Threat Feed

Threat Report 194

Written by Craig Pepper | Sep 28, 2026, 9:30:00 AM

Criminals are breaking into Citrix NetScaler devices worldwide using two brand new flaws, one of which needs no password at all.

A critical bug in F5's BIG-IP APM software is already being used by attackers to run their own code on victims' systems.

Working attack code has been published for a Veeam backup flaw that lets a low-level user seize full control of a Windows machine.

Dyfed-Powys Police is investigating whether staff data was stolen after a cyberattack knocked some of its systems offline.

Fraudsters are tricking HR and payroll staff into installing a fake desktop app that secretly hands over full remote control of their computer.

Revolut customers have been hit by a second data breach this month, after a US brokerage handed over old customer records to social engineers.

An OpenAI AI agent quietly accessed non-public files on an Australian government health data website while carrying out research, without anyone approving it first.

Read on to find out more...

Citrix NetScaler Devices Hit by Zero-Day Attacks Worldwide

Attackers are actively exploiting two newly disclosed vulnerabilities in Citrix NetScaler ADC and Gateway devices. One of the flaws allows an attacker to bypass authentication entirely, meaning they do not need a username or password to get in. NetScaler devices sit at the edge of many organisations' networks, controlling access to internal systems, which makes them a high-value target. Citrix has released patches, but exploitation was already under way before and shortly after the fixes were published.

NetScaler devices are widely used by UK businesses, including in the NHS supply chain, to manage secure remote access. A successful attack can give criminals a foothold deep inside a network, bypassing perimeter defences entirely. Because one of the flaws needs no credentials, even well-managed password policies offer no protection here.

Recommendations:

  • Identify every NetScaler ADC and Gateway device in your estate and confirm its patch level immediately.
  • Apply Citrix's security patches without delay, treating this as an emergency change if necessary.
  • Check logs for signs of compromise predating the patch, not just afterwards.
  • Restrict management interfaces to trusted networks only, never exposing them directly to the internet.
  • Review and rotate credentials and session tokens for any device that may have been exposed.

Critical F5 BIG-IP APM Flaw Actively Exploited

A critical vulnerability in F5's BIG-IP Access Policy Manager (APM) is being actively exploited to run attacker-controlled code on affected systems. BIG-IP APM is used to manage secure remote access and single sign-on for many enterprise networks. F5 has released a patch, but attackers began exploiting the flaw before many organisations had the chance to apply it.

Like the Citrix flaw above, this affects a piece of infrastructure that sits at the boundary of a network and controls access into it. Successful exploitation can let an attacker run their own commands with high privileges, potentially giving them a direct route to sensitive systems and data.

Recommendations:

  • Check whether your organisation or suppliers use F5 BIG-IP APM and confirm current patch status.
  • Apply F5's security update as a priority, given confirmed active exploitation.
  • Review access logs for unusual authentication or administrative activity.
  • Ensure management interfaces are not exposed to the public internet.
  • Ask any third-party IT providers to confirm they have remediated this on your behalf.

Working Exploit Published for Veeam Backup Privilege Escalation Flaw

Proof-of-concept exploit code has been published for a vulnerability in Veeam Backup & Replication that allows a low-privileged local user to escalate their access to full administrator (SYSTEM) level on a Windows machine. With working exploit code now public, the barrier to attackers using this flaw has dropped significantly.

Backup systems are a prime ransomware target, since destroying or encrypting backups removes an organisation's safety net. A flaw that lets even a low-level user seize full control of a machine running backup software is particularly dangerous if that machine is compromised through any other means, such as phishing.

Recommendations:

  • Identify all systems running Veeam Backup & Replication and check the version against the vendor's advisory.
  • Apply the vendor's patch as soon as possible, given public exploit code is now available.
  • Limit who has local login access to backup infrastructure.
  • Ensure backups are also stored offline or immutably, so they cannot be altered even if a backup server is compromised.
  • Monitor backup servers for unexpected privilege changes or new administrator accounts.

Dyfed-Powys Police Investigates Possible Staff Data Theft After Cyberattack

Dyfed-Powys Police has confirmed it is investigating a cyberattack that disrupted some of its IT systems, and is working to establish whether staff data was accessed or stolen. The force has not yet confirmed the full scale or nature of the incident, but has engaged the National Crime Agency and the National Cyber Security Centre as part of its response.

Attacks on police forces and public sector bodies show that no organisation, regardless of its security remit, is immune. For UK businesses and NHS suppliers, this is a reminder that incident response plans need to be tested and ready, and that being open about an ongoing investigation, as this force has been, is part of handling a breach well.

Recommendations:

  • Review your own incident response plan to confirm who needs to be contacted, and how quickly, if a breach is suspected.
  • Confirm you know how to engage the NCSC and, where relevant, the NCA or Action Fraud if you are attacked.
  • Practise your breach communications, including what you can and cannot say publicly during an active investigation.
  • Check that logging is in place to help establish quickly what was and was not accessed in an incident.
  • If you work with any public sector or police bodies as a supplier, review your own access controls to their systems.

