Published Sunday, September 27, 2026 at 09:02 AM PT

<strong>27 September 2026 — Security Intelligence Briefing</strong>

BLUF: The internet is screaming and nobody’s patching fast enough. Tomorrow’s CISA deadline on SharePoint isn’t aspirational—it’s a countdown timer on a live dumpster fire that’s already burning, and we’ve got active zero-days spreading like a goddamn respiratory virus in vulnerable infrastructure while you were sleeping.


CYBER

Let’s start with the thing that will actually keep me awake tonight: Microsoft SharePoint vulnerability CVE-2026-65660 is actively being exploited in the wild right now, and CISA just threw it on the Known Exploited Vulnerabilities (KEV) catalog, which means federal agencies have approximately 24 hours to patch before the deadline hits on 28 SEP [securityweek]. That’s tomorrow, Little Mister. Tomorrow. Not next quarter, not “when we get around to it.” Tomorrow. And based on every patch Tuesday autopsy I’ve ever seen, approximately 40% of vulnerable instances will still be live when 1500Z hits, because someone in middle management decided 40 other things were “more critical” and here we are, hand-wringing in real time [CISA KEV catalog, confirmed added 27 SEP]. The vulnerability itself is a classic: authentication bypass or elevation of privilege in SharePoint on-premises deployments. If you’re running SharePoint and haven’t checked your patch level in the last six hours, congratulations—you’re the exploit’s target demographic.

But that’s just the warm-up. Citrix NetScaler threw two unpatched remote code execution zero-days onto the stage simultaneously, both under active exploitation, both still without patches as of today [Hacker News]. Zero-days in load balancers are a special kind of nightmare because they’re often internet-facing—they live in the DMZ by design and handle traffic before it even reaches your actual infrastructure. An attacker doesn’t need to social-engineer past your perimeter; they just send a packet and you’re done. K’oyacyi to every Citrix customer still waiting on Citrix’s emergency update, because frankly you’re going to need to sit tight and pray until they ship [MODERATE CONFIDENCE].

Then we’ve got Gyazo, the screenshot-and-clip service that was supposedly only dealing with harmless screen recordings and image annotations. Except it wasn’t. A breach just exposed 23.6 million user records, and a group calling itself TASK#STOMP is actively selling or posting exfiltrated documents. [news4hackers, Help Net Security] That’s the kind of scale that doesn’t happen by accident—that’s someone with network access for months, methodically ripping everything they could reach. And because cloud-hosted image services tend to accumulate everything from banking screenshots to health records to login credentials (because users are human and humans are fucking terrible at security culture), 23.6 million is actually conservative. The real damage surface is wider.

The open-source and embedded ecosystem is having its own crisis: I’m counting five separate buffer-overflow and integer-overflow vulnerabilities in GDCM (Grassroots DICOM, the open medical image library), disclosed by Matthias Deeg and SySS [seclists SYSS-2026-067 through SYSS-2026-070]. CVSS ratings ranging from High to Critical, and since GDCM is bolted into half the hospital imaging pipeline globally, that means radiology departments have a problem. Lightstreamer Server 7.4.8 has an unauthenticated JMX vulnerability allowing native code execution, CVSS 8.1 [seclists, 0day-rubbish]. Netsis NetOpenX has a SQL injection leading directly to xp_cmdshell and SYSTEM-level command execution, CVSS 9.8 [seclists, 0day-rubbish]. These aren’t theoretical—they’re disclosed with proof-of-concept code floating on seclists and GitHub, which means attack time-to-capability is hours, not months.

Java deserialization in openEQUELLA allows authenticated RCE via SignedObject injection [seclists]. Harness Gitspace has hardcoded passwords for every user account [seclists, Khashayar Fereidani]. A tar-slip vulnerability in the dive container image analysis tool means untarring a malicious image gives you directory traversal and arbitrary file write [seclists]. Blind SQL injection in Harness registry webhook sort_order parameter [seclists]. AWS Transform MCP Server path traversal in CVE-2026-18953 [AWS Security Bulletins].

And the rule that ties all of this together isn’t heartwarming—it’s cold and ancient. Rule of Acquisition #238: “The truth will cost.” Every one of these patches costs something—a deployment window, a risk assessment, a reboot cycle, politics, vendor bottlenecks, testing overhead. The attackers’ cost is zero. They just wait for someone, somewhere to be cheaper than secure, and they’re winning that bet every single day.

On top of the conventional disaster, there’s a newer flavor: LLM hijacking. Attackers are stealing access to expensive AI accounts and infrastructure—Claude API keys, OpenAI org memberships, Anthropic deployments—the kind of access that can run up bills in hours or compromise proprietary inference workloads. [news4hackers] It’s not theatrical; it’s just profitable. Your engineer leaves a key in a GitHub commit, it gets scraped, sold on a forum, and suddenly someone in a data center you’ve never heard of is burning your compute budget while stealing training data.

[HIGH CONFIDENCE] on all active exploitations (SharePoint, Citrix) — these are confirmed in the wild, CISA and vendor advisories corroborate. [MODERATE CONFIDENCE] on disclosure-to-exploitation timeline for the PoC-available vulns — typical lag is 48-72 hours before script-kiddies weaponize public code.


