What Business Owners Need to Know This Week

Week 41 (27 September–3 October 2026): two South African organisations that run other organisations’ systems were the week’s victims, and in both cases the public learned of it from a document that was never written as a disclosure. Air Traffic and Navigation Services, the state-owned operator that manages South African airspace, revealed ransomware-linked malware in an airport operational technology network through a request for quotation for forensic investigators. BCX’s customers learned the attacker’s version of an incident from a leak site, four days after Telkom’s statement had placed it in a test environment. And the MIP breach reached a second insurer this week by way of a binder holder — which means an insurer can now appear on a leak site for data it never held itself.

The Bottom Line: All three cases put one question to a board in different words: for each supplier that builds, hosts or administers on your behalf, does the contract say who tells you, within what time, and in what form, when their environment is breached? On the technical side, Citrix disclosed two NetScaler zero-days that give pre-authentication remote code execution on a default configuration, 122 instances are exposed in South Africa, and the responder guidance runs against every patch programme’s instinct: look for the web shell before you patch, because the upgrade can remove the evidence of it.

The Week in Numbers

  • 135 cumulative SA ransomware victims — up 3 from 132; HIGH threat level for the 24th consecutive week.
  • 3 of 3 — SA-tagged leak-site claims in the window that survive the nationality check: BCX, LegalWise and Edcon, each on its own South African domain.
  • 500 GB in 4,224,088 files — claimed by INC Ransom from BCX, described as source code and documentation for six business applications and more than fifteen integration libraries.
  • ~6,000 funeral policies — the exposure Guardrisk attributes to its binder holder CoverCubed, by way of the June MIP incident.
  • 921 victims — The Gentlemen’s index, up 33 in a week, the largest move of any group in the aggregator’s table. Four South African listings since 7 September, three of them insurance-linked.
  • CVSS 9.5 × 2 — Citrix NetScaler CVE-2026-88771 (pre-auth command injection, default configuration) and CVE-2026-88772 (DTLS overflow), both exploited before disclosure.
  • 122 NetScaler instances — exposed to the internet in South Africa.
  • 7 new CISA KEV additions — down from ten, with five already past their remediation date at publication.
  • 17.5 billion spam calls — in the first half of 2026, by the National Consumer Commission’s count, as it gazettes draft rules for a national opt-out registry.
  • 31 March 2028 — the date the green barcoded ID book ceases to be a valid identity document.

Major Incidents: Who Was Hit and How

ATNS — Ransomware-Linked Malware in Airport OT, Disclosed by Tender

Air Traffic and Navigation Services issued a request for quotation on 18 September for cyber-forensic investigators. It states that preliminary investigation had identified malware commonly associated with the early stages of ransomware attacks in the operational technology environment supporting weather services at Chief Dawid Stuurman International Airport in Gqeberha, that network monitoring indicated possible data exfiltration to external addresses located in China, and that internal teams contained and removed it. A second workstream covers reports that employees may have unlawfully accessed personal information; the internal investigation could not substantiate them. ATNS’s spokesperson told the Sunday Times it cannot comment on compromised data until the forensic work is done. No actor is named — the China reference describes where traffic went, not who sent it. The system carries weather data to controllers, but nothing in the public record says a service stopped. What makes this the week’s lead is the route: the first public account of a national-infrastructure cyber incident was written by a procurement office for bidders, and a journalist found it.

BCX — INC Ransom Claims 500 GB of Source Code

INC Ransom listed BCX, Telkom’s IT services subsidiary, on 29 September, four days after Telkom placed an incident in a limited area of a BCX legacy testing environment. The actor claims 500 GB in 4,224,088 files: source code and technical documentation for six named business applications — including a cemetery-management system, an mSCOA posting-level creator, a receipting module and a portal single sign-on, which read as municipal line-of-business systems — plus more than fifteen integration libraries, with the claim that “numerous vulnerabilities” were found in current versions. Neither Telkom nor BCX had responded to the listing by the close of the window. The listing is CLAIMED; Telkom’s underlying incident stays CONFIRMED at the scope Telkom gave, and no public statement joins the two. For a BCX customer the practical exposure, if the claim is true, is secrets embedded in code and connectors rather than customer records — which makes the right response a rotation list, not a wait for news.

