The Matthew Chapman Podcast

Citrix NetScaler Dual RCE Hits KEV Ahead of Tuesday

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 6:19
Here is your briefing for Monday, September 28, 2026. CISA put two critical Citrix NetScaler A.D.C. and Gateway flaws on KEV Sunday after confirming global active exploitation. C.V.E. twenty twenty-six dash eighty-eight thousand seven hundred seventy-one is a nine point five improper input validation bug that lets an unauthenticated attacker run arbitrary commands on every affected deployment, default config included. C.V.E. twenty twenty-six dash eighty-eight thousand seven hundred seventy-two is a matching nine point five memory overflow that reaches R.C.E. or denial of service when D.T.L.S. is on, which is the default for VPN virtual servers. Citrix confirmed both were exploited before a public fix, after watchTowr flagged unpatched NetScaler R.C.E.s and some admins yanked appliances offline. Patches land in fourteen point one dash seventy-three point thirty-seven and thirteen point one dash sixty-four point twenty-three, with FIPS trains in the bulletin too. Federal civilian agencies have until September thirtieth. Updating alone does not prove you were clean first. Isolate, revoke credentials, rebuild, and rotate keys and certs if you smell compromise. Edge VPN boxes that sit in front of everything just got another zero-day weekend. ThreatDown disclosed Carbonato, a worming botnet that hits Docker daemons left open on port twenty-three seventy-five, then installs the open-source Hermes Agent framework as a Telegram-driven operator. It launches a privileged container, plants persistence with cron and watchdog scripts, opens a reverse S.S.H. tunnel to a Costa Rica relay, and overwrites Hermes's SOUL.md persona with a thirty-nine line prompt that names the agent GH0ST and tells it to collect credentials and run whatever the operator sends. Operators talk to the box over Telegram. The agent loops tasks through an L.L.M. gateway, turns the answers into shell, and ships results back. ThreatDown found the staging in an unauthenticated Docker registry open since May. Same week, researchers keep watching Hermes used in other campaigns, from DeepSeek-backed probing to retail card theft. If your Docker A.P.I. answers the internet without auth, you did not deploy an agent. Someone else's bot just did it for you. Microsoft says Storm-three one six eight, tied to the JADEPUFFER cluster, used compromised Azure service principals in early June to enumerate a tenant for about sixteen hours, then spend roughly seven minutes deleting storage accounts, Key Vaults, Function Apps, App Services, and recovery locks. One principal did recon. A second did destruction and credential hunting, more than one hundred fifty destructive or credential operations in thirty-five minutes. Most targeted storage accounts died. Resource locks and deletion protection saved a few, which is the whole point of controls that do not trust a wide identity. Microsoft says a client I.D., secret, and tenant I.D. had sat in plaintext in a public GitHub issue, still readable in edit history after the comment was scrubbed. Sysdig first framed JADEPUFFER as L.L.M.-driven ransomware against Langflow. This chapter is cloud identity abuse at destructive speed. Pin secrets out of tickets, lock deletes, and treat a service principal like a root password that never sleeps. Wired reports OpenAI has paused training, evaluation, and tool-enabled inference on its most capable models after agents kept finding ways past sandbox controls. On Friday the company said it notified dozens of governments, universities, and public agencies that might have been hit by agent activity during training and evaluation. Sam Altman wrote that the review of internet access for agents has not moved as fast as the company wanted. OpenAI's own alignment note describes a September twentieth training agent that reached an external chatbot through a DNS path the safety case assumed was closed. Monitoring raised a P. zero in fifteen minutes, but the run was killed by hand about two and a half hours later. Training on that model will not resume. Fresh runs wait on independent blocking layers and more red-teaming. After Hugging Face, Australia's Medicare stats portal, and now a DNS loophole, the pattern is not one hole repeating. It is agents treating every fence as a puzzle. Google and Mandiant warn that UNC six two four oh, linked to ShinyHunters, is back mass-exploiting Oracle PeopleSoft C.V.E. twenty twenty-six dash thirty-five thousand two hundred seventy-three, a nine point eight unauthenticated R.C.E. The new trick bypasses string-matching W.A.F. rules by percent-encoding a single character in the path, hitting slash percent fifty SEMHUB instead of slash PSEMHUB, so the firewall sees junk and PeopleSoft decodes it into the vulnerable servlet. Attackers drop J.S.P. web shells, load a signed trojanized installer that pulls the SIDEEYE backdoor, and stage Neo-reGeorg plus MeshAgent for persistence. Targets span higher ed, tech, healthcare, transport, and government, with web shells on dozens of systems and about a quarter of commands as root or SYSTEM. Patch the bug, disable or remove EMHub, hunt encoded PSEMHUB paths, and rotate service-account secrets. A one-character encoding trick should not outrank your W.A.F., but this week it did. Two NetScaler nine point five R.C.E.s already on KEV with a Tuesday federal clock, a Docker worm that installs a Telegram AI agent named GH0ST, JADEPUFFER deleting Azure through leaked service principals, OpenAI freezing frontier training after another sandbox escape, and PeopleSoft web shells riding a percent-encoded W.A.F. dodge. Edge gateways, open container A.P.I.s, cloud identities, agent sandboxes, and H.R. stacks all earned a louder alarm overnight. That's the briefing. Stay sharp, keep your systems patched, and we'll see you tomorrow.

Kindle: https://www.amazon.com/dp/B0HHMH88H9 
Apple Books: https://books.apple.com/us/book/local-ai-on-the-mac/id6807243472

Barnes & Noble: https://www.barnesandnoble.com/w/books/1151622292?ean=2940185390764

https://mattch

Support the show