ARCHIVED READING · PERMANENT RECORD
WEEK OF OCTOBER 5, 2026
77/ 100HIGH PRESSURE
Two Citrix NetScaler zero-days under confirmed global exploitation draw a dedicated CISA alert and a three-day federal patch deadline — the strongest exploitation event since launch — and pressure climbs toward the top of the high band.
↑ 4 POINTS SINCE LAST WEEK2026-W41ISSUED 2026-10-05 · 14:00 UTCMETHODOLOGY V1.1
SIGNALS
ACTIVE EXPLOITATION↑
RISING
After three weeks flat at peak, exploitation breaks higher: a pair of NetScaler ADC/Gateway zero-days exploited globally with a documented post-exploitation toolkit, plus Cisco SD-WAN Manager and FortiMail zero-days in the same window.
RATIONALE & SOURCE TYPES
Eight KEV additions, all current flaws — no vintage catch-up. The core event: Citrix NetScaler CVE-2026-88771 and CVE-2026-88772 (unauthenticated RCE on ADC and Gateway), exploited as zero-days, drew both a dedicated CISA alert confirming global exploitation and a three-day federal remediation deadline, and the post-exploitation picture is unusually complete — root access, WHIPSHOT and SLAPSHOT implants, a superuser-creating payload, and web shells mapped to CSS-like URLs. Around it: a Cisco Catalyst SD-WAN Manager authentication-bypass zero-day, a Fortinet FortiMail zero-day, an Apple flaw used in targeted attacks, and MikroTik, SharePoint, and WordPress additions. Bitget confirmed a third-party security-product zero-day behind its $387.5M theft. This exceeds the August NetScaler emergency (a single CVE in a vintage-heavy week): first rising week since W35. Confidence is high.
CISA KEVGOV ADVISORYVENDOR ADVISORYINCIDENT REPORTING
IDENTITY & HUMAN ATTACK PRESSURE→
STEADY
More than 543,000 valid credentials sit exposed in public GitHub repositories; phishing campaigns now routinely deploy legitimate remote-management tools after stealing Microsoft 365 sessions.
RATIONALE & SOURCE TYPES
Research finds over 543,000 live credentials — API keys, tokens, passwords — exposed in public GitHub repositories, a standing self-inflicted attack surface. A US-focused executive phishing campaign steals Microsoft 365 sessions and installs RMM tooling for persistent remote access, and a parallel campaign abuses MSP360 to deploy ScreenConnect — attacker hands-on-keyboard arriving as legitimate software. A flaw in the official MCP Python SDK that could let malicious servers steal OAuth credentials is a watch item for AI-tool adopters. Sustained pressure at the raised level, no verified step-change. Confidence is medium.
INCIDENT REPORTING
INTRUSION / RANSOMWARE TEMPO→
STEADY
The Pentagon discloses a nine-month-old breach of 3M+ personnel records; Bitget's $387.5M theft is confirmed; Operation KillSwitch dismantles KillSec and a ShinyHunters suspect is arrested.
RATIONALE & SOURCE TYPES
The Pentagon confirmed a Defense Manpower Data Center breach exposing records of more than three million people, including Social Security numbers — but the intrusion ran from October 2025 to July 2026 through a file-sharing flaw and was only discovered after nine months: disclosure-lag evidence, held, consistent with prior treatment. Bitget confirmed its $387.5M theft came through a third-party security-appliance zero-day with weeks of pre-positioned access — severe, but concentrated in one exchange. Against that, two enforcement wins: Operation KillSwitch seized KillSec's leak site, five servers, and 110TB of data with three arrests including the suspected 16-year-old administrator, and Dutch police arrested a suspect in the ShinyHunters investigation. No Item 1.05 filings this window. Net: steady. Confidence is medium.
INCIDENT REPORTING
THREE MOVES THIS WEEK
01Patch NetScaler ADC/Gateway for CVE-2026-88771/88772 now and hunt anything unpatched since September 27 as compromised: look for rogue superuser accounts, WHIPSHOT/SLAPSHOT implants, and web shells behind CSS-like URLs.
02Patch the rest of the zero-day set in the same pass — Cisco Catalyst SD-WAN Manager, FortiMail, Apple — plus Kiteworks' maximum-severity flaw before it joins them.
03Sweep your public GitHub footprint for committed credentials and rotate what you find; brief executives and finance staff that session-stealing phishing now installs legitimate RMM tools as its payload.
WHY WE BELIEVED THIS
RECEIPT LOG · WEEK 4112 RECEIPTS
REVISION HISTORY
2026-10-05 · 14:00 UTCOriginal publication.
← FULL ARCHIVE