Lead · Vulnerabilities

Two NetScaler zero-days, exploited before the patch, and a Wednesday deadline

CISA added CVE-2026-88771 and CVE-2026-88772 to the Known Exploited Vulnerabilities catalogue on Sunday and told US federal agencies to fix their Citrix estate by Wednesday; the Dutch, US and UK agencies all published on the same day.

confidence 0.95

Incident responders started warning about NetScaler Gateway on Saturday. By Sunday the agencies in the Netherlands, the United States and the United Kingdom had all put something out, CISA had added both CVE-2026-88771 and CVE-2026-88772 to the KEV catalogue on the strength of active exploitation, and federal agencies had a patching order with a Wednesday date on it. Citrix has now confirmed eight new vulnerabilities in total and shipped fixes for the two critical ones, which one write-up puts at 9.5 under CVSS 4.0. The public disclosure is titled, without embellishment, chained pre-auth RCEs weaponised in the wild.

The exploitation came before the patches, which is the part that should shape your morning. This was not a window in which you were slow; it was a window in which there was nothing to be slow about. That reframes the question from 'have we patched' to 'what did the box do between Saturday and now', and the answer lives in configuration, sessions and outbound connections rather than in a version string.

The public proof-of-concept currently on GitHub is deliberately incomplete: the code's own error string says the memory overflow trigger is not shipped because it is weaponised in the wild. One researcher posted about a NetScaler PoC, then deleted the post saying it appeared to have been a waste of time. So the capability gap runs the usual direction. The people attacking your gateway have the full chain; the people defending it have a checker.

Why it mattersIf you run NetScaler ADC or Gateway, patching is the floor, not the ceiling: assume pre-patch access and go looking for it in sessions, config changes and egress.

Today’s revelation

A key in a .env file is not a secret. It is a subscription you have opened, generously, to everyone who can type a URL.

— Sturgeon’s Revelations · Probably Fine Daily No. 2

§2

Top stories

The rest of the last 24 hours, with receipts.

AI & security

The scanners now ask for your Anthropic and OpenAI keys by name

Our own edge sensor recorded 79 distinct addresses making 1,026 requests hunting for AI API keys and AI tool credentials over the last 30 days, and 3 addresses making 59 such requests in the last 24 hours, against paths including /.claude/settings.json, /.claude/settings.local.json, /.env.anthropic, /.env.openai, /.anthropic/config.json and /.config/anthropic/credentials, alongside Vite dev-server /@fs/ reads of home directories and Claude Code credential files. The wider feeds agree from other angles: SOCRadar reports infostealer logs exposing AI account credentials and sessions tied to more than 80,000 corporate domains, the Carbonato botnet is dropping the Hermes Agent framework onto exposed Docker daemons and stealing AI API keys while it is there, and researchers note AI coding agents storing API keys and credentials in plain text. This week: scope every model key to one purpose and rotate the ones you cannot account for, put a hard spend cap and a billing alert on each, take dev servers off the internet entirely, and get secrets out of anything the web root can reach.

Why it mattersA model key in a .env file, a dev server on a public IP or a CI log is a live credential with a bill attached, and almost nobody has an alert for somebody else's inference spend.

confidence 0.93

Ransomware

Safepay published eighteen victims in a single morning

Between 07:30 and 08:34 on Sunday, Safepay posted claims against Holiday Inn Vilnius, eagroep.com, sumperk.cz, bio-strath.com, fedelmundo.com.ph, lfgholding.com, cromados.com, auromex.com and manno.ch, among eighteen entries tracked across ransomware.live and ransomlook, spanning agriculture, hospitality, manufacturing, finance, healthcare and municipal websites on several continents. The same day carried batches from 3am, Panzer, Qilin, emperador, akira, Storm, Inc Ransom, Play and medusalocker, making it the heaviest ransomware publication day in the window. A multi-sector, multi-country set posted inside about an hour is not eighteen intrusions before breakfast; it is a release schedule for material already in hand.

