Two actively exploited zero-days, a fresh China-nexus campaign using Microsoft 365 as a command-and-control channel, and AI coding agents accidentally publishing thousands of internal screenshots to public repositories. Today’s brief covers what defenders need to act on immediately and what should shape customer conversations this week.
In the News
Citrix NetScaler Zero-Day Exploited with Root-Level Web Shells
CVE-2026-88772 in Citrix NetScaler ADC and Gateway is under active exploitation, with technical details now public. Attackers are deploying two custom web shells - tracked as WHIPSHOT and SLAPSHOT - that provide persistent root-level access to compromised appliances. From that foothold, threat actors are pivoting into internal networks.
The exploitation timeline matters here. With technical details circulating publicly, the barrier for copycat attacks has dropped significantly. Any NetScaler appliance that was unpatched before September 29 should be treated as potentially compromised, not just patched and forgotten. A compromise assessment is the right next step: hunt for web shell artifacts, review authentication logs for anomalous admin sessions, and inspect east-west traffic patterns from the appliance.
NetScaler sits in the DMZ of thousands of enterprise networks, handling SSL VPN termination and load balancing. Root access to these devices gives attackers a position that is both highly privileged and often poorly monitored - most organizations do not run EDR on their network appliances.
What defenders should do: Patch CVE-2026-88772 immediately. On any appliance that was exposed before patching, hunt for WHIPSHOT and SLAPSHOT indicators, review scheduled tasks and cron entries for persistence, and audit all administrative access since September 25. Segment NetScaler management interfaces away from production networks.
Source: BleepingComputer
China-Nexus UAT-11587 Deploys Rust Backdoor via M365 C2
Cisco Talos published research on UAT-11587, a China-nexus threat actor targeting 16 government and policy organizations across 8 Asian countries. The campaign uses a five-stage infection chain initiated by spear-phishing emails and culminates in the deployment of Antino, a new Rust-based backdoor.
What makes Antino operationally significant is its command-and-control mechanism: it tunnels C2 traffic through Microsoft 365 services. This means domain-based blocking and traditional threat intelligence feeds that rely on known-bad infrastructure will miss the C2 channel entirely. The traffic looks like legitimate M365 API calls. Detection requires behavioral analysis of M365 API usage patterns - volume, timing, and payload characteristics that deviate from normal user activity.
The five-stage chain - spear-phish → loader → privilege escalation → Antino deployment → M365 C2 - demonstrates the operational maturity of UAT-11587. For organizations with operations in Southeast Asia, South Asia, or East Asia, or those working with government and policy entities in the region, this is a direct and current threat.
What defenders should do: Review email gateway telemetry for spear-phishing indicators consistent with this campaign. Audit M365 API access logs for anomalous patterns - particularly high-frequency Graph API calls from endpoints that do not normally interact with M365 programmatically. MITRE ATT&CK: T1071.001 (Application Layer Protocol: Web Protocols), T1566.001 (Spearphishing Attachment).
Source: Cisco Talos
Star Blizzard Scales Phishing with RedFlick - 100+ Organizations Compromised
Microsoft detailed a significant tradecraft evolution by Star Blizzard, a Russian APT previously known for highly targeted but low-volume operations. Since January 2026, the group has compromised over 100 organizations using fake event invitations that deploy the CosmicPulse backdoor through Windows scheduled tasks.
The RedFlick technique is notable for its evasion characteristics. Scheduled task persistence created by Office applications or browser processes avoids triggering endpoint detection rules focused on unsigned binary execution or process injection. It is a living-off-the-land approach that leverages legitimate Windows functionality for persistence - the scheduled task runs a legitimate Windows binary that side-loads the CosmicPulse payload.
Targets include organizations supporting Ukraine, Western NGOs, and think tanks - consistent with Star Blizzard’s historical targeting profile, but the scale is new. Moving from single-digit to triple-digit victims suggests either expanded operational capacity or a shift in strategic priority.
What defenders should do: Create detection rules for scheduled tasks spawned by Office applications (winword.exe, outlook.exe) or browser processes. Review existing scheduled tasks for unfamiliar entries created in 2026. MITRE ATT&CK: T1053.005 (Scheduled Task/Job: Scheduled Task), T1566.001 (Spearphishing Attachment).
Source: Microsoft Security Blog
AI Coding Agents Leak 13,000 Internal Images to Public GitHub
Glow Security discovered that AI coding agents operating under developer credentials committed over 13,000 internal screenshots to public GitHub repositories. The leaked assets included billing records, unreleased feature mockups, and internal dashboards - pushed to repos under individual developers’ personal accounts.
The root cause is not a vulnerability in the traditional sense. AI coding agents treated image files the same way they treat code dependencies - as assets to be committed. They lacked the contextual awareness to distinguish between a public-facing icon and an internal screenshot of a billing dashboard. The agents had the same repository permissions as the developers they operated under, which in most cases included push access to public repos.
