Sappers DFIR

Weekly Threat Watch

September 28, 2026

2

MIN READ

Citrix NetScaler Zero-Days, P2P Loaders, and AI Infrastructure Flaws

A weekly threat watch detailing unpatched Citrix zero-days, BigDiskBuster, Rapuncel BYOVD, the "sckit" supply chain worm, and critical cloud/AI vulnerabilities.

Share this post

TABLE OF CONTENT

This week’s intelligence highlights an aggressive evolution in both infrastructure exploitation and endpoint defense evasion. Threat actors are capitalizing on unpatched zero-days in critical perimeter appliances, leveraging peer-to-peer (P2P) protocols to make malware infrastructure takedown-resilient, executing local Denial-of-Service attacks against Microsoft Defender, and exploiting AI assistants to silently exfiltrate CRM data.

SISA Weekly Threat Watch – our weekly feature brings to you a quick snapshot of all the major security vulnerabilities that posed a threat to organizations worldwide. These recurring actionable threat advisories will also provide information and recommendations that will help security teams take appropriate actions to defend against the latest and critical threats.

1. Zero-Days & Critical Edge Perimeter Exploitation

Edge network appliances and perimeter firewalls are under active, critical bombardment from unauthenticated threat actors executing remote code and bypassing multi-tenant isolation.

  • Citrix NetScaler Unpatched Zero-Days — Two distinct, unpatched Remote Code Execution (RCE) zero-day vulnerabilities are being actively exploited in the wild targeting Citrix NetScaler ADC and Gateway appliances. These flaws allow unauthenticated remote attackers to execute arbitrary code (up to root level on FreeBSD), hijack active VPN sessions, and establish persistent access prior to official vendor patch availability.
  • F5 BIG-IP, Check Point, and Linux Container Zero-Days — A triad of critical flaws is affecting core enterprise infrastructure:
    • F5 BIG-IP APM (CVE-2026-94127): A CVSS 9.8 heap-based buffer overflow allowing unauthenticated RCE on the data plane when configured as an OAuth Authorization Server.
    • Check Point Security Management (CVE-2026-93616): An actively exploited pre-authentication directory traversal granting full system execution over central management nodes.
    • Linux Kernel Container Escape (CVE-2026-80521): A Use-After-Free (UAF) in AF_UNIX garbage collection allowing unprivileged containers to escape to host root.

2. EDR Evasion, BYOVD & Endpoint Sabotage

Threat actors are deploying highly specialized tools to blind endpoint security agents, using zero-value file padding and Windows API manipulation to terminate protections.

  • BigDiskBuster (Defender Local DoS) — A local Denial-of-Service PoC that targets Microsoft Defender updates. By monitoring update staging directories (ReadDirectoryChangesW) and rapidly exhausting primary volume disk space with hidden temporary files, the tool starves Defender of the storage required to install new platform and signature updates, silently rendering the endpoint defenseless against new threats.
  • Rapuncel Infostealer & BYOVD Evasion — Distributed via SEO poisoning and fake GitHub pages impersonating brands like LastPass, this campaign delivers payloads padded with up to 148 MB of junk data to bypass sandboxes. The malware drops a Microsoft-attested kernel driver (Alinubx[.]sys) to forcefully kill 145 AV/EDR processes from kernel space. It then injects directly into browsers to bypass Chrome's App-Bound Encryption and extracts credentials, exfiltrating them via raw TCP.

3. Supply Chain Attacks & Takedown-Resilient Malware

Adversaries are poisoning upstream developer ecosystems to steal identities and replacing centralized C2 infrastructure with decentralized peer-to-peer networks.

