Two Fires. Same Week. Only One Is Getting a Keynote.

The week did not pick a theme. It ran two.
Fire one: the old perimeter is on fire again
Citrix confirmed two NetScaler remote-code-execution flaws under active exploitation. CVE-2026-88771 and CVE-2026-88772. Fixes are out. One of the pair hits affected versions even in the default layout. watchTowr flagged exploitation before the bulletin. Some operators took boxes offline first. That is the honest move. A blog titled "We Take Security Seriously" is not.
CISA put Microsoft SharePoint CVE-2026-65660 on the Known Exploited Vulnerabilities list. Federal patch deadline is today, 28 September. If your SharePoint is still "we will get to it after the steering committee," you are late.
Cloudflare fixed a Containers and Sandboxes flaw that let a paid Workers tenant recover leftover disk from another customer's container on the same host. Cross-tenant leftovers. Same class of failure as a VPN that reports connected while the handshake is naked. Status text is not telemetry.
ShinyHunters is not only on a leak site this week. BleepingComputer: the crew is using a URL-encoding trick to walk around WAF rules meant to blunt Oracle PeopleSoft CVE-2026-35273, then putting web shells on boxes that were supposed to be mitigated. A control that only matches the pretty version of a URL is not a control.
Fire two: the agent still has the keys
OpenAI has now said it notified dozens of governments, universities and public bodies about agent activity. The Medicare statistics portal is one file in that pile, not the pile. The Record's archive work still says that portal's own JavaScript pointed at an unauthenticated guest endpoint. Albanese still calls it unauthorised. Both sentences can be true. They are not the same sentence.
The Guardian, 27 September: a former UN cyber negotiator said Australia runs on legacy systems that agents can walk. That is not a national insult. That is most of the public web. South Africa included. Guest endpoints. Public JS. Tokens in repos. Dashboards that were never an identity boundary.
SecurityWeek: a Windows botnet tagged x47.c is using xAI Grok to pick from a pre-written action list and to keep itself alive. That is not "Grok hacked the world." That is an operator who put an API key on a malware loop and let the model choose the next verb. Tool list is still the permission set. If the key works, the model will work.

US and China agreed to stand up a channel for AI-related incidents. Useful if someone actually picks up. Useless if the first notice is still a public mailbox 84 days later.
Adjacent, not decoration
About 16,000 Supabase projects were reported exposed after vibe-coded apps left secrets and tables facing the internet. That is agency with a junior developer and a default-open backend. Same failure class. Different letterhead.
GitHub Actions that had been pulled in a Mini Shai-Hulud campaign were turned back on by a maintainer and still pointed at malicious code. Supply chain is not a keynote. It is a toggle.
Bitget is still staring at roughly $352 million with North Korea in the frame. Patching still matters. Ransomware still matters. None of that replaces the new variable: actors that do not wait for a click.
What is valuable today
Not another MFA sermon.
Not a treaty press line.
A NetScaler that is patched or powered off.
A SharePoint that met the KEV date.
A WAF that canonicalises the URL before it decides.
An agent that cannot fetch, post, or follow a guest endpoint unless a policy engine outside the model says yes.
Telemetry on tool calls, DNS, and disk. Not on speeches.

I already lived the version where the dashboard lied and the packet did not. Bitdefender ticket #1011154500. Different vendor. Same lesson. Instrument the behaviour.
South Africa is not a spectator. Citrix and SharePoint sit in the same office parks as the public forms. Agents do not need a visa. Digital sovereignty is whether your tools work for you when the vendor's incentive is to keep the agent useful, not constrained.
Map the agents.
List the tools.
Patch the boxes that already have a CVE and a KEV date.
Assume the next input is hostile.
Put authorization outside the model.
Sources and scope. The Hacker News, "Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation," 27 September 2026. BleepingComputer, "Citrix confirms two NetScaler RCE zero-days exploited in attacks," 27 September 2026. SecurityWeek, "Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks," 27 September 2026. BleepingComputer, "Cloudflare fixes Containers cross-tenant flaw exposing customer data," 27 September 2026. BleepingComputer, "ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks," 26 September 2026. SecurityWeek, "New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining," 27 September 2026. The Record, "Doubts grow over claims OpenAI agent hacked Australian Medicare portal," 25 September 2026. The Guardian via TechNN listing, "Australia is run on legacy systems that AI agents can easily exploit," 27 September 2026. Cybernews, "16,000 Supabase databases exposed as vibe-coded apps leak sensitive user data," 26 September 2026.
Citrix exploitation-in-the-wild is the vendor confirmation plus watchTowr's prior reporting, not an Onyx packet capture. SharePoint KEV status is CISA as reported by SecurityWeek. Cloudflare's cross-tenant issue is the company's patch account. x47.c using Grok is SecurityWeek's malware analysis, not a statement that xAI endorsed the botnet. OpenAI's "dozens of notifications" is the company line as carried by 7NEWS and related desks. The Record's guest-endpoint finding is archival JS, not a finished ASD forensic. ShinyHunters FBIJobs volume and medical-file claims remain actor copy plus limited Reuters sample work. This piece does not treat unpublished exploits, a confirmed patient-record exposure, or a completed 2 TB FBI dump as fact.
Clayton Bax
Published under ONYX Digital Intelligence Following the #OnyxAudit methodology.
- X: @OnyxAudit
- Email: onyxdigitalintelligence85@protonmail.com
- https://github.com/Baximus85
- @Onyx_Digital@mastodon.social
Adjacent to true is not true.
Truth has no --flag nor favour--, only a standard. And it's heavy
Editors note: I use various AI agents to fetch my research. I check, strip and write the article. Facts are partly theirs. Interpretation is mine.