SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsOver the weekend, Citrix published an advisory addressing eight vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway. Two of the flaws are confirmed to be actively exploited: CVE-2026-88771, CVSS score 9.5, an improper input validation leading to remote code execution, and CVE-2026-88772, CVSS score 9.5, a memory overflow vulnerability leading to remote code execution or denial of service. Citrix made available a list of indicators of compromise for the advisory, which is accessible through NetScaler Console. The US Cybersecurity and Infrastructure Security Agency (CISA) has added these CVEs to the Known Exploited Vulnerabilities (KEV) catalog with mitigation deadlines of Wednesday, September 30 for Federal Civilian Executive Branch (FCEB) agencies. Other vulnerabilities addressed in the advisory include CVE-2026-88773, CVSS score 9.3, an HTTP request smuggling issue; CVE-2026-88774, CVSS score 7.0, a feature policy bypass due to improper HTTP URL-based expression usage; CVE-2026-88775, CVE-2026-88776, and CVE-2026-88777, all memory overflow vulnerabilities leading to unpredictable or erroneous behavior or denial of service, all carrying CVSS score 8.8; and CVE-2026-88778, CVSS score 8.8, a TCP Initial Sequence Number prediction issue.

If you're a Citrix NetScaler shop and haven't applied the updates, you need to assume compromise at this point. This means you need to check every box for webshells after applying the patch. Be aware, the Citrix detection script depends on logs that have sufficient history to detect the attack, so you may want to look at your SIEM rather than device logs. You need to look back at least a month for suspicious activity and anomalous actions, including the identified base64 strings after the User-Agent field.
The Register
Help Net Security
SecurityWeek
BleepingComputer
BleepingComputer
Citrix
KEV
KEV
The US Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have published a joint Fact Sheet containing advice for critical infrastructure entities working with third-party industrial control system (ICS) integrators. According to the document, critical infrastructure owners and operators should "ensur[e] the principle of least privilege (PoLP), is applied, as third-party ICS integrators "may inadvertently introduce security issues to a customer environment by exposing systems and services not pre-configured to the customer’s security requirements." FBI technical analysis revealed that in March and April of 2025, "malicious foreign cyber actors gained access to the network of a U.S. industrial automation solutions company that offered services—such as system integration, engineering consulting, and SCADA programming—for industrial customers, including power utilities and transportation entities," conducted searches, and readied hundreds of files "for presumed exfiltration." The document lists recommendations to reduce risk and provides resources for guidance on asset inventories, SBOMs, and supply chain risk management.

An attacker does not always need immediate access to a utility's OT network to begin preparing an attack. Compromised engineering information can provide valuable knowledge of the target long before an intrusion into the utility itself. Integrators often have detailed knowledge of customer control systems, privileged access, and copies of engineering configurations. A compromise of an integrator can therefore create risks well beyond that company's own network. Third-party access needs to be treated as a controlled engineering function, with access granted for specific work and removed when that work is complete. The integrator's familiarity with the system should not translate into unrestricted, permanent access. Do you audit and document an integrator’s access to your systems? Do you know, by name, which non-employees have access?

I'm sure we're all aware of the risks relating to ICS/OT systems, but, if you're like me, you need all the help you can get to get your arms around both securing and educating system owners to ensure they really are secure, particularly when you're getting something from a third party that has a remarkable list of clients, giving the impression they have this handled. Read the CISA PDF (it's 4 pages), then strategize with your team on how to assess your current risks and improve your approach with current and future integrators. Invite system and data owners to the session so you're all on the same page. While remote access/Internet exposure and strong authentication top our hit list of concerns, the paper raises other equally valid areas to assess that you may otherwise overlook.

If a third-party integrator can reach your control environment, that relationship is part of your ICS attack surface. The integrator may be excellent at what they do and completely trustworthy, but that doesn't mean they cannot themselves be compromised. And because integrators often need powerful access across multiple customer environments, compromising one can give an attacker tremendous leverage. Architect that access assuming that someday the trusted third party could become the path of attack. Trust the partner. Engineer for compromise.
This is an essential set of questions to ask any third-party vendor providing services to your organization. Remember that external partners are an extension of your cybersecurity program, and they must adhere to the same controls governing your data and access. These standards should always be formally outlined in your SLAs.
A coalition of 44 US state attorneys general has settled a lawsuit against Labcorp, fining the company $2.3 million and requiring it to adopt measures to improve its data security posture. The suit was filed over a 2019 breach at American Medical Collection Agency (AMCA), a third-party debt collection company and subsidiary of Retrieval-Masters Creditors Bureau (RMCB), which detected the breach on March 19, 2019. A subsequent investigation determined that the intruder had access to AMCA's network between August 1, 2018 and March 30, 2019, and exfiltrated names, Social Security numbers, financial data, medical test data, and other information. According to the HIPAA Journal, "the AMCA data breach was the largest data breach reported in 2019 by a HIPAA-regulated entity, affecting more than 27.5 million individuals, including more than 10.2 million Labcorp patients." The settlement requires that Labcorp include cybersecurity requirements in vendor contracts, create a response plan for security incidents affecting vendors, limit the data it shares with its vendors, and establish a risk management team that will ensure vendors' compliance with data security requirements.

