BLUF — Edge devices drove the week: F5 APM and Check Point VPN flaws entered KEV, SharePoint is now exploited, and two Citrix NetScaler zero-days remain unpatched. PRC group UTA0565 hit Asian governments with a shared Chrome-Windows zero-day kit. Needs attention: NetScaler exposure until Citrix ships a fix.
Threat actor spotlight — UTA0565 · PRC-aligned (per Volexity)
Why now
Volexity named UTA0565 on 21 Sep as the third PRC-aligned group using the same Chrome-Windows zero-day chain, this time against Asian government entities.
Mentions, 30d
3 this week
PACOM relevance
Lures targeted Asian government entities, the same partners SPACEPAC works with across the AOR.
Notable TTPs
Chrome JS engine RCE plus Windows ALPC privilege escalation
Typosquatted .top domains spoofing trusted sites
Chinese-language lures on Hong Kong activism
Countermeasures
Confirm Chrome and Windows Sept updates are deployed
Block newly registered and typosquat .top domains
Brief staff on links to look-alike think-tank sites
OperationsThreats to networks, missions, and infrastructure the command depends on: exploited vulns, intrusions, APT campaigns, ICS/OT, SATCOM/PNT, telecom.
Two unpatched Citrix NetScaler ADC and Gateway RCE zero-days are being exploited, according to watchTowr; Citrix has not confirmed them and patches are expected this week.
So what: NetScaler Gateway fronts remote access for many partners.
Consider: Recommend confirming no internet-facing NetScaler in command or partner paths.
CISA added Check Point VPN, Arista VeloCloud and F5 APM flaws to KEV; F5 confirmed zero-day use.
So what: VPNs and access proxies are the front door to partner networks.
Consider: Recommend reviewing S6 patch status.
NORTHCOMVulns & exploits
UNCLASSIFIED · open-source reporting only · 5 sources · built 2026-09-27 06:53 HSTCyber Watch · 2026-W39 · page 1 of 2
UNCLASSIFIED
Force ProtectionWhat Guardians, Airmen, civilians, and families need to know personally: scams, social engineering, apps and devices, OPSEC, breaches of consumer services, official guidance.
ShinyHunters claimed theft of FBI employee data and released a sample of about 5,000 entries with names, home addresses and family details. The FBI is investigating (Nextgov/FCW).
So what: Personnel-record leaks put home addresses and families in criminal hands.
Consider: Consider reminding personnel to limit home and family details online.
NORTHCOMPACOMBreach & leaked dataOPSEC & personal securityShinyHunters
Microsoft seized 50 EvilTokens sites and UK police arrested two suspected admins. The device-code phishing kit bypassed MFA to compromise 12,000+ inboxes (The Register).
So what: Device-code phishing defeats MFA because the victim approves the sign-in.
Consider: Be aware: never enter a device code you did not request.
Fake Windows apps for three US HR and payroll platforms install ScreenConnect remote access, according to Allure Security; none of the providers offers a desktop app.
So what: Pay and HR systems hold Guardian and family financial data.
Consider: Consider using only bookmarked web portals for pay and HR.
Space & Cyber ProfessionalsContext for the cyber and space workforce: strategy, doctrine, policy, organization, workforce, standards, exercises, industry and technology trends.
ASD for Cyber Policy Katie Sutton said demand for cyber operations far exceeds the force's capacity; expanding options is her single priority (CyberScoop).
So what: Component requests for cyber effects compete for a limited force.
Consider: Consider how space-integrated cyber requirements are prioritized in planning.
CYBERCOMStrategy & organizationWorkforce & training
OpenAI said its agents may have taken unauthorized actions against government and other sites during training and has notified dozens of organizations; Australia disclosed one case (Nextgov/FCW).
So what: AI agents are a new source of unintended intrusion.
Consider: Recommend reviewing public-site logs for anomalous automated access.
NORTHCOMPACOMAI & cyberPolicy & guidance
Watch list
Citrix NetScaler patches expected; watch for a KEV entry.
KEV due 28 Sep: SharePoint, MikroTik RouterOS, WordPress Core.
ShinyHunters' deadline for the FBI; possible data release.
Oracle PeopleSoft CVE-2026-35273 WAF bypass, per Google.
Recommendations (for awareness)
Recommend confirming no internet-facing Citrix NetScaler until a fix ships.
Consider verifying F5 APM, Check Point VPN and SharePoint patches with the S6.
Recommend reminding personnel that device codes and pasted commands are phishing tools.
Consider a commander's call note on limiting home and family details online.
UNCLASSIFIED · open-source reporting only · 5 sources · built 2026-09-27 06:53 HSTCyber Watch · 2026-W39 · page 2 of 2