All Posts
Anomali Cyber Watch
1
min read

Anomali Cyber Watch: Windows, Salesforce & Citrix Threats

Published on
September 29, 2026
Table of Contents

At a Glance

Attack Patterns
63
Exploit Public-Facing Application
4
Obfuscated Files Or Information
2
Unsecured Credentials: Credentials In Files
2
System Information Discovery
2
Process Discovery
2
* Frequency counts reflect mentions across collected reports
Story #1  |  September 10, 2026

Nightmare-Eclipse Releases "ShieldCrash," a Claimed Patch Bypass That Turns Windows Defender's Own Cleanup Process Against Itself

▶ expand
A security researcher known as Nightmare-Eclipse published a proof-of-concept (PoC) exploit called ShieldCrash on September 8, 2026, hours after Microsoft released its September Patch Tuesday updates. The researcher claims it bypasses Microsoft's patch for CVE-2026-69414 (ShieldBreak), a privilege escalation flaw in the Microsoft Malware Protection Engine, which was itself a patch bypass for CVE-2026-50656 (RoguePlanet), meaning the same underlying vulnerability class has now survived two consecutive rounds of Microsoft patching. Rather than targeting a memory corruption bug, the exploit abuses Defender's own remediation pipeline: it loads Defender's legitimate client library, triggers a controlled scan using an embedded EICAR antivirus test file to guarantee a detection, then instructs Defender to clean the flagged file. Before the scan begins, the exploit pre-places a chain of Windows Object Manager redirects (a mount point targeting the restricted kernel namespace, followed by a symbolic link from within that namespace to an attacker-chosen file) so that when Defender's engine process opens the flagged file for remediation under its SYSTEM security context, it instead reads the redirected target, a file the attacker's own account has no permission to access. The repository additionally imports the Cloud Files API and Kernel Transaction Manager, which may indicate the specific path Microsoft's prior patch left unaddressed, though this has not been independently confirmed. The initial PoC released on September 8 failed to demonstrate the claimed read primitive in independent lab testing, consistently returning a world-readable system file rather than the specified target. A revised version published on September 15 has since been independently validated as functional, successfully reading files protected from the unprivileged test account, including a Windows registry hive. Microsoft did not respond to a request for comment at press time.
Analyst Comment
The pattern ShieldCrash extends is more significant than the exploit itself: the same underlying mechanism has now survived two consecutive rounds of Microsoft patching, suggesting remediation has targeted specific exploitation paths rather than the root cause, and further bypasses remain plausible. Risk requires calibration. ShieldCrash delivers an arbitrary file read under SYSTEM privilege, not a full privilege escalation; it provides no SYSTEM shell or write capability, but does enable access to protected files including credential material in the SAM and SECURITY registry hives, making it a meaningful post-compromise component rather than a standalone threat. It requires an existing low-privilege foothold and cannot be used for initial access. The original PoC was non-functional until a revised version appeared September 15, validated in independent lab testing. No in-the-wild exploitation has been confirmed as of the reporting date, though Microsoft rates CVE-2026-69414 as "Exploitation More Likely." The September 2026 patch should not be treated as closed: the researcher has indicated intent to develop a fuller primitive and has publicly invited the community to complete the exploit, a pattern this cluster has executed before. BlueHammer, an earlier release from the same researcher, moved from a buggy public PoC to confirmed ransomware exploitation within three months. Detection should focus on behavioral signals: Object Manager mount points targeting \BaseNamedObjects\Restricted and symbolic links to protected files such as SAM and ELAM are unlikely in normal operations, though production false-positive rates have not been publicly characterised. Disabling Defender is not a proportionate response.
MITRE ATT&CK Techniques ▼
Story #2  |  September 22, 2026

