Cyware at MM-ISAC Conference
Understand Where You Are on the CTI Maturity Curve
Daily Threat Briefing
Diamond Trail

Cyware Daily Threat Intelligence - September 28, 2026

8 min read
shutterstock 2069195879

Summary

Attackers are slashing through browser defenses with a new Python-based infostealer that targets 17 Chromium browsers and Firefox, siphoning credentials, payment data, and session cookies from Windows user paths. Cyware.com notes the malware’s use of AES-256-GCM decryption and persistence tricks, putting account takeovers and payment fraud within easy reach for operators.

Ransomware is halting business in Japan, where The Gentlemen and Qilin have driven a 4.7% rise in attacks during H1 2026. The Gentlemen’s double-extortion tactics and Qilin’s AI-powered wipers have hit SMEs and manufacturers, with Qilin linked to over 1,400 global victims and The Gentlemen responsible for 14 incidents.

Retail operations at Keio Corporation ground to a halt after a ransomware attack on September 26, leaving customers unable to pay by credit card. The company severed network connections and called in external experts, highlighting how ransomware can quickly disrupt daily commerce even before any data leak is confirmed.

Critical vulnerabilities in Citrix NetScaler ADC and Gateway, including CVE-2026-88771 and CVE-2026-88772 with CVSS scores up to 9.5, are under active attack. Exploitation lets adversaries run arbitrary commands or disrupt services, prompting urgent patching to NetScaler versions 14.1-73.37, 13.1-64.23, and later.

Microsoft SharePoint servers are under fire as attackers actively exploit CVE-2026-65660, a remote code execution flaw that requires no user interaction. Microsoft has issued urgent updates after shifting its risk assessment, but technical details remain scarce, leaving defenders to act quickly with limited guidance.

A years-old bug, CVE-2019-18935 in Telerik UI for ASP.NET AJAX, is fueling new attacks in Korea, where adversaries deploy web shells and scan for exposed WordPress configs. The flaw grants code execution on IIS servers, and researchers urge patching to version 2020.1.114 or later to block ongoing exploitation.

CTA_1_LI_Monday_DTI_After_Overview

Top Malware Reported in the Last 24 Hours

New Python infostealer raids 18 browsers

A new Python-based infostealer is being sold as malware-as-a-service and is built to siphon data from 17 Chromium-based browsers plus Firefox. It goes after saved credentials, payment-card details, browsing history, and session cookies, then bundles the haul into a zip archive for exfiltration through operator-configured webhooks. It specifically hunts browser data in Windows user paths like %LOCALAPPDATA% and %APPDATA%, and it uses AES-256-GCM to decrypt Chrome-format entries; it also pulls Wi-Fi keys, Discord tokens, and even .ROBLOSECURITY cookies tied to Roblox accounts. To stay resident and harder to study, it sets persistence using registry keys and scheduled tasks, and it attempts to evade analysis by checking for low-capacity disks, sandbox time limits, and attached debuggers. For victims, the real-world fallout is account takeovers and payment fraud that can continue even after a password change if stolen sessions remain active. The source says defenders may respond by using behavior-based detection, enforcing multifactor authentication, revoking browser sessions and resetting credentials after suspected compromise, and blocking identified hashes and scanning for compromise.

The Gentlemen and Qilin hit Japan

Ransomware incidents in Japan rose 4.7% in H1 2026, with The Gentlemen and Qilin cited as the most active groups, especially against SMEs and manufacturers. The Gentlemen, described as a RaaS operation, accounted for 14 incidents and used double-extortion tactics that pressure victims with the threat of stolen-data exposure. It allegedly gained access through VPNs and by exploiting CVE-2025-24799 in GLPI, then used tools including Chisel, Ligolo-ng, and BloodHound to move through networks and exfiltrate data. Qilin, meanwhile, is reported to use AI-generated scripts to automate destructive steps such as wiper deployment and disabling backup systems, and the report attributes to it more than 1,400 global victims. For targeted businesses, these campaigns can mean halted production, prolonged outages, and negotiations under the added strain of potential data leaks.

Keio ransomware outage halts card payments

Keio Corporation has reported a ransomware attack that disrupted operations at some of its retail stores, leaving customers unable to pay by credit card. The company said it detected the incident in the early hours of September 26 and moved to contain it by severing network connections while it investigates. It also notified police and brought in external experts to support the response. At the time of reporting, no data leaks had been confirmed, but the interruption shows how ransomware can quickly spill into day-to-day customer experience and revenue. Keio said it will disclose additional findings as they become available.

