Bharat Threat FeedGlobal threats, decoded for Indian defenders
Government & Defence Sector Edition · September 2026

Government & Defence Sector Edition — September 2026

Two unauthenticated remote code execution flaws in Citrix NetScaler were being exploited from 5 September, more than three weeks before Citrix disclosed them, and NetScaler Gateway is the appliance many Indian financial institutions and global capability centres use to front branch, vendor and remote-staff access. In the same fortnight attackers moved roughly 351 million dollars out of a crypto exchange without touching a private key, by making a backend service authorise transfers it should have refused. Add a management plane that is now a target in its own right, a CRM assistant that will act on text an outsider supplied, and an RBI framework that commenced with no transition window. For Indian BFSI the pattern is one gap: the edge and the authorisation layer are being attacked faster than the change control that governs them.

1. Sector snapshot

Supervisory expectations moved first this quarter. The Reserve Bank's Cybersecurity, Technology Risk, Resilience and Assurance Framework Directions, issued on 31 July 2026, replaced the 2016 framework with one consolidated instrument per entity class and commenced immediately on issuance, with no phased date or transition window. Operationally, September was dense: CISA added NetScaler, SonicWall, FortiOS, Cisco and SharePoint entries to its exploited-vulnerability catalogue across five separate dates in the month, and every one of those products sits on a control path that Indian banks, NBFCs and insurers depend on. On the fraud side, Global Fintech Fest 2026 in Mumbai heard that digital-arrest scams have fallen by about 67 percent after sustained awareness work, with investment fraud rising in their place, which is displacement rather than reduction.

Source (with date): Reserve Bank of India Directions (31 Jul 2026); Elets BFSI (18 Sep 2026).

2. Threats targeting BFSI

NetScaler zero-days exploited for three weeks before the patch. CVE-2026-88771 (improper input validation leading to unauthenticated remote code execution, affecting all NetScaler ADC and Gateway deployments) and CVE-2026-88772 (memory overflow leading to code execution or denial of service where DTLS is enabled) both carry CVSS 9.5. Citrix published the covering bulletin on 27 September 2026 and confirmed exploitation in the wild; eSentire reports observing exploitation of 88771 against internet-facing Gateway appliances as early as 5 September. Post-exploitation activity includes webshell deployment, credential theft and lateral movement, with Google reporting the WHIPSHOT webshell and the SLAPSHOT tunnelling tool used against 88772. Fixed builds are 14.1-73.37 and later and 13.1-64.23 and later, including the FIPS variants.Exposed:any institution using NetScaler Gateway for remote access or as an AAA virtual server.Action:run a compromise assessment and preserve gateway logs and filesystem artefacts before upgrading, since the patch closes the vulnerability but does not remove an actor already present.

Source (with date): Citrix security bulletin; CISA KEV (27 Sep 2026); eSentire (29 Sep 2026); Help Net Security (28 Sep 2026).

A crypto exchange lost 351 million dollars with its keys intact. Bitget reported that on 24 September 2026 attackers reached a backend system within its wallet infrastructure, spoofed transaction data and triggered the exchange's own authorisation process to release funds; the company states private keys were not compromised, and later tallies put the loss nearer 388 million dollars across seven chains. Attribution is an analytical assessment rather than a settled finding: Bitget's chief executive called North Korean involvement very likely, TRM Labs describes it as a likely North Korea attack while stopping short of definitive attribution, and Elliptic cites laundering patterns and infrastructure overlap with earlier DPRK-linked thefts.Exposed:Indian virtual digital asset platforms directly, and by pattern any bank, NBFC or payment aggregator where a payout, treasury or payment-initiation service can be induced to authorise an instruction it did not originate.Action:confirm that transaction authorisation is validated independently of the service submitting it, and that dual control cannot be satisfied by two components inside the same compromise boundary.

Source (with date): The Hacker News (25 Sep 2026); TRM Labs (25 Sep 2026); Elliptic, reported by Insurance Journal (29 Sep 2026).

Two SonicWall SMA1000 flaws confirmed under exploitation. CVE-2026-83548, a server-side request forgery, and CVE-2026-83549, an operating system command injection, were both added to the CISA catalogue on 2 September 2026 on evidence of active attacks.Exposed:institutions running SMA1000 as a remote-access concentrator for branch or third-party vendor connectivity.Action:patch, then review which vendor accounts still reach the network through the appliance and withdraw those that no longer have a contractual basis.