CLOSEDQUORUM Windows Implant Replaces Human Operator With AI Decision Panel

▶ expand
Researchers have identified CLOSEDQUORUM, described as the first publicly documented Windows implant to replace traditional command and control (C2) infrastructure with a panel of commercial large language models (LLMs). Rather than consulting an attacker-operated server, the 64-bit Go-compiled binary queries up to four AI providers (DeepSeek, Qwen, Mistral, and Google Gemini), tallying votes to determine the next action; host context, including hostname, OS architecture, CPU count, Windows version, and admin status, is collected once at initialization and passed statically to each LLM prompt alongside a per-cycle process list. Three of four schema options have active handlers: credential theft simultaneously targeting LSASS memory, browser passwords in Chrome, Edge, and Firefox, and cryptocurrency wallets in MetaMask, Exodus, and Ethereum; code injection into suspended processes; and persistence via Registry Run key, scheduled task, and WMI event subscription. The implant suppresses ETW (Event Tracing for Windows) telemetry, delays initial execution by five minutes, and uses Windows Update-themed naming to slow triage. Stolen data is AES-256-GCM encrypted and exfiltrated in chunks to an operator-controlled Discord webhook. No in-the-wild deployment is confirmed; binary artifacts link the developer to carding forum activity from 2025. Researchers assess the developer compiles a per-operator binary with LLM API keys and a Discord webhook injected at build time, structuring CLOSEDQUORUM as a credentials-as-a-service offering.
Analyst Comment
CLOSEDQUORUM's individual post-compromise techniques are well-documented and, absent ETW suppression, detectable by mature endpoint tooling. The significance here is architectural. After deployment, the operator no longer needs to be present for the decision loop to execute; a human configured the binary, selected the API keys, and handled delivery, but ongoing tactical decisions run without them. That asynchronous model likely reduces the operational overhead for the attacker and, assessed, removes one of the more reliable disruption opportunities available to defenders. Before overstating the threat: no in-the-wild deployment has been confirmed, and Talos did not observe a complete end-to-end execution of the architecture, which was established through static analysis only. However, the developer's documented presence on carding forums suggests operational intent rather than research, and the credentials-as-a-service distribution model likely lowers the barrier for less capable actors to deploy it. On detection, Talos's behavioral correlation guidance is sound but carries an implicit assumption of EDR maturity that many organisations will not meet. The implant suppresses ETW telemetry by overwriting EtwEventWrite, and if that suppression occurs early in execution, endpoint tools dependent on ETW instrumentation may be partially blinded before the behavioral signals Talos recommends correlating become visible. Defenders should assess whether ETW integrity monitoring is in place as a prerequisite to the behavioral correlation approach. The broader intelligence implication that likely outlasts this specific implant is that commercial LLM API endpoints are now viable C2 infrastructure. They cannot be blocked without significant operational disruption, and they will not appear in conventional threat intelligence feeds. Monitoring strategies that do not account for LLM API traffic as a potential adversarial signal have a visibility gap that CLOSEDQUORUM demonstrates is architecturally viable and, given the carding forum context, likely intended for operational use.
MITRE ATT&CK Techniques ▼
T1059.001 - Command and Scripting Interpreter: Powershell T1547.001 - Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder T1053.005 - Scheduled Task/Job: Scheduled Task T1546.003 - Event Triggered Execution: Windows Management Instrumentation Event Subscription T1055.004 - Process Injection: Asynchronous Procedure Call T1055.012 - Process Injection: Process Hollowing T1027 - Obfuscated Files Or Information T1480.001 - Execution Guardrails: Environmental Keying T1497.003 - Virtualization/Sandbox Evasion: Time Based Evasion T1036.005 - Masquerading: Match Legitimate Name Or Location T1003.001 - OS Credential Dumping: Lsass Memory T1555.003 - Credentials from Password Stores: Credentials From Web Browsers T1552.001 - Unsecured Credentials: Credentials In Files T1082 - System Information Discovery T1057 - Process Discovery T1005 - Data From Local System T1074.001 - Data Staged: Local Data Staging T1567.004 - Exfiltration Over Web Service: Exfiltration Over Webhook T1030 - Data Transfer Size Limits T1102.002 - Web Service: Bidirectional Communication T1573.001 - Encrypted Channel: Symmetric Cryptography T1132.001 - Data Encoding: Standard Encoding T1685 - Disable or Modify Tools
Story #3  |  September 24, 2026

