• FluTrackers.com Inc. does not provide medical advice. Information on this web site is collected from various internet resources, and the FluTrackers board of directors makes no warranty to the safety, efficacy, correctness or completeness of the information posted on this site by any author or poster. The information collated here is for instructional and/or discussion purposes only and is NOT intended to diagnose or treat any disease, illness, or other medical condition. Every individual reader or poster should seek advice from their personal physician/healthcare practitioner before considering or using any interventions that are discussed on this website. By continuing to access this website you agree to consult your personal physican before using any interventions posted on this website, and you agree to hold harmless FluTrackers.com Inc., the board of directors, the members, and all authors and posters for any effects from use of any medication, supplement, vitamin or other substance, device, intervention, etc. mentioned in posts on this website, or other internet venues referenced in posts on this website.
  • We are not asking for any donations. Do not donate to any entity who says they are raising funds for us.

Cyber Incidents USA 2026-27

The Rising Drone Threat: Why Our Critical Infrastructure Has Become Dangerously Exposed​

MONDAY, SEP 28, 2026
Excerpt:

Our Glass House: The Vulnerability of Critical Infrastructure​

America's refineries, pipelines, power grids, and data centers are, unfortunately, wide open. They sit in plain sight, mapped by publicly available satellite imagery, and their locations are cataloged in government databases that have long since been compromised. Anyone with insider knowledge or even rudimentary research skills can identify single points of failure that would cause chaos for millions of people. The vulnerability is not theoretical; it is a matter of public record.

The recent Joliet refinery incident is a perfect illustration of how fragile our systems have become. When that refinery went down, it triggered a diesel panic and sent shockwaves through the regional fuel supply chain. Imagine that same scenario replicated across a dozen refineries simultaneously. The economic fallout would be catastrophic, and our current strategies for defending these sprawling assets are nothing short of inadequate. You cannot surround hundreds of square miles of pipeline with barbed wire and armed guards.

Russia has already recognized this reality. Its government authorized its central bank and Sberbank to operate anti-drone systems and arm personnel to defend financial infrastructure, effectively turning bankers into air-defense operators. Putin even moved to allow the state to temporarily seize commercial critical infrastructure that is not sufficiently protected from drone strikes. I find it telling that Russia, which we are supposed to consider our inferior, is adapting to this threat while our own officials issue warnings but do nothing. The FBI has publicly acknowledged that cheap commercial drones now pose a significant threat to U.S. security and the homeland, and that low-cost drones can kill personnel and damage critical infrastructure. That warning should have been a wake-up call. Instead, it has been largely ignored.

 

(TLP:CLEAR) Vulnerability Notification – Citrix NetScaler Zero-Days Actively Exploited​

September 28, 2026
ACTION MAY BE REQUIRED for utilities using customer-managed Citrix NetScaler ADC or NetScaler Gateway appliances, including Secure Private Access Hybrid deployments that rely on NetScaler instances. Utilities that outsource technology support may need to consult their service providers for assistance with remediation actions.

Summary: Two critical remote code execution vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway are being actively exploited in the wild. They are tracked as CVE-2026-88771(CVSS v4 9.5) and CVE-2026-88772 (CVSS v4 9.5), attackers have exploited both as zero days. CVE-2026-88771 allows an unauthenticated attacker to execute arbitrary commands. It affects all NetScaler deployments, including those running the default configuration. CVE-2026-88772 is a memory overflow that can lead to remote code execution or denial of service on appliances with DTLS enabled, which is the default on NetScaler Gateway VPN virtual servers.

CISA has added both vulnerabilities to its Known Exploited Vulnerabilities Catalog and reports that threat actors are actively exploiting them globally. CISA also notes that updating NetScaler appliances can be complex and may require downtime. Citrix’s bulletin addresses six additional high- and critical-severity NetScaler vulnerabilities (CVE-2026-88773 through CVE-2026-88778).

Analyst Note: NetScaler appliances sit at the network edge. They often provide VPN, remote access, and authentication services for staff, contractors, and critical support systems. Successful exploitation could give attackers a foothold inside trusted network environments, potentially enabling lateral movement, credential theft, or access to systems supporting OT environments.

Citrix is updating Citrix-managed cloud services and Citrix-managed Adaptive Authentication directly.

WaterISAC strongly encourages members to review Citrix’s advisory and the CISA alert, and to take the following actions:

Continued:
 

Annapolis, Md​

Luminis Health restores MyChart after cyber incident​

1 hour ago
Annapolis, Md.-based Luminis Health has restored its MyChart patient portal as it recovers from a cybersecurity incident, the health system said in a Sept. 29 update.

Patients can again use MyChart, which had been down since Sept. 1, to schedule appointments, request prescription refills and message providers. However, some patient notes, lab results and imaging results may not yet appear in the portal.

Continued: https://www.beckershospitalreview.c...health-restores-mychart-after-cyber-incident/
 

What to Know About the Pentagon Breach Affecting Millions​

Updated: SEP 29, 2026 12:15 PM ET. Published: SEP 29, 2026 6:15 AM ET
A reported monthslong breach in the Defense Department’s human resources database exposed personal information of millions of military personnel and those related to them, including their Social Security numbers and job details.

A Pentagon official confirmed to TIME Tuesday that some 2.76 million “living individuals” and 294,000 “deceased individuals” have been affected by the breach at the Defense Manpower Data Center (DMDC).

The breach was first reported by defense-focused news publication Military Timeson Thursday, citing a breach notification letter to a person whose information was in the affected files.

Continued: https://time.com/article/2026/09/29...wer-data-center-breach-personnel-information/
 
Please see Post #27

Andover Still Reviewing Possible Data Theft Six Weeks After Cyberattack​

ANDOVER, MA — More than six weeks after a cyberattack disrupted Andover’s computer network, investigators have not determined whether attackers obtained protected personal information or who might need to be notified, Town Counsel Doug Heim said Monday.

Heim gave the update during the Sept. 28 Select Board meeting after board member Kevin Coffey asked when the Town would provide an official account of the attack and its aftermath.

“We’ve recently had a bunch more news released based on a data request for the cyberattack,” Coffey said. “Now information’s coming out sort of secondhand through news.”

Continued: https://andovermanews.com/andover-still-reviewing-possible-data-theft-six-weeks-after-cyberattack/
 

Astrana Health Notifies SEC About Social Engineering Incident​

Sep 29, 2026
Astrana Health, a managed services organization that helps healthcare providers deliver value-based, coordinated care to patients, has notified the U.S. Securities and Exchange Commission (SEC) about a material cybersecurity incident that exposed patient, employee, and provider information.

According to the Form 8-K filing, Astrana Health subsidiary Astrana Health Management identified unusual activity within its information technology environment. The forensic investigation found that threat actors had conducted a series of social engineering attempts against employees. The threat actors impersonated company personnel and spoofed the company’s main telephone number and tricked employees into providing them with access to company systems.

Continued: https://www.hipaajournal.com/astrana-health-data-breach/
 
Back
Top Bottom