Weekly Security Roundup: September 29 to October 6, 2026

Part of our weekly series. Previous: Roundup for September 22 to 28, 2026.

Sherlock Forensics security roundup for September 29 to October 6, 2026. Pwn2Own Ireland paid 457,250 US dollars for more than eighteen zero-days on day one, including the first exploits against the AI stack (LiteLLM, Oracle Autonomous AI Database and OpenAI Codex). Citrix NetScaler CVE-2026-88771 (9.5 pre-auth RCE) was exploited within a day of disclosure using a web shell disguised as stylesheet files. Apple patched a CoreGraphics image flaw (CVE-2026-86950) used in targeted mercenary-spyware attacks, and FortiMail CVE-2026-104286 (9.8) allowed unauthenticated arbitrary file write on the mail gateway. Read the way an examiner reads evidence.

A working examiner's read of the week's most interesting compromises. What happened, how it happened and what it means for anyone who has to reconstruct the event afterward.

Some weeks the security calendar hands you a theme. This was one of them. Between September 29 and October 6 the recurring story was the edge: the mail gateway, the remote-access appliance, the image parser sitting one layer below every app on the phone. These are the devices that face the internet so the rest of the network does not have to, and this week attackers spent their time proving that the guard at the gate is still the softest target in the building. We also watched a competition in Cork turn a hotel ballroom into the most productive vulnerability-research lab on earth, and for the first time the machines in the crosshairs included the artificial intelligence stack itself.

Here is the week, read the way an examiner reads a disk: not as headlines, but as events that leave traces.

Pwn2Own Ireland: the hardware fell, and so did the AI

The marquee event opened October 6 in Cork, and the Zero Day Initiative's own day-one tally tells the story better than any marketing line could. Fourteen successful exploit attempts. At least eighteen fresh zero-day vulnerabilities burned in a single afternoon. A running total of 457,250 US dollars paid out before the first day was over.

The headline target was the Samsung Galaxy S26, Samsung's newest flagship, and it did not survive the afternoon intact. Multiple teams put working exploit chains on the board against it. Viettel Cyber Security, Interrupt Labs and Ikotas Labs all landed code on the device, though in several cases the vendor already knew about one or more of the bugs in the chain, which trims the payout and the points under Pwn2Own rules. A phone that is one software generation old is already being pulled apart by four-bug chains in a controlled setting. That is the honest baseline for mobile security in 2026, and it is the reason a defensible mobile examination never assumes the handset in evidence was clean.

The part that makes this year different is what else fell. Pwn2Own has always been a parade of routers, printers, network attached storage and smart-home gear, and this year delivered all of it. VinSOC disclosed seven zero-days in a single run against the Philips Hue Bridge Pro, the little white box that sits on a home network and speaks to every light in the house. McCaulay Hudson and VinSOC both cracked the Sonos Era 300 speaker, and Hudson's chain is the one worth framing: an out-of-bounds write combined with a format string bug, two classic memory-safety primitives stitched into a 50,000 dollar exploit on a consumer speaker. The Lexmark CX532adwe office printer was compromised three separate ways. Garmin's Index BPM health monitor fell in the wellness category.

Then the new category. For the first time the target list included the artificial intelligence stack, and it did not hold. Teams landed exploits against LiteLLM, against Oracle's Autonomous AI Database and against OpenAI's Codex. The lesson is not that AI is uniquely fragile. The lesson is that AI infrastructure is now ordinary attack surface, built from the same parsers, the same memory-unsafe code and the same trust-the-input mistakes that have fed Pwn2Own for a decade. The model is new. The bugs underneath it are not.

For an examiner the Pwn2Own result is a reminder that lives well past the competition. Every one of those zero-days now enters a disclosure window with the vendor, and the gap between a ballroom demo and a patched fleet is where real intrusions live. When a Galaxy S26 or a Hue bridge or a network printer turns up in a case six months from now, the question is never whether it could have been compromised. It is what the device recorded while it was.

Citrix NetScaler: a web shell wearing a stylesheet

If Pwn2Own was the week's spectacle, the Citrix NetScaler campaign was its craft. This is the story that rewards a close read.

Citrix disclosed a pair of serious flaws in NetScaler ADC and NetScaler Gateway, the appliances that sit at the perimeter and broker remote access into the enterprise. The lead vulnerability, CVE-2026-88771, is an improper-input-validation flaw rated 9.5 out of 10 that allows pre-authentication arbitrary command execution. In plain terms, an attacker who can reach the login page can run commands as the device, no credentials required. A companion flaw, CVE-2026-88772, shipped alongside it. The United States Cybersecurity and Infrastructure Security Agency flagged the appliances as under active zero-day attack, and reporting through the week described exploitation landing within roughly twenty-four hours of public technical detail becoming available. Worse, a further zero-day surfaced against appliances that administrators had patched only days earlier, which is the kind of timeline that turns a patch cycle into a footrace.