SalesBleed: Prompt Injection in Salesforce Agentforce Enables Zero-Click CRM Data Exfiltration and Anonymous Slack Phishing

▶ expand
Researchers identified three vulnerabilities in Salesforce Agentforce, collectively named "SalesBleed," enabling zero-click Customer Relationship Management (CRM) data exfiltration and anonymous Slack phishing without attacker authentication. The entry point was Salesforce's Web-to-Lead form, which routes external submissions into the CRM. Attackers embedded malicious instructions in a lead field via indirect prompt injection; when an internal user asked an Agentforce agent to review leads, the agent executed those instructions using existing General CRM subagent permissions without privilege escalation. Two exfiltration paths used the same mechanism: the agent queried the Accounts table, encoded results in an attacker-controlled Domain Name System (DNS) subdomain, and delivered it via an auto-rendered HTML image tag or Slack URL unfurling. Three techniques bypassed Agentforce's Trusted URLs filter: unrecognized top-level domains, mishandled termination characters, and markdown link text. A flaw in the default Slack Knowledge subagent's Reply to a Slack Thread action, which lacked user confirmation and invoker attribution, allowed injected instructions to post phishing messages under the agent's identity. Injected leads persisted in the Leads table and re-executed on each review; Salesforce stated no exploitation had been identified, assigned no CVE identifiers, and remediated the Trusted URLs bypass by August 19 and remaining fixes by September 21, 2026.
Analyst Comment
SalesBleed is best understood as the consequence of an absent architectural principle rather than individual application flaws. Neither Web-to-Lead accepting external input nor an agent holding broad permissions is a flaw in isolation. The failure: no boundary principle prevented untrusted external input from reaching a privileged actor without human review. That gap is not Salesforce-specific; defenders should audit these conditions across any agentic deployment. A single poisoned CRM record could trigger chat exfiltration, Slack URL unfurling exfiltration, and phishing across multiple threads; each additional integration likely compounds this exposure. The service account analogy is useful but incomplete: agent behavior is non-deterministic where service account behavior is not. Permissions define access; they do not define what an agent can be induced to do with it. Permissions auditing is therefore insufficient; defenders likely also need visibility into agent actions and tool invocations. That ownership likely falls in the gap between security teams and platform administrators; clarifying that boundary before an incident is more practical than after. Three distinct bypass techniques against a single output redaction control in one disclosure illustrate why redaction alone is insufficient. Defense in depth at the agent layer is the more durable posture.
Story #4  |  September 26, 2026

Oracle PeopleSoft WAF Mitigation Bypassed as ShinyHunters Resume Global Exploitation Campaign