Source (with date): CISA KEV (2 Sep 2026).

The gap between public exploit detail and attack is now days. Citrix patched CVE-2026-19490, a NetScaler authentication bypass, on 19 August 2026; exploitation began around 3 September 2026, shortly after proof-of-concept code appeared publicly, and the flaw was catalogued on 9 September 2026. Microsoft SharePoint Server CVE-2026-65660, a code-injection route to remote execution for an authenticated low-privilege user, was patched in the August 2026 Patch Tuesday and came under attack roughly six weeks later, days after technical analysis was published; it was catalogued on 25 September 2026, with webshell attempts observed.Exposed:patch governance that defers a non-catalogued vulnerability to the next quarterly window.Action:shift the emergency-change trigger from catalogue listing to publication of exploit detail.

Source (with date): CISA KEV (9 Sep 2026); CISA KEV (25 Sep 2026); SecurityWeek (25 Sep 2026).

3. Sector tech & exposures

- The security management plane is now a target in its own right. Cisco Firewall Management Center CVE-2026-20079, an authentication bypass through an alternate path, was catalogued as exploited on 9 September 2026, and Cisco Secure Email Gateway SQL injection CVE-2026-76461 followed on 14 September 2026. Firewall policy integrity and mail-gateway inspection both sit upstream of payment instruction and KYC correspondence, so a compromise here is a control-assurance failure, not only a host failure. FortiOS remains on the same list: CVE-2025-25249, a heap-based buffer overflow allowing unauthorised code execution through crafted packets across the 6.4 to 7.6 branches, was catalogued on 9 September 2026. Source (with date): CISA KEV (9 Sep 2026); CISA KEV (14 Sep 2026). - Agentic assistants will act on text an outsider supplied. Zenity Labs disclosed three Salesforce Agentforce flaws, together called SalesBleed, in which an indirect prompt injection planted through a public Web-to-Lead form remains dormant until an employee asks the assistant about leads; the agent then embeds retrieved CRM records in image requests to attacker infrastructure, exfiltrating data without a click. A third issue allowed phishing to be sent from a trusted internal Slack identity. Salesforce resolved all three, confirmed on 21 September 2026. Indian banks and insurers extending agentic assistants into sales and servicing desks should treat every untrusted inbound field as executable input. Source (with date): Zenity Labs (24 Sep 2026); The Register (24 Sep 2026). - Managed backends are leaking through defaults, not defects. UpGuard examined roughly 300,000 domains using Supabase and found 16,326 databases with readable tables, more than half showing indicators of personal data, including user records, one-time passcodes and credentials. The cause is missing row-level security policy rather than a platform flaw, and UpGuard associates the volume with AI-assisted development. Fintech and NBFC product teams building on managed backends should audit row-level security before the next release rather than after it. Source (with date): UpGuard, reported by BleepingComputer (25 Sep 2026); TechCrunch (25 Sep 2026).

4. Regulatory & compliance watch

- The RBI framework is in force now. The 31 July 2026 Directions cover commercial banks, small finance banks, payments banks, urban co-operative banks, all-India financial institutions, NBFCs and credit information companies, consolidating governance, technology management, resilience, incident response, business continuity and audit. Insurers and intermediaries sit under the IRDAI Information and Cyber Security Guidelines, 2026, in force since 6 April 2026, and SEBI-regulated entities remain under the CSCRF tiering, so a group with banking, insurance and capital-market arms is now reporting against three distinct instruments. Source (with date): Reserve Bank of India Directions (31 Jul 2026); IRDAI Information and Cyber Security Guidelines (6 Apr 2026). - The DPDP clock reaches its first hard marker in six weeks. The Rules were notified on 13 November 2025. At the twelve-month point in November 2026 the consent-manager registration framework opens, with consent managers required to be incorporated in India and to hold minimum net worth of two crore rupees, and the initial soft-enforcement phase is expected to close. Full substantive compliance, covering notice and consent, security safeguards, breach reporting, data-principal rights and significant-data-fiduciary duties, becomes enforceable at the eighteen-month point in May 2027. Source (with date): MeitY DPDP Rules (13 Nov 2025); India Briefing (Sep 2026). - CERT-In's six-hour intimation remains the tightest clock. The CERT-In directions of 28 April 2022 require initial intimation of a reportable incident within six hours and impose 180-day log retention, and the RBI expects regulated entities to align with them, so the six-hour window operates as a banking-sector obligation alongside the RBI's own reporting requirements. Source (with date): CERT-In directions (28 Apr 2022), as applied through the RBI Directions (31 Jul 2026).