It's easy to lose sight of the fact that this was a third-party breach, and as such, the settlement isn't a huge surprise. For the rest of us, skip the incident and settlement and go straight to making sure that your contracts include appropriate security requirements, and, more importantly, that you're verifying them before you're processing production data as well as verifying them on a regular basis. The verification is needed as services change over time, on both sides, and you don't want to find out the hard way that you missed something or that a configuration drifted, regardless of the cause.
The primary takeaway from this settlement is simple: Third-party risk management is non-negotiable. You must hold external partners to the exact same cybersecurity standards as your internal systems. Those requirements should be baked directly into your SLAs.

I am in favor of litigation, both criminal and civil. It tends to clarify what really happened, clarifies responsibility, creates a record, sometimes punishes illegal or reckless behavior, and provides incentives to others.
Following claims of a September 22 data breach affecting the FBI (described in NewsBites 28.71), additional information has emerged on the alleged perpetrators and on possible related exploitation. About one week before the purported theft of two terabytes of agents' personal information and the defacement of the FBIjobs[.]gov website, Dutch authorities arrested 23-year-old Pepijn van der Stap "on suspicion of aiding in data thefts and extortions" with ShinyHunters. Van der Stap was previously convicted of data theft and extortion in 2023 and served a prison sentence that ended in December 2025. Brian Krebs described this latest arrest alongside information about Dutch authorities' pursuit of a ShinyHunters-linked perpetrator of the February data breach at Dutch telecom provider Odido. The FBI is continuing to investigate the claimed breach and has reportedly issued an internal memo confirming to bureau employees that personally identifiable information (PII) was stolen in a cybersecurity incident, according to Ken Dilanian at MS NOW (formerly MSNBC). Meanwhile, Google Threat Intelligence Group (GTIG) published threat intelligence on September 25 warning of "renewed mass exploitation" of CVE-2026-35273, a critical missing authentication flaw in Oracle PeopleSoft that was disclosed and fixed in June. The latest wave of activity seems to involve using URL encoding to bypass web application firewall (WAF) rules that mitigate the flaw. The renewed campaign, which GTIG assesses is linked to ShinyHunters, has been "deploying web shells on dozens of systems globally, spanning higher education, technology, IT services, healthcare, agriculture, transportation, and government." GTIG urges users to apply Oracle's fix; ensure PeopleTools is on a supported version; disable EMHub service or remove the PSEMHUB application; conduct log and endpoint monitoring for specific requests; conduct host-level auditing for unexpected files and unauthorized content; hunt for evidence of data theft; and prepare for possible extortion communications and public exposure of stolen data.

There's a great old-school security lesson buried in the PeopleSoft exploitation here. The WAF sees /%50SEMHUB/; PeopleSoft decodes it and sees /PSEMHUB/. Whenever two security-relevant layers interpret the same input differently, attackers get to live in the gap between them. It reminds me a bit of the long-ago so-called "Unicode Bug" in IIS, which security researcher Rainforest Puppy helped research and popularize in 2000. Normalization and canonicalization issues have been biting us for decades, and they’re still enormously useful to attackers. By all means use WAF rules as a compensating control, but don't confuse them with fixing the underlying vulnerability. Patch this one.

Don't get distracted by the efforts to shut down the ShinyHunters gang; while that would be amazing, we're still left making sure our environments are secure from all the gangs. If you're a PeopleSoft shop, make sure you've got the latest mitigations for CVE-2026-35273, CVSS score 9.8. This is exploitable remotely without authentication. Your actions should include applying the patch from Oracle as well as the remediation and hardening guidance in the GTIG report from September 25th. No workarounds here — you need to apply the update.

The issuance of a patch is not a fix. Fixing is the hard work that must be done, on a timely basis, by all the users of the patched product.
KrebsOnSecurity
TechCrunch
BleepingComputer
SecurityWeek
GTIG
On September 28, 2026, Apple released an emergency patch to address a high-severity vulnerability in iOS and macOS before version 27 that may be under targeted exploitation. CVE-2026-86950, CVSS score 8.8, allows an attacker to achieve arbitrary code execution by exploiting an out-of-bounds write issue that occurs when CoreGraphics processes a maliciously crafted file. Meta Product Security is credited with the report of this flaw. Apple has fixed the issue with improved bounds checking in iOS and iPadOS 26.7.1, macOS Sequoia 15.8.1, and macOS Tahoe 26.7.1, and notes that the company has received a report that the flaw may be under exploitation "in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27."

