Articles

Threat Thursday: October 1st, 2026

Written by Aidan Brown | Oct 1, 2026, 12:00:00 PM

Welcome to Threat Thursday, Galactic’s weekly threat intelligence roundup.

Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what it could mean for your organization, and what to do about it.

Five of this week's six stories involve something built to check who's allowed in, and in each case that check is what failed. A password prompt, a login screen, a certificate confirming a connection is genuine. The one story that breaks the pattern is an Apple zero-day, and even that one makes the point from a different angle: the device in your pocket is now a gatekeeper too. This week, the gatekeepers let everyone in.

This Week’s Cycle

1. TeamViewer Patches Five Flaws in Its Remote-Access Software (CVE-2026-92370)

TeamViewer, the software many businesses and IT teams use to connect to computers remotely for support, released an update to fix five security flaws. The most serious could let an attacker take actions during a remote session that they should not be able to, and potentially run their own malicious code on the machine. The others could let someone already on a computer gain higher-level control, in some cases all the way to full administrator access. The fixes cover the Windows, Mac, and Linux versions and ship in TeamViewer 15.82. TeamViewer says it has no evidence anyone has worked out how to use these flaws yet, and no public instructions for doing so have appeared, which makes this a rare chance to fix a problem before attackers act on it.

Potential impact: Remote-access software is a high-value target for a simple reason: it’s built to control other people’s computers, so a flaw in it hands an attacker the same reach the tool was designed to provide. That’s also true for the IT providers who run TeamViewer across dozens or hundreds of client machines, where one weakness becomes a path to many. The reassuring detail is the timing. With no known exploitation and no public exploit yet, organizations that update promptly close this out entirely. The ones who leave it are betting that nobody reverse-engineers the patch, and that bet tends to lose.

What to do: Anyone using TeamViewer should update to version 15.82 across all computers, including the technician machines that run the software, not just the ones being supported. Where updates are managed centrally, confirm the change applied rather than assuming it did. Since the worst flaw involves remote sessions, it’s also worth reviewing who is allowed to start unattended connections and tightening those permissions.

Source: BleepingComputer

2. Apple Fixes a Zero-Day in iPhones and Macs Already Used in a Targeted Attack (CVE-2026-86950)

Apple released emergency updates for iPhones, iPads, and Macs to fix a flaw it says has already been used in what it calls an extremely sophisticated attack. The problem is in CoreGraphics, the part of Apple’s software that draws images and documents on screen, and it means simply opening a malicious file could let an attacker run their own code on the device. Apple’s careful wording usually points to targeted spyware aimed at specific high-profile people, such as journalists, executives, or government figures, rather than a broad campaign against everyone. The fixes are in iOS and iPadOS 26.7.1 and the latest macOS updates. Researchers at Meta reported the flaw, and it lands in the same month Apple fixed a separate flaw that needed no interaction at all.

Potential impact: It would be easy to file this under “not my problem” because the attacks are narrow and expensive to run, but that misreads the risk. The phone in someone’s pocket now holds email, saved passwords, multi-factor codes, and a direct line into company systems, which makes it as much a way in as any server. A single well-placed spyware infection on the right person’s device can quietly expose all of that. The wider point is that mobile devices deserve the same patch urgency as laptops and servers, and many organizations still treat a phone update as optional. When the attack needs nothing more than a booby-trapped file, optional is the wrong setting.

What to do: Affected iPhones, iPads, and Macs should be updated to the latest versions right away. Organizations that manage devices centrally should push and enforce the update rather than leaving it to individuals, and give extra attention to people whose role makes them a likelier target, such as executives, finance, and legal staff. For the highest-risk individuals, Apple’s Lockdown Mode adds real protection against exactly this kind of attack.

Source: Infosecurity Magazine

3. Two NetScaler Gateway Flaws Are Under Active Attack (CVE-2026-88771 and CVE-2026-88772)

Citrix released fixes for two serious flaws in NetScaler, a widely used gateway that sits at the edge of a network and lets employees connect in securely from outside. Both were being used in real attacks before Citrix even had a fix available, and the U.S. government has added them to its list of vulnerabilities under active exploitation. The more dangerous of the two, CVE-2026-88771, lets an attacker take control of the gateway with no login at all and works against systems in their normal, out-of-the-box setup. The second, CVE-2026-88772, needs a specific feature switched on to work. A security firm has already published a working demonstration of how to attack these, which usually means broader, more automated attacks follow quickly.

Potential impact: A gateway like NetScaler is the worst place to have a flaw that needs no login, because it’s exposed to the internet by design and it’s the doorway to everything behind it. An attacker who takes it over doesn’t need to break in anywhere else; they are already past the perimeter. The detail that raises the stakes is the timing. These flaws were exploited before the fix existed, so any organization that had one of these gateways online has to assume attackers may have gotten in during that window. That turns a patch job into an investigation, and treating it as a simple update is how a quiet compromise gets missed.

What to do: Affected organizations should update every NetScaler system to a fixed version immediately, because a public attack demonstration plus confirmed real-world use leaves no safe waiting period. Since these were attacked before the fix was released, patching isn’t enough on its own: administrators should follow Citrix’s guidance to check for signs of a break-in, reset passwords and security keys the gateway could reach, and move its management controls off the public internet.

