Skip to content

Sam's News — security — 2026-09-28

Security

8 CISA adds two critical Citrix NetScaler flaws to known exploited vulnerabilities list

The US Cybersecurity and Infrastructure Security Agency officially catalogued two critical Citrix NetScaler vulnerabilities as being actively exploited globally.

  • Two unpatched zero-day remote code execution vulnerabilities
  • Actively exploited in the wild before any patch existed
  • Distinct from CVE-2026-19490 (patched August 19)
  • Discovered during forensic investigations; exploitation occurred pre-patch
  • Citrix patches expected early week of September 28
  • No vendor bulletin or workaround available; future patches won't show prior access

Sources: The Hacker News RSS, SecurityWeek RSS Update to: Two Unpatched Citrix NetScaler Zero-Day Vulnerabilities Exploited in Wild

8 JadePuffer ransomware operators conduct agentic AI attacks on Azure cloud infrastructure

The JadePuffer ransomware gang is using AI-driven agents to target Azure tenants, conduct reconnaissance, steal credentials, and destroy cloud resources.

Sources: BleepingComputer RSS Update to: JADEPUFFER-linked attackers use compromised service principals to delete Azure resources

7.5 FBI declares cyber incident; ShinyHunters sets 7-day deadline

The FBI formally designated a cybersecurity incident affecting its FBIJobs.gov recruiting portal on September 28, with the extortion group ShinyHunters claiming responsibility and setting a seven-day deadline. A stolen sample revealed names, addresses, phone numbers, dates of birth, Social Security numbers, and emergency contacts for thousands of FBI employees, though the entry point and total scope remain unconfirmed.

  • FBI designated incident on September 28; ShinyHunters claimed responsibility 4 days earlier
  • ShinyHunters set 7-day deadline with demands at two named officials
  • Stolen sample: 5,000-line spreadsheet with names, addresses, SSNs, emergency contacts for FBI employees
  • FBI unable to confirm entry point: own systems or third-party FBIJobs vendor

Sources: Shattered AI Web Searched, shattered.io RSS

7.5 Over 16,000 misconfigured Supabase databases expose PII and authentication tokens

UpGuard discovered approximately 16,000 misconfigured Supabase databases exposing sensitive user data including names, addresses, passwords, and authentication tokens. Exposures span worldwide but concentrate in the U.S., with data from adult streaming sites, valet services, immigration firms, and government consulates; the issue is attributed to insecure configurations in AI-generated code.

  • ~16,000 Supabase databases misconfigured, worldwide but U.S.-concentrated
  • Exposed: names, addresses, passwords, authentication tokens, contact information
  • One database used for SMS interception in virtual SIM farm scams
  • Attributed to AI-generated code with security flaws or inadequate configuration awareness

Sources: TechCrunch AI Web Searched, BleepingComputer RSS

7.5 Bitget Exchange Reports $388M Theft Via Third-Party Security Flaw

Bitget Exchange disclosed that attackers exploited a zero-day vulnerability in a third-party security product to steal approximately $388 million on September 28. The attacker obtained internal credentials, made small test transfers at 18:31 UTC to evade risk controls, then executed larger transfers 30 minutes later using legitimate credentials disguised as routine operations.

  • $388 million stolen via zero-day in third-party security product
  • Attacker obtained high-level internal credentials through vulnerability
  • Test transfers at 18:31 UTC below risk threshold; larger transfers 30 minutes later using legitimate credentials
  • Funds from hot/warm wallets; cold wallets unaffected; no private keys compromised

Sources: The Hacker News AI Web Searched

7.5 80,000+ organizations' AI logins exposed in infostealer credential theft

Infostealer malware has compromised AI account credentials and sessions across over 80,000 corporate domains, creating risks of account takeover and LLMjacking attacks. The breach affects shadow AI deployments and represents significant exposure of enterprise AI infrastructure.

  • 80,000+ corporate domains' AI credentials compromised
  • Risks include account takeover and LLMjacking attacks
  • Affects shadow AI deployments across enterprises
  • Stolen credentials enable unauthorized AI service and model access
  • Stolen Claude, Gemini, Cursor Pro, and Devin credentials most heavily traded
  • Average prices for stolen AI accounts doubled in 2026 compared to prior year
  • Infostealer malware increasingly targeting AI service credentials
  • Criminals use stolen accounts for automating phishing, malware development, and credential theft
  • Coding-assistant credentials highly attractive for software analysis and modification

Sources: Google News RSS AI Web Searched, BleepingComputer RSS, csoonline.com RSS

7 DC Health Agency Data Breach Exposes 400,000 Medicaid Records

The DC Department of Health Care Finance exposed Medicaid IDs and personal information of approximately 400,000 beneficiaries in a non-malicious data breach. Two website reports designed to display only summary statistics contained hidden personal data accessible to unauthorized users between 2023 and July 2026.

  • 400,000 Medicaid and DC Healthcare Alliance beneficiaries affected
  • Exposed data: Medicaid IDs, provider names, DOB, race, gender, ethnicity, ward
  • Not exposed: Social Security numbers, names, financial information
  • Breach occurred 2023–July 2026; discovered July 2026 and immediately remediated
  • No evidence of actual unauthorized access or misuse

Sources: SecurityWeek AI Web Searched

7 Gyazo data breach exposes 23.6 million user records

Screenshot platform Gyazo suffered a data breach affecting 23.62 million user records and approximately 490 million image metadata records discovered September 11, 2026. An unauthorized third party exploited a vulnerability in the image upload server accepting arbitrary command execution and deployed malware for database access.

  • 23.62 million user records and ~490 million image metadata records compromised
  • Exposed user data: names, emails, password hashes, device/session IDs, SSO tokens, subscription plans, usage statistics
  • 490 million metadata records from uploads January 2019 and earlier
  • Payment information (credit cards, bank accounts) not exposed
  • Threat actor access terminated within hours; no ransom demand or cybercrime group claim disclosed

Sources: CPO Magazine AI Web Searched

7 New Mexico jury finds Facebook liable for privacy deception

A New Mexico jury determined that Facebook deceived consumers regarding data privacy practices, awarding damages for approximately 44 million violations.

  • Over 43 million violations of New Mexico consumer protection law found
  • Cambridge Analytica breach: third-party app harvested ~87 million user profiles
  • Trial focused on deceptive statements about data protection and third-party app investigations
  • Maximum penalty requested: $5,000 per violation; final damages determined by judge
  • Jury rejected claims about false statements regarding harmful content removal

Sources: SecurityWeek AI Web Searched, The Record RSS

7 Nvidia launches AI agent safety platform with hardware watchdog

Nvidia announced the Open Agent Safety Platform on September 28, 2026, combining open-source software and hardware-based monitoring to constrain AI agent behavior. The platform uses OpenShell runtime and Sentry watchdog running on BlueField-4 DPUs to enforce policies outside agent control.

  • Two components: OpenShell (open-source runtime) and Sentry (hardware watchdog on BlueField-4 DPUs)
  • OpenShell v0.1.0 available broadly; originally introduced March 2026
  • Supports agents: Codex, Claude Code, Pi, Hermes
  • Kernel-level controls manage filesystem, process activity, and API access; all network traffic inspected
  • Response to incidents where frontier AI labs reported agents escaping evaluation environments

Sources: SecurityWeek AI Web Searched