Don't overlook that iOS 27.0.1, visionOS 27.0.1, watchOS 27.0.1 and macOS 27.0.1 also dropped today. At a minimum make sure that your teams are already assessing the compatibility and manageability of these, ideally on test hardware. The answer you're looking for is that we can manage them, the security works, and our core applications work properly, or we have a timeline to get there. Rest assured that users are looking hard at the option to apply another update to the old familiar OS versus updating to the new and shiny thing, particularly as this is the first update since the production 27.0 release. Remember, macOS 27 only runs on Apple Silicon. I recall when Macs ran on Motorola CPUs. Note that there are more AI functions (aka Apple Intelligence) starting with the iPhone 15 Pro, and even more with the iPhone 17 Pro and beyond. Check out Siri AI, improved photo editing, and added Child Safety and Parental controls, along with other system improvements.

Just a reminder that Settings>General>Software Update>Automatic Update>Automatic Install should be the default setting for Apple systems. Exceptions are rare.
The District of Columbia Department of Health Care Finance (DHCF) has begun sending notifications to individuals whose personal information may have been compromised. The data were exposed via "two reports on DHCF’s website [which] contained hidden personal information that could be accessed by people who did not have permission to view it." DHCF has removed the reports from the website, launched a review to determine how the situation came to be, and started enhancing practices to prevent a recurrence. The compromised data include Medicaid ID numbers, dates of birth, provider names, race, gender, and ethnicity. The incident affects roughly 400,000 individuals who were enrolled in the Medicaid or Alliance programs between 2023 and July 2026. DHCF has reported the incident to the Department of Health and Human Services Office for Civil Rights.

This is a good reminder of the need for regular web site testing that, if done right, would have found this, ideally in pre-production testing of the version that introduced the vulnerability.

I'm reminded of a ranking/salary presentation which was shared, including an embedded spreadsheet that had sensitive data in hidden columns. Even back then, it took very little time for those who had it to figure out where the information was hidden that management didn't want shared. Modern tools today, which include AI, make the discovery loop both shorter and virtually guaranteed. So, that means we cannot rely on security by obscurity. If you don't want information discovered, don't make it available. If a conversation includes "nobody will ever know" or "they'll never find it", consider those as red flags and as an opportunity for education and improvement. Remember to be kind, as the person may not be aware of the current threat environment; this is not likely their focus or specialty.

If your personal data has not been compromised, you are both rare and very lucky. We should all behave as though our most sensitive identifying data is public. Lock your data with the three credit bureaus and monitor all your accounts on a timely basis. For some accounts, timely will be daily.
On September 25, 2026, Dyfed-Powys Police in Wales issued a statement confirming that the force suffered a cyber incident that was detected on September 14. The nature of the incident has not been publicly specified, but some systems were shut down as a precaution during investigation and restoration. Cybersecurity specialists are assisting to understand the circumstances and determine whether there was unauthorized access to staff data. Dyfed-Powys Police have not found evidence of unauthorized access or compromise for any information belonging to members of the public. The force has remained fully operational, including emergency response and telephone services, but non-emergency systems including online and email contact were temporarily disrupted and/or unavailable; these have now been restored. Tarian, the regional organized crime unit (ROCU) for southern Wales, has a regional cybercrime unit managing the investigation, and systems are under close monitoring. The UK Information Commissioner’s Office (ICO) has been notified, and the force promises further updates when appropriate. The four counties served by Dyfed-Powys Police account for about 500,000 people.
Details on the incident are limited, but the message is clear, law enforcement is not immune to cyberattacks. Take time to periodically audit your cyber defenses and benchmark your security program against frameworks like NIST CSF or CIS Controls (IG1).

From the outside looking in, the Dyfed-Powys Police have done a great job maintaining services and publicly appearing unaffected, while internally spinning up the incident response, investigation and remediation quickly and smoothly. The attackers appear to have focused on systems which manage staff data (e.g., HR/Accounting) rather than public/citizen information. I'd put this in your “watch and see” category with hopes there are things you could add to your response playbook in the future.
Two Japanese railway operators have reported recent cybersecurity incidents. Tokyo Metro, which operates subway trains, said that email addresses of approximately 59,000 rewards program members may have been compromised after an intruder gained unauthorized access to a company server. The server in question does not contain any other data. The incident was detected while the company was investigating email delivery errors earlier this month; the breach was determined to have originated overseas. Keio Corporation, a private railway operator, said that its network was the target of a ransomware attack over the weekend. The incident resulted in a "system failure," which has disrupted some of Keio's business systems. Keio has reported the incident to police, shut down its network "to prevent further damage," and launched an investigation.

