@2Workly

Helping SOC, detection, and CTI teams stay ahead with cybersecurity news, CTI reporting, and IOC coverage they can act on.

Joined August 2026
Kiteworks urged shutdowns of self-hosted servers after federal warnings of threat activity targeting a flaw in its Advanced Forms module. Review instances, isolate the module, and verify release 9.5.1 securityweek.com/kiteworks-u… 2workly.com
1
CISA added two critical Citrix NetScaler flaws to KEV (CVE-2026-88771 and CVE-2026-88772, CVSS 9.5) amid active global exploitation for unauthenticated RCE. Prioritize patching and inspect DTLS configs thehackernews.com/2026/09/ci… 2workly.com
7
Citrix patched 2 NetScaler zero-days under active exploit: CVE-2026-88771 (unauth RCE) & CVE-2026-88772 (DTLS overflow). CVSS 9.5. Check IOCs before patching. Details: securityweek.com/citrix-conf… Intel to enforcement: 2workly.com #2workly
8
Active exploitation observed for Microsoft SharePoint RCE (CVE-2026-65660), with actors deploying webshell backdoors. CISA added to KEV. Patch now and monitor SharePoint directories. Details: securityweek.com/microsoft-s… Intel: 2workly.com #2workly
3
Two unpatched Citrix NetScaler RCE zero-days are under active exploitation with no fix yet released. Restrict management interfaces immediately and preserve logs/core dumps if investigating compromise thehackernews.com/2026/09/wa… 2workly.com
11
A CSRF flaw in Elementor 4.3.0/4.3.1 lets attackers create rogue WordPress admins via crafted REST API requests with "elementor/v1/events/" in the URI. Patch to 4.3.2 and monitor logs. Details: thehackernews.com/2026/09/el… More: 2workly.com #2workly
CISA added SharePoint CVE-2026-65660 & MikroTik CVE-2026-67279 to KEV. The MikroTrick chain enables unauthenticated admin takeover on exposed RouterOS devices. Patch perimeter assets now. Details: thehackernews.com/2026/09/sh… 2workly.com #2workly
6
DOJ sentenced threat actor Cameron Wagenius (kiberphant0m) to 70 months for extortion campaigns tied to the 2024 Snowflake breaches and SSH credential theft. Track identity-based cloud threats: Source cyberscoop.com/cameron-wagen… 2workly.com
2
Actor "Kiberphant0m" sentenced to 70 months for telecom extortions via compromised cloud credentials lacking MFA. Identity telemetry and mandatory MFA remain vital controls against bulk data exfiltration krebsonsecurity.com/2026/09/… 2workly.com
Kothamine RAT evades network blocks by using Tailscale tailcat to tunnel C2 traffic over local ports. Detect execution of tailcat.exe forward commands and Defender exclusions in AppData. Intel: Enforce via malwarebytes.com/blog/threat… 2workly.com
1