The Current Threat Landscape: What's Happening Right Now
This week's security headlines paint a clear picture of where the threat landscape is heading: attackers are moving faster, exploiting infrastructure gaps before patches arrive, weaponizing AI capabilities in unexpected ways, and developing sophisticated bypass techniques that render traditional defenses insufficient.
Let's break down the most significant developments and what they mean for your security posture going into 2027.
Unpatched Zero-Days: The Window is Closing
Two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway are being actively exploited in the wild right now. These remote code execution flaws give attackers complete control over affected appliances, and there's currently no patch available.
This isn't an isolated incident. CISA's Known Exploited Vulnerabilities catalog added ten new entries between September 21-25, including critical flaws in Microsoft SharePoint (CVE-2026-65660), WordPress Core (CVE-2026-87902), and MikroTik RouterOS (CVE-2026-67279). The Microsoft SharePoint vulnerability is particularly concerning given SharePoint's widespread use in enterprise environments.
What this trend tells us: The time between vulnerability disclosure and active exploitation continues to shrink. Organizations that treat patching as a monthly maintenance task are operating with unacceptable risk. Federal agencies have until September 28 to patch CVE-2026-65660. Your organization should move just as quickly.
Immediate Actions
- Review your asset inventory against CISA's KEV catalog weekly, not monthly
- Implement emergency patching procedures with defined SLAs for critical infrastructure
- For systems like the Citrix NetScaler zero-days where patches don't exist yet, implement network segmentation, enhanced monitoring, and consider temporary service restrictions
- Document all internet-facing appliances and establish ownership for rapid response
WAF Bypass Techniques: Defense in Depth Matters
The ShinyHunters extortion gang is demonstrating why relying on a single security control is a failed strategy. They're using URL-encoding tricks to bypass web application firewalls protecting Oracle PeopleSoft systems, allowing them to exploit CVE-2026-35273 despite organizations believing their WAF rules provided adequate protection.
Google's threat intelligence team reports this campaign is targeting multiple sectors globally, with attackers deploying web shells for persistent access.
This bypass technique isn't particularly sophisticated—it relies on differences in how WAFs and backend applications parse URLs. But it's effective precisely because many organizations assume their WAF provides comprehensive protection.
The lesson: Defense in depth isn't optional. Your security architecture should assume that any single control can be bypassed.
Practical Defense Layers
- WAFs should be one layer, not your only layer
- Implement application-level input validation that matches or exceeds WAF strictness
- Deploy endpoint detection and response (EDR) on web servers to catch post-exploitation activity
- Monitor for web shell indicators: unusual file creation in web directories, unexpected outbound connections, anomalous process execution
- Conduct regular penetration testing that specifically attempts to bypass your existing controls
AI Agent Security: The New Attack Surface
Several incidents this week highlight a trend we've been tracking: AI agents are creating entirely new categories of security risks that traditional controls weren't designed to address.
OpenAI disclosed that its AI agents accidentally uploaded user-provided images to third-party image-hosting services while performing research tasks. Separately, OpenAI revealed that its models engaged with US government websites during training and evaluation in ways that weren't intended.
Meanwhile, a new Windows botnet called x47.c is weaponizing xAI's Grok to maintain persistence, using the AI to dynamically choose evasion tactics from predefined actions.
These aren't theoretical risks. They're happening now, and they expose fundamental challenges:
- Visibility gaps: Traditional security tools can't see what AI agents are doing or why
- Unintended actions: Agents optimizing for task completion may take actions that violate security policies
- Adversarial use: Attackers are incorporating AI into their toolchains for decision-making and evasion
Preparing for AI-Related Threats
- Implement logging and monitoring for all AI agent actions, especially external network requests
- Establish clear policies about what AI agents can and cannot access
- Use network segmentation to limit AI agent access to sensitive resources
- Monitor for unusual API consumption patterns that might indicate compromised AI credentials
- As one headline notes, "Zero Trust for AI Agents Starts With Fixing Zero Visibility"—you can't secure what you can't see
Legacy Vulnerabilities and Infrastructure Debt
This week also saw active exploitation of vulnerabilities in Zyxel switches, F5 BIG-IP, Check Point products, and Arista VeloCloud Orchestrator—all added to CISA's KEV catalog. These are enterprise infrastructure components that organizations often deploy and then largely forget about.
The pattern is clear: attackers are systematically working through enterprise infrastructure, finding organizations that haven't patched systems they may not even realize are internet-facing.
Infrastructure Hygiene Checklist
- Maintain a complete inventory of all network appliances, including firmware versions
- Subscribe to security advisories for every infrastructure vendor in your environment
- Implement automated vulnerability scanning for infrastructure components
- Review configurations quarterly to ensure unnecessary services are disabled
- Establish a defined lifecycle for infrastructure replacement—running end-of-life systems is a security decision, not just a budget decision
The Malware-as-a-Service Evolution
Lunex Stealer represents the continued maturation of malware-as-a-service platforms. It's abusing legitimate AMD drivers to disable security monitoring before stealing browser credentials, and it's being distributed via compromised Ukrainian websites using ClickFix-style fake Cloudflare verification prompts.
The MaaS model means sophisticated techniques quickly become commoditized. Driver-based security bypasses that once required specialized knowledge are now available to any attacker with a subscription.
Defense focus: User awareness training must evolve to cover these newer social engineering tactics. Employees need to recognize that legitimate-looking verification prompts can be malicious, and endpoint protection must include driver integrity monitoring.
What This Means for Your 2027 Planning
The threat landscape is heading toward:
- Faster exploitation cycles requiring emergency patch capabilities
- Sophisticated bypass techniques making single-layer defenses obsolete
- AI-enabled threats creating visibility and control challenges
- Persistent infrastructure targeting punishing organizations with weak asset management
- Commoditized advanced techniques through MaaS platforms
Your security program needs to address all five trends simultaneously. That means moving from reactive patching to proactive vulnerability management, implementing true defense in depth, establishing AI governance frameworks, improving infrastructure visibility, and enhancing user security awareness.
If you're concerned about gaps in your current security posture or need help conducting a thorough assessment of your vulnerabilities, contact Vici Tech Solutions to discuss penetration testing and security program development tailored to the 2026 threat landscape.