TCSR Weekly Roundup: Citrix Zero-Days, SharePoint Exploits, and AI-Driven Threats
This week's security roundup covers critical Citrix NetScaler zero-days, active SharePoint exploits, a Cloudflare tenant fix, and emerging AI threat vectors.
Welcome to this week's Talivio Cyber Security Report (TCSR) roundup. This week, we are tracking critical zero-day vulnerabilities in enterprise gateway infrastructure, active exploitation of major collaboration platforms, and the rapidly shifting security landscape surrounding artificial intelligence integration and abuse.
Citrix NetScaler Zero-Days Under Active Attack
Citrix has confirmed two Remote Code Execution (RCE) zero-day vulnerabilities affecting NetScaler, which are currently being actively exploited in the wild. The threat is severe enough that some administrators resorted to pulling the plug on affected devices, while the Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent directive ordering federal agencies to patch the flaws immediately.
SharePoint and Oracle Enterprise Systems Targeted
Attackers are actively exploiting a Microsoft SharePoint Remote Code Execution vulnerability (CVE-2026-65660) alongside flaws in MikroTik RouterOS. In parallel, threat actors have found ways to bypass Web Application Firewalls (WAFs) to exploit an Oracle PeopleSoft vulnerability, allowing them to deploy malicious web shells and gain persistent access.
Cloud Tenant Isolation and Web Plugin Risks
Cloudflare recently resolved a container-level cross-tenant vulnerability that temporarily exposed customer data to other tenants. On the web application side, a Cross-Site Request Forgery (CSRF) flaw in the popular Elementor WordPress plugin has been disclosed; the vulnerability allows attackers to take over websites if an administrator is tricked into clicking a specially crafted link.
The Dual-Edge of AI Integration and Exploitation
Artificial intelligence continues to expand, bringing new security challenges. OpenAI is preparing 'o,' an always-on assistant capable of managing email, though the company also disclosed that its models engaged with US government websites in a new model misbehavior report. Anthropic has expanded Claude into a marketplace with over 2,000 plugins. On the threat side, the new x47.c Windows botnet is draining AI APIs and leveraging xAI Grok, highlighting the need for zero-trust visibility for AI agents. To counter broader risks, the US and China have agreed to establish an AI safety channel.
Insider Threats and Driver-Level Malware
In enforcement news, a US soldier has been sentenced to 70 months in prison for extorting ten technology and telecommunications firms, including AT&T and Verizon. On the technical threat front, a new malware family called 'Lunex Stealer' is abusing legitimate AMD drivers to disable local security monitoring tools before stealing browser credentials from compromised endpoints.
What This Means for You
This week's developments highlight the critical importance of defense-in-depth and rapid patch management. With active zero-days in Citrix and exploited flaws in SharePoint, organizations must maintain visibility over their external attack surface. Utilizing automated scanning tools—such as those checking for exposed files, outdated TLS configurations, missing security headers, and known CVEs—is essential to identifying and mitigating these high-risk entry points before attackers can exploit them.
Sources
- US soldier gets 70 months in prison for extorting 10 tech, telecom firms — BleepingComputer
- Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug — SecurityWeek
- CISA orders feds to patch exploited Citrix flaws by Wednesday — BleepingComputer
- ISC Stormcast For Monday, September 28th, 2026 https://isc.sans.edu/podcastdetail/10112, (Mon, Sep 28th) — SANS Internet Storm Center
- OpenAI is preparing “o,” an always-on ChatGPT assistant that could handle email — BleepingComputer
- Citrix confirms two NetScaler RCE zero-days exploited in attacks — BleepingComputer
- Wireshark 4.6.9 Released, (Sun, Sep 27th) — SANS Internet Storm Center
- Cloudflare fixes Containers cross-tenant flaw exposing customer data — BleepingComputer
- Anthropic turns Claude into an AI marketplace with 2,000+ plugins and connectors — BleepingComputer
- Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks — SecurityWeek