The tradecraft is where this one earns its place in the roundup. Researchers recovered a post-exploitation payload, a Perl script, that did three things an examiner should memorize. First, it edited the appliance configuration to create a local account named sec_monitor and handed it the superuser role, a name chosen to read like a benign monitoring account in a hurried log review. Second, it dropped a PHP web shell into the logon path, giving the operator remote command execution plus file upload and download. Third, and this is the detail worth the price of admission, it modified the web server configuration to serve that web shell under URLs built to look like ordinary NetScaler stylesheet resources. The malicious endpoint was dressed up to resemble the CSS a NetScaler login page legitimately requests on every visit.

That last move is pure anti-forensics. A defender skimming web logs sees requests for what look like stylesheet files, the most boring and most ignored lines in any access log, and moves on. The account named sec_monitor survives the same lazy glance. This is an adversary who expects someone to look and has planned for the look to fail.

For incident responders the takeaways are concrete. Patching a NetScaler does not evict an attacker who was already resident, because the superuser account and the web shell live in configuration and on disk, not in the vulnerable code path you just closed. A NetScaler examination after suspected compromise has to include the on-box configuration for unexpected accounts, the logon directory for files that do not belong and the web server configuration for rules that map real URLs to places they should never resolve. Pull the configuration, diff it against a known-good baseline and treat any stylesheet URL that executes code as exactly what it is.

Apple CoreGraphics: one crafted image, total compromise

The quietest high-severity story of the week is also the one closest to our own work in mobile forensics. On September 28 Apple shipped fixes for CVE-2026-86950, an out-of-bounds write in CoreGraphics, the framework that draws and decodes images across iOS, iPadOS and macOS. The flaw carries a CVSS score of 8.8 and allows arbitrary code execution when the system processes a maliciously crafted file. The United States Cybersecurity and Infrastructure Security Agency added it to the Known Exploited Vulnerabilities catalog on September 29 and set a federal remediation deadline of October 2.

Two details separate this from a routine patch. Apple described the bug as already used in an extremely sophisticated attack against specific targeted individuals, the language Apple reserves for mercenary spyware and nation-state tooling rather than commodity crime. And the flaw was reported by Meta's product security team, which puts two of the largest platform-security organizations on the planet on the same narrow bug in the image pipeline.

Think about what a CoreGraphics flaw means in practice. CoreGraphics decodes images almost everywhere, which means a hostile image delivered through a message, a webpage or an attachment can reach vulnerable code with little or no interaction from the target. This is the shape of the modern targeted-phone compromise: not a phishing link the victim has to fall for, but a file that does its work the moment the device renders it. Fixes shipped in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1, and the devices most exposed were those that had stayed on the iOS 26 line rather than moving forward.

The forensic angle is direct. When a phone belonging to a journalist, an executive or an activist comes in with a plausible targeting concern, the examination has to account for exactly this class of bug: a logic-free, low-interaction image exploit that may leave very little on the surface. The evidence lives in crash logs, in anomalous process behavior and in the timeline of what rendered what and when. A logical acquisition that captures those diagnostic artifacts is not optional for this kind of case. It is the case.

FortiMail: a 9.8 at the mail gateway

The week's highest raw severity score went to Fortinet. CVE-2026-104286 is a 9.8 flaw in FortiMail, Fortinet's mail security gateway, and it is the unpleasant combination of a path-traversal bug plus improper handling of NULL characters that lets an unauthenticated attacker write arbitrary files to the underlying system through crafted web requests. Arbitrary file write with no login, on the device that inspects your inbound mail, is about as bad as the category gets, because a file write on that kind of appliance is usually a short hop to code execution and persistence.

The timeline is the tell. The United States Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog on October 1, a day before the broader write-ups landed on October 2. KEV placement means exploitation is not theoretical, it is happening. Affected builds span the FortiMail 7.2, 7.4, 7.6 and 8.0 lines, with fixes in 8.0.2, 7.6.7 and 7.4.9. A mail gateway sits in a uniquely sensitive spot, with a view of inbound and outbound mail for an entire organization, so a compromise here is both an intrusion and a potential data-exposure event at once. Anyone running FortiMail should treat an unpatched appliance as presumed-exposed and work the incident accordingly rather than waiting for a cleaner signal.

The breaches worth your attention

Three disclosures stood out, each a different failure mode.

