Threat Intelligence Brief - Wednesday, September 30, 2026

Operational threat reporting for defenders who need signal, not noise.

By DevSecOpsDad

Threat Radar

  • Citrix NetScaler ADC and Gateway are under active exploitation — attackers are achieving root access and deploying novel malware (WHIPSHOT, SLAPSHOT) against North American and European organizations. Patch status alone is insufficient if exploitation preceded remediation.

  • A US-focused phishing campaign is actively targeting C-suite executives, stealing Microsoft 365 session tokens and establishing persistent remote access via RMM tools across technology, manufacturing, government, and consulting sectors.

  • Russian state-sponsored actor Star Blizzard has scaled up phishing operations using the RedFlick infection chain to deliver the CosmicPulse backdoor, signaling a broad-targeting espionage campaign.

  • Bitget lost $387.5 million after attackers exploited a zero-day in third-party security tooling — a direct warning to any organization that grants security vendors privileged access to financial or operational systems.

  • Ransomware was deployed on operational networks supporting South Africa’s air traffic control, confirming that safety-critical infrastructure remains an active target with real-world consequence potential.



Immediate Action Required

  • Citrix NetScaler ADC / Gateway — Active Exploitation: Confirm patch application dates against the exploitation window. If patching occurred after the September 2026 exposure window, treat affected appliances as potentially compromised. Initiate forensic review for WHIPSHOT and SLAPSHOT indicators. Techniques: T1190, T1548.

  • Microsoft 365 Executive Accounts — Session Hijacking Campaign: Audit conditional access logs and active sessions for C-suite accounts. Enforce phishing-resistant MFA (FIDO2). Review executive endpoints for unauthorized RMM tool installation. Techniques: T1566.002, T1110.004, T1021.004.

  • Star Blizzard / CosmicPulse — State-Sponsored Phishing: Brief threat intelligence and SOC teams on the RedFlick infection chain and CosmicPulse backdoor indicators. Priority sectors: government, technology, and critical infrastructure. Techniques: T1566.002, T1059.

  • Third-Party Security Vendor Review — Bitget Zero-Day: Inventory third-party security products with privileged access to your environment. Contact vendors directly to determine whether their tooling was affected. Treat vendor-side zero-days as a supply chain risk requiring immediate escalation. Technique: T1190.



High-Impact Developments

Citrix NetScaler Actively Exploited — Root Access and Novel Malware Deployed

  • What happened: Unknown threat actors exploited a patched vulnerability in Citrix NetScaler ADC and NetScaler Gateway to gain root-level access and deploy two previously undocumented malware families — WHIPSHOT and SLAPSHOT — against organizations in North America and Europe. Activity was confirmed by Mandiant and Google GTIG in September 2026.

  • Why it matters: Root access on a network edge device is a worst-case scenario. Attackers with root on NetScaler can intercept traffic, pivot into internal networks, and maintain persistence through reboots. Novel malware deployment indicates a sophisticated, well-resourced actor with post-exploitation objectives beyond opportunistic access.

  • Who should care: Infrastructure, SOC, and CISO teams at any organization running Citrix NetScaler ADC or Gateway — particularly in financial services, government, and technology sectors.

  • Recommended action: Verify patch application dates against the exploitation window. If exposure is plausible, treat the appliance as compromised: isolate, image for forensics, and rebuild. Hunt for WHIPSHOT and SLAPSHOT indicators across network telemetry. Patching does not retroactively close the risk.

  • Confidence: High — confirmed active exploitation with named malware families, attributed to Mandiant and GTIG research.

  • Search metadata: T1190, T1548 — Citrix NetScaler ADC, Citrix NetScaler Gateway — WHIPSHOT, SLAPSHOT

Intelligence Context



C-Suite Microsoft 365 Session Theft and Star Blizzard Backdoor Campaign — Dual Phishing Threat

  • What happened: Two concurrent phishing campaigns are targeting organizations. First, a US-focused operation documented across 351 sandbox analyses is stealing Microsoft 365 session tokens from C-suite executives and deploying RMM tools for persistent remote access — with 51% of submissions originating from the US. Second, Russian APT Star Blizzard is running a scaled-up phishing campaign using the RedFlick infection chain to deliver the CosmicPulse backdoor, targeting government, technology, and critical infrastructure organizations.

