Cyber Threat Brief — September 30 2026

⚠️ This report is AI-generated. Always validate findings.

1. Mandiant: NetScaler root access deploys WHIPSHOT and SLAPSHOT — CVE-2026-88772 / CVE-2026-88771

TL;DR: Mandiant/GTIG documented post-exploit tooling on compromised NetScaler ADC/Gateway: PHP web shells (WHIPSHOT) and a Python tunneler (SLAPSHOT). CISA KEV due is today (2026-09-30) — preserve forensics, hunt the IoCs below, then patch to ≥14.1-73.37 / ≥13.1-64.23.

What’s New:

  • Google Cloud / Mandiant blog (2026-09-29) names WHIPSHOT and SLAPSHOT; THN and BleepingComputer amplify 2026-09-29/30. Dozens of orgs hit in North America and Europe.
  • Persistence maps /vpn/media/*.ico → .sig PHP under /var/netscaler/gui/vpn/scripts/linux/, or runs .deb as PHP via httpd.conf.
  • Command channel uses NetScaler-looking headers (NSC_CLIENTTYPE, NSC_LDAP, X-UX*). SLAPSHOT leaves /tmp/.uxdport and /tmp/.uxdlock.
  • eSentire traces CVE-2026-88771 webshell installs to 2026-09-05; GreyNoise reports mass exploitation surge after disclosure.

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
CVE-2026-88771 / CVE-2026-88772 on NetScaler ADC/Gateway before 14.1-73.37 or before 13.1-64.23 (FIPS tracks: before 14.1-73.37 FIPS / before 13.1-37.279). KEV due 2026-09-30 (forensic triage Yes).Vulnerable edge / KEVT1190Inventory / show ns versionPreserve snapshot, support bundle, and /var/core before upgrade. Install the fixed build. Rotate secrets and certs that traversed the appliance. DTLS-off / block UDP/443 only mitigates CVE-2026-88772, not CVE-2026-88771.
/etc/httpd.conf containing AddHandler application/x-httpd-php .deb (or .sig) and/or AliasMatch from /vpn/media/*.ico to /var/netscaler/gui/vpn/scripts/linux/*.sigPersistence / config IoCT1505.003 / T1036Appliance filesystem / config backupGrep httpd.conf for application/x-httpd-php, php_flag, and AliasMatch. Treat hits as compromise; rebuild rather than clean in place.
Webshell path /var/netscaler/gui/vpn/scripts/linux/*.sig (or PHP-bearing *.deb / nsginstaller* / nsgclient* in that directory)Webshell IoCT1505.003Filesystem / fileRun file and grep for <?php, eval(, and base64_decode( under the VPN scripts directory. Quarantine matches and rebuild.
SHA256 5ea5ea61e9062822bee3f66ef5ff47c217178d9e31936ad6daf10c5dfae44d12 (eSentire .ico-variant webshell)File hash IoCT1505.003Appliance filesystem / malware scannerHash-scan NetScaler VPN script dirs for this SHA256. Also check sibling hash 7add390ceee4a1373211b3e340451b34f08965fc4d805f94c9b8cebdc0775774 (.deb variant).
HTTP request header NSC_CLIENTTYPE (or NSC_LDAP / X-UX) carrying Base64 command dataC2 / webshell trafficT1071 / T1505.003NetScaler httpaccess / AppFlowAlert when NSC_CLIENTTYPE, NSC_LDAP, or X-UX headers contain Base64 payloads. Correlate with /vpn/media/*.ico requests that return HTTP 404 with multi-KB bodies.
Lock/port files /tmp/.uxdport and /tmp/.uxdlock (SLAPSHOT)Process IoCT1090Appliance filesystem / sockstatList /tmp/.uxdport and /tmp/.uxdlock. Read the port from .uxdport and inspect the listener. Hunt nohup/Python processes that reference those paths.
/bin/sh permissions -rwsr-xr-x (setuid root) on the NetScaler appliancePriv persistT1222 / T1548.001Appliance filesystemRun ls -l /bin/sh. Treat setuid root as compromise evidence; rebuild and rotate credentials after patch.
Actor IPv4 143.198.7.94 (Mandiant scanning/staging; also hunt 157.254.167.12 and eSentire list including 149.104.78.141)Network IoCT1190Firewall / NetScaler auditBlock or heighten logging for 143.198.7.94 and related campaign IPs. Correlate with NSPPE crashes and DTLS handshake failures.

Detection

SourceRuleGap
Splunk ESCUNone — verifiedExisting CitrixBleed / CVE-2023-3519 / CitrixBleed2 analytics target /oauth/idp/..., SAML paths, or memory-overread URLs — not WHIPSHOT headers, .uxdport, or .sig/.deb PHP handlers.
ElasticNone — verifiedNo emerging-threat rule for CVE-2026-88771/88772, WHIPSHOT, or SLAPSHOT in local rule tree.
SigmaNone — verifiedET rules cover CVE-2019-19781 / CVE-2020-8193 / CVE-2023-4966 only. No WHIPSHOT / NSC_CLIENTTYPE / /tmp/.uxdport rule.

Hunt hint: Inventory builds against 14.1-73.37 / 13.1-64.23. Preserve forensics, then patch. Grep httpd.conf for non-.php PHP handlers and /vpn/media/ AliasMatch. Hunt NSC_CLIENTTYPE / NSC_LDAP / X-UX headers, /tmp/.uxdport, setuid /bin/sh, and NSPPE crash plus DTLS handshake-failure pairs. Run NetScaler Console IOC scan after patch.

Sources: Google / Mandiant · The Hacker News · BleepingComputer · eSentire · CTX697096 · CISA KEV · THN on X · Sep 28 brief


Status Updates

  • CVE-2026-86950 (Apple CoreGraphics): CISA added to KEV on 2026-09-29 (catalog 2026.09.29 / 1729). Due 2026-10-02; forensic triage Yes. Keep patching to iOS/iPadOS 26.7.1, Tahoe 26.7.1 (25G241), Sequoia 15.8.1 (24H32). Sep 29 brief.
  • CVE-2026-88771 (Citrix NetScaler): KEV due TODAY 2026-09-30. See section 1 for WHIPSHOT/SLAPSHOT hunts. Sep 28 brief.
  • CVE-2026-88772 (Citrix NetScaler DTLS): KEV due TODAY 2026-09-30. DTLS-off is temporary only for this CVE. Sep 28 brief.
  • GHSA-qx49-fqc8-xw99 (MCP Python SDK OAuth): No material change. Keep mcp ≥1.30.0 / ≥2.2.0 and issuer= on unattended providers. Sep 29 brief.
  • CVE-2026-65660 (SharePoint): KEV due was 2026-09-28. Confirm fixed builds / sphealth.aspx hunts. Sep 26 brief.
  • CVE-2026-67279 (MikroTik): KEV due was 2026-09-28. Confirm RouterOS ≥6.49.21 / ≥7.23.4 / ≥7.24.2. Sep 06 brief.
  • CVE-2026-87902 (WordPress): KEV due was 2026-09-28. Confirm WP ≥7.1.2. Sep 24 brief.
  • Carbonato / CVE-2026-62062 (Elementor): No material change. Keep TCP/2375, GH0ST/SOUL.md, and elementor/v1/events/ hunts; Elementor ≥4.3.2. Sep 28 brief.