Briefing โ€” 28 September 2026

๐ŸŽง Subscribe to the podcast feed

Security News

Citrix NetScaler ADC & Gateway โ€” 8 CVEs including Unauthenticated RCE (Citrix / NVD) โ€” Citrix published eight vulnerabilities (CVE-2026-88771 through CVE-2026-88778) affecting NetScaler ADC and Gateway; two are Critical (CVSS 4.0: 9.5) including an unauthenticated arbitrary command execution flaw โ€” patch immediately to 14.1-73.37 or 13.1-64.23.

Alleged Data Breach of Meta (Threat Intelligence) โ€” An actor on a major underground forum is claiming a data breach affecting Meta; details remain unconfirmed but the claim is circulating across multiple channels and warrants monitoring.

Alleged Sale of X (Twitter) Farm Infrastructure Access (Threat Intelligence) โ€” Bulk account and automation infrastructure access for X is being advertised on dark markets, suggesting compromised tooling rather than a traditional data dump.

Alleged Sale of Wealthfront User Data โ€” 1.3M Records (Threat Intelligence) โ€” A threat actor is claiming to sell 1.3 million records from US investment platform Wealthfront; no public confirmation from the company at time of writing.

Alleged Data Sale โ€” Alaxione, 8.6M Records from 168 Medical Centres (Threat Intelligence) โ€” โš ๏ธ A French firm called Alaxione, reportedly aggregating data from 168 medical centres, is the subject of a claimed sale of 8.6 million records โ€” a significant potential healthcare data exposure.

Alleged Data Sale โ€” Principal Financial Group, 2.2GB (Threat Intelligence) โ€” A dataset of approximately 2.2 gigabytes attributed to Principal Financial Group, a major US insurance and financial services company, is being offered for sale underground.

Alleged Data Breach of Banco Azteca (Grupo Salinas / Elektra) (Threat Intelligence) โ€” An actor claims to be selling employee records and customer data from Banco Azteca, part of Mexico's Grupo Salinas conglomerate.

MariaDB Information Disclosure Zero-Day for Sale (Threat Intelligence) โ€” A zero-day vulnerability in MariaDB with information disclosure impact is being actively advertised on underground markets; organisations running MariaDB in production should monitor for patches and review exposure.

โš ๏ธ Alleged Unauthorised Access to Bangla Trac Group's Daudkandi Power Plant (Threat Intelligence) โ€” A threat actor claims network access to the Daudkandi Power Plant operated by Bangla Trac Group in Bangladesh โ€” a live electricity generation facility, representing a potential OT intrusion.

โš ๏ธ Alleged Sale of Spanish Gas & Energy Company Database (Threat Intelligence) โ€” A database attributed to an unnamed Spanish gas and energy company is circulating on underground forums, raising concerns for the European energy sector.

โš ๏ธ Alleged Breach of Southern Company โ€” 400K PII Records (Threat Intelligence) โ€” Southern Company, a major US electric utility, is named in a breach claim involving approximately 400,000 personal records.

INC RANSOM Claims North Slope Borough School District (Threat Intelligence) โ€” INC RANSOM has posted North Slope Borough School District in Alaska as a new victim, continuing the group's targeting of public sector education.

AHEAD IT Services Hit by INC RANSOM (Threat Intelligence) โ€” Managed IT services provider AHEAD has been listed on the INC RANSOM leak site.

Dediserve Limited Posted by n0n Ransomware (Threat Intelligence) โ€” UK-registered hosting and cloud provider Dediserve Limited has appeared on the n0n ransomware group's victim blog.

UK & Critical National Infrastructure

No UK-specific cyber incidents were surfaced in today's feeds. The NCSC published no new alerts or advisories in the past 48 hours.

The priority for UK defenders this week is the Citrix NetScaler disclosure. NetScaler ADC and Gateway are deployed across UK public sector, financial services, and CNI operators as perimeter appliances handling VPN and remote access. CVE-2026-88771 permits unauthenticated remote code execution โ€” an attacker does not need credentials to compromise the device. Fixed builds are 14.1-73.37 and 13.1-64.23. Organisations should patch immediately, and review NetScaler access logs for suspicious activity against management interfaces and authentication endpoints dating back to Saturday 27 September.

Also note the power plant intrusion claim (Bangla Trac / Bangladesh) and the sale of a Spanish energy company database โ€” indicators of continued threat actor interest in operational technology and energy sector targeting globally, relevant to UK CNI risk assessment.

Ransomware Victims (48h)

9 victims ยท 5 groups

GroupVictimCountrySector
arcusmediaPantaneiro CapasBRManufacturing
BarracudaInternational Chemical Co.โ€”Manufacturing
emperadorCar Service AbschleppDEโš ๏ธ Transportation
m3rxcipher.systemsUSTechnology
qilinXICOMXโ€”
qilinIslandCATechnology
qilinRevenga Smart SolutionsESTechnology
qilinWillatt & FlickingerUSโ€”
StormFirst Secure Bank GroupUSFinancial Services
Show Comments