Guardrisk — The MIP Cascade Arrives Through a Binder Holder

Guardrisk answered last week’s open question on 28 and 30 September. By its account, the data on The Gentlemen’s site appears to be linked to the June MIP incident through its binder holder CoverCubed, a Johannesburg health-insurance intermediary, covering about 6,000 funeral policies — and not to any compromise of Guardrisk’s own systems. CoverCubed, Guardrisk says, has notified the Information Regulator under section 22 and its affected clients. That matters for every insurer in the country: the MIP cascade now reaches names that never contracted with MIP, and an insurer can be listed and extorted for data its intermediary processed. Guardrisk’s denial of an own-system breach is rated CONFIRMED on its statements to two publications; the MIP origin and CoverCubed’s filing are Guardrisk’s account of a third party, since CoverCubed has published nothing.

LegalWise and Edcon — Two More Listings From The Gentlemen

The Gentlemen listed LegalWise, the legal-expenses insurer, and Edcon, the retail group in business rescue since 2020, within the same minute on 30 September. Neither listing carries a data volume, sample or deadline, and both are CLAIMED. LegalWise is the one to watch: it is an insurer by licence, its group is 38% owned by Hollard, and both the Hollard case and, on the insurer’s account, the Guardrisk case resolved to the MIP data set — though none of that makes LegalWise an MIP client, and this report does not infer it. Edcon is a different kind of record: its trading businesses were sold in 2020, so anything held would be legacy data from a wound-up retailer with four million store-card accounts in its past — which is still personal information, whether or not the responsible party still trades.

Citrix NetScaler — Two Zero-Days, and Check Before You Patch

Citrix disclosed CVE-2026-88771, a pre-authentication command injection in the default configuration, and CVE-2026-88772, a DTLS overflow, on Sunday 27 September — both already exploited. Mandiant and Google describe a campaign running since at least early September that leaves a PHP web shell and a Python tunneller on the appliance and sets the SUID bit on /bin/sh, against government, financial, technology, education and legal targets. Rapid7 saw the first attempt on 20 September and two compromises in which the attacker archived /flash/nsconfig — the directory holding the administrator and directory bind credentials, TLS private keys and SSH host keys. That is why the guidance is to examine first, patch second, and rotate everything the appliance held even if the checks come back clean. The rest of the week’s catalogue: Cisco Catalyst SD-WAN Manager, Fortinet FortiMail, Apple CoreGraphics, and a Zammad helpdesk pair used against a Dutch vulnerability-disclosure institute.

POPIA and Regulatory

The duty followed the data. Against the Regulator’s 25 September position that it had received only MIP’s notification for a breach touching about 45 insurers, the record now holds three filings: MIP’s, Bidvest Bank’s in the RelyComply case, and CoverCubed’s, as Guardrisk reports it. A binder holder that collects and administers policy data under its own licence can be the responsible party for that data — so every binder and outsourcing agreement should say, in a clause, which party notifies under section 22 for which processing. Procurement as disclosure: no sector rule obliges an air navigation provider to tell the public about a cyber incident — the Cybercrimes Act’s section 54 duty runs to SAPS and the Critical Infrastructure Protection Act to the minister — which is why the first account was written for bidders. Boards that run infrastructure should assume their tender documents will be read as disclosures. Opt-out registry: the National Consumer Commission gazetted draft guidelines requiring every direct marketer — including insurers, financial institutions and retailers — to register, renew annually and cleanse its databases against the registry at R0.12 per name, with penalties of up to R1 million or 10% of annual turnover; comment closes in the week of 16 October. Identity documents: production of the green barcoded ID book ends on 31 March 2027 and it stops being valid on 31 March 2028, while Home Affairs demonstrated a digital ID in the MyMzansi app. The Information Regulator’s register still carries nothing later than 10 June.

