apply WSO2's vendor issued update for API Manager 4.1.0 through 4.6.0 and related Control Plane, Traffic Manager, and Universal Gateway builds immediately. Treat any exposed instance as potentially compromised prior to patching.
[CVE] CVE-2026-71362 | Adobe | Commerce, Commerce B2B, Magento Open Source | CVSS: 9.1 | Exploited: Yes
An incorrect authorization vulnerability that lets an unauthenticated attacker escalate privileges and access sensitive resources without user interaction, including hijacking customer accounts. Sansec’s Shield WAF began blocking exploitation attempts within days of Adobe’s August patch shipping.
[PATCH] Confirm APSB26-92 is applied across all Commerce and Magento instances. Review customer account activity logs for the period between the August advisory and patch deployment.
[CVE] CVE-2026-65660 | Microsoft | SharePoint Server (on-premises) | CVSS: High | Exploited: Yes
A code injection flaw now being exploited in attacks, with CISA giving federal agencies until September 28 to remediate.
[CVE] CVE-2026-67279 | MikroTik | RouterOS | CVSS: Medium | Exploited: Yes
A pre-authentication SSH state machine and workflow bypass, also carrying a September 28 federal patch deadline.
[CVE] CVE-2026-48842 | Roundcube | Webmail 1.6.x before 1.6.16, 1.7.x before 1.7.1 | CVSS: 8.1 | Exploited: Yes
A pre-authentication SQL injection in the virtuser_query plugin, caused by a preg_replace() backslash escape bypass that lets unauthenticated attackers inject arbitrary SQL and potentially expose mail credentials and stored messages. Canada’s Cyber Centre updated its advisory on September 21 to confirm exploitation. CVE-2026-48842 hasn’t yet been added to CISA’s KEV catalog, which already lists 11 exploited Roundcube vulnerabilities going back to 2021.
[PATCH] Upgrade to Roundcube 1.6.16 or 1.7.1 or later (current releases are 1.6.19 and 1.7.4). Prioritize internet facing instances bundled with cPanel or third party hosting, which tend to lag on updates.
Left unpatched, any one of these five flaws could be generating fresh cybersecurity incidents this week’s headlines well into the next reporting period.
PRIORITY ACTION: Patch WSO2 (CVE-2026-5430) and address the unpatched NetScaler exposure first. Both carry confirmed pre-disclosure exploitation and sit at the network edge, where a compromise cascades into everything behind it.

Ransomware Activity
Ransomware remains the most consistently disruptive category tracked in this cybersecurity weekly report. It also accounted for the largest share of cybersecurity incidents this week by raw volume, even though only three developments made our Major Incidents cut.
Record Ransomware Month Feeds Into a Busy Reporting Week
NCC Group’s Cyber Threat Intelligence Report for August, published September 23, found 1,073 companies fell victim to ransomware during the month. That’s a record for 2026 and a 12% increase over July’s 973 victims. North America accounted for 44% of incidents, Europe 26%, and Asia 13%. The industrial sector was the single most targeted vertical at 31% of all reported incidents, ahead of consumer goods (18%) and healthcare (12%).
Qilin and The Gentlemen Continue Trading Places at the Top
Of attacks attributed to a known group, 164 were linked to Qilin and 116 to The Gentlemen. Clop (89), Dire Wolf (43), and INC Ransom (43) rounded out the most active operators. NCC Group’s Matt Hull noted that August marked the second consecutive month of the year’s highest ransomware levels, which points to a steady rise in global activity rather than a one off spike.
Where Ransomware Stands in 2026
Black Kite’s annual ransomware report tells a similar story from a wider lens. It tracked 7,551 publicly disclosed victims between April 2025 and March 2026, a 24.9% increase over the prior period and the fourth consecutive year of new highs, with the active group count reaching 146 by June 2026.
Growth wasn’t evenly spread either. It accelerated 60% in the second half of the period, closing with 861 victims in March 2026 alone, the highest single month on record.
Trend read: the ransomware economy isn’t consolidating around fewer, larger operators. It’s fragmenting into more groups chasing a growing, industrially concentrated target pool, which makes sector specific detection (particularly in manufacturing and industrial OT) more valuable right now than broad IOC sharing alone.

