On Call Brief – Week of September 27 – October 3, 2026

2026-09-27 — 2026-10-03 Briefing: 2026-09-27 Last updated 11 hours ago (Oct 1, 2026 3:51 am EDT) 18 min read
Share
Category:
Tags:

This week's top stories

1. Custom ChatGPTs push ClickFix attacks to deploy RAT malware

  • Category: Deep Dive
  • What happened: Custom versions of ChatGPT are being used in ClickFix attacks to redirect users to malicious sites that deploy RAT malware. These attacks exploit sponsored Google results to target unsuspecting individuals.
  • Takeaway: Operators should be aware of the potential for malware delivery through deceptive AI tools, which could compromise systems and data security - vigilance in monitoring and user education is essential.
  • Source: Bleeping Computer
  • Tags:

2. Ray, Weaviate, MCP, LiteLLM Default Configs Allow Unauthenticated Access

  • Category: Deep Dive
  • What happened: An audit of default Helm charts and Docker configurations for popular AI stack tools revealed significant security flaws. Key issues include unauthenticated job submissions in Ray, insecure local protection in MCP servers, plain-text database credentials in LiteLLM migration jobs, and multiple charts allowing anonymous access. The findings highlight the need for stricter security measures, such as enforcing NetworkPolicies and using tools like Kyverno or OPA to secure Kubernetes deployments.
  • Takeaway: The identified vulnerabilities could lead to unauthorized access and execution within Kubernetes clusters, posing a risk to production environments. Teams should review their deployments of these tools and implement necessary security policies to mitigate these risks.
  • Source: Reddit r/devops
  • Tags:

3. ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)

  • Category: Deep Dive
  • What happened: Attackers are exploiting the ScreenConnect client by sending phishing emails that link to a malicious executable. The executable is a legitimate ScreenConnect client configured to connect back to the attacker's server. This highlights the risk of trusted remote management tools being misused for unauthorized access.
  • Takeaway: Organizations using ScreenConnect or similar remote management tools should review their security measures, especially regarding email filtering and executable downloads, to prevent such phishing attacks.
  • Source: SANS ISC
  • Tags:

4. Metamask discloses security incident affecting its infrastructure

  • Category: Deep Dive
  • What happened: MetaMask has reported a security incident impacting its infrastructure, although specific details about the nature of the incident and its implications are still unclear. The company is actively addressing the situation.
  • Takeaway: This incident could affect users' access to MetaMask services and may pose security risks for transactions. Operators should monitor for updates and potential vulnerabilities.
  • Source: Bleeping Computer
  • Tags:

CVE & Security

5. Apple Patches Actively Exploited Zero-Day in iOS 26 and macOS (CVE-2026-86950)

  • Category: Security / Patch
  • What happened: Apple released emergency security updates for iOS 26, macOS 26, and macOS 15 to fix CVE-2026-86950, an actively exploited zero-day vulnerability in CoreGraphics that was used in sophisticated targeted attacks reported by Meta. The vulnerability is not present in newer iOS and macOS 27 versions. Operators should immediately deploy these patches to affected devices, prioritizing iOS 26 and macOS 26/15 systems to prevent exploitation of this actively used attack vector. Organizations running macOS 27 or newer iOS versions can verify they are not affected by this specific vulnerability.
  • Do this Monday: Operators using affected versions of iOS and macOS should prioritize applying these patches to mitigate the risk of exploitation. The vulnerability's active exploitation highlights the need for vigilance in monitoring and updating systems.
  • Sources: SANS ISC, Bleeping Computer
  • Tags:

6. Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path

  • Category: Security / Patch
  • What happened: A proof-of-concept for CVE-2026-86950 has been released, demonstrating a vulnerability in Apple CoreGraphics that can be exploited through a malicious PDF containing a crafted embedded font. This flaw can crash unpatched iPhones and Macs, indicating a potential attack vector targeting specific individuals.
  • Do this Monday: This vulnerability poses a risk to users of unpatched Apple devices, as it can be exploited via malicious PDFs, leading to crashes and potential denial of service. Operators should ensure devices are updated to mitigate this risk.
  • Source: The Hacker News
  • Tags:

7. Citrix NetScaler CVE-2026-8452: Pre-Auth Root RCE & Active CISA KEV Exploitation

  • Category: Security / Patch
  • What happened: CVE-2026-8452 is a critical memory-overflow vulnerability in Citrix NetScaler ADC and Gateway appliances that allows unauthenticated remote code execution with root privileges. This flaw has been confirmed as actively exploited and is included in CISA's Known Exploited Vulnerabilities catalog. Administrators are advised to upgrade to patched firmware, audit SAML endpoints, and isolate management interfaces to mitigate risks.
  • Do this Monday: The vulnerability poses a significant risk as it allows attackers to gain immediate access to corporate environments through compromised NetScaler appliances, which handle authentication and remote access. Immediate action is required to prevent exploitation.
  • Source: dev.to (DevOps tag)
  • Tags:

8. Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

  • Category: Security / Patch
  • What happened: Citrix NetScaler ADC and NetScaler Gateway are affected by two critical zero-day remote code execution vulnerabilities, CVE-2026-88771 (improper input validation) and CVE-2026-88772 (memory overflow in the DTLS protocol), that are being actively exploited in the wild to drop web shells and steal configuration data. CISA has added both vulnerabilities to its Known Exploited Vulnerabilities Catalog and mandated U.S. federal agencies patch by Wednesday. Citrix released patches on September 27, 2024 for all affected NetScaler products. Operators should immediately apply available security updates, review systems for indicators of compromise including web shells mapped to CSS-like URLs, and check for unauthorized superuser accounts or configuration changes that may indicate post-exploitation activity.
  • Do this Monday: This vulnerability could lead to unauthorized access and control over affected NetScaler instances, potentially compromising sensitive data and configurations - operators should prioritize patching and monitoring for unusual activity.
  • Sources: The Hacker News, Tenable Blog, CISA Cybersecurity Advisories (+1 more)
  • Tags:

9. Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft

  • Category: Security / Patch
  • What happened: Bitget confirmed that a zero-day vulnerability in third-party security products was exploited to steal $387.5 million from the exchange. The investigation by SlowMist revealed malicious activity and a customized tool used by the attackers.
  • Do this Monday: This incident highlights the risks associated with third-party security products and the potential for significant financial loss due to zero-day vulnerabilities - operators should review their reliance on external security solutions.
  • Source: The Hacker News
  • Tags:

10. ESXi Exploitation in the Wild

  • Category: Security / Patch
  • What happened: The article discusses the exploitation of a vulnerability in ESXi, which allows attackers to escape from a virtual machine and execute code on the host. This vulnerability has been observed in the wild, raising concerns about the security of ESXi deployments. The discussion highlights the implications for organizations using ESXi and the need for immediate patching to mitigate risks.
  • Do this Monday: Organizations using ESXi should prioritize patching to prevent potential exploitation of this vulnerability, which could lead to significant security breaches.
  • Source: Huntress via Lobsters
  • Discussion: https://lobste.rs/s/f6dogm/esxi_exploitation_wild
  • Tags:

11. Cloudflare fixes Containers cross-tenant flaw exposing customer data

  • Category: Security / Patch
  • What happened: Cloudflare has addressed a vulnerability in its Containers and Sandboxes that permitted customers with a Workers Paid account to access residual data from other customers' containers on the same physical host. This flaw posed a risk of data exposure between tenants.
  • Do this Monday: This fix is critical as it mitigates the risk of cross-tenant data exposure, which could affect customer trust and compliance. Operators using Cloudflare's services should ensure they are on the latest version to benefit from this patch.
  • Source: Bleeping Computer
  • Tags:

12. 10 vulnerabilities attackers are exploiting right now: what to patch this week (21 to 25 September 2026)

  • Category: Security / Patch
  • What happened: This article lists ten vulnerabilities that are currently being exploited, as added to CISA's Known Exploited Vulnerabilities (KEV) catalogue between September 21 and 25, 2026. Each entry includes the product affected and its corresponding CVE ID, emphasizing the urgency for patching these vulnerabilities. Additionally, it highlights alerts from European authorities regarding critical vulnerabilities in F5 BIG-IP APM and WordPress Core, suggesting that these should be prioritized for remediation. The article also mentions a data breach involving LimeLeads, advising readers to check if their addresses were compromised.
  • Do this Monday: Operators should prioritize patching the listed vulnerabilities to mitigate the risk of exploitation. The overlap of alerts from CISA and European authorities indicates a heightened threat level for certain products, particularly F5 BIG-IP APM and WordPress Core. Awareness of the LimeLeads breach is also crucial for assessing potential risks to user accounts.
  • Source: dev.to (DevOps tag)
  • Tags:

13. Chromium: 2 security fixes

  • Category: Security / Patch
  • What happened: Microsoft's Security Update Guide listed 2 Chromium vulnerabilities this week, which reach Microsoft Edge through its Chromium engine: CVE-2026-91728 (integer overflow); CVE-2026-91745 (use after free).
  • Do this Monday: This CVE could potentially allow attackers to exploit the integer overflow, leading to security risks in applications using Chromium. Operators should assess their use of Chromium and apply necessary patches.
  • Sources: Microsoft MSRC Security Update Guide
  • Tags:

14. ALAS2023-2026-3103 (important): kernel6.12

  • Category: Security / Patch
  • What happened: This advisory addresses multiple CVEs related to kernel version 6.12, highlighting critical vulnerabilities that could affect system security. The listed CVEs include CVE-2026-64058, CVE-2026-64068, CVE-2026-72288, CVE-2026-72398, CVE-2026-72413, CVE-2026-74347, CVE-2026-74405, CVE-2026-80844, and CVE-2026-81000.
  • Do this Monday: Operators should prioritize applying the security patches for kernel 6.12 to mitigate risks associated with these vulnerabilities, as they could lead to significant security breaches.
  • Source: Amazon Linux 2023 Security Advisories (ALAS2023)
  • Tags:

15. ALAS2KERNEL-5.4-2026-131 (important): kernel

  • Category: Security / Patch
  • What happened: This advisory addresses multiple CVEs affecting the kernel in Amazon Linux 2, specifically CVE-2026-64564, CVE-2026-68138, CVE-2026-74582, and CVE-2026-74688. It is important for users to apply the recommended updates to mitigate potential security vulnerabilities.
  • Do this Monday: Failure to update may expose systems to security risks associated with the listed CVEs - critical for maintaining system integrity and security.
  • Source: Amazon Linux 2 Security Advisories (ALAS2)
  • Tags:

16. ALAS2023-2026-3114 (important): dotnet8.0

  • Category: Security / Patch
  • What happened: Amazon Linux 2023 has released a security advisory for dotnet 8.0 addressing vulnerabilities identified as CVE-2026-58649 and CVE-2026-62886. These vulnerabilities may pose security risks and require immediate attention from users of dotnet 8.0 on Amazon Linux 2023.
  • Do this Monday: Operators using dotnet 8.0 on Amazon Linux 2023 should prioritize applying the security updates to mitigate potential risks associated with the identified vulnerabilities.
  • Source: Amazon Linux 2023 Security Advisories (ALAS2023)
  • Tags:

17. ALAS2023-2026-3112 (important): qemu

  • Category: Security / Patch
  • What happened: The advisory details multiple vulnerabilities in QEMU, specifically CVE-2026-17516, CVE-2026-63323, and CVE-2026-66022. These vulnerabilities may affect systems running QEMU and require attention for patching to maintain security.
  • Do this Monday: Operators should prioritize applying security patches for QEMU to mitigate risks associated with these vulnerabilities - failure to do so could lead to potential exploitation.
  • Source: Amazon Linux 2023 Security Advisories (ALAS2023)
  • Tags:

18. USN-8825-1: Requests vulnerability

  • Category: Security / Patch
  • What happened: A vulnerability in the Requests library was found where it fails to properly handle the generation of random temporary file paths. This flaw could allow an attacker to execute arbitrary code.
  • Do this Monday: This vulnerability could pose a significant risk if the Requests library is used in applications that handle untrusted input, potentially leading to code execution vulnerabilities in production environments.
  • Source: Ubuntu Security Notices (USN)
  • Tags:

19. RHSA-2026:72264: Critical: unbound security update

  • Category: Security / Patch
  • What happened: A critical security update for unbound is available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Telecommunications Update Service. This update addresses vulnerabilities rated as critical by Red Hat Product Security, with detailed severity ratings provided via CVSS.
  • Do this Monday: Operators using Red Hat Enterprise Linux 8.8 should prioritize applying this critical update to mitigate potential security risks associated with unbound vulnerabilities.
  • Source: Red Hat Security Advisories (RHSA)
  • Tags:

20. USN-8826-1: LXC vulnerabilities

  • Category: Security / Patch
  • What happened: Two vulnerabilities in LXC have been identified: one related to improper logging that could lead to sensitive information leakage (CVE-2022-47952), and another concerning user authorization that may result in denial of service (CVE-2026-39402). These issues affect multiple versions of Ubuntu, including 16.04 LTS through 24.04 LTS.
  • Do this Monday: Operators using affected Ubuntu versions should apply the security updates to mitigate risks of information leakage and denial of service attacks.
  • Source: Ubuntu Security Notices (USN)
  • Tags:

21. Status page: 2 service incidents

  • Category: Security / Patch
  • What happened: GitLab is experiencing two separate service degradations on their SaaS platform: security and vulnerability reports are failing to load or ingest for some users, and email delivery is delayed for certain email service providers. The GitLab team has identified the root cause of the security report issue and is actively implementing mitigation measures while monitoring processing improvements. For the email delays, GitLab has escalated the problem with their email delivery provider and implemented interim measures to reduce impact. SRE teams using GitLab SaaS should monitor their security dashboards for report availability and be aware that notification emails may arrive late, potentially affecting incident response workflows or security alert pipelines.
  • Do this Monday: This incident may affect users relying on security reports for vulnerability management, potentially delaying their ability to respond to security issues.
  • Sources: GitLab Status
  • Tags:

22. k3s v1.35.9+k3s1: Kubernetes update, Traefik ingress-nginx provider renamed

  • Category: Security / Patch
  • What happened: The v1.35.9+k3s1 release updates Kubernetes to v1.35.9 and includes a breaking change in the Traefik chart, where the ingress-nginx provider name changes. It also addresses various issues and includes multiple image version bumps, including Traefik to v3.7.13 and updates related to CVE-2026-84445.
  • Do this Monday: The breaking change in the Traefik chart may require updates to configurations using ingress-nginx. The update to Kubernetes and various image bumps could affect stability and performance, so testing in a staging environment is advised before deploying to production.
  • Source: k3s releases
  • Tags:

Also this week

Deep dives & postmortems

23. Job processing and scheduling is degraded affecting multiple Atlassian products

  • Category: Deep Dive
  • What happened: Atlassian is experiencing a platform-wide incident affecting job processing and scheduling across Jira, Confluence, and Bitbucket Cloud. Users are experiencing delayed or missing job executions, which impacts email-to-ticket processing in Jira, scheduled tasks across all products, and other automated workflows that depend on the job scheduling infrastructure. Operators should monitor the Atlassian status pages for updates and prepare to handle backlogs of delayed jobs once processing resumes. Consider temporarily increasing manual monitoring of critical automated processes and alerting end users about potential delays in ticket creation from email and other scheduled operations.
  • Takeaway: This incident may lead to delays in ticket processing and response times, affecting service level agreements and backlog management for users relying on Atlassian products. Operators should be aware of potential disruptions in scheduled tasks and job executions.
  • Sources: Jira Status, Bitbucket Status, Confluence Status
  • Tags:

24. Copilot Code Review is unable to complete reviews

  • Category: Deep Dive
  • What happened: Copilot Code Review experienced performance issues, preventing successful reviews. The incident has been resolved, and users can now re-request reviews on their pull requests. A detailed root cause analysis will be provided later.
  • Takeaway: This incident affected the ability to complete code reviews using Copilot, which may have delayed development workflows for teams relying on this feature - users should re-request reviews for previously impacted pull requests.
  • Source: GitHub Status
  • Tags:

25. Bitbucket Cloud - Database Maintenance

  • Category: Deep Dive
  • What happened: Bitbucket will conduct scheduled database maintenance on October 3rd, 2026, from 16:00 to 16:30 UTC, which will result in a short downtime affecting all Bitbucket Cloud services. Users are advised to plan their operations accordingly as performance degradation may occur during the maintenance window.
  • Takeaway: This maintenance will impact all Bitbucket Cloud services, including the website, Git operations, API requests, and Bitbucket Pipelines, potentially leading to downtime and degraded performance.
  • Source: Bitbucket Status
  • Tags:

Human Stories

The security stories this week share an uncomfortable truth: the tools we're rushing to adopt - AI frameworks, remote support clients, even ChatGPT customizations - are outpacing our muscle memory for hardening them. When Ray and Weaviate ship with unauthenticated access by default, or when ScreenConnect becomes an attacker's favorite persistence mechanism, we're seeing the gap between innovation velocity and security maturity play out in real time. What strikes me about the Atlassian job processing incident and the Copilot Code Review degradation is how dependent we've become on these platforms working flawlessly, yet we're still figuring out how to deploy the next generation of tooling safely. The MetaMask disclosure and those ClickFix attacks remind us that our users are being targeted through the same trust relationships we rely on daily, which means our responsibility extends beyond keeping services up to keeping people safe from increasingly sophisticated social engineering that exploits the very tools meant to help them.

Also worth reading

How Do I Version and Roll Back an AI Pipeline in Production? (dev.to (DevOps tag))

The article discusses the importance of versioning AI pipelines in production to facilitate easier rollbacks. It emphasizes creating immutable versions of the pipeline that can be deployed without affecting traffic, allowing for quick recovery from errors. The author highlights a case where a minor

I made my compliance tool fail the build rather than lie in the audit report (dev.to (DevOps tag))

The author describes a compliance tool designed to fail builds if required evidence is missing, rather than generating misleading reports. The tool, Opencomplai, ensures that audit documentation is accurate by blocking deployments when necessary evidence is not provided, promoting genuine compliance

We added a fourth server and made our cluster easier to break (dev.to (SRE tag))

The article discusses a recent experience with a Consul cluster where adding a fourth server inadvertently created a new failure mode. During a planned maintenance, a switch reboot caused a split in the cluster, preventing a majority from being reached and leading to service disruptions. The author