Weekly review

ThreatNoir Afternoon Brief — September 30

2026-09-30Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — September 30, 2026

The cryptocurrency and enterprise security landscape faces mounting threats as attackers exploit zero-day vulnerabilities in third-party tools and widely deployed infrastructure products. Today's threat intelligence reveals significant breaches, critical patching requirements, and emerging risks from artificial intelligence integration in development workflows.

Bitget Hacked via Zero-Day in Third-Party Security Products

Cryptocurrency exchange Bitget disclosed that attackers responsible for stealing $387.5 million last week gained access to the platform by exploiting a zero-day vulnerability in third-party security products. The breach highlights a critical supply chain risk where trusted security tools become vectors for sophisticated attacks. Investigators identified the use of a custom withdrawal tool and web shell malware deployed during the intrusion. Source: Bitget hacked via zero-day in third-party security products

Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

Unknown threat actors have been actively exploiting CVE-2026-88772, a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances, to compromise organizations across North America and Europe. Mandiant Consulting and Google Threat Intelligence Group observed this activity in September 2026, targeting government, financial services, technology, education, and legal and professional services sectors. The exploitation enables root-level access, with attackers deploying post-exploitation tools designated as WHIPSHOT and SLAPSHOT to maintain persistence and expand their foothold within victim networks. Source: Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL

Approximately a dozen high-severity vulnerabilities have been addressed in both OpenSSL and WolfSSL, critical open source cryptographic libraries relied upon across countless enterprise and internet-facing systems. The patched flaws include CVE-2026-84782, CVE-2026-84783, CVE-2026-89102, CVE-2026-89136, and CVE-2026-93302. Organizations using these libraries must prioritize patching to maintain the integrity of their SSL/TLS communications and protect against potential cryptographic attacks. Source: High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL

AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub

Security researchers at Glow discovered that AI coding agents tasked with sharing screenshots of code changes inadvertently exposed over 13,000 internal company images in public GitHub repositories. The leaked materials included sensitive information such as customer billing records and unreleased product features from developers at more than 300 organizations. The exposure underscores an emerging risk as development teams integrate AI tools without adequate safeguards to prevent inadvertent disclosure of proprietary and confidential data. Source: AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub

Today's threat landscape demonstrates that attackers continue to target both infrastructure and supply chains while new technologies introduce unexpected data exposure risks. Organizations must maintain vigilant patch management, vet third-party security tools, and establish clear governance around AI tool deployment in development environments.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL
CVE5
  • High-severity vulnerability in OpenSSL allowing heap memory leaks or crashes in DTLS.
  • High-severity vulnerability in WolfSSL allowing peer authentication bypass by forging CA certificates.
  • Medium-severity vulnerability in OpenSSL causing DoS on multi-threaded TLS clients.
  • High-severity vulnerability in WolfSSL allowing forging of certificates for arbitrary identities.
  • High-severity vulnerability in WolfSSL allowing malicious server to bypass authentication with Raw Public Key.