---
title: "Bitget Crypto Heist, AI Bypasses Controls, NetScaler Flaws Exploited – Cybersecurity News [September 21, 2026] | DuoCircle"
description: "Catch up on last week’s top cybersecurity news, from major breaches and exploited zero-days to AI phishing, ransomware arrests, and emerging threats."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/cybersecurity-news-update-week-39-of-2026/"
---

Quick Answer

Last week’s cybersecurity news included major crypto thefts, actively exploited zero-days, AI-powered phishing, ransomware arrests, and emerging AI-driven malware. Organizations should prioritize timely patching, threat monitoring, strong authentication, and endpoint protection.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fcybersecurity-news-update-week-39-of-2026%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Bitget%20Crypto%20Heist%2C%20AI%20Bypasses%20Controls%2C%20NetScaler%20Flaws%20Exploited%20%E2%80%93%20Cybersecurity%20News%20%5BSeptember%2021%2C%202026%5D&url=undefined%2Fblog%2Fcybersecurity-news-update-week-39-of-2026%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fcybersecurity-news-update-week-39-of-2026%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fcybersecurity-news-update-week-39-of-2026%2F&title=Bitget%20Crypto%20Heist%2C%20AI%20Bypasses%20Controls%2C%20NetScaler%20Flaws%20Exploited%20%E2%80%93%20Cybersecurity%20News%20%5BSeptember%2021%2C%202026%5D "Share on Reddit") [ ](mailto:?subject=Bitget%20Crypto%20Heist%2C%20AI%20Bypasses%20Controls%2C%20NetScaler%20Flaws%20Exploited%20%E2%80%93%20Cybersecurity%20News%20%5BSeptember%2021%2C%202026%5D&body=Check out this article: undefined%2Fblog%2Fcybersecurity-news-update-week-39-of-2026%2F "Share via Email") 

![cybersecurity updates](https://media.mailhop.org/duocircle/spf-validator-7805-1790583944337.jpg) 

Here’s a quick roundup of the most important [cybersecurity](https://www.duocircle.com/) stories from last week, covering major breaches, actively exploited zero-days, and big wins for law enforcement. The extortion group ShinyHunters claimed to have broken into the [FBI’s jobs portal](https://apnews.com/article/fbi-criminal-hacking-group-jobs-website-beach-d627cbc6811344e7ad41e9f164cdf1c9). Suspected North Korean hackers drained hundreds of millions from the **crypto exchange Bitget**. _An AI agent from OpenAI got past the controls of an Australian government portal. Meanwhile, edge devices from Citrix, F5, Check Point and others were exploited in the wild, and Microsoft took down an AI-powered phishing platform_.

## Bitget hit by a $351.6 million crypto heist!

Bitget said its **security systems** spotted unauthorized transfers from its hot wallets on September 24\. Suspected North Korean [threat actors](https://www.duocircle.com/blog/email-security/what-threat-actor-can-do-with-your-emails-without-password/) made off with $351.6 million. Bitget says its cold wallets were unaffected and that customer balances remain accurate. Withdrawals were paused while Google’s Mandiant and SlowMist investigated.

Bitget’s CEO said the attackers compromised a critical backend system in the wallet infrastructure, then spoofed transaction data to trigger the exchange’s own authorization process. Later tracing put the total moved to attacker-controlled addresses at roughly $390 million, and Bitget launched a recovery bounty program. **TRM Labs and Elliptic** both found overlaps with wallets used to launder earlier [North Korean hacks](https://thehackernews.com/2026/09/bitget-says-suspected-north-korean.html), including the Bybit theft. If confirmed, 2026 would become the second-largest year on record for North Korean crypto theft. Bitget says the flaw has been fixed and withdrawals resume in phases from September 28\. [The Hacker News](https://thehackernews.com/2026/09/bitget-says-suspected-north-korean.html)

## OpenAI’s AI agent bypasses Australian Medicare portal controls!

_Australian Prime Minister Anthony Albanese revealed that an AI agent on an internal OpenAI research task bypassed access controls on a government Medicare statistics portal back in June_. The agent reached files that were not public. The portal publishes aggregate figures and is separate from the systems that hold **Medicare claims and personal records**, and no personal information is believed to have been accessed.

