Someone else’s computer is not an architecture... AI • Tesla • Cyber Security. rootwall.info - WIP

Pinned Tweet
🚨URGENT 🚨 DROP EVERYTHING. Internet-facing NetScaler boxes are under active fire. Multiple unpatched Citrix NetScaler RCE and auth-bypass flaws are already being exploited in the wild. If you cannot patch right now, take those instances offline immediately. This is not a “patch next maintenance window” problem. Attackers are already dropping webshells and walking past login. Unpatched Gateway / AAA / SAML IdP appliances should be treated as compromised until proven otherwise. Act now: isolate or shut down exposed NetScaler instances, then patch to the fixed builds and hunt for compromise. Every hour they stay up is an open door. 🚨URGENT 🚨
We are currently rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild. While details are scarce, the information is credible. watchTowr Platform clients have been made aware of their Citrix NetScaler exposure.
2
1
3
2,197
For this past few weeks of cybersecurity news, the internet was not quiet. You were just looking at the wrong layer. No flashy worm. Just PeopleSoft, Cisco ISE, SharePoint, MikroTik, TeamCity, Zyxel, F5, Check Point, and a file-transfer vendor telling customers to power off for nine hours. A WAF is not a patch. ShinyHunters proved it with one encoded letter. %50 slipped past the filter, PeopleSoft decoded it, web shells landed. If your fix was a string match on /PSEMHUB/, you filtered the polite attackers. Same plot everywhere. Edge boxes on the internet. Build servers treated like toasters. Switches still on factory passwords. About $352 million walked out of Bitget hot wallets. ShinyHunters claimed FBI Jobs. OpenAI agents wandered into government sites. A stolen Cloudflare key painted ClickFix across roughly 100,000 pages. None of this needed a movie villain. It needed unpatched hubs, management ports on 443, device-code OAuth, and someone clicking Approve. If it terminates TLS for other people, patch it. If it builds your software, treat a breach as a credential incident. If an agent can fetch URLs, log it like a junior admin with prod keys. See the thread below! Be warned, this will wear off your rosy view of technology....
26
164
This was the news for today. Patch what you can tonight. Until next time.
2
CISA KEV catalog itself (source of truth for the scores above) Not an exploit. It is the list federal civilian agencies must meet under BOD 26-04. @CISAgov cisa.gov/known-exploited-vul… Fix: Pull the JSON feed daily. Ticketing SLA = KEV due date, not “next change window.”
3
WSO2 pre-auth admin takeover (standalone because of the 10.0) CVE-2026-5430 | CVSS 10.0 | KEV yes (24 Sep, due 27 Sep) Forged JWT / unsupported algorithm on API Manager 4.1.0–4.6.0 and related Control Plane / Gateway 4.5–4.6. Honeypot hits from 13 Sep. Same article as #7. @BleepinComputer bleepingcomputer.com/news/se… Fix: Vendor patch. Do not expose admin or token endpoints.
1
40
Japan Digital Agency VPN breach CVE not named in the weekly. CVSS N/A. KEV unknown pending vendor CVE. About 246,000 names and contacts of officials and contractors. @checkpoint research.checkpoint.com/2026… Fix: Patch the VPN appliance. MFA. Treat the contact list as spear-phish fuel.
59
x47.c Windows botnet, AI API drain CVE N/A. CVSS N/A. KEV no. Sold by WraithTools. C2 panel, 18 DDoS methods, SOCKS5, credential theft. “AI stealth” module is advertised as using Grok to pick persistence (startup, scheduled tasks). “AI API drain” burns paid OpenAI / xAI credits. @SecurityWeek securityweek.com/new-x47-c-w… @InfosecurityMag infosecurity-magazine.com/ne… Fix: EDR on Windows. Alert on unexpected LLM API calls from endpoints. Rotate leaked API keys. Cap auto top-ups on AI billing.
44
Cisco Secure Email Gateway root RCE CVE-2026-76461 | CVSS 9.8 | KEV yes (federal due 17 Sep) Crafted mail, SQL in parser, root on AsyncOS. @TheHackersNews thehackernews.com/2026/09/ci… Fix: 15.5.5-0141, 16.0.4-302, or 16.5.0-780. No workaround.
47
WaterPlum (DPRK): 30,000 devices, $10.7 million CVE N/A. CVSS N/A. KEV no. Joint advisory. Dec 2025 through Jul 2026 activity, public this window. @BleepinComputer bleepingcomputer.com/news/se… Fix: Hardware keys. Isolated crypto workstation. No cracked “wallet update” installers.
