An Apple zero-day reported by Meta’s security team, a $387 million cryptocurrency heist that started with a vendor’s own security product, and 16,000 databases left open because the defaults were not secure. Monday morning brought enough to fill every customer conversation this week - and the Citrix KEV additions with a Wednesday deadline mean some of those conversations need to happen today.
In the News
Apple Patches CoreGraphics Zero-Day Exploited in Targeted Attacks
Apple released emergency patches Sunday for CVE-2026-86950, an out-of-bounds write in the CoreGraphics framework that enables arbitrary code execution on iOS, iPadOS, and macOS. The vulnerability was reported by Meta’s security team, which described the exploitation as “extremely sophisticated” - a characterization Meta reserves for attacks that bypass multiple layers of defense.
The “extremely sophisticated” label matters operationally. It signals that standard enterprise mobile device management and app-layer defenses likely did not catch the exploitation chain. For organizations with BYOD policies or executive mobility programs, this is not a routine patch - it is a re-evaluation of whether device health attestation policies enforce OS-level patching SLAs, not just application updates.
Patches are available in iOS 18.5, iPadOS 18.5, and macOS 15.5. Apple has not published technical details of the exploit chain, consistent with its policy of withholding specifics until patch adoption reaches critical mass.
What defenders should do: Enforce OS version minimums through MDM policies immediately. Verify that mobile threat defense tooling covers kernel-level exploitation, not just app-layer threats. If your organization uses conditional access, block authentication from devices running iOS versions below 18.5 - today, not next sprint.
Bitget Confirms $387M Crypto Heist via Third-Party Security Product
Cryptocurrency exchange Bitget confirmed that an attacker stole $387 million in digital assets by exploiting a vulnerability in a third-party security product integrated into the exchange’s infrastructure. The attacker pivoted from the vendor flaw to internal wallet credentials, draining funds before the breach was detected.
The attack vector is the story. A security product - a tool explicitly trusted with privileged access - became the initial access point. The attacker did not need to phish employees or brute-force credentials. They exploited the trust relationship between the vendor’s product and Bitget’s production environment, then used that foothold to reach wallet credentials that should have been isolated.
This is the clearest supply-chain trust case study of the quarter. Organizations integrating third-party security tooling into production environments need to treat those integrations with the same suspicion they apply to any other privileged access path: microsegmentation between vendor tooling and credential stores, monitoring for anomalous API calls from service accounts tied to vendor products, and contractual SLAs for vendor patch response times.
What defenders should do: Audit the permissions granted to every third-party security product in your environment. Microsegment vendor integrations away from production credential stores. Monitor service accounts tied to vendor tooling for anomalous behavior - the signal is lateral movement from a vendor’s namespace to production secrets.
16,000 Supabase Databases Expose PII, Passwords, and Auth Tokens
Security researchers identified over 16,000 misconfigured Supabase instances exposing personally identifiable information, plaintext passwords, and authentication tokens. Supabase - a popular backend-as-a-service platform among startups and developer teams - ships with default configurations that do not enforce row-level security.
The scale is the point. Sixteen thousand databases is not a rounding error - it represents a systemic failure in the default-secure design of a platform used by organizations that often lack dedicated security teams. Developers choose Supabase for speed. The default configuration rewards that speed by shipping without access controls, and most teams never circle back to lock it down.
This is a cloud security posture management and shadow IT problem. Most enterprise security teams do not have visibility into BaaS platforms that developers adopt without procurement review. The databases exposed here are not in AWS, Azure, or GCP inventories - they are in Supabase’s infrastructure, invisible to CSPM tools configured only for the big three hyperscalers.
What defenders should do: Extend CSPM and DSPM coverage to backend-as-a-service platforms, not just hyperscaler environments. Use DNS-layer visibility to identify corporate endpoints connecting to Supabase and other BaaS platforms the security team has not approved. Require row-level security enablement as a deployment gate for any application using Supabase.