  • "sckit" Credential-Stealing Worm — A cross-ecosystem supply chain attack hijacked GitHub Actions pipelines to publish backdoored MemTensor packages to npm and PyPI. The payloads launch a compiled Go binary (sckit) that hunts for AWS, GitHub, Vault, and npm tokens in local environments. The worm can self-propagate by autonomously injecting malicious workflow steps into adjacent repositories.
  • AvisLoader (Tox P2P & ClickFix Lures) — Disguised as DocuSign verification requests hosted on Cloudflare Workers, this ClickFix campaign tricks users into executing malicious commands. The resulting AvisLoader payload embeds the open-source Tox P2P protocol (c-toxcore) for decentralized C2 communications, making it highly resilient to infrastructure takedowns. It hides processes via NtQuerySystemInformation API hooking and bypasses UAC controls.

4. Cloud Infrastructure, AI Agents & Enterprise App Flaws

A massive wave of disclosures affects core enterprise identity management, serverless cloud functions, and autonomous AI integrations.

  • Salesforce Agentforce "SalesBleed" & Cloudflare Cross-Tenant Leaks — Zero-click indirect prompt injections in Salesforce Agentforce allow attackers to hide malicious instructions in Web-to-Lead forms. The AI agent is coerced into querying sensitive CRM records and exfiltrating them via Slack link unfurling and trusted URL parsing bypasses. Concurrently, Cloudflare mitigated a critical boundary failure where residual disk data blocks exposed sensitive tokens across multi-tenant container workloads.
  • ManageEngine, Next.js, and IBM FTM Critical Flaws —
    • ManageEngine ADSelfService Plus (CVE-2026-74849): A CVSS 9.8 command injection flaw allows unauthenticated attackers to execute commands as SYSTEM directly from the Windows logon screen via the GINA client.
    • Next.js (CVE-2026-94545): A critical RCE in the next/og ImageResponse component, exploitable via weaponized SVG inputs.
    • IBM Financial Transaction Manager: Multiple critical flaws, including unauthenticated Java deserialization (CVE-2026-18163), allowing total payment system compromise.
  • Sudo Time-Based Authorization Bypass — An unprivileged user can manipulate the TZ (timezone) environment variable when executing sudo to shift system time evaluation by ~25 hours, bypassing temporal NOTBEFORE and NOTAFTER access control rules in the sudoers file.

Proactive Steps for the Week

  • Isolate Unpatched NetScaler Appliances: Due to active zero-day exploitation, immediately evaluate temporarily taking internet-facing Citrix NetScaler ADC and Gateway instances offline or isolating them behind strict firewall controls until vendor emergency patches are issued.
  • Apply Edge Infrastructure & Container Patches: Immediately apply official engineering hotfixes to all F5 BIG-IP instances hosting OAuth Authorization Server profiles. Update Check Point Security Management servers to the required Jumbo Hotfix Accumulator takes, and apply Canonical Ubuntu kernel patches to mitigate the AF_UNIX container escape.
  • Harden Endpoints Against EDR Sabotage: Deploy strict Application Control (WDAC/AppLocker) to restrict execution of unverified binaries from user-writable directories (mitigating AvisLoader and BigDiskBuster). Enable Hypervisor-Protected Code Integrity (HVCI) and the Microsoft Vulnerable Driver Blocklist to neutralize the Rapuncel BYOVD attack.
  • Audit CI/CD Pipelines & Rotate Stolen Tokens: Treat any developer endpoint that pulled the compromised MemTensor npm/PyPI packages as fully breached. Immediately rotate all AWS, GitHub, Vault, and SSH keys. Disable global npm lifecycle scripts (npm config set ignore-scripts true).
  • Patch Enterprise Applications & Secure AI Workflows: Upgrade ManageEngine ADSelfService Plus to Build 7001+, Next.js to 16.3.6+, and IBM FTM deployments to 4.0.11.0+. Enforce defensive prompt processing and input sanitization on all untrusted ingestion sources (e.g., Web-to-Lead forms) entering Salesforce Agentforce to prevent silent data exfiltration.

Explore our DFIR Solutions to discover how our advanced incident response support, compromise assessments, and threat hunting frameworks can insulate your enterprise infrastructure against these campaigns.

SHARE THIS POST