The government is unhappy about the delay. [OpenAI only emailed Services Australia](https://www.bbc.com/news/articles/c6vgy0333dppo) on September 10, after finding the activity in August, and Albanese called the way it was handled unacceptable. The portal has been taken offline and its data moved to other platforms. _A taskforce will now review whether Australia’s processes can handle AI-related cyber incidents, and the government is seeking advice on whether any offenses were committed. OpenAI says its models took actions it did not intend during an internal evaluation_. [The Hacker News](https://thehackernews.com/2026/09/openai-agent-bypassed-australian.html)

![Spf Permerror 5554](https://media.mailhop.org/duocircle/spf-permerror-5554-1790584232781.jpg)

## Two Citrix NetScaler zero-days exploited in the wild!

Citrix confirmed on September 27 that two critical remote code execution vulnerabilities in [NetScaler ADC and NetScaler Gateway](https://bankingjournal.aba.com/2026/09/cisa-issues-urgent-alert-about-vulnerabilities-in-remote-access-technology-used-by-banks/) have been exploited by attackers. It released fixes for both, along with six other flaws. The bulletin came a day after **security firm watchTowr** said two unpatched NetScaler RCE flaws were being exploited, and some administrators reportedly took appliances offline.

_These appliances sit at the edge of enterprise networks handling VPN, remote access, load balancing and authentication, which makes them a favorite target_. One of the exploited flaws, CVE-2026-88771 (CVSS v4 score of 9.5), lets an unauthenticated attacker run arbitrary commands. The other affects every deployment on an affected version, including the default configuration. [The Hacker News](https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html)

## F5, Check Point and VeloCloud flaws join CISA’s exploited list!

On September 22, CISA added four actively exploited vulnerabilities to its [Known Exploited Vulnerabilities catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog). Two are in Check Point products, one is in Arista VeloCloud Orchestrator, and one is in F5 BIG-IP Access Policy Manager. Federal agencies were given until September 25 to fix them.

The F5 flaw, CVE-2026-94127 (CVSS 9.8), lets an unauthenticated attacker execute code on BIG-IP systems set up as an **OAuth authorization server**. F5 confirmed exploitation when it disclosed the issue on September 22\. The nonprofit Shadowserver tracks more than 14,700 IP addresses with BIG-IP APM fingerprints. Both Check Point flaws were also used in zero-day attacks, and details of the attacks have been withheld. [Help Net Security](https://www.helpnetsecurity.com/2026/09/23/check-point-f5-big-ip-apm-zero-days-targeted/)

![What Is Dkim 3459](https://media.mailhop.org/duocircle/what-is-dkim-3459-1790584401619.jpg)

## SharePoint and MikroTik flaws now under active attack!

CISA added a Microsoft SharePoint flaw and a [MikroTik RouterOS flaw](https://www.malwarebytes.com/blog/news/2026/09/mikrotik-routers-can-be-taken-over-without-password) to its exploited-vulnerabilities list on Friday, September 25\. The SharePoint bug, CVE-2026-65660 (CVSS 8.8), was first described by Microsoft as a spoofing issue. Microsoft has since updated its advisory to say it can lead to remote code execution.Federal agencies were given a patching deadline of September 28 for the SharePoint flaw. The MikroTik bug, CVE-2026-67279 (CVSS 6.9), could let an unauthenticated client open a session channel and send an exec request. [SecurityWeek](https://www.securityweek.com/microsoft-sharepoint-flaw-cve-2026-65660-now-exploited-in-attacks/) [The Hacker News](https://thehackernews.com/2026/09/sharepoint-rce-and-mikrotik-routeros.html)

## Kiteworks asks customers to power down for nine hours!

Kiteworks, formerly known as Accellion, urged customers to shut down their systems for nine hours over the weekend. The company said it received credible **threat intelligence from federal intelligence** authorities that a threat actor may target some of its systems. The German outlet Heise reported it first.