Why it mattersLeak-site volume is a publishing signal, not an intrusion timeline: date your exposure from initial access, not from the day the blog post landed.

confidence 0.85

Ransomware

3am posts seven victims, and reaches one tracker six hours before the other

3am listed stjames.wa.edu.au, bhn-expertise.com, apexus.com, midwestbit.com, pistonespersan.com.ar, coosalud.com and safescaffolding.net on ransomlook at 12:35 on Sunday; the same claims appeared on ransomware.live between 18:49 and 18:53, roughly six hours later. Two of the named organisations sit in healthcare finance and healthcare delivery: Apexus manages the 340B Prime Vendor Program supporting the US 340B Drug Pricing Program, and Coosalud EPS is a major Colombian health promotion entity. Every other group we tracked over the same window ran the other way round, with ransomware.live carrying the claim first.

Why it mattersIf your intel process is 'we check one leak-site aggregator', for this actor that process has a six-hour delay baked into it; watch both.

confidence 0.80

Threat actors

An arrest in the Netherlands, and ShinyHunters got louder rather than quieter

Dutch police confirmed an arrest in the ShinyHunters investigation, described in one report as a 23-year-old convicted cybercriminal suspected of aiding data thefts and extortions and in another as a 24-year-old Amsterdam man detained earlier this month. In the days after the arrest the remaining members escalated rather than went dark, including claiming credit for an attack on the FBI's jobs site. Separately, Mandiant and Google are warning that the group has modified its exploit for the Oracle PeopleSoft vulnerability CVE-2026-35273 and is running a fresh campaign with it.

Why it mattersCVE-2026-35273 is the actionable part: if you run PeopleSoft, treat this week as active targeting regardless of what you believe about attribution.

confidence 0.82

AI & security

JadePuffer used compromised Azure service principals to delete the cloud

Microsoft, tracking the actor as Storm-3168, describes JadePuffer conducting destructive activity inside an Azure environment using compromised service principals, with reporting that the agent-driven attacks handle reconnaissance, credential theft and the destruction of core components including cloud storage, applications and databases. Coverage characterises it as an evolution of the actor's tradecraft and as an agentic threat actor working from exposed credentials. Whether or not the agentic framing survives contact with the technical report, the control that matters is unglamorous: anomaly detection on service principal credentials, before anything starts deleting.

Why it mattersNon-human identities in your cloud tenant have standing privilege, no working hours and no line manager; monitor their credential use the way you monitor an admin's.

confidence 0.75

Vulnerabilities

Apple patches a CoreGraphics flaw already used in targeted attacks, and the version boundary is the risk

Apple shipped emergency updates for CVE-2026-86950, an out-of-bounds write in CoreGraphics that can lead to arbitrary code execution and that Apple says may have been exploited in targeted attacks. The fixes land in iOS 26, macOS 26 and macOS 15; iOS and macOS 27 are not affected, and the iOS fix ships as 26.7.1. Targeted attacks with no named actor is the usual shape of this kind of disclosure, and the practical exposure sits with whatever part of your fleet has not moved forward.

Why it mattersYour risk here is an upgrade-cycle question, not a patch question: count the devices still on 26 and 15 before you report this as handled.

confidence 0.88

Vulnerabilities

16,000 Supabase databases left readable, and a bulk CVE batch across the rest of the modern stack

Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables containing personally identifiable information, passwords or authentication tokens, mostly through missing row-level security policies on publicly reachable anon keys. Two days earlier, a single NVD batch timestamped 2026-09-26T14:16 dropped dozens of authorisation flaws across unrelated products in the same ecosystem: Capgo API-key and tenancy issues, PostgREST-adjacent row-level security bypasses, Flowise SSO authentication bypass and cross-workspace credential exposure through 3.1.4, vLLM denial-of-service via unbounded parameters, SiYuan path traversals and Netty HTTP/3 request smuggling and resource exhaustion. Four IDs in the same batch, CVE-2026-100655 through CVE-2026-100658, were rejected as duplicates on publication.

Why it mattersBackend-as-a-service defaults and AI orchestration frameworks are now production infrastructure with production data; inventory them and check who can read what without logging in.

confidence 0.85

Oddities

A model called LOLLM is now credited in kernel CVE text, and a brand-new leak site asks 'WHO IS NEXT??'

