- web shellDeployed by attackers on compromised security appliance.
- custom withdrawal toolUsed by attackers to steal cryptocurrency.
ThreatNoir Afternoon Brief — September 30
Afternoon Review in IT Security — September 30, 2026
The cryptocurrency and enterprise security landscape faces mounting threats as attackers exploit zero-day vulnerabilities in third-party tools and widely deployed infrastructure products. Today's threat intelligence reveals significant breaches, critical patching requirements, and emerging risks from artificial intelligence integration in development workflows.
Bitget Hacked via Zero-Day in Third-Party Security Products
Cryptocurrency exchange Bitget disclosed that attackers responsible for stealing $387.5 million last week gained access to the platform by exploiting a zero-day vulnerability in third-party security products. The breach highlights a critical supply chain risk where trusted security tools become vectors for sophisticated attacks. Investigators identified the use of a custom withdrawal tool and web shell malware deployed during the intrusion. Source: Bitget hacked via zero-day in third-party security products
Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT
Unknown threat actors have been actively exploiting CVE-2026-88772, a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances, to compromise organizations across North America and Europe. Mandiant Consulting and Google Threat Intelligence Group observed this activity in September 2026, targeting government, financial services, technology, education, and legal and professional services sectors. The exploitation enables root-level access, with attackers deploying post-exploitation tools designated as WHIPSHOT and SLAPSHOT to maintain persistence and expand their foothold within victim networks. Source: Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT
High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL
Approximately a dozen high-severity vulnerabilities have been addressed in both OpenSSL and WolfSSL, critical open source cryptographic libraries relied upon across countless enterprise and internet-facing systems. The patched flaws include CVE-2026-84782, CVE-2026-84783, CVE-2026-89102, CVE-2026-89136, and CVE-2026-93302. Organizations using these libraries must prioritize patching to maintain the integrity of their SSL/TLS communications and protect against potential cryptographic attacks. Source: High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL
AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub
Security researchers at Glow discovered that AI coding agents tasked with sharing screenshots of code changes inadvertently exposed over 13,000 internal company images in public GitHub repositories. The leaked materials included sensitive information such as customer billing records and unreleased product features from developers at more than 300 organizations. The exposure underscores an emerging risk as development teams integrate AI tools without adequate safeguards to prevent inadvertent disclosure of proprietary and confidential data. Source: AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub
Today's threat landscape demonstrates that attackers continue to target both infrastructure and supply chains while new technologies introduce unexpected data exposure risks. Organizations must maintain vigilant patch management, vet third-party security tools, and establish clear governance around AI tool deployment in development environments.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- NetScaler ADC and Gateway appliance vulnerability
- WHIPSHOTPHP web shell used for C2 communication
- SLAPSHOTPython tunneler for internal network access
- High-severity vulnerability in OpenSSL allowing heap memory leaks or crashes in DTLS.
- High-severity vulnerability in WolfSSL allowing peer authentication bypass by forging CA certificates.
- Medium-severity vulnerability in OpenSSL causing DoS on multi-threaded TLS clients.
- High-severity vulnerability in WolfSSL allowing forging of certificates for arbitrary identities.
- High-severity vulnerability in WolfSSL allowing malicious server to bypass authentication with Raw Public Key.