  • Why it matters: Session token theft bypasses MFA entirely — attackers inherit an authenticated session without needing credentials. Combined with RMM tool deployment, this creates a persistent foothold with legitimate-looking remote access. The Star Blizzard campaign adds a state-sponsored espionage dimension: CosmicPulse is a backdoor designed for long-term persistence and data exfiltration, not opportunistic crime.

  • Who should care: Executive leadership, IAM teams, and SOC analysts at US-based technology, manufacturing, government, and consulting organizations. Government and critical infrastructure security teams should treat the Star Blizzard campaign as a direct threat.

  • Recommended action: For the M365 campaign: enforce token binding where supported, review conditional access policies for anomalous session activity, and audit executive endpoints for unauthorized RMM software. For Star Blizzard: brief threat intelligence teams on RedFlick and CosmicPulse indicators and review inbound phishing telemetry for spear-phishing patterns consistent with this campaign.

  • Confidence: High — both campaigns confirmed active with documented tooling and victim telemetry.

  • Search metadata: T1566.002, T1110.004, T1021.004, T1059 — Microsoft 365 — Star Blizzard — CosmicPulse — RMM

Intelligence Context



Bitget Breach — $387.5M Stolen via Zero-Day in Third-Party Security Products

  • What happened: Cryptocurrency exchange Bitget disclosed that attackers stole $387.5 million by exploiting a zero-day vulnerability in third-party security products integrated into its environment. The breach occurred before public disclosure of the underlying flaw.

  • Why it matters: This is a supply chain attack that bypassed Bitget’s own controls by targeting trusted vendors with privileged access. The financial loss is secondary to the architectural implication: security tooling itself became the attack surface. Any organization granting third-party security vendors privileged access to networks, APIs, or financial systems carries analogous exposure.

  • Who should care: CISOs, risk management, and vendor management teams across financial services and any sector using third-party security tooling with elevated access privileges.

  • Recommended action: Inventory third-party security vendors with privileged or API-level access to critical systems. Contact vendors directly to determine whether their products were among those affected. Apply least-privilege principles to vendor integrations and scope or segment vendor access pending disclosure.

  • Confidence: High — disclosed by Bitget directly; specific vendor identity not yet public.

  • Search metadata: T1190 — Bitget — Zero-Day Exploitation

Intelligence Context



Ransomware Deployed on South Africa Air Traffic Control Operational Networks

  • What happened: South Africa’s air traffic control systems were compromised in a ransomware attack, with a ransomware toolkit confirmed installed on at least one operational network. South Africa has sought external assistance in response.

  • Why it matters: Ransomware reaching operational networks in aviation infrastructure — not just IT systems — directly threatens safety-critical functions. This follows an escalating pattern of attacks against transportation and critical infrastructure globally and should be read as a sector-wide warning.

  • Who should care: CISOs and OT security leads at aviation, transportation, and critical infrastructure organizations. Government security teams with oversight of national infrastructure.

  • Recommended action: Review network segmentation between IT and OT environments. Validate that ransomware response playbooks cover operational technology scenarios, not just IT systems. Confirm backup integrity and offline recovery capability for safety-critical systems.

  • Confidence: High — confirmed incident with external assistance requested; attribution not yet established.

  • Search metadata: T1486 — Air Traffic Control Systems — Ransomware — Critical Infrastructure

Intelligence Context



Monitor Only

  • OpenSSL patched a high-severity DTLS flaw that can leak unencrypted heap memory or crash applications; exploitation status is currently unknown but a patch is available and should be applied this week to any service using DTLS connections. Source: OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted — https://thehackernews.com/2026/09/openssl-fixes-high-severity-dtls-flaw.html



Analyst Observation

Today’s brief reflects a threat environment where the network edge, the vendor stack, and the executive inbox are all active attack surfaces simultaneously. The NetScaler exploitation is the most operationally urgent item — root access on an edge device with novel malware means organizations that patched late may already be compromised and don’t know it. The Bitget breach deserves more attention than it will likely receive: the attack vector was the security tooling itself, a category of risk that most vendor risk programs are not built to catch. The dual phishing cluster — one financially motivated, one state-sponsored — is not coincidence; it reflects a mature threat ecosystem where criminal and nation-state actors run parallel operations against the same target pool. The relevant question for CISOs is whether their session management and MFA implementation are robust enough to withstand both simultaneously, because right now, both are active.





Generated by DevSecOpsDadAttack cyber threat intelligence.

Share: X (Twitter) LinkedIn