5. Actor in focus

TraderTraitor, the DPRK-linked financial cluster. The group's target set is exchanges, custody platforms and payment-authorisation infrastructure worldwide, and the Bitget tradecraft is what matters for Indian defenders. Rather than attacking key custody, which most exchanges and banks now protect reasonably well, the operators compromised the service that authorises transactions and made it issue instructions on their behalf, then laundered across seven chains quickly enough that only a small fraction of stablecoins could be frozen. Bitget engaged Mandiant and SlowMist for the investigation. Confidence: the DPRK link is the working assessment of named analytics firms and the exchange itself, not a confirmed government finding, and TRM Labs has not issued a definitive attribution. No Indian institution has been named in this incident; the relevance is the pattern.

Source (with date): TRM Labs (25 Sep 2026); Elliptic, reported by Insurance Journal (29 Sep 2026).

6. IOC pack

Public, attributed indicators only. No leaked data reproduced.

IndicatorTypeContextSource (with date)
CVE-2026-88771 / CVE-2026-88772CVENetScaler ADC and Gateway zero-daysCitrix; CISA KEV (27 Sep 2026)
WHIPSHOTWebshellPost-exploitation on NetScaler (CVE-2026-88772)Google, via eSentire (29 Sep 2026)
SLAPSHOTTCP tunnelling toolDeployed alongside WHIPSHOTGoogle, via eSentire (29 Sep 2026)
/var/netscaler/gui/vpn/scripts/linux/*.sigFile pathWebshell drop locationeSentire (29 Sep 2026)
PHP-bearing .deb files in /var/netscaler/gui/vpn/scripts/linux/File artefactWebshell varianteSentire (29 Sep 2026)
NSC_CLIENTTYPE header carrying base64 dataLog patternNetScaler exploitation attempteSentire (29 Sep 2026)
Requests to /vpn/media/*.ico with base64 PHP beginning PD9 appended to the User-AgentLog patternWebshell interactioneSentire (29 Sep 2026)
CVE-2026-19490CVEEarlier NetScaler authentication bypassCISA KEV (9 Sep 2026)
CVE-2026-83548 / CVE-2026-83549CVESonicWall SMA1000 SSRF and command injectionCISA KEV (2 Sep 2026)
CVE-2025-25249CVEFortiOS heap-based buffer overflowCISA KEV (9 Sep 2026)
CVE-2026-20079CVECisco Firewall Management Center authentication bypassCISA KEV (9 Sep 2026)
CVE-2026-76461CVECisco Secure Email Gateway SQL injectionCISA KEV (14 Sep 2026)
CVE-2026-65660CVESharePoint Server code injection to remote executionCISA KEV (25 Sep 2026)

7. Tiered actions

Board: Ask for one page mapping NetScaler, SonicWall, Cisco Firewall Management Center, FortiOS and SharePoint exposure to business services rather than asset counts, and a written position on where the institution stands against the RBI Directions of 31 July 2026, which carry no transition period.

CISO: Make compromise assessment, not patch completion, the closure criterion for every exploited internet-facing system this month. Move the emergency-change trigger to publication of exploit detail. Test whether a payout or payment-initiation authorisation can be validated independently of the service that submits it. Audit row-level security on managed backends and review agentic assistant permissions wherever untrusted inbound text reaches an agent.

SOC: Hunt NetScaler appliances for the webshell paths, the NSC_CLIENTTYPE base64 header and the PD9 User-Agent pattern listed above; review authentication logs for sessions created from 5 September onward; alert on new privileged accounts on gateways and on management-plane logins to Cisco Firewall Management Center from unexpected sources.

8. Source index

Citrix · CISA Known Exploited Vulnerabilities catalogue · eSentire · Google · Help Net Security · CERT-EU · Dataquest India · The Hacker News · TRM Labs · Elliptic · Insurance Journal · CoinDesk · Zenity Labs · The Register · UpGuard · BleepingComputer · TechCrunch · SecurityWeek · Reserve Bank of India · IRDAI · MeitY (DPDP Rules) · India Briefing · CERT-In · Elets BFSI.

9. Byline

1

Nirad Threat Research

NBTF — BFSI Sector Edition | 30 September 2026