
Multiple Active Cybersecurity Threats: Macfinger ClickFix, Citrix Vulnerabilities, and Oracle PeopleSoft Exploits
This September 28, 2026 SANS Internet Storm Center Stormcast covers multiple active cybersecurity threats. Brad Duncan identified a Macfinger ClickFix campaign targeting macOS that deploys an information stealer, possibly a variant of Atomic macOS Stealer (Amos), which uses websockets for data exfiltration and comes in separate ARM and x86-64 versions rather than a unified binary. Citrix released patches for eight vulnerabilities in Netscaler ADC and Gateway on Sunday, with two remote code execution vulnerabilities currently being actively exploited; other patched issues include HTTP request smuggling, feature policy bypass, and a TCP initial sequence number prediction vulnerability. A Dutch information security agency advised constituents to turn off Citrix Netscalers on Sunday prior to the patch release. Kiteworks sent emails to customers on Saturday requesting they shut down servers for a specific six-hour window due to a zero-day attack, though details remain limited. Mandiant reported that the Shiny Hunters group continues exploiting a June 2026 Oracle PeopleSoft vulnerability while bypassing web application firewalls through simple URL encoding techniques.