Content 

01. News Bites
  • Nearly three in four EU workers encounter cyber threats

  • South African air traffic services provider investigates ransomware-linked malware

  • Citrix patches two critical NetScaler Zero-Days exploited in attacks

  • Cisco patches critical SD-WAN Zero-Day allowing administrator access

  • Russian hackers use email conversations to target over 100 organisations

02. Conclusion

Quick News Bites

Nearly three in four EU workers encounter cyber threats

Nearly three in four EU workers have encountered cyber-attacks or digital threats at work, according to a recent Eurobarometer survey, highlighting the continued importance of employee cybersecurity awareness.

More than 39% of respondents reported encountering phishing links or messages, while AI-generated attacks accounted for around 15% of workplace scams. These techniques can help criminals create convincing messages and impersonations that are harder to identify.

The survey also revealed gaps in awareness. Around 69% of respondents said they were unaware that work-related information should not be shared on social media, potentially exposing organisations to targeted phishing and social engineering.

Meanwhile, 48% said they could recognise AI-generated fake videos, although confidence does not necessarily demonstrate an ability to detect sophisticated deepfakes.

The findings highlight why organisations of every size need regular awareness training, clear guidance on sharing information and straightforward reporting processes to help employees recognise suspicious activity and respond more effectively.

South African air traffic services provider investigates ransomware-linked malware

South Africa’s Air Traffic and Navigation Services (ATNS) has launched a search for cyber-forensics specialists after discovering ransomware-linked malware in an operational technology (OT) network supporting weather services.

The state-owned company, which supports approximately 10% of the world’s airspace, said technical teams had contained the suspicious activity and removed the malware. However, further investigation is needed to establish the cause, extent of the compromise and any remaining risks.

Public procurement documents also identified indications of possible data exfiltration to external IP addresses in China. This does not establish who was responsible for the incident.

A separate suspected insider data theft is also included in the investigation request. The timing of the incidents remains unclear, although ATNS requested forensic services from 18 September.

The case highlights the importance of monitoring OT environments, investigating potential data loss and validating containment measures across aviation infrastructure, where disruption can have significant consequences for operations.

Citrix patches two critical NetScaler Zero-Days exploited in attacks

Citrix has released security updates for two critical NetScaler vulnerabilities following confirmation that attackers are actively exploiting both flaws.

Tracked as CVE-2026-88771 and CVE-2026-88772, the vulnerabilities affect NetScaler ADC and NetScaler Gateway appliances and both carry severity scores of 9.5.

The first allows unauthenticated attackers to execute arbitrary commands and affects deployments even in their default configuration. The second can enable remote code execution or denial of service when DTLS is enabled, which is the default for VPN virtual servers.

NetScaler appliances are attractive targets because they commonly provide internet-facing remote access and application delivery services. A successful compromise could give attackers a foothold into corporate networks.

The updates also address six additional vulnerabilities. Organisations running affected customer-managed appliances should prioritise upgrading to the recommended versions.

Where immediate patching is not possible, reducing internet exposure where operationally feasible can help limit risk while teams prepare to apply the necessary security updates.

Cisco patches critical SD-WAN Zero-Day allowing administrator access

Cisco has released security updates for a critical vulnerability in Catalyst SD-WAN Manager that attackers are actively exploiting to gain administrator privileges.

Tracked as CVE-2026-76504, the flaw affects all deployments regardless of configuration. It allows unauthenticated remote attackers to bypass authentication by sending a specially crafted HTTP request to an affected system’s API.

Formerly known as SD-WAN vManage, the platform enables organisations to monitor and manage up to 6,000 SD-WAN devices through a single dashboard, making unauthorised access particularly concerning.

Cisco became aware of exploitation in September and strongly recommends upgrading to a fixed software release. It has also published indicators of compromise to help security teams investigate suspicious authentication requests and identify potential intrusions.

CISA has added the vulnerability to its Known Exploited Vulnerabilities catalogue, requiring US federal agencies to remediate it by 3 October.

This marks the fifth actively exploited Cisco SD-WAN zero-day reported so far in 2026.

Russian hackers use email conversations to target over 100 organisations

Russian state-linked hacking group Star Blizzard has targeted more than 100 organisations through a phishing operation that builds trust before delivering malicious files.

Researchers identified at least 13 campaigns between January and August 2026, primarily targeting US and UK organisations. Targets included government, research, journalism and financial groups involved in Ukraine-related work.

The initial email contains no malicious attachment, instead inviting recipients into seemingly legitimate professional conversations. Those who respond receive password-protected archives, with passwords supplied as images to hinder automated inspection.

The files can contain Windows shortcuts disguised as PDFs or virtual disks that trigger malicious downloads. The RedFlick delivery chain has been observed deploying the CosmicPulse backdoor, potentially giving attackers persistent access to compromised devices.

The campaign highlights why an established email conversation should not automatically be trusted. Organisations should verify unexpected document requests through known channels and investigate suspicious archives, scripts and scheduled tasks promptly.

Closing Summary

If you are worried about any of the threats outlined in this bulletin or need help in determining what steps you should take to protect yourself from the most material threats facing your organisation, please contact your account manager, or alternatively Get in touch to find out how you can protect your organisation. 

Disclaimer

The Threat Intel Roundup was prepared by Integrity360 summarising threat news as we observe it, current at the date of publishing. It should not be considered to be legal, consulting or any other professional advice. Any recommendations should be considered in the context of your own organisation. Integrity360 does not take any political stance in the information that we share. Moreover, the opinions expressed may not necessarily be the views of Integrity360.