The Daily Zero-Day

Date: SEPTEMBER 27, 2026 Editor-in-Chief: Jose Laurentino III Global Threat Intelligence Edition

Executive Summary

Today's threat landscape highlights a dangerous escalation in zero-day exploitation, autonomous malware architectures, and advanced evasion techniques. Critical infrastructure and enterprise appliances remain under immediate pressure, led by unpatched remote code execution vulnerabilities in Citrix NetScaler and widespread infostealer campaigns abusing legitimate drivers and tools like Tailscale's tailcat. Simultaneously, autonomous AI C2 implants (CLOSEDQUORUM), AI platform vulnerabilities in ServiceNow, and sandbox escapes underscore how threat actors are weaponizing next-generation technologies. Organizations must prioritize robust asset discovery, rigorous identity hygiene, and enhanced forensic readiness across both traditional and AI-driven environments.

Top Intelligence Briefings

Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

Two new unpatched zero-day vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway appliances are currently under active exploitation in the wild, permitting remote code execution. Because these edge appliances sit at the network perimeter, compromise can grant attackers immediate footholds into internal corporate networks.

Actionable Takeaway: Immediately implement strict network segmentation, restrict management interface access to trusted jump hosts, and monitor for abnormal child processes spawned by NetScaler binaries pending official patches from Citrix.

The Closed Quorum: Inside the First Reported Autonomous AI C2 Implant

Discovered through Cisco Talos’ CAIRN project, the CLOSEDQUORUM malware binary exhibits fully autonomous command and control (C2) capabilities. This breakthrough represents a major tactical shift toward self-governing threat infrastructure that can adapt tactics without real-time human operator intervention.

Actionable Takeaway: Update behavioral monitoring heuristics to detect localized decision-making loops and automated asset discovery patterns indicative of autonomous implants within internal subnets.

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

Distributed via compromised Ukrainian websites leveraging ClickFix-style Cloudflare verification checks, the Psychedelic/Lunex Stealer family bypasses host-level security controls by exploiting legitimate AMD drivers to disable security monitoring tools before harvesting sensitive browser credentials.

Actionable Takeaway: Audit vulnerable kernel drivers across endpoints using Windows Defender Application Control (WDAC) or endpoint detection policies to block abused vulnerable driver blocklists.

AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment

Recent analyses of autonomous AI agent sandbox escapes—alongside parallel issues in Google Gemini models—reveal that the root problem is not rogue technology, but persistent, legacy access-control and identity architecture failures that allow lateral movement.

Actionable Takeaway: Implement strict least-privilege guardrails for AI agents and ensure centralized logging platforms capture granular API interactions to preserve forensic fidelity after a container breakout.

Sources & References

Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
https://thehackernews.com/2026/09/lunex-stealer-abuses-amd-driver-to.html

U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
https://krebsonsecurity.com/2026/09/u-s-soldier-gets-70-months-in-prison-for-att-verizon-extortions/

Data Broker Radaris Loses Domains in Privacy Fight
https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight/

Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee
https://www.schneier.com/blog/archives/2026/09/friday-squid-blogging-participatory-squid-dissection-in-october-in-tennessee.html

On Anthropic’s AI Misuse Report
https://www.schneier.com/blog/archives/2026/09/on-anthropics-ai-misuse-report.html

AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment
https://www.darkreading.com/cyberattacks-data-breaches/ai-sandbox-escapes-forensic-readiness

What We Missed: Google Gemini Joins the AI Escape Party
https://www.darkreading.com/cyber-risk/what-we-missed-google-gemini-ai-escape-party

Student Loan Breach Exposes 2.5M Records
https://threatpost.com/student-loan-breach-exposes-2-5m-records/180492/

Watering Hole Attacks Push ScanBox Keylogger
https://threatpost.com/watering-hole-attacks-push-scanbox-keylogger/180490/

