Skip to content Skip to footer

AI Security & Cybersecurity — September 28, 2026

Findings

  1. [1] 2026-09-28 Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild

    Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild appeared first on Unit 42.

  2. [2] 2026-09-28 NeedyMantis: Unpacking a post-compromise malware family used in targeted operations

    In this article Observed operators and targetingMalware packaging and distributionNeedyMantis architecture and capabilitiesMitigation and protection guidanceHunting queriesIndicators of compromise Microsoft Threat Intelligence has identified NeedyMantis, a modular post-compromise malware family observed in a limited number of targeted operations affecting telecommunications… NeedyMantis is observed during the post-compromise stage of an intrusion after an actor has established access to the target environment. While one known user of the malware, Storm-3069, has been associated with supply chain compromises, Microsoft has not observed NeedyMantis… The malware’s configuration was stored in a dnsapi.dll file from the custom file archive. This file name spoofs a Windows networking library. In the sample analyzed, the file contains a 3448-byte binary structure. The structure includes the following fields: 0x00:… Microsoft Defender customers can refer to the list of applicable detections below. Microsoft Defender coordinates detection, prevention, investigation, and response across endpoints, identities, email, apps to provide integrated protection against attacks like the threat discussed in this blog. Tactic Observed… Identify connectivity utilizing the NeedyMantis hard-coded user-agent. search in (DeviceNetworkEvents, DeviceEvents, UrlClickEvents, EmailUrlInfo) "Firefox/21.0" | where Timestamp > ago(7d) | extend SourceTable = $table | project Timestamp, DeviceName = iff(isnull(DeviceName), "", DeviceName), AccountUpn = coalesce(InitiatingProcessAccountUpn, AccountUpn, ""), AccountName = coalesce(InitiatingProcessAccountName,…

Where Kimbodo Comes In

Kimbodo builds and operates this in production for businesses — see our AI Security & Guardrails practice, or Request a Security Review.

Sources

  1. [1] Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild
  2. [2] NeedyMantis: Unpacking a post-compromise malware family used in targeted operations

Leave a comment

0.0/5