Cyber Threat Brief — September 30 2026
⚠️ This report is AI-generated. Always validate findings.
1. Mandiant: NetScaler root access deploys WHIPSHOT and SLAPSHOT — CVE-2026-88772 / CVE-2026-88771
TL;DR: Mandiant/GTIG documented post-exploit tooling on compromised NetScaler ADC/Gateway: PHP web shells (WHIPSHOT) and a Python tunneler (SLAPSHOT). CISA KEV due is today (2026-09-30) — preserve forensics, hunt the IoCs below, then patch to ≥14.1-73.37 / ≥13.1-64.23.
What’s New:
- Google Cloud / Mandiant blog (2026-09-29) names WHIPSHOT and SLAPSHOT; THN and BleepingComputer amplify 2026-09-29/30. Dozens of orgs hit in North America and Europe.
- Persistence maps
/vpn/media/*.ico→.sigPHP under/var/netscaler/gui/vpn/scripts/linux/, or runs.debas PHP viahttpd.conf. - Command channel uses NetScaler-looking headers (
NSC_CLIENTTYPE,NSC_LDAP,X-UX*). SLAPSHOT leaves/tmp/.uxdportand/tmp/.uxdlock. - eSentire traces CVE-2026-88771 webshell installs to 2026-09-05; GreyNoise reports mass exploitation surge after disclosure.
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
| CVE-2026-88771 / CVE-2026-88772 on NetScaler ADC/Gateway before 14.1-73.37 or before 13.1-64.23 (FIPS tracks: before 14.1-73.37 FIPS / before 13.1-37.279). KEV due 2026-09-30 (forensic triage Yes). | Vulnerable edge / KEV | T1190 | Inventory / show ns version | Preserve snapshot, support bundle, and /var/core before upgrade. Install the fixed build. Rotate secrets and certs that traversed the appliance. DTLS-off / block UDP/443 only mitigates CVE-2026-88772, not CVE-2026-88771. |
/etc/httpd.conf containing AddHandler application/x-httpd-php .deb (or .sig) and/or AliasMatch from /vpn/media/*.ico to /var/netscaler/gui/vpn/scripts/linux/*.sig | Persistence / config IoC | T1505.003 / T1036 | Appliance filesystem / config backup | Grep httpd.conf for application/x-httpd-php, php_flag, and AliasMatch. Treat hits as compromise; rebuild rather than clean in place. |
Webshell path /var/netscaler/gui/vpn/scripts/linux/*.sig (or PHP-bearing *.deb / nsginstaller* / nsgclient* in that directory) | Webshell IoC | T1505.003 | Filesystem / file | Run file and grep for <?php, eval(, and base64_decode( under the VPN scripts directory. Quarantine matches and rebuild. |
| SHA256 5ea5ea61e9062822bee3f66ef5ff47c217178d9e31936ad6daf10c5dfae44d12 (eSentire .ico-variant webshell) | File hash IoC | T1505.003 | Appliance filesystem / malware scanner | Hash-scan NetScaler VPN script dirs for this SHA256. Also check sibling hash 7add390ceee4a1373211b3e340451b34f08965fc4d805f94c9b8cebdc0775774 (.deb variant). |
HTTP request header NSC_CLIENTTYPE (or NSC_LDAP / X-UX) carrying Base64 command data | C2 / webshell traffic | T1071 / T1505.003 | NetScaler httpaccess / AppFlow | Alert when NSC_CLIENTTYPE, NSC_LDAP, or X-UX headers contain Base64 payloads. Correlate with /vpn/media/*.ico requests that return HTTP 404 with multi-KB bodies. |
Lock/port files /tmp/.uxdport and /tmp/.uxdlock (SLAPSHOT) | Process IoC | T1090 | Appliance filesystem / sockstat | List /tmp/.uxdport and /tmp/.uxdlock. Read the port from .uxdport and inspect the listener. Hunt nohup/Python processes that reference those paths. |
/bin/sh permissions -rwsr-xr-x (setuid root) on the NetScaler appliance | Priv persist | T1222 / T1548.001 | Appliance filesystem | Run ls -l /bin/sh. Treat setuid root as compromise evidence; rebuild and rotate credentials after patch. |
| Actor IPv4 143.198.7.94 (Mandiant scanning/staging; also hunt 157.254.167.12 and eSentire list including 149.104.78.141) | Network IoC | T1190 | Firewall / NetScaler audit | Block or heighten logging for 143.198.7.94 and related campaign IPs. Correlate with NSPPE crashes and DTLS handshake failures. |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | None — verified | Existing CitrixBleed / CVE-2023-3519 / CitrixBleed2 analytics target /oauth/idp/..., SAML paths, or memory-overread URLs — not WHIPSHOT headers, .uxdport, or .sig/.deb PHP handlers. |
| Elastic | None — verified | No emerging-threat rule for CVE-2026-88771/88772, WHIPSHOT, or SLAPSHOT in local rule tree. |
| Sigma | None — verified | ET rules cover CVE-2019-19781 / CVE-2020-8193 / CVE-2023-4966 only. No WHIPSHOT / NSC_CLIENTTYPE / /tmp/.uxdport rule. |
Hunt hint: Inventory builds against 14.1-73.37 / 13.1-64.23. Preserve forensics, then patch. Grep httpd.conf for non-.php PHP handlers and /vpn/media/ AliasMatch. Hunt NSC_CLIENTTYPE / NSC_LDAP / X-UX headers, /tmp/.uxdport, setuid /bin/sh, and NSPPE crash plus DTLS handshake-failure pairs. Run NetScaler Console IOC scan after patch.
Sources: Google / Mandiant · The Hacker News · BleepingComputer · eSentire · CTX697096 · CISA KEV · THN on X · Sep 28 brief
Status Updates
- CVE-2026-86950 (Apple CoreGraphics): CISA added to KEV on 2026-09-29 (catalog 2026.09.29 / 1729). Due 2026-10-02; forensic triage Yes. Keep patching to iOS/iPadOS 26.7.1, Tahoe 26.7.1 (25G241), Sequoia 15.8.1 (24H32). Sep 29 brief.
- CVE-2026-88771 (Citrix NetScaler): KEV due TODAY 2026-09-30. See section 1 for WHIPSHOT/SLAPSHOT hunts. Sep 28 brief.
- CVE-2026-88772 (Citrix NetScaler DTLS): KEV due TODAY 2026-09-30. DTLS-off is temporary only for this CVE. Sep 28 brief.
- GHSA-qx49-fqc8-xw99 (MCP Python SDK OAuth): No material change. Keep
mcp≥1.30.0 / ≥2.2.0 andissuer=on unattended providers. Sep 29 brief. - CVE-2026-65660 (SharePoint): KEV due was 2026-09-28. Confirm fixed builds /
sphealth.aspxhunts. Sep 26 brief. - CVE-2026-67279 (MikroTik): KEV due was 2026-09-28. Confirm RouterOS ≥6.49.21 / ≥7.23.4 / ≥7.24.2. Sep 06 brief.
- CVE-2026-87902 (WordPress): KEV due was 2026-09-28. Confirm WP ≥7.1.2. Sep 24 brief.
- Carbonato / CVE-2026-62062 (Elementor): No material change. Keep TCP/2375,
GH0ST/SOUL.md, andelementor/v1/events/hunts; Elementor ≥4.3.2. Sep 28 brief.