22
Ubuntu AF_UNIX container escape CVE-2026-80521 | CVSS 7.8 | KEV no at last check Use-after-free. Host root from a container. Upstream fixed 6 Aug. Ubuntu LTS still listed vulnerable when the exploit dropped. @TheHackersNews thehackernews.com/2026/09/ex… Fix: Watch Ubuntu kernel USNs for 22.04/24.04/26.04. Do not share a host kernel with untrusted containers.
29
Brevo + Cloudflare Worker ClickFix, about 100,000 sites CVE N/A. CVSS N/A. KEV no. Stolen Cloudflare API key. Malicious Worker in front of brevo.com / sibforms.com on 14 Sep. @SecurityWeek securityweek.com/brevo-suppl… Fix: Rotate Cloudflare tokens. Review Workers. CSP on third-party marketing scripts.
24
EvilTokens device-code phishing takedown CVE N/A. CVSS N/A. KEV no. Storm-2992. 12,000+ Microsoft accounts, 10,000+ orgs. UK arrests. @BleepinComputer bleepingcomputer.com/news/se… Fix: Disable unused device-code grant. Alert on new OAuth apps. Never type a code you did not request.
37
OpenAI agents on government sites CVE N/A. CVSS N/A. KEV no. Census and SEC data access, Education probe, earlier Australia Medicare stats portal. Late notice criticized. @Nextgov nextgov.com/cybersecurity/20… Fallback index dated 25 Sep 2026 @Nextgov nextgov.com/topic/cyber-thre… Fix: Challenge and rate-limit agent user-agents. No bulk extract without a human session.
41
Check Point Management path traversal + Gateway VPN RCE CVE-2026-93616 | CVSS 9.8 | KEV yes (added 22 Sep, due 25 Sep) CVE-2026-85102 | CVSS 9.8 | KEV yes (added 22 Sep, due 25 Sep) 93616: unauth script upload on Management / MDS / Log / SmartEvent, exploited from 23 Jul, wave from 12 Sep. 85102: pre-auth VPN cert RCE on Security Gateway. @BleepinComputer bleepingcomputer.com/news/se… @BleepinComputer bleepingcomputer.com/news/se… Fix: R82.20 Security Hotfix. Management behind a firewall. Trusted Clients only. Hunt CN=vpn cert subjects in the advisory.
22
F5 BIG-IP APM OAuth 0-day RCE CVE-2026-94127 | CVSS 9.8 | KEV yes (added 22 Sep, due 25 Sep) Hits APM when it is an OAuth Authorization Server. OAuth client-only setups not affected. @BleepinComputer bleepingcomputer.com/news/se… Fix: F5 hotfix. iRule from support if you cannot patch today. Hunt OAuth failures then TMM SIGABRT.
34
Arista VeloCloud Orchestrator on-prem 0-day CVE-2026-93952 | CVSS 10.0 | KEV yes (added 22 Sep, due 25 Sep) Improper input validation when Edge cert auth is on. No tenant creds needed. Needs network to the VCO web UI. @BleepinComputer bleepingcomputer.com/news/se… Fix: Hosted 5.2.3.16+ or 6.4.2.8+. On-prem follow Arista advisory. VCO not on the internet.
36
Zyxel GS1900 stack overflow CVE-2026-7273 | CVSS 8.8 | KEV yes (added 21 Sep, due 24 Sep) LAN unauth CGI overflow. About 996 switches in 48 countries. Many still on default creds. @TheHackersNews thehackernews.com/2026/09/zy… Fix: Firmware newer than 2.90(.1)C0. Change factory passwords. Isolate management VLAN.
14
JetBrains TeamCity auth bypass, now ransomware CVE-2026-63077 | CVSS 9.8 | KEV yes (added 5 Aug, ransomware flag updated 24 Sep) HTTP(S) to OS command execution on on-prem TeamCity. @BleepinComputer bleepingcomputer.com/news/se… Fix: 2025.11.7 or 2026.1.3+. No public login. Rotate every token that lived on the box.
35
CISA KEV batch: SharePoint, MikroTik, WSO2, Adobe Commerce CVE-2026-65660 SharePoint code injection | CVSS 8.8 | KEV yes (25 Sep, due 28 Sep) CVE-2026-67279 MikroTik RouterOS workflow bypass | CVSS about 6.5, chain to CVE-2026-86060 | KEV yes (25 Sep, due 28 Sep) CVE-2026-5430 WSO2 JWT / path auth bypass | CVSS 10.0 | KEV yes (24 Sep, due 27 Sep) CVE-2026-71362 Adobe Commerce / Magento authz | CVSS 9.1 | KEV yes (24 Sep, due 27 Sep) @BleepinComputer bleepingcomputer.com/news/se… Fix: Patch all four. MikroTik off WAN SSH. If the router was public, rebuild.
21