Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Sep 28, 2026·4m

Cyber Security News for September 28 2026 - Daily DefSec Brief

Show notes

1. NetScaler zero-days exploited before the patch — CVE-2026-88771, CVE-2026-88772 — Fixed: 14.1-73.37, 13.1-64.23, 13.1-37.279 (FIPS and NDcPP) — federal due 2026-09-30 — Do: Patch NetScaler, then hunt for compromise — https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html

2. One encoded letter gets past PeopleSoft WAF rules — CVE-2026-35273 — Do: Patch PeopleSoft, don't rely on the WAF — https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft/

3. SharePoint "spoofing" flaw is now exploited — CVE-2026-65660 — Fixed: 16.0.10417.20198 (2019), 16.0.19725.20522 (SE), 16.0.5565.1001 (2016) — federal due 2026-09-28 — Do: Install August's SharePoint update on every farm — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660

4. RouterOS SSH skips the login after a rekey — CVE-2026-67279 — Fixed: 6.49.21, 7.23.4, 7.24.2 — federal due 2026-09-28 — Do: Upgrade RouterOS and fence off SSH — https://www.cve.org/CVERecord?id=CVE-2026-67279

5. WordPress core file-load flaw now exploited — CVE-2026-87902 — Fixed: 7.1.2 (backports down to 4.7.37) — federal due 2026-09-28 — Do: Make sure WordPress updates reach every site — https://wordpress.org/news/2026/09/wordpress-7-1-2-release/

6. Leaked service principal deletes Azure resources — Do: Rotate any service principal secret ever posted — https://www.microsoft.com/en-us/security/blog/2026/09/25/storm-3168-agentic-driven-cloud-attacks-using-compromised-service-principals/

7. Public lead form hijacked Salesforce Agentforce — Do: Limit agents that read public web forms — https://labs.zenity.io/post/salesbleed-0-click-data-exfiltration-on-agentforce

8. New RAT takes commands over Tailscale's tailcat — Do: Alert on unsanctioned VPN software on endpoints — https://www.malwarebytes.com/blog/threat-intel/2026/09/kothamine-malware-uses-tailscales-tailcat-to-evade-network-detection

9. Disabled malicious GitHub Actions came back online — Do: Pin GitHub Actions to commit hashes — https://socket.dev/blog/mini-shai-hulud-actions