This represents a new category of supply-chain data leakage. The risk is not malicious insiders or compromised credentials - it is autonomous tooling that operates with legitimate permissions but without judgment about data classification.
What defenders should do: Audit AI coding agent permissions in your GitHub organization. Implement pre-commit hooks or repository scanning that flags non-code assets (images, PDFs, archives) being pushed to public repositories. Review DLP policies to ensure they extend to developer tooling and CI/CD pipelines.
Source: The Hacker News
Today’s Deep Dive - Cloud-Native C2 Evasion
Two of today’s stories - UAT-11587 using Microsoft 365 as C2 and Storm-3068 pivoting from Azure DevOps to Kubernetes - highlight a trend that defenders must internalize: threat actors are not building bespoke C2 infrastructure when they can tunnel through services customers already trust.
The operational advantage is clear. Microsoft 365 API traffic from an endpoint is expected. Graph API calls do not trigger most network detection rules. DNS-layer visibility shows connections to legitimate Microsoft domains. The anomaly is not in the destination - it is in the behavior: the volume of API calls, the timing patterns, the payload sizes, and the specific API endpoints being hit.
Detection requires a shift from indicator-based blocking to behavioral analytics on cloud API telemetry. For M365 environments, this means monitoring Microsoft Graph API audit logs for unusual application registrations, consent grants, and high-frequency data access patterns from endpoints that do not normally use those APIs. MITRE ATT&CK: T1102 (Web Service), T1071.001 (Application Layer Protocol: Web Protocols).
For Azure DevOps-to-Kubernetes pivots as documented by Microsoft DART in the Storm-3068 case, the kill chain depends on a single compromised identity with excessive cross-service permissions. The primary mitigation is enforcing least-privilege access across cloud identity - specifically, ensuring that developer identities with Azure DevOps access cannot also modify Kubernetes cluster configurations without additional authentication gates.
Source: Microsoft Security Blog - Storm-3068
Detection Spotlight
Detecting scheduled task persistence created by Office applications - the mechanism used in Star Blizzard’s RedFlick technique. This Splunk SPL query identifies scheduled task creation events where the parent process is an Office application or browser, which is anomalous in most environments.
index=wineventlog EventCode=4698
| rex field=Message "ParentProcessName\":\"(?<parent_proc>[^\"]+)\""
| where match(parent_proc, "(?i)(winword|excel|powerpnt|outlook|msedge|chrome|firefox|iexplore)\.exe")
| stats count by host, parent_proc, TaskName, _time
| sort - _time
This query pulls Windows Security Event ID 4698 (scheduled task created) and filters for tasks where the creating process is an Office application or browser. In most enterprise environments, these applications should never be creating scheduled tasks - any hit warrants immediate investigation. False positives are rare but can occur with legitimate Outlook add-ins that create reminder tasks; baseline your environment before alerting.
Defender Action Items
- Patch CVE-2026-88772 on all NetScaler ADC and Gateway appliances immediately; hunt for WHIPSHOT/SLAPSHOT web shells on any appliance that was unpatched before September 29
- Update Apple devices to iOS 18.1.2, iPadOS 18.1.2, and macOS Sequoia 15.1.2 to address actively exploited CVE-2026-86950
- Audit M365 Graph API access logs for anomalous high-frequency calls from endpoints, particularly in organizations with Asia-Pacific operations
- Create endpoint detection rules for scheduled tasks spawned by Office applications or browser processes
- Review AI coding agent permissions and implement pre-commit hooks to block non-code assets from public repository commits
- Patch OpenSSL for the high-severity DTLS handshake flaw if running VPN or SD-WAN products that use OpenSSL for UDP-based TLS
References
- BleepingComputer - Citrix NetScaler Zero-Day
- Cisco Talos - UAT-11587 Antino Backdoor
- Microsoft Security Blog - Star Blizzard RedFlick
- The Hacker News - AI Coding Agents Leak
- Microsoft Security Blog - Storm-3068
- BleepingComputer - Apple CoreGraphics Zero-Day
- Palo Alto Security Advisory - CVE-2026-0307
- The Hacker News - OpenSSL DTLS Flaw
- The Hacker News - PhantomSub npm Packages
Related Briefs
- Apple CoreGraphics Zero-Day CVE-2026-86950 Patched
- Storm-3168 Deleted Azure via Service Principals
- NetScaler Zero-Days CVE-2026-88771 and 88772 Exploited
- AI Agent Accessed a Government Portal - Was It Open?
- Roundcube Pre-Auth SQLi CVE-2026-48842 Exploited
Subscribe to it-learn Brief
Get it-learn Brief in your inbox (Mon–Fri) - Daily cybersecurity news, SE angles, and detection queries.