Several of Friday's Linux kernel CVEs carry the same odd credit line in their descriptions: LOLLM noticed that the rtrmap and rtrefcount maxlevels functions forget to account for the inode root, LOLLM noticed a backwards unit conversion in per_binval, LOLLM complains that xfs_healthmon_unmount does an unlocked insert. Meanwhile, two actors with no prior history in our data turned up on the same busy Sunday: Global Cybernetic Collective, whose leak index includes an entry titled 'WHO IS NEXT??' advising organisations to prepare their security posture or expect exposure, and imnotavillian, with eleven entries. A third, vladivostok, posted a launch announcement in Russian saying it is open for business and that contact details will follow.

Why it mattersNew leak-site brands with no cross-source history cannot be threat-scored yet; log them, do not rank them.

confidence 0.80
§3

Hidden

The daily deep read: what is under the feeds, not on top of them.

The vulnerability feed and the attack feed came apart: NVD went silent exactly when the ransomware feeds had their biggest day.

  1. Exception 01

    NVD produced nothing on the heaviest threat-operations day of the window

    NVD published 132 items through 2026-09-27T16:33 and then stopped; 27 September carried only 7 items in total across all sources, and the 28 September surge of 208 items was composed entirely of ransomware feeds, cyber-news and Mastodon, with zero NVD contribution. A defender whose primary signal is NVD received nothing at all on the busiest day.

    confidence 0.88
    Wrong if
    If NVD did publish on 28 September and the items were held back by an ingestion lag or API throttle on our side rather than an actual silence.
    Watch
    Whether NVD resumes with a compensatory batch, and whether CVSS records for CVE-2026-88771 and CVE-2026-88772 appear there.
  2. Exception 02

    3am claims reach ransomlook about six hours before ransomware.live, consistently

    All eight 3am-attributed entities in the window appear on ransomlook 6.2 to 6.3 hours before ransomware.live, the reverse of Safepay (+5.3h), Panzer (+7.2h), Qilin (+18.7h) and Storm (+23.4h), which all appear on ransomware.live first. Consistency across eight independent victims argues against crawl jitter and for a distinct publication or collection path for this actor.

    confidence 0.67Speculative
    Wrong if
    If ransomlook's documented crawl interval for 3am's Tor blog is simply shorter by design, or if the next 3am batch shows the normal ransomware.live-first direction.
    Watch
    The next 3am batch, and any published sourcing methodology from either aggregator.
  3. Exception 03

    Two zero-history actor brands emerged on the same peak day

    imnotavillian (11 entries) and Global Cybernetic Collective (7 entries) both appear for the first time in the dataset on 28 September, the highest-volume day, and neither has any cross-source confirmation. That is consistent with a rebrand split into two arms, a deliberate launch under cover of a noisy day, or coincidence; nothing in the data separates those options.

    confidence 0.50Speculative
    Wrong if
    If either name is documented in external threat intelligence under an alias predating 28 September, or if the claimed organisations deny contact.
    Watch
    Cross-platform appearance within seven days, and any technical overlap with an established group.
  4. Exception 04

    'Payload' is probably a field name, not an actor, and it is the largest entity in the set

    actor:payload spans 217 items across Mastodon, NVD, ransomware.live and ThreatFox, which is more than any real group in the window. ThreatFox uses 'payload' as a structured field value describing the malicious artefact, so an extraction pipeline that treats it as an actor name manufactures a very busy cross-sector adversary that does not exist.

    confidence 0.48Speculative
    Wrong if
    If 'Payload' is a documented actor with independent prior reporting and ThreatFox is labelling it by name rather than by field.
    Watch
    Any threat-intelligence platform publishing a 'Payload' actor profile built on these records.

Nothing to seeNo evidence of a coordinated state sponsor linking multiple ransomware groups. Bitget's North Korea attribution for the theft rests entirely on Bitget's own statement, with the headline figure of $387.5 million sitting against a body text of over $350 million and a separate account of about $388 million; treat as unverified. The vladivostok actor is a single item with no victims and no IOCs. Carbonato appears in a two-item cluster with no ThreatFox corroboration. Medusalocker's Junta de Andalucía claim and the DC Health Agency 400,000-record exposure are each single-feed. The normal ransomware.live-first lag for Safepay, Panzer, Qilin and Storm is ordinary aggregation cadence and means nothing.

