Latest Threat Intelligence — Week of September 28, 2026
Our security analysts track vendor advisories, CISA alerts, and live attack campaigns, then translate each one into what it means for a business that has to keep working. At the top of the feed right now: two Citrix NetScaler zero-days under attack with no patch, no advisory and not even a CVE number assigned, in the appliance staff use to reach the network from outside; a Microsoft SharePoint Server flaw being exploited against the server holding your internal documents, with a federal patch deadline that lands today; a Roundcube webmail flaw that lets an attacker tamper with the mail database before anyone logs in, patched back in May and still being used; and a flaw in WordPress core itself, not a plugin, that lets a stranger with no account run code on the server hosting your website. Notice what these have in common: one cannot be patched at all yet, and one was patched five months ago. Patching is necessary and it is not sufficient — what decides the cost of an incident is how fast someone notices and what evidence you can hand the bank, the insurer and your customers afterward.