▶ expand
ShinyHunters (UNC6240) has resumed mass exploitation of CVE-2026-35273, a CVSS v3.1 9.8 unauthenticated remote code execution flaw in Oracle PeopleSoft's Environment Management Hub, using URL encoding to bypass web application firewall (WAF) rules. Organizations that relied on literal-path WAF rules blocking /PSEMHUB/ rather than applying Oracle's security update may remain exposed: attackers request /%50SEMHUB/ instead, substituting the percent-encoded form of the letter P. Many WAF and reverse-proxy rules match the literal request path before decoding, while Oracle WebLogic decodes and routes the request to the vulnerable servlet normally. Attackers deployed web shells on dozens of systems globally across higher education, healthcare, government, technology, and additional sectors. Before exploitation, targeted servers typically receive five to 15 probe requests that can confirm exploitability without writing files or disrupting services. Exploitation delivers JavaServer Pages (JSP) web shells for command execution and file staging, with fileless command execution also observed. On Windows systems, a trojanized installer signed with a valid Extended Validation (EV) code-signing certificate, with revocation requested, loads the SIDEEYE backdoor in memory, enabling credential theft, interactive reverse shell, and reverse-proxy capabilities. The open-source Neo-reGeorg toolkit enables lateral movement; MeshAgent maintains Linux persistence. Patching is the recommended remediation; WAF rules are not a substitute.
Analyst Comment
The adaptation from zero-day exploitation to WAF bypass within three to four months of published mitigation guidance is the most significant intelligence signal here. ShinyHunters adapted to the defensive response, exploiting a weakness in string-based path matching by URL-encoding a single character in the exploit path to resume operations at scale. That feedback loop between published guidance and exploit modification demonstrates the group's ability to adapt quickly to defensive controls. For organizations that exposed PSEMHUB during either campaign, the question is not only whether they remain vulnerable but whether compromise occurred before remediation. Exposed environments should be investigated for prior compromise regardless of current patch status: patching closes the vulnerability but does not remove existing web shells, SIDEEYE installations, or MeshAgent deployments. Initial hunting can begin with standard host and log review: inspect PSEMHUB.war for unexpected JSP and executable files, review WebLogic access logs for encoded path variants, look for unexpected MeshCentral agents and, where compromise is identified, rotate credentials accessible from the PeopleSoft tier. The use of a valid EV-signed trojanized installer increased the payload's appearance of legitimacy and is consistent with defense-evasion objectives. Compensating controls can reduce exposure. Patching removes the vulnerable condition; active hunting determines whether that condition was already exploited.
MITRE ATT&CK Techniques ▼
T1595.002 - Active Scanning: Vulnerability Scanning T1190 - Exploit Public-Facing Application T1027 - Obfuscated Files Or Information T1027.002 - Obfuscated Files or Information: Software Packing T1036 - Masquerading T1553.002 - Subvert Trust Controls: Code Signing T1620 - Reflective Code Loading T1059.003 - Command and Scripting Interpreter: Windows Command Shell T1059.004 - Command and Scripting Interpreter: Unix Shell T1505.003 - Server Software Component: Web Shell T1016 - System Network Configuration Discovery T1033 - System Owner/User Discovery T1057 - Process Discovery T1082 - System Information Discovery T1083 - File And Directory Discovery T1552.001 - Unsecured Credentials: Credentials In Files T1090 - Proxy T1095 - Non-Application Layer Protocol T1105 - Ingress Tool Transfer T1219 - Remote Access Software T1571 - Non-Standard Port T1665 - Hide Infrastructure T1048 - Exfiltration Over Alternative Protocol
Story #5  |  September 21, 2026

Clop's Dark Web Infrastructure Breached via CVE-2026-42608; Victim Payment Records Threatened

▶ expand
ShinyHunters breached the Clop ransomware gang's dark web data leak site on September 18, 2026, exploiting CVE-2026-42608, an unauthenticated path traversal and arbitrary file-write vulnerability in Grav content management system (CMS) core, allowing attacker-controlled files to be written outside intended form-upload paths. The flaw was fixed in Grav 2.0.0-beta.2 in April 2026 but had not been backported to the 1.7 branch; according to ShinyHunters, Clop's server ran Grav 1.7.43. Grav released version 1.7.53.4 with the backported fix. ShinyHunters claimed to have stolen source code, Grav CMS plugins, server logs, and Clop's Tor onion service private keys; none have been independently verified. Clop acknowledged its Grav installation had not been fully updated but denied that operational or financial data was on the compromised server. ShinyHunters demanded an eight-figure payment and threatened to publish records identifying organizations that allegedly paid Clop during its 2025 Oracle E-Business Suite (EBS) extortion campaign, including payment amounts and Bitcoin addresses. ShinyHunters frames the attack as retaliation over CVE-2025-61882, an Oracle EBS zero-day the group claims originally belonged to it; this has not been independently verified. Clop migrated to a new Tor address and was removed from ShinyHunters' data leak site. Clop denied any contact or negotiations; ShinyHunters declined to explain the removal.
Analyst Comment
The most direct potential risk is to organizations that allegedly paid Clop during its 2025 Oracle EBS campaign. If ShinyHunters obtained the claimed payment records, those organizations could face renewed extortion or exposure from a second actor, and any prior payment to Clop would provide no assurance against this. The incident reinforces a broader defensive principle: once data is exfiltrated, it cannot be assumed to remain under one criminal actor's control. Criminal infrastructure cannot be assumed secure, and additional copies create opportunities for subsequent theft, resale, or disclosure. Organizations should treat exfiltration as a persistent exposure risk, maintain monitoring of relevant leak sites and extortion channels, and prepare stakeholder communications in advance. Organizations running Grav 1.7 should upgrade to at least version 1.7.53.4 as a priority and plan migration to the current 2.x branch; CVE-2026-42608 requires no authentication and detailed exploitation instructions are publicly available.
Story #6  |  September 27, 2026