Correction to Week 40

The Week 40 edition, covering 20–26 September, did not carry the ATNS incident. The Sunday Times published it on Saturday 26 September, the last day of that window, with the operator’s spokesperson on record, and the request for quotation that discloses it is dated 18 September. W40 counted one South African organisation confirming a breach in its window, Telkom; it should have counted two, and its Government and Transport heatmap rows were scored without it. The W40 threat-level reasoning, which turned on no systemically important institution going out of service, is unchanged, because ATNS reports containment and no service disruption.

Full Intelligence Report

The complete Week 41 technical report covers the ATNS operational technology incident and its tender disclosure, the BCX listing against Telkom's earlier scope statement, Guardrisk's binder-holder account and the LegalWise and Edcon listings, all seven catalogue additions with vendor log checks for NetScaler, Cisco SD-WAN Manager and FortiMail, the WHIPSHOT and SLAPSHOT indicators and YARA rules, the opt-out registry and identity-document changes, structured hunt missions with IOC tables, the correction to Week 40, and the full source list.

What Your Business Should Do Right Now

  • Examine every NetScaler ADC and Gateway for compromise before you upgrade it: Preserve a VM snapshot, then check /etc/httpd.conf for application/x-httpd-php, php_flag or AliasMatch directives; look for PHP in the VPN scripts and media directories; check for /tmp/.uxd* files; confirm /bin/sh is not setuid; and look for a Python process referencing .uxd. Any hit is an incident: isolate the appliance and disable HA sync.
  • Then patch and rotate what the appliance held: Upgrade to 14.1-73.37 or 13.1-64.23 (13.1-FIPS 13.1.37.279). On every appliance that was internet-facing and unpatched after 20 September, rotate administrator, LDAP, RADIUS, TACACS, SNMP and NITRO credentials and reissue TLS and SSH keys — whether or not the checks found anything. Where DTLS is not needed, disable it or block UDP/443 upstream.
  • If BCX, or any provider, builds or hosts applications for you, treat this week as a secrets-rotation exercise: Ask in writing whether your source code, integration libraries or embedded credentials sat in the affected environment. What you can control is whether any connection string, API key or service account in that code still works. Get the answer in writing by Friday 9 October and keep it.
  • Insurers: put the same question to every binder holder and underwriting manager: Guardrisk was named on a leak site before any notice reached it, for data its intermediary processed. Add a clause to each binder and outsourcing agreement stating which party notifies under section 22, for which processing, and within how many hours.
  • Check Cisco Catalyst SD-WAN Manager logs, then upgrade: Search serviceproxy-access.log and vmanage-server.log for POST requests to j_security_check carrying percent-encoded characters such as %6a from addresses you do not recognise. Move to 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 or 26.2.1.
  • Check FortiMail, then upgrade: Search for archive-account configuration changes from 79.141.169.187 and any POST carrying ../ to an /ibe path. Disable IBE if you do not use it, and move to 8.0.2, 7.6.7 or 7.4.9.
  • Push the Apple updates through MDM: iOS 26.7.1, iPadOS 26.7.1, macOS 26.7.1 or 15.8.1, and report fleet compliance by Friday 9 October.
  • Test the ATNS lesson on your own OT: Any weather, SCADA or building-management network reachable from the corporate side needs two answers — is it segmented, and would you see it sending data to an external address? ATNS caught the exfiltration through network monitoring; most organisations do not watch that egress at all.
  • Plan the green ID book’s retirement in onboarding: After 31 March 2028 a green book is not an identity document. KYC and FICA flows that accept a photographed green book need a retirement date in the plan now — and the copies of ID documents those flows store are exactly what the MIP and RelyComply breaches yielded.