Deep read: 643 items read · $1.61 of compute

§4

Forecast

Dated, falsifiable calls. We mark our own homework in public.

Today’s calls

  1. DueSat 3 Oct5 days

    NVD resumes publishing new CVE records, with at least one batch dated on or after 29 September appearing in the feed.

    Wrong ifNo NVD-sourced items dated 29 September or later appear in the feed by the due date.

    f-2026-09-29-1

    Confidence0.85
  2. DueWed 7 Oct8 days

    A public exploit for CVE-2026-88771 or CVE-2026-88772 that includes the memory-overflow trigger, rather than a check-only PoC, is published and carried by the news or Mastodon feeds.

    Wrong ifNo public repository or advisory carrying a full exploit chain for either CVE is reported in these feeds by the due date.

    f-2026-09-29-2

    Confidence0.50
  3. DueFri 9 Oct10 days

    Our edge sensor's trailing 30-day count of distinct addresses probing AI-credential paths exceeds 79.

    Wrong ifThe trailing 30-day figure reported on our edge on 9 October is 79 or fewer distinct addresses.

    f-2026-09-29-3

    Confidence0.70

Scorecard

1 partly

  1. partly

    A named CVE or formal advisory identifying the Kiteworks threat is published by 12 October 2026.

    Called Mon 28 Sep · due Mon 12 Oct

    Kiteworks issued a precautionary advisory naming an 'Advanced Forms Vulnerability' and urging server shutdown, but no formal CVE number or named-flaw agency alert has been published yet; the article says no evidence of compromise and no CVE ID is mentioned.

Glossary of terms you will be expected to nod at

Agentic (n.)
The adjective applied to automation when it completes the destructive phase before the bridge call has finished apologising for the audio. Formerly: a script. See also: sophisticated.
§5

From our edge

Live attacks on our own servers in the last 24 hours. Yes, really ours.

On our own servers in the last 24 hours the sensor profiled 101 hostile sources (57 scanners, 37 bot crawlers, 5 targeted operators, 2 brute forcers) sending 12,525 requests between them, of which 20 went past reconnaissance into exploitation attempts and 15 groups of addresses shared a behavioural fingerprint; 2,414 addresses touched the edge from 84 countries, 846 of them for the first time. The busiest was 35.237.148.217, a scanner at hostility 6.4/10, which sent 1,407 requests at 27 a minute across three of our sites asking for /.env.local, /.env.production, /.env.staging, /.env.development and /.env.test. The most hostile was 130.12.180.117 at 6.6/10, 22 requests for /.env, /.git/HEAD, /.env.backup and /.env.old, best-matched at 42% to AndroxGh0st and reaching exploitation. One bot crawler, 80.94.95.211, sent 330 requests and shares fingerprint f2377df86d03 with fourteen other addresses, which is one tool or one operator rotating IPs. Another fired 31 requests in about 1.2 seconds for /database.sql, /.ssh/id_rsa, /.env.production and /server.key, and a single address sent two requests shaped like CVE-2018-20062 exploitation, because nothing is ever truly retired. Raw logs never left the server; only the findings did.

101hostile sources profiled
12,525requests from them
20reached exploitation
15shared-DNA clusters
6.6/10top hostility
2,414addresses at our edge
846first seen today
84countries

The WTF list

  1. WTF #1

    Looking for your AI keys

    34.156.206.32, a scanner (hostility 5.5/10), sent 119 requests to one of our sites, probing for /.aws/.env, /.aws/credentials.bak, /.docker/laravel/app/.env, /.aws/config.

    Why it’s weirdWent straight for AI credentials: /.anthropic/config.json. Model API keys are now on the scanners' shopping list next to cloud keys.

    attribution: unknownTue 29 Sep, 04:00 UTC

    Detail
    kill chain: reconnaissance → weaponization · DNA 18e39c4b41fb
  2. WTF #2

    The most determined visitor

    130.12.180.117, a scanner (hostility 6.6/10), sent 22 requests to one of our sites, probing for /.env, /.git/HEAD, /.env.backup, /.env.old.