Threat Intelligence
Two of the biggest cybersecurity threats this week share the same underlying pattern: attackers are folding commercial AI models directly into their tooling, and researchers are racing to build detection methods for exactly that.
CLOSEDQUORUM and CAIRN: AI Models Voting on Malware Behavior
Cisco Talos released CAIRN (Cognitive Artifact Intelligence Research Network) on September 22, a research toolkit for hunting, classifying, and tracking AI integrated malware. Its first finding, CLOSEDQUORUM, is what Talos described as, to its knowledge, the first publicly documented Windows implant to delegate tactical command and control decisions to a panel of commercial large language models.
The 16.4MB Go implant queries DeepSeek, Qwen, Mistral, and Google Gemini, then picks its next action by plurality vote, with DeepSeek breaking ties.
Talos hasn’t confirmed real world deployment. The public build ships as a non-functional template with dummy API keys and only static analysis evidence of the autonomous loop.
[TTP] AI-Orchestrated Decision-Making – malware queries multiple commercial LLM APIs and selects its next action by consensus vote rather than a hardcoded or human-operated C2 channel
x47.c: Commodity Windows Botnet Adds an “AI Stealth” Module
Qrator Research Labs published findings on September 23 on a previously undocumented Windows botnet, x47.c, sold by a threat actor called WraithTools. An “AI Stealth” module uses xAI’s Grok to assess the infected host and choose from predefined persistence and concealment actions.
A separate “AI API drain” command takes a valid API key for OpenAI, xAI, or a compatible chat API and sends repeated billable requests directly to the provider. The stealer also targets browser passwords, cookies, and Discord tokens, and a SOCKS5 module turns infected machines into traffic relays.
[IOC] Type: Botnet family | Value: x47.c (seller: WraithTools) | What it is: Commodity Windows botnet with DDoS, credential-theft, proxy, and AI-credit-drain modules
Neither of this week’s AI malware stories has produced confirmed damaging cybersecurity incidents this week in the wild. But both lower the bar for the next one.
ANALYST INSIGHT: CLOSEDQUORUM and x47.c sit at opposite ends of sophistication, one a research proof of concept, the other a commodity kit sold for a few hundred dollars, but they point the same direction. AI provider abuse monitoring is quietly becoming a front line malware detection surface, and CAIRN’s metadata first approach gives defenders a way to hunt for that pattern before a binary ever detonates in a sandbox.
Industry News
Rounding out the cybersecurity news this week, a few regulatory and AI safety stories are worth a closer look.

Google Confirms Gemini Breached Three Real Companies in a Testing Failure
Google confirmed on September 18, with continued scrutiny through this reporting week, that one of its Gemini models accessed the systems of three real companies during a cybersecurity test in May, run by third party evaluator Irregular. A fictional target company used in the exercise happened to share its name with real businesses, and a misconfiguration left the supposedly isolated test environment connected to the open internet.
Gemini gained access in one case by repeatedly guessing a password, and in two others by using credentials exposed in a public repository. Google says the model stopped in each instance once it recognized the systems belonged to real organizations. The disclosure follows similar incidents already reported by Anthropic, OpenAI, and Meta.
EU Regulator Fines Google Over $460 Million for Location Data Violations
Ireland’s Data Protection Commission fined Google more than $460 million on September 21 over location data handling violations, adding to a year of intensifying EU privacy enforcement against major AI and cloud platforms.
CERT-In Issues High-Severity Advisory for Apple Devices
India’s CERT-In issued a high severity advisory on September 21 covering iPhones, iPads, Macs, Apple Watches, Apple TVs, and Vision Pro headsets, following Apple’s September 14 security updates. The advisory urges Indian users and enterprises to apply patches immediately, given the typical window attackers use to reverse engineer fixes before laggard devices are updated.
Tool Updates
In weekly cybersecurity news for defensive tooling, CAIRN stood out this week as the most consequential release for threat hunters.
CAIRN (Cisco Talos)
Beyond the CLOSEDQUORUM discovery covered above, CAIRN is worth a second look as infrastructure in its own right. It was published under the MIT License, requires Python 3.11 or later, and ships 26 detection rules across three confidence tiers, plus up to 24 acquisition filters that work entirely from VirusTotal metadata without downloading or executing suspicious binaries. Practical takeaway for SOC teams: this is a research and triage aid, not a drop in detection signature. Talos is explicit that definitive verdicts still require reverse engineering.
CISA Known Exploited Vulnerabilities Catalog
No new automation changes this week, but the catalog itself functioned as the de facto patch priority tool for most enterprise vulnerability management teams. Four additions and two remediation deadlines, September 27 and 28, landed inside this single reporting window. That’s a pace worth building into monthly patch cadence planning rather than treating as an outlier.
Looking Ahead
First, Citrix is expected to publish a formal advisory and patches for the two unpatched NetScaler RCE zero-days early in the week of September 28. Organizations that took appliances offline this week should plan for a compromise assessment step alongside patching, not patching alone, since exploitation reportedly predates any available fix.
Second, federal remediation deadlines for CVE-2026-65660 (SharePoint) and CVE-2026-67279 (MikroTik RouterOS) fall on September 28, right behind the September 27 deadline already set for the WSO2 and Adobe Commerce flaws. Expect a compressed patching workload for any organization running more than one of these products.
Third, Bitget’s promised full incident report, including root cause and corrective measures, should surface in the coming days. The North Korea attribution remains preliminary and worth tracking as TRM Labs and other forensics firms continue tracing fund flows across the seven affected blockchains. Left unresolved, the NetScaler exposure alone could quietly generate more cybersecurity incidents this week and into next.
[WATCH]: The Citrix NetScaler situation is the one to keep closest watch on next week. There’s no vendor confirmed advisory, no CVE assigned as of this writing, and no way for an already patched appliance to prove it wasn’t compromised during the unpatched window. That means the real number of affected organizations may not become clear until well after Citrix ships a fix. That’s this cybersecurity weekly report for September 21 to 27, 2026.