Source: The Hacker News

4. OpenSSL and wolfSSL Patch Flaws That Can Fake a Trusted Identity

Two pieces of open-source software that quietly secure a huge share of the internet’s encrypted connections, OpenSSL and wolfSSL, both released security fixes. OpenSSL patched 14 issues, the most serious of which could let an attacker crash a program or read stray bits of its memory over the network without logging in. wolfSSL patched 11, and three of those matter most: they could let a malicious server fake a trusted digital identity and slip past the checks that are supposed to confirm a website or service is genuine. In plain terms, that’s like getting past a bouncer with a convincing fake ID. None of these flaws are known to have been used in attacks. wolfSSL is fixed in version 5.9.4, and OpenSSL released fixes across all its supported versions.

Potential impact: The catch with this kind of software is that almost nobody installs it directly. It comes bundled inside other things: firewalls, routers, smart devices, and business applications that most organizations do not even realize are running it. So the real work isn’t updating one program; it’s finding everywhere this code is hiding and waiting on each of those vendors to ship their own fix. The identity-faking bugs in wolfSSL are the ones worth watching, because the whole point of these libraries is to prove that the thing you are connecting to is really what it claims to be. When that guarantee breaks, encryption can look fine while quietly protecting a connection to an impostor.

What to do: Organizations should update OpenSSL and wolfSSL through their normal operating-system and vendor update channels, and treat this as an inventory exercise as much as a patch. It helps to ask key vendors, especially those supplying internet-facing equipment, whether their products use wolfSSL and whether they are on version 5.9.4. Anything that sits at the edge of the network and handles encrypted traffic should be first in line.

Source: SecurityWeek

5. Kiteworks Shut Its Customers Down for Nine Hours to Fix a Critical Flaw

Kiteworks, a platform companies use to send and store sensitive files securely, did something unusual in late September. After a warning from federal authorities about a possible imminent attack, it asked customers to shut their systems down for about nine hours overnight while it investigated, rather than waiting to see whether an attack materialized. During that shutdown it found and fixed a critical flaw. Kiteworks says there is no evidence the flaw was ever actually used, and that fewer than one percent of its customers had the affected feature switched on. No formal vulnerability ID has been assigned yet, and the company has not publicly detailed which versions were affected.

Potential impact: Secure file-transfer platforms have become a favorite target, because they concentrate exactly the sensitive documents attackers want in one place, and recent years have seen mass breaches built on flaws in this category. Against that backdrop, a vendor choosing to pull the fire alarm on a tip, before any proof of an attack, is genuinely notable. It trades a night of downtime for a much larger risk avoided, and it’s the opposite of the more common pattern where customers learn about a flaw only after it has been exploited. The open question is how many organizations actually heeded the warning and took their systems offline, since the protection only works if the alert is acted on.

What to do: Organizations using Kiteworks should confirm their systems were brought back online only after the vendor’s fix was applied, and check whether the affected feature was even enabled in their environment. Reviewing access and file-transfer logs across the warning window is worthwhile even though the vendor reports no exploitation. It’s also worth subscribing to Kiteworks security notices so the formal vulnerability details and any further fixes are caught as soon as they are published.

Source: The Hacker News

6. Cisco Warns Its SD-WAN Network Console Is Under Active Attack (CVE-2026-76504)

Cisco warned customers about a serious flaw in Catalyst SD-WAN Manager, the console businesses use to control how their network routes traffic between offices and sites. The flaw lets an attacker skip the login screen entirely by sending the system a specially crafted web request, and Cisco has confirmed attackers are already using it. Because the affected system manages the whole network, getting past its login effectively hands an attacker the controls for how traffic flows across the business. There is no temporary workaround, so the only fix is to install Cisco’s update. Cisco has published specific fingerprints defenders can look for in their logs to spot attempted or successful attacks.

Potential impact: An attacker skipping the login is among the plainest and most dangerous kinds of flaw, because there is no clever exploitation required; the intruder simply walks past the lock. When the lock is on the console that runs the entire network, the consequences scale with it. Someone there could reroute traffic, weaken defenses, or use the position as a launch point deeper into the environment. The fact that Cisco published clear indicators of compromise is a gift worth using, because it means an organization doesn’t have to guess whether it was hit; it can go and look. Skipping that check on a flaw already under attack leaves a straightforward question unanswered.

What to do: Organizations running Catalyst SD-WAN Manager should install the fixed version immediately, since there is no workaround and the flaw is already under attack. Before and after updating, defenders should search the specific logs Cisco identified for the encoded-character requests and suspicious service-account activity the company flagged. If anything turns up, collect the diagnostic files Cisco recommends, engage Cisco’s response team for a compromise assessment, and reset credentials the console manages.

Source: BleepingComputer

The Big Picture

Every serious flaw this week lived in something built to check who's allowed in, and the check itself is what broke. That's a different failure than a server getting hacked. Nothing was forced open. The gatekeeper just stopped asking the right question, and an attacker walked through wearing whatever answer worked.

Two of these gatekeepers, NetScaler and Cisco's SD-WAN console, were already being exploited before a fix existed, which means the patch closes the door without telling you who came through it first. The rest are cleaner cases where a prompt update keeps the door shut before anyone tries it. Knowing which kind of problem you're solving decides whether patching is the whole job or just the first half of it.

Make sure to check back here each week for another Threat Thursday update. See you then!