Contacts
Book a Meet
Close

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

02.10, article

DIAMATIX Cybersecurity Weekly Digest: Active Exploitation, Detection Gaps and the Human Layer

This week’s cybersecurity developments point to a recurring operational problem: knowing that a threat exists is only the beginning. Organizations also need to understand whether they are exposed, whether compromise has already happened and how quickly they can detect it.

From nine months of unauthorized access inside a U.S. defense system to actively exploited Citrix infrastructure and ransomware claims in Bulgaria, we selected the developments that matter most for organizations managing critical systems, sensitive data and regulatory responsibilities.

Pentagon breach: nine months before detection

A breach affecting the U.S. Defense Manpower Data Center exposed a fundamental detection problem: unauthorized access reportedly persisted for approximately nine months before being discovered.

The important question is not simply how an attacker entered the environment. It is how malicious access can remain unnoticed for months inside systems containing sensitive information.

For organizations, this reinforces the need for continuous monitoring, identity visibility and detection capable of identifying abnormal behavior after initial access.

Read our analysis:
Nine Months of Unauthorized Access: What the Pentagon Personnel Breach Reveals About Detection Gaps

Citrix NetScaler: patching and compromise assessment need to go together

Two critical vulnerabilities in Citrix NetScaler ADC and Gateway, CVE-2026-88771 and CVE-2026-88772, are being actively exploited. Both carry a CVSS score of 9.5.

The operational issue is particularly important because NetScaler appliances often provide internet-facing VPN, authentication and remote-access functions. Applying the available fixes closes the vulnerability, but organizations also need to determine whether exploitation occurred before remediation.

The practical sequence is identify affected systems → patch → assess for compromise → continue monitoring.

Read our analysis:
Citrix NetScaler Under Active Attack: Patching Is Not Enough Without Compromise Assessment

CISA is moving vulnerability management toward real-world risk

That same principle is visible in a broader change from CISA. On September 28, the agency discontinued its traditional Weekly Vulnerability Bulletin as part of a move away from primarily severity-based prioritization toward risk-based vulnerability management.

The new approach gives greater weight to factors such as active exploitation and actual exposure, with the Known Exploited Vulnerabilities catalog becoming increasingly important for prioritization.

For security teams, the signal is useful: a CVSS score alone does not tell you what should be fixed first.

Oracle PeopleSoft attacks expand across sectors

Another example comes from Oracle PeopleSoft. Google’s Mandiant reported renewed large-scale exploitation associated with ShinyHunters, with attacks expanding beyond universities into healthcare, government and technology organizations.

According to Reuters, attackers were able to bypass web application firewall defenses in some cases where organizations had not implemented Oracle’s patch.

Again, the operational lesson is about exposure and remediation, rather than vulnerability counts alone.

Three in four EU employees encounter cyber threats at work

Technology is only one part of the attack surface.

Recent Eurobarometer findings show that three in four EU employees face cyber threats in the workplace, with phishing remaining the leading risk.

The finding matters because identity compromise and social engineering continue to provide attackers with routes around otherwise strong technical controls.

Read our analysis:
Three in Four EU Employees Face Cyber Threats at Work: Phishing Remains the Leading Risk

The timing also aligns with European Cybersecurity Month. ENISA’s latest data shows that social engineering remains a persistent threat, while 73% of targeted organizations in its threat landscape analysis were entities classified as essential or important under NIS2.

Bulgaria: MedusaLocker lists ABV.BG as an alleged victim

Closer to home, the MedusaLocker ransomware group has listed Bulgarian email provider ABV.BG as an alleged victim.

At this stage, it is important to separate the ransomware group’s claim from independently confirmed facts. A listing on a leak site does not by itself establish the scope of an incident, what systems may have been affected or whether data was successfully exfiltrated.

Read what is confirmed and what remains unclear:
MedusaLocker Lists ABV.BG as an Alleged Victim

From DIAMATIX: running for a cause

This week, Kiril Brambarov, Channel Sales Account Manager at DIAMATIX, joined Светулки RUN, a charity night run supporting people with visual or mobility impairments.

The initiative brings runners together after dark, using headlamps and flashlights, with funds raised through the event supporting partner organizations working with people with disabilities.

For us, participation in initiatives like this is another way our team contributes beyond our everyday work in cybersecurity.

Learn more about the initiative:
Светулки RUN

DIAMATIX Weekly Signal

This week’s common thread is exposure time.

A vulnerability can be patched. Credentials can be reset. A malicious message can be blocked. But organizations still need to answer a harder question:

What happened before we knew there was a problem?

The Pentagon breach, active NetScaler exploitation and current ransomware activity all point toward the same operational requirement: detection, compromise assessment and response readiness need to work as one process.

Follow the DIAMATIX Cybersecurity Weekly Digest for the signals that matter, without the noise.

What’s next at DIAMATIX

Next week, the DIAMATIX team will be on the ground at two industry events.

On 6–7 October, we’ll join interworks.cloud Malta Partner Days, where we’ll meet with the local partner community and discuss how MSPs can expand their cybersecurity services with MDR 360° powered by DIAMATIX SOC.

On 7 October, DIAMATIX will also be at Acronis Tech Community Day Balkans 2026 in Sofia, connecting with the regional technology and cybersecurity community.

If you’re attending either event, come and meet the DIAMATIX team.

Sources: CISA, Reuters, ENISA, Citrix, European Commission/Eurobarometer.

Subscribe for latest updates & insights

Please enable JavaScript in your browser to complete this form.