The largest by raw count was a Pentagon data breach that exposed records on roughly three million people, reported as 2.76 million living individuals plus about 294,000 who are deceased. A breach that includes the dead alongside the living is a reminder that records outlive the people they describe, and that retention is a liability long after the subject is gone.

The most instructive was an insider case at the East Suffolk and North Essex NHS Foundation Trust in the United Kingdom, where ten staff members were suspended amid an investigation into alleged unauthorized access to a single patient's medical records. No perimeter was breached. No exploit was fired. People with legitimate credentials allegedly looked at a record they had no business opening. Insider access is the threat that no firewall addresses and the one that only logging and audit can catch, which is the entire argument for read-tracking and access review inside sensitive systems.

The most quietly alarming was in France, where an attacker used stolen staff passwords to walk into the national tax administration and take data on hundreds of thousands of taxpayers and businesses across June and July, a theft surfacing only now. No vulnerability, no malware, just valid credentials used by the wrong hands. It is the oldest intrusion technique there is and still among the most effective, and it is why credential theft and reuse belong at the top of every threat model rather than the bottom.

The ransomware ledger

Ransomware kept its usual grim pace through the window, and the victim list is a cross-section of soft targets.

The City of Vicksburg, Mississippi, was hit on October 1 and had to take municipal computer systems offline, though police, fire and 911 service stayed up while investigators checked whether personal data was reached. Osaka Metropolitan University in Japan was struck on October 2, with roughly 500 servers going dark, campus systems disrupted and data on at least 130,000 students and staff potentially exposed. The Ukrainian grocery chain ATB Market confirmed an attack on October 3, with a 400,000 dollar ransom demand posted directly on the company's own website while its online services went down, a crude but effective way to make the breach impossible to hide.

The most technically interesting ransomware activity came from the Warlock operator, a crew assessed as China-linked, observed on October 3 exploiting Microsoft SharePoint vulnerabilities to disable security tooling and deploy ransomware against organizations in Portuguese-speaking and Spanish-speaking countries. The pattern there is the one to watch: an internet-facing enterprise application as the entry point, defensive tools neutralized before the payload runs and a regional targeting focus that suggests a deliberate campaign rather than opportunistic spray.

On the watchlist

A few more items earned a place on the patch-now list without dominating the week.

A campaign dubbed FortiBleed was reported harvesting credentials from Fortinet firewalls at scale, with figures citing tens of thousands of affected devices and, in some cases, administrators being locked out of their own equipment. Treat it as distinct from the FortiMail flaw above and audit Fortinet estates accordingly.

OpenSSL disclosed a high-severity flaw in its DTLS handling that can leak heap memory across a connection or crash the process. DTLS runs under a great deal of real-time and VPN traffic, so the blast radius is wide even if the bug is less flashy than a 9.8 file write. Patch the library and rebuild what links against it.

And reporting through the period continued to flag active exploitation of a critical, unauthenticated Atlassian flaw affecting the Jira, Confluence and Bitbucket families, the collaboration and source-control systems that sit at the center of most engineering organizations. Anyone running self-managed Atlassian should confirm their patch level rather than assume it.

The forensic read

Pull back from the individual items and the week has one argument to make. The soft spot is the edge, and the edge is getting harder to examine, not easier.

Look at where the real damage clustered. A mail gateway. A remote-access appliance. An image parser underneath every app on the phone. These are not endpoints a user sits at. They are devices that are supposed to be invisible, which means nobody is watching them until something breaks, and when an attacker gets in they stay in by editing the very configuration that the rest of the network trusts. The Citrix web shell dressed as a stylesheet is the perfect emblem of the week, because it tells you the adversary has already thought about the person who will investigate and has arranged for that person to see nothing.

The defensive lessons are not new, but this week sharpened every one of them. Patch velocity is survival, because exploitation is now landing within a day of public detail and sometimes against appliances patched days before. Appliance compromise outlives the patch, so remediation has to include configuration review, account review and on-box artifact hunting rather than a reboot and a version bump. Credentials remain the master key, as France and the NHS both showed, which means logging and access audit are not compliance paperwork, they are the only sensors that catch an intruder who never had to break anything. And on mobile, the low-interaction image exploit is the live threat for anyone who might be specifically targeted, which makes a careful logical acquisition of diagnostic artifacts the difference between a conclusion and a shrug.

That is the through-line Sherlock Forensics cares about. An intrusion is not finished when the attacker leaves. It is finished when someone can reconstruct what happened in a form that holds up to scrutiny. The harder adversaries work to make the edge unexaminable, the more the examination has to be deliberate, documented and defensible. That is the work. See you next week.

Sources

Previous in this series: Weekly Security Roundup: September 22 to 28, 2026.