JADEPUFFER Destroys Azure Cloud Resources via Compromised Service Principals
Microsoft disclosed that the threat actor JADEPUFFER compromised Azure service principals to perform automated reconnaissance, credential theft, and destructive deletion of cloud storage and databases. Microsoft characterized the attack pattern as “agentic AI attacks,” reflecting the automated, multi-step nature of the operations.
Non-human identities - service principals, managed identities, API keys with standing permissions - are the lateral movement surface that most organizations have not inventoried. JADEPUFFER exploited this gap: compromised a service principal, used its permissions to enumerate resources, stole additional credentials, and then destroyed data. The entire kill chain was automated, executed faster than human SOC response times.
What defenders should do: Inventory all service principals and managed identities in Azure AD. Enforce least-privilege permissions and conditional access policies for non-human identities. Monitor Azure AD audit logs for unusual deletions, permission escalations, and sign-in anomalies from service principals - MITRE ATT&CK techniques T1078.004 (Valid Accounts: Cloud Accounts) and T1485 (Data Destruction).
Defender Action Items
- Update all Apple devices to iOS 18.5, iPadOS 18.5, and macOS 15.5 and enforce the version minimum in MDM and conditional access policies
- Audit permissions granted to third-party security products - microsegment vendor integrations away from production credential stores
- Extend CSPM/DSPM coverage to backend-as-a-service platforms (Supabase, Firebase, PlanetScale) and use DNS-layer visibility to detect shadow BaaS adoption
- Inventory Azure service principals and managed identities; enforce least-privilege and monitor for anomalous deletions and permission changes
- Patch Citrix NetScaler ADC/Gateway for CVE-2026-88771 and CVE-2026-88772 before Wednesday’s CISA KEV deadline or isolate from internet
Detection Queries
Monitor for destructive operations by Azure service principals - the core detection signal for JADEPUFFER-style attacks. This Splunk SPL query identifies service principal accounts performing bulk resource deletions in Azure Activity logs:
index=azure sourcetype="azure:activity"
operationName="Microsoft.Storage/storageAccounts/delete" OR operationName="Microsoft.Sql/servers/databases/delete" OR operationName="Microsoft.Resources/subscriptions/resourceGroups/delete"
| eval caller_type=if(like(identity.claims.appid, "%"), "ServicePrincipal", "User")
| where caller_type="ServicePrincipal"
| stats count by identity.claims.appid, operationName, resourceGroup, _time
| where count > 3
| sort - count
This query catches service principals performing three or more delete operations across storage accounts, SQL databases, or resource groups. False positive rate is low in environments where service principals are not routinely performing bulk deletions - any hit warrants immediate investigation. Tune the threshold based on your environment’s normal automation patterns.
References
- Apple patches CoreGraphics zero-day flaw exploited in attacks - BleepingComputer
- Bitget says attacker exploited third-party security product - The Hacker News
- Misconfigured Supabase apps expose data in over 16,000 databases - BleepingComputer
- JADEPUFFER agentic AI attacks target Azure, destroy cloud resources - BleepingComputer
- CISA orders feds to patch exploited Citrix flaws by Wednesday - BleepingComputer
- Carbonato botnet compromises Docker hosts - The Hacker News
- NeedyMantis malware dissected by Microsoft - SecurityWeek
- OpenAI shelves GPT-6.1 Astra after safety tests - The Hacker News
Related Briefs
- Storm-3168 Deleted Azure via Service Principals
- NetScaler Zero-Days CVE-2026-88771 and 88772 Exploited
- AI Agent Accessed a Government Portal - Was It Open?
- Roundcube Pre-Auth SQLi CVE-2026-48842 Exploited
- Check Point VPN Zero-Day - CVE-2026-85102 Pre-Auth RCE
Subscribe to it-learn Brief
Get it-learn Brief in your inbox (Mon–Fri) - Daily cybersecurity news, SE angles, and detection queries.