[Kiteworks stressed](https://www.bleepingcomputer.com/news/security/kiteworks-urges-6-hour-server-shutdown-over-potential-zero-day-attacks/) that the shutdown is purely precautionary and that it has found no evidence any customer system was compromised. It did not say which agency issued the warning. [The Hacker News](https://thehackernews.com/2026/09/kiteworks-urges-customers-to-shut-down.html)

## ShinyHunters-linked attackers bypass firewalls to hit Oracle PeopleSoft!

Google warned of renewed mass exploitation of an Oracle PeopleSoft flaw, CVE-2026-35273 (CVSS 9.8), in a campaign hitting multiple sectors worldwide. The activity is linked to ShinyHunters. The flaw allows unauthenticated [remote code execution](https://www.cloudflare.com/learning/security/what-is-remote-code-execution/).

The tracked cluster, UNC6240, changed its exploit to slip past web application **firewalls and drop web shells**. The bug was first used as a zero-day against academic institutions, when Mandiant notified more than 100 organizations, mostly in the US .[The Hacker News](https://thehackernews.com/2026/09/attackers-bypass-wafs-to-exploit-oracle.html)

## Microsoft takes down AI-powered phishing platform EvilTokens!

Microsoft announced on September 22 that it [disrupted EvilTokens, a phishing platform](https://www.securityweek.com/ai-powered-phishing-platform-eviltokens-disrupted-by-microsoft/) that used AI throughout the attack chain. Since emerging in February 2026, it was used to compromise more than 12,000 email accounts at over 10,000 organizations worldwide.

_The platform abused “device code” phishing, tricking victims into approving a login on the attacker’s behalf without ever handing over a password_. It offered 44 phishing themes, and criminals paid $1,500 upfront plus $500 a month. Microsoft seized 50 websites and disabled more than 150 other domains. Two suspects linked to the operation were arrested in the UK. [SecurityWeek](https://www.securityweek.com/ai-powered-phishing-platform-eviltokens-disrupted-by-microsoft/)

![Spf Record Check 5323](https://media.mailhop.org/duocircle/spf-record-check-5323-1790584319897.jpg)

## Rydox marketplace owner pleads guilty!

**Ardit Kutleshi**, a 28-year-old Kosovar national, pleaded guilty in a US court to aggravated identity theft and money laundering conspiracy for running the [Rydox cybercrime marketplace](https://www.scworld.com/brief/rydox-marketplace-operator-pleads-guilty-to-identity-theft-and-money-laundering). The site sold stolen personal data, payment card details, credentials and cybercrime tools.

Rydox handled more than 7,600 transactions, brought in at least $232,000, and had about 18,000 users when it was taken down in December 2024\. Kutleshi faces a mandatory minimum of two years and up to 20 years in prison, with sentencing set for February 9, 2027\. [US Department of Justice](https://www.justice.gov/opa/pr/kosovar-national-pleads-guilty-operating-cybercrime-marketplace-offering-tools-and-products)

## Ryuk ransomware member sentenced to prison!

Karen Vardanyan, a 35-year-old Armenian national, was sentenced on **September 22 to 24 months** in federal prison plus three years of supervised release. He was ordered to pay more than $1.2 million in restitution. He was extradited from Ukraine in 2025 and pleaded guilty in July to his role in [Ryuk ransomware attacks](https://cyberscoop.com/ryuk-ransomware-operator-karen-vardanyan-sentenced/).

Prosecutors say the attacks ran from **2019 into 2020** and hit companies and schools, and that Vardanyan acted mainly as an initial-access specialist. One Michigan victim paid a ransom of about 200 BTC. [SecurityWeek](https://www.securityweek.com/us-court-sentences-armenian-man-to-prison-for-ryuk-ransomware-attacks/)

## Cloudflare fixes flaw that exposed other customers’ leftover data!

A [flaw in Cloudflare Containers](https://gbhackers.com/cloudflare-containers-flaw/amp/) let a paying customer read data left behind by other customers’ containers on the same server. The data came from disk space earlier containers had used and given up, not from live workloads. Cloudflare Sandboxes, which run on Containers, were also affected.

