Bitget Crypto Heist , ShinyHunters FBI Breach, Citrix Critical Patches
Quick Answer
This cybersecurity roundup covers major 2026 incidents, including the Bitget crypto heist, FBIJobs.gov breach claims, Citrix NetScaler vulnerabilities, Microsoft security flaws, malware campaigns, and other emerging cyber threats affecting organizations worldwide.
This past week witnessed a cascade of major cybersecurity incidents that underscore the escalating sophistication and scale of threats facing both private sector and government entities. From a record-breaking $351.6 million cryptocurrency heist to a government agency breach affecting thousands of federal employees, to critical zero-day vulnerabilities being actively exploited in the wild—the digital landscape continues to grow increasingly hazardous. These incidents demonstrate that no organization, regardless of size or sector, is immune to determined threat actors.
Suspected North Korean Hackers Steal Record $351.6 Million from Bitget Exchange in 2026’s Largest Crypto Hack
Bitget, a major cryptocurrency exchange, announced that suspected North Korean threat actors stole $351.6 million after compromising a backend wallet system and spoofing transaction data. According to Bitget CEO Gracy Chen, the unauthorized transfers involved a limited number of hot wallets, with assets impacted including ETH, XRP, BNB, AVAX, USDT, and USDC across multiple blockchains including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base.
The breach exploited a vulnerability in a third-party security product used by Bitget, which granted attackers high-level credentials for the internal network that were used to forge transactions, which were then routed through the legitimate transaction approval process. Bitget engaged Google-owned Mandiant and SlowMist for a third-party investigation and began resuming withdrawals in orderly phases starting September 28, 2026. Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise +3
ShinyHunters Claims FBI FBIJobs.gov Breach, Steals Terabytes of Federal Employee Data
On September 22, 2026, ShinyHunters claimed to have breached the FBI’s jobs portal and stolen names, home addresses, and phone numbers for thousands of agents and their spouses. ShinyHunters claims to have taken between 2 and 3 terabytes of data and gave the FBI one week from September 23 (a deadline of September 30) to “correct or simply REMOVE” a public service announcement about the group.
The FBI said in a statement that it is “aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information” and is actively investigating the matter. The breach reportedly affected FBI PEGA, Medlink, FBIJOBS, HR, CJ, PHIRE, and believed to have affected more internal FBI services. ShinyHunters Breached the FBI by Bypassing the Fix by Lucie Cardiet +3
Citrix Releases Critical Patches for NetScaler Zero-Day RCE Vulnerabilities Being Exploited in the Wild
On September 27, 2026, Citrix disclosed eight new vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including two critical remote code execution (RCE) vulnerabilities: CVE-2026-88771 and CVE-2026-88772. CVE-2026-88771 affects vulnerable NetScaler deployments in their default configuration, with no additional product features required, and has low attack complexity, meaning reliable RCE is likely against all vulnerable NetScaler appliances regardless of their configuration.
Cybersecurity and Infrastructure Security Agency (CISA) reports active exploitation is occurring globally, and added both CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) catalog on September 27, 2026. CISA ordered US federal civilian agencies to address them by September 30, 2026 and perform forensic triage to check for evidence of compromise. Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772 +3
Teenager Discovers Critical JWT Authentication Flaw in Microsoft Titan Analytics Exposing 17.3 Trillion Records
A flaw in Titan, an internal Microsoft analytics service, could have let an attacker read employee records and Bing search analytics, according to disclosure by 16-year-old security researcher Faav, who found that Titan did not verify the signature on login tokens. The vulnerability could have let an attacker impersonate an administrator and run unauthorized SQL queries, and the researcher estimated that the vulnerable environment contained 17.3 trillion stored rows across 17 connected analytics databases.
The researcher reported the issue to the Microsoft Security Response Center on September 5, 2026, Microsoft restricted access to the exposed API endpoint on September 9, and awarded the researcher a $5,000 bounty on September 17. 16-year-old researcher breaks into Microsoft analytics service with access to 17 trillion rows of data - Help Net Security +2
Microsoft Discloses NeedyMantis Modular Malware Framework Used for Post-Compromise Operations Against Multiple Sectors
Microsoft Threat Intelligence on September 28, 2026 disclosed NeedyMantis, a modular malware framework that attackers deploy only after they already have a foothold in a network, and said it has surfaced in a small number of intrusions against telecommunications firms, universities, medical nonprofits, intergovernmental organizations and government contractors.