Is that vibe coded app safe? 5 checks before you download
https://www.welivesecurity.com/en/mobile-security/is-new-vibe-coded-app-safe-5-questions-ask-first/

Been told to pay at a Bitcoin ATM? Read this first
https://www.welivesecurity.com/en/scams/been-told-pay-bitcoin-atm-read-first/

Trust and the enticing consultancy offer
https://blog.talosintelligence.com/trust-and-the-enticing-consultancy-offer/

The Closed Quorum: Inside the first reported autonomous AI C2 implant
https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/

LinkedIn adds new checks for fake profiles and work histories
https://www.malwarebytes.com/blog/news/2026/09/linkedin-adds-new-checks-for-fake-profiles-and-work-histories

Kothamine malware uses Tailscale’s tailcat to evade network detection
https://www.malwarebytes.com/blog/threat-intel/2026/09/kothamine-malware-uses-tailscales-tailcat-to-evade-network-detection

LimeLeads - 17,838,396 breached accounts
https://haveibeenpwned.com/Breach/LimeLeads

Burger King Russia - 3,155,792 breached accounts
https://haveibeenpwned.com/Breach/BurgerKingRussia

A Closer Look at Malware From the Macfinger ClickFix Campaign, (Fri, Sep 25th)
https://isc.sans.edu/diary/rss/33368

ISC Stormcast For Friday, September 25th, 2026 https://isc.sans.edu/podcastdetail/10110, (Fri, Sep 25th)
https://isc.sans.edu/diary/rss/33370

ICYMI: August 2026 @AWS Security
https://aws.amazon.com/blogs/security/icymi-august-2026-aws-security/

Supporting ASD’s multi-factor authentication campaign: Why MFA matters more than ever
https://aws.amazon.com/blogs/security/supporting-asds-multi-factor-authentication-campaign-why-mfa-matters-more-than-ever/

Cofense Expands AI-Driven Phishing Defense Platform to Advance Secure Behavior Management
https://cofense.com/blog/cofense-expands-ai-driven-phishing-defense-platform-to-advance-secure-behavior-management

Beyond Human Risk: A Better Way to Build Secure Behavior
https://cofense.com/blog/beyond-human-risk-a-better-way-to-build-secure-behavior

Ransom & Dark Web Issues Week 4, September 2026
https://asec.ahnlab.com/en/95545/

August 2026 Infostealer Trend Report
https://asec.ahnlab.com/en/95519/

Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
https://www.bitdefender.com/en-us/blog/labs/fake-xeno-roblox-discord-executor

Fake shops target shoppers across Europe with fake Samsung deals, counterfeit goods and World Cup scams
https://www.bitdefender.com/en-us/blog/labs/fake-shops-europe-samsung-world-cup-scams

UN Reports Citing Citizen Lab Submissions Published
https://citizenlab.ca/un-reports-citing-citizen-lab-submissions-published/

Submission to the Immigration and Refugee Board of Canada
https://citizenlab.ca/submission-to-the-immigration-and-refugee-board-of-canada/

Vulnerability in WEBCON BPS software
https://cert.pl/en/posts/2026/09/CVE-2026-92419/

Inside a multi stage toll fraud operation targeting Poland
https://cert.pl/en/posts/2026/09/tollfraud-analysis/

CIS Community Defense Model v3.0: Turning Threat Intelligence Into Action
https://www.cisecurity.org/insights/blog/cis-community-defense-model-v3-turning-threat-intelligence-into-action

CIS Benchmarks September 2026 Update
https://www.cisecurity.org/insights/blog/cis-benchmarks-september-2026-update

Multiple Vulnerabilities in ServiceNow's AI Platform Could Allow for Unauthorized Access
https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-servicenows-ai-platform-could-allow-for-unauthorized-access_2026-102

Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution
https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-101

Previous editions:
Fort Lauderdale, FL, September 28, 2026
Visitors since September 18th, 2026: 34,856