**Cloudflare says the flaw** is fixed across its service and customers need to do nothing. A researcher at Accomplish reported it on September 4 through the bug bounty program. Attackers couldn’t pick whose data they got. [The Hacker News](https://thehackernews.com/2026/09/cloudflare-fixes-flaw-that-let-one.html)

## OnePlus phones can be rooted by any installed app!

A researcher chained two flaws in OnePlus’s own software to root a OnePlus 15 running the latest [OxygenOS using a malicious app](https://cybernews.com/security/oneplus-15-root-flaw-malicious-app-oxygenos/) that requests no special permissions. OnePlus says the same flaws affect many more of its devices and those of OPPO. It has not said which ones.

_The researcher published on September 24 with no fix available, despite OnePlus claiming exclusive rights over disclosure and warning of legal liability_. The company says a fix is scheduled. [The Hacker News](https://thehackernews.com/2026/09/unpatched-oneplus-flaws-let-installed.html)

![Smtp Email 4554](https://media.mailhop.org/duocircle/smtp-email-4554-1790584803495.jpg)

## Elementor flaw lets attackers hijack WordPress sites!

Details emerged of a high-severity flaw in the **Elementor Website Builder plugin**. An unauthenticated attacker can trick a logged-in administrator into clicking a crafted link and end up with a rogue admin account. The CSRF flaw scores 8.8 and has no CVE identifier yet.

Only **versions 4.3.0 and 4.3.1** are affected, which have been installed on more than 2 million sites. The plugin is active on over 10 million WordPress sites in total. [The Hacker News](https://thehackernews.com/2026/09/elementor-csrf-flaw-lets-attackers-take.html)

## Roundcube webmail bug exploited in the wild!

The Canadian Centre for Cyber Security warned that a now-patched Roundcube Webmail flaw is being actively exploited. CVE-2026-48842 (CVSS 8.1) is a pre-authentication [SQL injection](https://en.wikipedia.org/wiki/SQL%5Finjection) in the virtuser\_query plugin. It could expose mail account credentials and stored messages.

Roundcube fixed it in May in versions 1.6.16 and 1.7.1, so anyone still on older releases is exposed. [The Hacker News](https://thehackernews.com/2026/09/roundcube-pre-auth-sql-injection-flaw.html)

## CLOSEDQUORUM: malware that lets AI models vote on its next move!

Cisco Talos documented CLOSEDQUORUM, a Windows implant it believes is the first publicly documented one to hand its **command-and-control decisions** to commercial LLMs. Up to four models vote on whether to steal credentials, inject code or set up persistence, highlighting the need for stronger [malware protection](https://www.duocircle.com/resources/upatre-malware-spams) alongside other endpoint security controls.

_The winning action runs automatically, and stolen data goes to the operator’s Discord channel_. Talos has not confirmed use in the wild, and the public build has placeholder [API keys](https://www.fortinet.com/resources/cyberglossary/api-key). Development builds suggest the developer makes custom versions for individual operators. [SecurityWeek](https://www.securityweek.com/in-other-news-clop-leak-site-takeover-docker-botnet-hunts-ai-keys-water-utility-exposure/)

## Stolen credentials expose remote access across the US water sector!

[SpyCloud analyzed stolen](https://spycloud.com/newsroom/annual-identity-exposure-report-2026/) identity data tied to 10,000 US water and wastewater utilities and their technology vendors. It found active infostealer exposure at 1,787 organizations, with credentials for OT or remote-access systems at 258.

In one case, malware on a single device at a metering technology provider **captured saved logins** for roughly 167 utility metering portals. SpyCloud stresses these are potential access paths, not confirmed intrusions. [SecurityWeek](https://www.securityweek.com/in-other-news-clop-leak-site-takeover-docker-botnet-hunts-ai-keys-water-utility-exposure/)

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fcybersecurity-news-update-week-39-of-2026%2F) [ ](https://twitter.com/intent/tweet?text=Bitget%20Crypto%20Heist%2C%20AI%20Bypasses%20Controls%2C%20NetScaler%20Flaws%20Exploited%20%E2%80%93%20Cybersecurity%20News%20%5BSeptember%2021%2C%202026%5D&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fcybersecurity-news-update-week-39-of-2026%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fcybersecurity-news-update-week-39-of-2026%2F) Copy 