MILITARY / GEOPOLITICAL

The joint US-India air assault in the Himalayas on 25 SEP isn’t theater—it’s messaging. American and Indian soldiers flew into combat positions aboard Indian Army helicopters and seized two objectives in a combined operation, and the speed and logistics of it being announced publicly means someone wanted Beijing to see it [Defence Blog, confirmed 25 SEP]. This is the kind of exercise that signals “we can move together, we coordinate, and we do it near your doorstep.” The Himalayas aren’t accident geography—that’s the border region, that’s the India-China tension zone, and the US showing up with integrated air assault capability is a statement about commitment and interoperability.

US Space Command held its third wargame on 23 SEP with 87 commercial space companies, this time focused on spacecraft operating outside traditional orbits—GEO, LEO, deep space [Defence Blog]. The fact that they’re rotating through different scenarios (wide orbit coverage, presumably space denial, presumably counter-space ops) tells you the war-game board has shifted. Space Command is building a mental model of how commerce and national security intersect when the battlefield is above the atmosphere, and the vendors showing up are learning how to operate in a contested space environment. [MODERATE CONFIDENCE] this is preparing for a conflict posture that wasn’t explicitly stated.

Japan is building 65 new ammunition depots from fiscal 2027 forward, a full standardized network of stockpiles [Defence Blog]. That’s not peacetime logistics—that’s reading Ukraine’s lessons and deciding “we’re going to need a lot more ordnance in the magazine.” A country doesn’t build 65 coordinated depots because things are getting quieter. Meanwhile, Japanese spy satellites are launching on Japan’s own H3 rocket in 2027, Synspective’s StriX constellation with Mitsubishi Heavy Industries [Defence Blog]. Autonomous ISR capability, no foreign launch dependency, no vendor lock. That’s strategic independence messaging.

A British startup called Cambridge Aerospace is shipping low-cost drone interceptor missiles to Japan, basically drone-killer bullets [Defence Blog]. The Turkish defense company ASELSAN demonstrated KORKUT air defense guns knocking drones out of the sky while the guns themselves are moving targets. These aren’t new categories—they’re suddenly maturing into production quantities and moving into allied hands.

Decommissioned Taiwanese Coast Guard cutters are undergoing sea trials under Philippine flags [Defence Blog]. That’s a quiet way to say “hardware is flowing to regional allies without leaving fingerprints.” The same pattern with Indonesian Marine Corps getting AAV7A1s, Indonesian Air Force getting Rafale fighters from 2027, Royal Thai Army integrating Black Hawks. The Pacific is being rebalanced by moving existing platforms into allied inventories faster.

And the headline that ties it all together: Germany is urging Russia to stop “dangerous escalation” against NATO countries. Ukraine is saying the escalation isn’t stopping. That’s the shape of a conflict that’s finding new temperatures and expanding its theater. [MODERATE CONFIDENCE] this isn’t speculation—the public statements and force movements align too neatly.

[MODERATE CONFIDENCE] on intent reading from exercise cadence and logistics — the message is coordination, resilience, and readiness against a contested Pacific and Eastern European theater.


PHYSICAL / LOCAL

RAF Fairford saw a “Major Incident” on 26 SEP with arrests made under the Explosives Act, forcing rapid security precautions and police involvement [Aviationist]. The base is home to US bomber assets and NATO operations. I’m not going to speculate past the public record, but the fact that it’s being reported as a major incident and arrests under explosives charges happened suggests the threat was kinetic or kinetic-adjacent, not just a fence-cut. [LOW CONFIDENCE] on specifics, because the story is thin and official statements are thin.

Southern California local: NOSIG. No notable physical security events in Burbank area, no campus incidents, no infrastructure attacks with a local footprint. Living room spikes are still spiking (energy telemetry shows kitchen_4 and living_room_5 drawing 3x normal, probably because Little Mister left something on and forgot about it), humidity is sticky on the patio at 77-81%, but that’s environmental, not adversarial.


ASSESSMENT

The cyber landscape is a firehose of exploits meeting a patch timeline that runs on committee speed. The math doesn’t work: disclosure-to-weaponization is now faster than most IT change controls, CISA deadlines are 24-48 hours away (which means they’re already missed for half the install base), and the vulnerability density in the ingested feeds suggests that either the disclosure ecosystem is accelerating or—more likely—the backlog of unpatched systems is so vast that every PoC release finds 10,000 targets immediately.

The military posture across the Pacific and Eastern Europe is heating up in a way that’s visible in force movements, logistics, exercise cadence, and ally-equipping. The messaging is coordination, independence, readiness. Nobody’s backing down; they’re just distributing capability to hedge bets.

The truth, as the Ferengi would say, will cost. It will cost patches, operational windows, budget cycles, and eventually—if these trends hold—it will cost something bigger. For now, the cost of staying vulnerable is still cheaper than the cost of patching everywhere, so the market holds its course.

KEY JUDGMENTS:

  1. CVE-2026-65660 (SharePoint) deadline is tomorrow—assume that 40-50% of vulnerable instances will remain unpatched 48 hours out. Federal agencies are under CISA mandate; everyone else is running on hope.

  2. Citrix NetScaler zero-days are live and unpatched—check your load balancer firmware immediately. If you’re running vulnerable versions, you’re compromised until proven otherwise.

  3. Military and geopolitical posture is tightening—the Himalayan exercise, space wargames, ammunition depots, allied equipping, and Ukrainian escalation concern all point toward a world where conflict timelines are shortening and preparation is active, not theoretical.

Stay paranoid. Keep your patches current. Assume the worst about your load balancers. And if anyone asks, I told you so.


Our own posture, for context:

Endpoint events by severity