Fake HR and Payroll Apps Trick Staff Into Installing Remote Access Tool

Security researchers have found a scam that tricks HR and payroll staff into installing a fake "desktop app" for software they already use every day. The real HR and payroll providers being copied do not actually offer a Windows app, but the fake one looks convincing. It shows what looks like a genuine Microsoft installer window and is even downloaded from GitHub, a trusted code-sharing website. Behind the scenes, it quietly installs a real, legitimate remote access tool, set up so the victim never sees a warning, an icon, or any sign that someone else can now control their computer. It restarts automatically and stays connected, giving the attacker long-term, hidden access.

HR and payroll staff routinely handle some of an organisation's most sensitive information, including salaries, bank details, home addresses and, in health and care settings, sometimes staff or patient records too. Because every part of this scam uses genuine, trusted tools rather than obvious malware, it is very hard to spot using normal antivirus checks. UK businesses, NHS suppliers and healthtechs should treat this as a reminder that a convincing "faster app" download is a growing route into an organisation, especially for staff who are not typically security-trained.

Recommendations:

  • Check with your HR and payroll software providers whether they actually offer a desktop app; if not, warn staff never to install one claiming to be theirs.
  • Block staff from installing new remote access or remote monitoring tools without IT approval.
  • Review which remote access tools are authorised on your network, and alert on any others found running.
  • Brief HR, payroll and finance staff specifically, as they are being directly targeted by this campaign.
  • Report any suspicious downloads or unexpected installers to your IT or security team immediately.

Revolut Customers Caught Up in Second Data Breach This Month

Revolut customers have been affected by a data breach at DriveWealth, a US brokerage that used to handle Revolut customers' US stock trading before Revolut changed its arrangements. Criminals talked their way into DriveWealth's systems using a social engineering trick, convincing someone to hand over access rather than hacking in directly. They stole old customer records, including names, email addresses, phone numbers, postal addresses and partial account numbers. Passwords and card details were not taken. This is the second breach affecting Revolut customers in September; an earlier, separate incident saw criminals trick Revolut itself into handing over more sensitive data, including passport and driving licence details, by pretending to be a government agency.

This shows how customer data can remain at risk long after an organisation stops working with a particular supplier or partner, because that old data often stays on the supplier's systems. UK businesses and NHS suppliers that have changed suppliers, migrated systems, or ended a partnership should think about what historic data those former partners might still hold, and for how long. It is also a reminder that social engineering, tricking a real member of staff into helping, remains one of the most effective ways for criminals to get past technical security controls altogether.

Recommendations:

  • Keep a record of every third party that has ever held your customer or staff data, even suppliers you no longer use.
  • Ask former suppliers and partners to confirm how long they retain your data and when it will be deleted.
  • Train staff to recognise social engineering attempts, including requests that look official or urgent.
  • Review what verification steps are required before releasing customer data to any third party, including trusted partners.
  • Encourage customers to be alert for phishing messages that reference real account details, as stolen data is often used to make scams more convincing.

AI Agent Quietly Accessed Non-Public Files on Government Health Website

Australia's Prime Minister has revealed that an OpenAI AI agent accessed an Australian government website without permission while carrying out research, including some non-public files. The agent was looking up Medicare health statistics, Australia's national health insurance scheme, but ended up reaching further into the site than it should have, including internal file names and information that was not meant to be public. OpenAI said it found the incident while reviewing cases where its AI agents had behaved unexpectedly. The company took over two months to tell the Australian government what had happened, and initially only sent the news to a general, unmonitored email address rather than contacting officials directly. No personal information is believed to have been taken.

AI agents, tools that can browse the internet and take actions on their own to complete a task, are increasingly being used inside organisations to save time on research and admin. This incident shows they can end up accessing systems and files well beyond what anyone intended or approved, sometimes without the organisation even knowing until much later. UK businesses, NHS suppliers and healthtechs that use or are considering AI agents, whether bought in or built in-house, should think carefully about what those agents can reach, and make sure there is a clear, tested way to find out quickly if something goes wrong. For organisations handling health data, the fact that a government health statistics portal was the one affected here is a useful reminder to think about AI agent access as part of your own risk assessments.

Recommendations:

  • Keep a record of every AI agent or tool with browsing or autonomous action capabilities used across your organisation.
  • Restrict what systems and data any AI agent can access, following the same least-privilege principle used for staff accounts.
  • Ask any AI vendor you use how quickly they commit to telling you if their tool accesses something it should not.
  • Monitor for unusual or automated-looking access patterns on public-facing systems and portals.
  • Include AI agent and tool usage in your supplier and third-party risk reviews, including for DSPT purposes where relevant.

If you're worried about any of the threats covered in this week's report, get in touch with Periculo; we're here to help.