Top Vulnerabilities Reported in Last 24 hours

Attackers exploit Citrix NetScaler bugs

Multiple critical vulnerabilities in Citrix NetScaler ADC and Gateway—including remote code execution, memory overflows, HTTP request smuggling, and TCP ISN prediction—can let attackers run arbitrary commands, disrupt services, or trigger unpredictable behavior, with CVSS scores reported up to 9.5. The most severe issues include CVE-2026-88771 (unauthenticated remote command execution) and CVE-2026-88772 (a memory overflow that can cause denial of service and may enable code execution), both of which can turn an edge appliance into an attacker entry point. Attackers are already exploiting this in the wild, with exploitation specifically observed for CVE-2026-88771 and CVE-2026-88772. Citrix credited Michael Tucker, Chew Keong Tan, Alex Bernier of JPMorgan Chase XOR Team, and Maxim Suhanov for identifying the issues. Fixes are available in NetScaler versions 14.1-73.37, 13.1-64.23, and later, and Citrix also calls out TCP configuration changes for CVE-2026-88778 plus configuration preconditions that can affect exposure (for example, default configurations for CVE-2026-88771 and DTLS-enabled virtual servers for CVE-2026-88772).

Active SharePoint attacks prompt Microsoft update

Microsoft says attackers are actively exploiting a Microsoft SharePoint remote code execution flaw (CVE-2026-65660), a shift from its earlier assessment that exploitation was “less likely.” An attacker who can reach a vulnerable SharePoint server can use a specially crafted request to execute code without needing a user to click anything, potentially turning a collaboration portal into a foothold for data theft or disruption. Attackers are already exploiting this in the wild. Microsoft has not shared technical details about the attacks, leaving many defenders to assess risk with limited public information. A fix is available via Microsoft’s latest SharePoint security updates.

Old Telerik bug resurfaces in attacks

A long-known remote code execution bug in Telerik UI for ASP.NET AJAX (CVE-2019-18935) is still being weaponized, with two recent intrusion cases reported in Korea where attackers deployed a web shell and ran additional tooling on compromised servers. The flaw lets attackers execute code on IIS web servers with the privileges of the web worker process, which can translate into full control of the affected application server. Attackers are actively exploiting this, according to the reported incident write-up. Researchers describing the cases tied post-exploitation activity to installing a reverse shell and using a scanner to look for exposed WordPress configuration pages. A fix is available in Telerik UI for ASP.NET AJAX version 2020.1.114 or later.

CTA_2_LI_Monday_DTI_Before_FAQ

Frequently Asked Questions

  1. What is The Gentlemen? Ransomware incidents in Japan rose 4.7% in H1 2026, with The Gentlemen and Qilin cited as the most active groups, especially against SMEs and manufacturers. The Gentlemen, described as a RaaS operation, accounted for 14 incidents and used double-extortion tactics that pressure victims with the threat of stolen-data exposure.

  2. What is Qilin? Ransomware incidents in Japan rose 4.7% in H1 2026, with The Gentlemen and Qilin cited as the most active groups, especially against SMEs and manufacturers. The Gentlemen, described as a RaaS operation, accounted for 14 incidents and used double-extortion tactics that pressure victims with the threat of stolen-data exposure.

  3. What is CVE-2026-88771? Multiple critical vulnerabilities in Citrix NetScaler ADC and Gateway—including remote code execution, memory overflows, HTTP request smuggling, and TCP ISN prediction—can let attackers run arbitrary commands, disrupt services, or trigger unpredictable behavior, with CVSS scores reported up to 9.5. The most severe issues include CVE-2026-88771 (unauthenticated remote command execution) and CVE-2026-88772 (a memory overflow that can cause denial of service and may enable code execution), both of which can turn an edge appliance into an attacker entry point.

  4. What is CVE-2026-65660? Microsoft says attackers are actively exploiting a Microsoft SharePoint remote code execution flaw (CVE-2026-65660), a shift from its earlier assessment that exploitation was “less likely.” An attacker who can reach a vulnerable SharePoint server can use a specially crafted request to execute code without needing a user to click anything, potentially turning a collaboration portal into a foothold for data theft or disruption.

  5. What is CVE-2019-18935? A long-known remote code execution bug in Telerik UI for ASP.NET AJAX (CVE-2019-18935) is still being weaponized, with two recent intrusion cases reported in Korea where attackers deployed a web shell and ran additional tooling on compromised servers. The flaw lets attackers execute code on IIS web servers with the privileges of the web worker process, which can translate into full control of the affected application server.

Discover Related Resources