TL;DR
Apple patched a CoreGraphics zero-day possibly exploited in targeted attacks; Microsoft issued its largest patch batch ever (974 vulnerabilities); ShinyHunters escalated attacks after a member's arrest in the Netherlands, now exploiting Oracle PeopleSoft workarounds.
Executive Summary
- Apple released security updates for CVE-2026-86950, a CoreGraphics out-of-bounds write in iOS, iPadOS, and macOS that may have been exploited in targeted attacks.
- Microsoft published its largest security update ever, addressing at least 974 vulnerabilities across Windows and other products, with AI cited as a discovery accelerant.
- ShinyHunters hacking group escalated attacks after a 23–24 year old member's arrest in Amsterdam, now using modified exploits against Oracle PeopleSoft vulnerability CVE-2026-35273.
- Cryptocurrency exchange Bitget confirmed a $388 million theft exploited a third-party security product vulnerability, not an exchange platform flaw.
- Misconfigured Supabase databases exposed over 16,000 instances containing PII, passwords, and authentication tokens.
Top Threats Today
1. Apple CoreGraphics Zero-Day Possibly Exploited
Severity: HIGH Affected: Technology
Apple has released security updates to address CVE-2026-86950, an out-of-bounds write vulnerability in the CoreGraphics component affecting older versions of iOS, iPadOS, and macOS [1]. The company stated the flaw may have been exploited in targeted attacks [1]. Specific version numbers and patch details were not disclosed in available reports.
Sources:[1] The Hacker News
Recommended Action
- Prioritize updates to iOS, iPadOS, and macOS devices, particularly in organizations managing high-value targets
- Monitor endpoints for suspicious CoreGraphics-related process behavior or memory corruption crashes
- Review logs for any indicators of targeted attack activity on Apple platforms
2. Microsoft Patches Record 974 Vulnerabilities
Severity: HIGH Affected: Technology
Microsoft Corp. issued updates to plug at least 974 security holes in Windows operating systems and other software, representing its largest single patch batch ever [1]. The company cited artificial intelligence as a tool helping to speed vulnerability discovery, though security experts warn many of the newly patched flaws may have been unknown to defenders until now [1].
Sources:[1] Krebs on Security
Recommended Action
- Establish an expedited testing and deployment schedule for the Microsoft patch batch
- Prioritize Windows systems and commonly-targeted Microsoft products (Office, Exchange, Edge)
- Verify patch applicability to your environment and test in isolated infrastructure before broad deployment
3. ShinyHunters Escalate Attacks on Oracle PeopleSoft After Member Arrest
Severity: HIGH Affected: Technology
Dutch police arrested a 23–24 year old convicted cybercriminal in connection with the prolific ShinyHunters hacking group; in the days following the arrest, remaining ⚠ ShinyHunters members dramatically escalated their attack activity [1]. The group is now exploiting CVE-2026-35273, a vulnerability in Oracle PeopleSoft, using modified exploits in targeted campaigns [2][3]. Mandiant researchers and Google have both warned of this escalating activity [2][3].
Sources:[1] Krebs on Security[2] The Record[3] SecurityWeek
Recommended Action
- Audit Oracle PeopleSoft instances for unauthorized access and patch CVE-2026-35273 immediately
- Review authentication logs for brute-force attempts or unusual credential usage against PeopleSoft systems
- Monitor for data exfiltration from HR, payroll, and financial modules targeted by ShinyHunters in prior campaigns
4. Bitget Cryptocurrency Exchange Loses $388M via Third-Party Security Product Flaw
Severity: HIGH Affected: Finance
Bitget cryptocurrency exchange disclosed a theft of approximately $388 million; the attacker exploited a vulnerability in a third-party security product used by the exchange to obtain high-level internal credentials [1]. On September 24, the attacker used those credentials to access and drain cryptocurrency holdings ⚠[1]. This incident highlights supply-chain risks in security tooling itself.
Sources:[1] The Hacker News
Recommended Action
- Audit all third-party security products and admin tools for known vulnerabilities and credential exposure
- Implement privileged access management (PAM) to limit exposure of high-level internal credentials
- Review transaction logs and withdrawal activity for anomalies in the 30 days prior to and following September 24, 2026
5. Over 16,000 Supabase Databases Misconfigured, Exposing Credentials and PII
Severity: HIGH Affected: Technology
Researchers discovered more than 16,000 misconfigured Supabase databases exposing readable tables containing personally identifiable information, passwords, and authentication tokens [1]. Supabase is a widely-used backend-as-a-service platform; the scale of exposure indicates systematic configuration errors across a large developer base.
Sources:[1] BleepingComputer
Recommended Action
- If you operate Supabase instances, immediately verify row-level security (RLS) policies are enabled and correctly configured
- Rotate any credentials or API keys that may have been exposed through misconfigured databases
- Audit recent access logs for unauthorized data access attempts
Ongoing Monitoring
- Citrix NetScaler CVEs: Earlier coverage of CVE-2026-88771 and CVE-2026-88772 remains current; both are now in CISA's Known Exploited Vulnerabilities catalog with federal remediation deadline 2026-09-30 [31, 32].
- NeedyMantis Malware: Microsoft reports the NeedyMantis malware family is being used to maintain long-term access in targeted intrusions at telecommunications, university, and medical nonprofit organizations [2].
- RatHat Android Banking Trojan: Cleafy reports the RatHat Android banking trojan malware-as-a-service model, with nearly 100 deployed command consoles traced since April 2026 and operators using AI (Gemini) to identify higher-value victims [5].
- JadePuffer Agentic Ransomware on Azure: JadePuffer ransomware operators are conducting agent-driven attacks against Azure tenants, performing reconnaissance, stealing credentials, and destroying cloud resources [10].
- Arrests & Sentencing: Dutch police confirmed a 24-year-old Amsterdam resident arrested in connection with ShinyHunters [8]. A U.S. Army soldier was sentenced to 70 months in federal prison for hacking AT&T, Verizon, and other telecom companies, stealing call and text metadata for over 100 million AT&T customers [12].
Today’s Action Checklist
- ☐ URGENT: Deploy Microsoft's 974-vulnerability patch batch to Windows and Microsoft products on an expedited timeline
- ☐ URGENT: Audit Oracle PeopleSoft systems for CVE-2026-35273 and apply patches; review authentication and data access logs
- ☐ Update iOS, iPadOS, and macOS to latest versions addressing CVE-2026-86950
- ☐ If using Supabase, verify row-level security policies are enabled and audit for unauthorized access
- ☐ Review third-party security tools and admin credentials for exposure; implement privileged access management controls