Weekly review

ThreatNoir Morning Brief — September 29

2026-09-29Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — September 29, 2026

The threat landscape continues to evolve rapidly as vendors struggle with timely disclosure practices, industrial systems face new vulnerabilities, and sophisticated threat actors deploy advanced persistence mechanisms and AI-driven attacks across critical infrastructure and cloud environments.

Citrix Patches Actively Exploited NetScaler Zero-Days After Weekend of Unofficial Warnings

Citrix has released patches for zero-day vulnerabilities affecting its NetScaler products following a weekend period during which unofficial warnings circulated ahead of official vendor disclosure. The company's products remain a frequent target for attackers, and the delayed official notification left some customers vulnerable during the critical window between initial warnings and patch availability. Source: Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings

The affected vulnerabilities have been assigned CVE-2026-88771 and CVE-2026-88772. This incident highlights ongoing challenges in vendor communication and coordinated disclosure practices, particularly when unofficial warnings precede official security advisories.

One Packet Can Crash OT Servers in Industrial Sectors

A high-severity zero-day vulnerability has been identified in the TDengine time-series database, which is widely deployed across industrial, IoT, energy, and automotive environments. The vulnerability can be triggered by a single malformed packet, enabling attackers to crash operational technology servers with minimal effort. Source: One Packet Can Crash OT Servers in Industrial Sectors

This vulnerability, tracked as CVE-2024-22137, poses significant risk to critical infrastructure operators who rely on TDengine for time-series data collection and analysis. The ease of exploitation combined with the widespread deployment of the affected software underscores the need for immediate patching in vulnerable environments.

Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

Microsoft has published technical analysis of a malware family called NeedyMantis that threat actors are using to establish persistent, long-term access within networks they have already compromised. The malware has been observed in targeted intrusions against telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Source: Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

NeedyMantis leverages DLL sideloading techniques and employs a component known as WinSparkle.dll to maintain stealth and evade detection. The malware's use extends back at least several years, indicating a sustained campaign by sophisticated threat actors focused on maintaining durable access to high-value targets across multiple critical sectors.

JadePuffer Agentic AI Attacks Target Azure, Destroy Cloud Resources

The JadePuffer ransomware operator has escalated its capabilities by deploying agent-driven attacks specifically targeting Azure tenants. These sophisticated attacks leverage artificial intelligence to conduct reconnaissance, steal credentials, and systematically destroy core cloud infrastructure components. Source: JadePuffer agentic AI attacks target Azure, destroy cloud resources

The attacks employ multiple tactics including account enumeration, credential theft, and resource destruction, representing a significant evolution in cloud-targeting ransomware capabilities. This development underscores the growing threat posed by AI-augmented attack frameworks that can autonomously navigate cloud environments and cause widespread damage with minimal human intervention.

As threats continue to advance in sophistication and speed, organizations must prioritize rapid patch deployment, enhance monitoring of industrial and cloud environments, and strengthen detection capabilities for advanced persistence mechanisms and AI-driven attacks.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).