Jessica Entwistle
September 28 2026
Today's brief reflects three recurring themes that UK organisations should recognise: unpatched enterprise infrastructure under active attack, cloud identity and access management failures enabling lateral movement, and emerging security risks in AI agent deployments. Each story highlights the importance of timely patching, robust identity governance, and careful evaluation of new technologies before they reach production environments.
CISA and Citrix confirmed on 27 September that two critical zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway products are being actively exploited. The Register reports that Citrix released emergency patches for eight vulnerabilities in total, including CVE-2026-88771 and CVE-2026-88772, both of which allow remote code execution. One of the flaws affects every deployment running an affected version, including those in default configurations. CISA has added both vulnerabilities to its Known Exploited Vulnerabilities catalogue and confirmed receiving reports of active exploitation targeting these systems.
NetScaler products are widely deployed across UK organisations as application delivery controllers and secure remote access gateways, often sitting at the network perimeter with privileged access to internal systems. Active exploitation of these vulnerabilities means attackers can gain initial access to corporate networks, move laterally, and potentially compromise sensitive systems before detection. For organisations using NetScaler in any capacity, this is not a theoretical risk but confirmed hostile activity targeting a commonly deployed enterprise platform. The fact that one vulnerability affects default configurations removes any assumption that custom deployments might be protected.
For UK businesses running Citrix NetScaler infrastructure, this is a prompt to apply the emergency patches immediately and review access logs for any signs of compromise. If patching cannot be completed within hours, organisations should consider isolating affected systems or implementing additional network segmentation until updates are deployed.
Source: The Register
Microsoft published threat intelligence on 25 September detailing cloud attacks by a threat actor tracked as Storm-3168, linked to the JADEPUFFER malware family. The Microsoft Security Blog reports that the actor is using compromised Azure service principals to conduct reconnaissance, delete cloud resources, and access credentials across targeted environments. The attacks demonstrate how compromised service accounts with elevated permissions can enable attackers to move laterally across cloud infrastructure, enumerate resources, and cause operational disruption without requiring traditional user credentials.
Service principals are non-human identities used to automate tasks, integrate applications, and manage cloud resources across Azure environments. Many UK organisations rely on service principals for DevOps pipelines, infrastructure-as-code deployments, and third-party integrations. When these accounts are compromised, attackers gain persistent access that often bypasses multi-factor authentication and user-focused monitoring. The operational risk is significant because service principals frequently hold broad permissions across subscriptions, resource groups, and sensitive data stores. This activity highlights a gap in how many organisations monitor and govern non-human identities in cloud environments.
For many organisations, this is a prompt to review how service principals are created, what permissions they hold, and whether their activity is being monitored effectively. Ensuring that service accounts follow the principle of least privilege and that their credentials are rotated regularly should be part of routine cloud governance.
Source: Microsoft Security Blog
Infosecurity Magazine reports that security researchers have identified a set of vulnerabilities, collectively named SalesBleed, affecting Salesforce's Agentforce AI agents. The flaws allow attackers to exploit prompt injection techniques and DNS exfiltration methods to access customer relationship management data without requiring user interaction. The vulnerabilities demonstrate how AI agents, which are designed to autonomously retrieve and process data, can be manipulated to bypass access controls and leak sensitive information through carefully crafted inputs or network-based exfiltration channels.
Salesforce is widely used across UK businesses for managing customer data, sales pipelines, and service interactions. The introduction of AI agents into these environments creates new attack surfaces that many organisations may not yet have considered. Unlike traditional application vulnerabilities, AI agent flaws can be triggered through natural language inputs, making them harder to detect using conventional security controls. The risk is particularly relevant for organisations deploying AI-driven automation in customer-facing or data-sensitive contexts, where the agent's ability to retrieve and process information could be exploited to access data beyond what the attacker should be able to reach.
For UK businesses using or evaluating Salesforce AI agents, this is a reminder to review what data these agents can access, how their permissions are scoped, and whether their activity is being logged and monitored. Organisations should ensure that AI agent deployments are treated with the same rigour as any other privileged system integration.
Source: Infosecurity Magazine
SecurityWeek reports that CISA has added CVE-2026-65660, a vulnerability affecting Microsoft SharePoint, to its Known Exploited Vulnerabilities catalogue. The agency has given federal agencies a patching deadline of 28 September, indicating that the flaw is now being actively exploited in the wild. While specific details of the exploitation activity have not been disclosed, the inclusion in CISA's KEV catalogue confirms that attackers are targeting this vulnerability in real-world environments.
SharePoint is a core collaboration and document management platform used across UK organisations in both on-premises and cloud-hosted configurations. Vulnerabilities in SharePoint can provide attackers with access to sensitive business documents, internal communications, and shared resources that underpin day-to-day operations. The fact that this vulnerability is now being exploited means organisations running affected versions are at immediate risk. For many businesses, SharePoint holds a significant portion of their institutional knowledge, project documentation, and operational data, making it a high-value target for attackers seeking to establish persistence or exfiltrate information.
For UK businesses running Microsoft SharePoint, this is a prompt to confirm that patches have been applied and to review access logs for any unusual activity. Organisations should ensure that SharePoint permissions are regularly reviewed and that external sharing settings are appropriately restricted.
Source: SecurityWeek
The stories in today's brief reflect a familiar pattern: attackers continue to exploit unpatched systems, compromised identities, and emerging technologies where security controls have not yet matured. The organisations best positioned to respond are those that already have clear processes in place for patch management, identity governance, and technology evaluation before incidents occur. Good security is built on practical discipline, not reactive urgency. When patching, monitoring, and access control are routine habits rather than crisis responses, organisations can respond to new threats with confidence rather than alarm.