    Why it’s weirdHighest hostility on the board; its kill chain reached exploitation.

    attribution: AndroxGh0st (sensor's best match, 42%)Tue 29 Sep, 04:00 UTC

    Detail
    kill chain: reconnaissance → weaponization → exploitation · DNA dfef4501b216
  3. WTF #3

    Trying CVE-2018-20062 on us

    1 address sent 2 requests shaped like CVE-2018-20062 exploitation (/index.php), including 93.152.221.156.

    Why it’s weirdA known, named exploit still being sprayed at the internet; our edge saw it today, whatever the patch notes say about the year.

    attribution: unknown

    Detail
    probe family: webshell
  4. WTF #4

    Same DNA, different addresses

    80.94.95.211, a bot crawler (hostility 4.4/10), sent 330 requests, probing for /.env, /../.env, /../../.env, /api/.env.

    Why it’s weird14 IPs share one behavioural fingerprint (DNA f2377df86d03): one tool or one operator rotating addresses: 2a0f:ca80:b00b:d666::5, 185.19.40.244, 206.189.141.20, 146.70.194.236, 193.26.115.12 and more.

    attribution: unknownTue 29 Sep, 04:00 UTC

    Detail
    kill chain: reconnaissance → weaponization → exploitation · DNA f2377df86d03
  5. WTF #5

    The strangest shopping list

    35.237.148.217, a scanner (hostility 6.4/10), sent 1,407 requests at 27 a minute to 3 of our sites, probing for /.env.local, /.env.production, /.env.staging, /.env.development.

    Why it’s weirdAsked for files almost nobody else asks for: /.env.local, /.env.production, /.env.staging, /.env.development, /.env.test.

    attribution: .env credential-harvesting mass scan (sensor's best match, 58%)Tue 29 Sep, 04:00 UTC

    Detail
    kill chain: reconnaissance → weaponization · DNA 77ad4cdb3cb7
  6. WTF #6

    In a hurry

    81.171.72.93, a scanner (hostility 4.7/10), sent 31 requests to one of our sites, probing for /database.sql, /.ssh/id_rsa, /.env.production, /server.key.

    Why it’s weirdFired 31 requests in about 1.2 seconds.

    attribution: unknownTue 29 Sep, 04:00 UTC

    Detail
    kill chain: reconnaissance → weaponization · DNA ce6ecdfacbe3
§6

From the vault

Things we built, shipped, retired or forgot. One a day.

Written 2026-09-01. Never published.

Read by Machines, written 1 September, never published

The post about it was called 'Read by Machines', it was written on 1 September, and it has sat there ever since, unpublished, being read by nobody and, presumably, by everything.

§7

Ride-alongs

Free, live tools. No sign-up, no sales call.

§8

Colophon

How this edition was made, plainly.

Edition 2 was made by machine and checked by code. Every item published by 9 public threat feeds in the 24 hours to 05:05 UK (643 items) was read in full: statistics computed in code, each slice read by Claude Sonnet, the structure synthesised by Claude Opus. Claude Opus then edited the paper. Every story cites the items it rests on; stories whose receipts did not resolve, or whose numbers were not in their sources, were dropped before publication (0 today). Forecasts are graded in public in later editions. 'From our edge' is live attack data from our own servers. Cost of this edition: $2.85. It is written by machine in the voice of ScottG, author of Everything Is Probably Fine, and nobody edited it by hand, which is either the point or the problem.

643items read
24hour window
$2.85cost of this edition
04:05 UTCgenerated

Sources this morning

  • ThreatFox250ok
  • NVD132ok
  • infosec.exchange95ok
  • RansomLook66ok
  • ransomware.live47ok
  • Security news42ok
  • RSS9ok
  • Our edge · Ninja Labz1ok
  • From the vault · Ninja Labz1ok

ITEMS READ: 643SOURCES: 9STORIES DROPPED FOR LACK OF RECEIPTS: 0COST: $2.85STATUS: NOT ENTIRELY FINE

OWNER: the machineEDITOR: the rulesCALLS OPEN: 3NEXT REVIEW: tomorrow 06:00 UK