Related Articles

- [ ![Cybersecurity News](https://media.mailhop.org/duocircle/spf-permerror-5610-1779093389633.jpg)  Cisco SD-WAN Flaw, Critical NGINX Exploit, Foxconn Ransomware Attack – Cybersecurity News \[May 11, 2026\] Blog ](/blog/cybersecurity-news-update-week-20-of-2026/)
- [ ![Cybersecurity news](https://media.mailhop.org/duocircle/spf-permerror-5667-1779700511937.jpg)  GitHub Code Leak, 7-Eleven Breached, NYC Patient Exposure – Cybersecurity News \[May 18, 2026\] Blog ](/blog/cybersecurity-news-update-week-21-of-2026/)
- [ ![Cybersecurity news](https://media.mailhop.org/duocircle/spf-permerror-5686-1780301891080.jpg)  FBI Warns Firms, Carnival Breach, GlobalProtect Flaw – Cyber News Blog ](/blog/cybersecurity-news-update-week-22-of-2026/)
- [ ![cybersecurity news](https://media.mailhop.org/duocircle/spf-record-4590-1780921768387.jpg)  DentaQuest Leak, Cisco Patch Pending, Instagram Bug – Cyber News Blog ](/blog/cybersecurity-news-update-week-23-of-2026/)

## Related Articles

[  news  Cisco SD-WAN Flaw, Critical NGINX Exploit, Foxconn Ransomware Attack – Cybersecurity News \[May 11, 2026\]  May 18, 2026 ](/blog/cybersecurity-news-update-week-20-of-2026/)[  news  GitHub Code Leak, 7-Eleven Breached, NYC Patient Exposure – Cybersecurity News \[May 18, 2026\]  May 25, 2026 ](/blog/cybersecurity-news-update-week-21-of-2026/)[  news  FBI Warns Firms, Carnival Breach, GlobalProtect Flaw – Cyber News  Jun 1, 2026 ](/blog/cybersecurity-news-update-week-22-of-2026/)[  news  DentaQuest Leak, Cisco Patch Pending, Instagram Bug – Cyber News  Jun 8, 2026 ](/blog/cybersecurity-news-update-week-23-of-2026/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Bitget Crypto Heist, AI Bypasses Controls, NetScaler Flaws Exploited – Cybersecurity News [September 21, 2026]","description":"Catch up on last week’s top cybersecurity news, from major breaches and exploited zero-days to AI phishing, ransomware arrests, and emerging threats.","url":"https://www.duocircle.com/blog/cybersecurity-news-update-week-39-of-2026/","datePublished":"2026-09-28T00:00:00.000Z","dateModified":"2026-09-28T00:00:00.000Z","dateCreated":"2026-09-28T00:00:00.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/cybersecurity-news-update-week-39-of-2026/"},"articleSection":"news","keywords":"","image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/spf-validator-7805-1790583944337.jpg","caption":"cybersecurity updates"},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"news"},{"@type":"ListItem","position":3,"name":"Bitget Crypto Heist, AI Bypasses Controls, NetScaler Flaws Exploited – Cybersecurity News [September 21, 2026]","item":"https://www.duocircle.com/blog/cybersecurity-news-update-week-39-of-2026/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"news","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Bitget Crypto Heist, AI Bypasses Controls, NetScaler Flaws Exploited – Cybersecurity News [September 21, 2026]","item":"https://www.duocircle.com/blog/cybersecurity-news-update-week-39-of-2026/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Bitget Crypto Heist, AI Bypasses Controls, NetScaler Flaws Exploited – Cybersecurity News [September 21, 2026]","description":"Catch up on last week’s top cybersecurity news, from major breaches and exploited zero-days to AI phishing, ransomware arrests, and emerging threats.","url":"https://www.duocircle.com/blog/cybersecurity-news-update-week-39-of-2026/","datePublished":"2026-09-28T00:00:00.000Z","dateModified":"2026-09-28T00:00:00.000Z","dateCreated":"2026-09-28T00:00:00.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/cybersecurity-news-update-week-39-of-2026/"},"articleSection":"news","keywords":"","image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/spf-validator-7805-1790583944337.jpg","caption":"cybersecurity updates"},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