Two Actively Exploited Citrix NetScaler Zero-Days Patched; CISA Sets September 30 FCEB Deadline

▶ expand
Citrix released fixes on September 27 for two actively exploited zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway, both rated CVSSv4 9.5. CVE-2026-88771, an improper input validation flaw, allows an unauthenticated attacker to execute arbitrary commands on all affected deployments, including those using the default configuration. CVE-2026-88772, a memory overflow, can lead to remote code execution or denial of service when Datagram Transport Layer Security (DTLS) is enabled, the default for VPN virtual servers. Pre-disclosure reporting attributed both vulnerabilities to customer incident investigations; researchers separately report webshell deployment on affected appliances and activity running throughout September, details not independently confirmed by Citrix or CISA. CISA added both to its Known Exploited Vulnerabilities (KEV) catalog on September 27, set a September 30 remediation deadline for Federal Civilian Executive Branch (FCEB) agencies, and advised checking for compromise and preserving forensic evidence before updating. Fixed builds are 14.1-73.37 and 13.1-64.23 for standard branches, and 14.1-73.37 FIPS and 13.1-37.279 for FIPS and NDcPP variants. Citrix has confirmed exploitation only of the two named CVEs; six additional vulnerabilities are addressed in the same bulletin. Appliances updated for CVE-2026-19490 in August remain vulnerable; patching does not rule out prior compromise, and internet-facing appliances warrant compromise assessment.
Analyst Comment
The instinct to patch immediately is understandable, but CISA and NCSC-NL both advise preserving forensic evidence first, checking for indicators of compromise, and then updating, because patching first may reduce forensic visibility into whether an attacker was already present. That sequence is harder than it sounds. Citrix warns that its File Integrity Monitoring should be treated as a source of investigative leads, not proof that an appliance is clean, and if appliance logs have rotated, which is possible given a researcher-reported weeks-long exploitation window, some of that forensic ground may already be gone. The operationally critical detail about CVE-2026-88771 is that attack complexity is low, and Citrix confirms all affected deployments meet the vulnerability's configuration precondition with no additional feature required. No hardening measure substitutes for the patch. The discovery chain also matters: active exploitation came to light through customer incident investigations, meaning malicious activity preceded public disclosure and patch availability, though no attribution has been made public. A clean scan does not equal a clean network. For previously exposed internet-facing appliances, assess surrounding identity and network telemetry and rotate credentials where compromise is suspected or confirmed.

FEATURED RESOURCES

September 29, 2026
Anomali Cyber Watch

Anomali Cyber Watch: Windows, Salesforce & Citrix Threats

Latest cyber threats: Windows Defender & CLOSEDQUORUM implants, Salesforce SalesBleed data leaks, Oracle WAF bypasses, Citrix zero-days, and more.
Read More
September 28, 2026
AI
Operationalized Threat Intelligence

From Feeds to Agents: What the AI Shift Asks of Your Data Foundation

New Gartner® research examines AI in cyberthreat intelligence operations. Our view on why the data foundation decides what your agents can safely do.
Read More
September 23, 2026
No items found.

When Criminals Hack Criminals: ShinyHunters' Breach of Clop and What It Reveals About the Ransomware Underground

Read More
Explore All