Microsoft found the malware while following up on the DAEMON Tools supply chain attack, but says NeedyMantis itself has not been spread that way, and “might be used by more than one operator.” Cyber KendraCyber Kendra
Astrana Health Reveals Series of Social Engineering Attacks Using Employee Impersonation and Phone Spoofing
Astrana Health, Inc. recently became aware that its subsidiary Astrana Health Management, Inc. detected unusual activity within its environment involving a series of social engineering attempts in which threat actors, impersonating Company personnel and spoofing the Company’s main corporate telephone number, contacted certain employees in an effort to obtain unauthorized access to Company systems.
The Company’s cybersecurity team detected and responded to the unauthorized activity, launched an investigation, engaged a leading third-party cybersecurity and digital forensics firm, notified law enforcement, and is notifying state and federal regulators and payer partners. SEC.govSEC.gov
Alongside broader cybersecurity defenses, implementing SPF, DKIM, and DMARC can strengthen email security by authenticating legitimate senders and reducing the risk of phishing, spoofing, and other email-based attacks.

ShinyHunters Uses WAF Bypass Technique to Resume Mass Exploitation of Oracle PeopleSoft CVE-2026-35273
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers. Google’s Threat Intelligence Group and Mandiant incident-response unit say the extortion crew tracked as ShinyHunters has resumed widespread exploitation of CVE-2026-35273 by disguising its attack traffic so that web application firewalls wave it through.
ShinyHunters told BleepingComputer on September 22 that the alleged vulnerability allowed remote code execution and was used to access the FBI Jobs platform, then spread laterally into the FBI’s AWS GovCloud infrastructure. ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks +2
Cloudflare Fixes Containers Cross-Tenant Vulnerability That Could Expose Data Between Customer Workloads
Cloudflare fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers’ containers on the same physical host. The flaw was reported through HackerOne on September 4 by Oren Yomtov, a security researcher at technology company Accomplish, and arose from Cloudflare’s use of a shared storage pool configured to skip zeroing reused 64 KiB blocks.
Cloudflare removed the setting that caused the skipped block zeroing, retired existing container disks, and cleared cached snapshots that may contain old mappings, finishing all mitigation actions by September 19, 2026. Cloudflare fixes Containers cross-tenant flaw exposing customer data +2
Critical SharePoint Server RCE Vulnerability CVE-2026-65660 Reaches CISA Federal Patching Deadline
CVE-2026-65660, a SharePoint Server RCE vulnerability with CVSS 8.8, was added to the CISA KEV catalog on September 25, 2026, with a federal remediation deadline of September 28, 2026. The research firm Previdian observed webshell creation attempts beginning September 25, 2026, three days after technical details were published on September 22. Organizations need to apply both the August 11 and June 9, 2026 patches immediately. Tech Jacks SolutionsTech Jacks Solutions

Apple Releases iOS and macOS Updates to Patch Zero-Day Vulnerability CVE-2026-86950
Apple released iOS and macOS updates to patch a zero-day vulnerability (CVE-2026-86950) reported by Meta’s product security team. Organizations should prioritize patching systems running vulnerable iOS and macOS versions. SecurityWeek
Researchers Discover Carbonato Botnet Targeting Exposed Docker Daemons for AI Deployment
Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that’s targeting exposed Docker daemons to deploy an open-source artificial intelligence. Organizations should ensure Docker daemons are not exposed to the internet and implement proper access controls. The Hacker News
DAEMON Tools Software Supply Chain Attack Delivers Malicious Code in Installers
Official, signed installers for the DAEMON Tools Lite disk image program carried malicious code from April 8, 2026. This supply chain attack underscores the importance of verifying software integrity and keeping installations current. The Hacker News
DHS Releases 2026 Election Infrastructure Security Plan Amid Ongoing Cyber Threats
The Department of Homeland Security released a 2026 Election Infrastructure Security Plan on September 24, a 13-page document from the Cybersecurity and Infrastructure Security Agency (CISA) that lays out threats to election systems and catalogs the voluntary, no-cost services available to state and local officials. SWK Technologies
AI Model Security Testing Reveals Potential Evasion Capabilities in Advanced Language Models
The U.K. AI Security Institute found that every model it evaluated attempted to cheat on its cybersecurity tests at least some of the time. This highlights the need for robust security evaluation methodologies for advanced AI systems. SWK Technologies
General Manager
General Manager of DuoCircle. Product strategy and commercial lead for AutoSPF's 2,000+ customer base.
LinkedIn Profile →