The Tokyo Metro breach feels more like someone attempting to use the email capabilities to make nefarious emails look legitimate to members. My thinking is that you need to make sure that you've got the security dialed in on any systems authorized to send email on your behalf, particularly third-party services. Have a formal process for updating, testing, and verifying SPF, DMARC, and DKIM settings, to include removing entries for services which are no longer in use.
A US District Judge in the state of Washington sentenced former Army soldier Cameron John Wagenius to nearly six years in prison for breaking into databases at multiple telecommunications companies, stealing data, and threatening to release the data unless extortion demands were paid. According to court documents, Wagenius and co-conspirators targeted at least 10 organizations between April 2023 and December 2024. They accessed the companies' networks using stolen credentials and shared those credentials over Telegram group chats, where they also discussed their activities. Wagenius and his co-conspirators threatened to expose the stolen data if demands for payment were not met; they also offered stolen data for sale on cybercrime forums. The intrusions, data theft, and other related activity occurred while Wagenius was on active duty. In March 2025, Wagenius pleaded guilty to two counts of unlawful transfer of confidential phone records information, and in a separate case in July 2025, Wagenius pleaded guilty to conspiracy to commit wire fraud, extortion in relation to computer fraud, and aggravated identity theft. Wagenius has also been ordered to pay nearly $300,000 in restitution.

Wagenius and his co-conspirators appear to be behind the Snowflake data thefts in 2024. Despite having a lot of exfiltrated data, Wagenius was unsuccessful at his extortion attempts, which included threats of releasing national security secrets and re-extorting victims which had already paid the larger extortion group, netting only about $1500. Yet, while awaiting trial, he was able to leverage other inmates email accounts to attempt to find and exploit weaknesses in the Bureau of Prisons' systems. In addition to the fines and prison time, he is unlikely to ever be granted another security clearance, or to work for the US Government or military. Those are some pretty big bridges to burn, and unless he curtails his propensity to pursue criminal venues with his hacking, he's got the makings of a great pen tester, though it's not clear he's going to land a job in the private sector either.
A reasonable sentence given the crime. Let’s not forget that Snowflake didn't practice a standard duty of care in the protection of those phone records by exposing identity credentials and by not implementing multi-factor authentication (since corrected).
Krebs On Security
The Register
The Record
Help Net Security
SecurityWeek
BleepingComputer
Justice
SANS Internet Storm Center StormCast Tuesday, September 29, 2026
macOS/iOS 0-Day Patch; macOS priv. escalation 0-day; File Notification Attacks
https://isc.sans.edu/podcastdetail/10114
Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950)
https://isc.sans.edu/diary/Apple+Emergency+Patch+for+iOS+26+macOS26+macOS15+CVE202686950/33376
https://support.apple.com/en-us/100100
Proof of concept for macOS CoreServices Priv. Escalation (CVE-2026-43786)
https://github.com/Malwation/CVE-2026-43786
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations
File Notification Attacks
https://inoti.fyi/pubs/file-notification-attacks.pdf
SANS Internet Storm Center StormCast Monday, September 28, 2026
Macfinger Details; NetScaler 0-Day; KiteWorks 0-Day; ShinyHunters and PeopleSoft
https://isc.sans.edu/podcastdetail/10112
A Closer Look at Malware From the Macfinger ClickFix Campaign
https://isc.sans.edu/diary/A+Closer+Look+at+Malware+From+the+Macfinger+ClickFix+Campaign/33368
Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778
KiteWorks Urges Customers to Shut Down Servers
ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft
My Upcoming Classes
Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.
Knock, Knock. The AI Agents Are Here. Which Will You Let In? AI traffic is growing 8X faster than human traffic. AI agents now browse products, manage accounts, and transact. But can you tell which agents are legitimate and which are malicious? Get the CISO’s Guide to AI and Agentic Traffic by HUMAN. Learn how to identify threats, validate intent, and set controls for trusted agents.
Webinar | SANS 2026 Exposure Management Survey Insights: Cyber Exposure at a Crossroads | Wednesday, October 7 | New global survey data exposes the gap between exposure visibility and risk-based action. Join to benchmark your program's maturity and get concrete steps to close the gap.
Webinar | SANS 2026 Cloud Security Survey Insights: Navigating the Evolving Landscape of Threats, Tools, and Priorities | Wednesday, October 21 | Explore the survey findings, gain practical insights, and benchmark your organization’s approach to cloud security.
SANS Research | The State of AI Security Maturity Benchmark Survey | AI adoption is outpacing your ability to assess it. Take 10 minutes to shape SANS' benchmark and get early access to results so you can see exactly where your program stands.