What Business Owners Need to Know This Week

Week 38 (6–12 September 2026): the thing that failed this week belonged to someone else. On Saturday 12 September Bidvest Bank and EasyEquities each told customers that a third-party service provider had suffered a cyber incident and that data held there should be treated as potentially affected. Neither named the provider; EasyEquities described its provider as the firm that runs its client verification checks. No source connects the two notifications and this report does not. Earlier in the week Cartrack confirmed its incident and Rohloff Group acknowledged the INC Ransom listing from W36 — four victim confirmations in one window, the most this series has carried, and two of the four concern someone else’s breach.

The Bottom Line: A defender who checked the vendor page for Fortinet, Citrix or N-able on Friday 11 September would have read that exploitation was unconfirmed, unmentioned or denied — while the CISA catalogue said otherwise for all three. A vendor’s advisory records what the vendor has decided to say; the catalogue records what has been observed. They disagreed three times in one week. For a board the practical question is which of its suppliers, verification providers and software vendors would tell it first, and how many hours later.

The Week in Numbers

  • 14 new KEV additions — between 8 and 11 September, the largest weekly count this series has recorded, with seven already overdue; HIGH threat level for the 21st consecutive week.
  • 7 of 14 — sit on the network edge or the management plane: Citrix NetScaler, Cisco Secure FMC at CVSS 10.0, FortiOS, two MikroTik RouterOS flaws, N-able N-central and ConnectWise ScreenConnect.
  • 3 vendor pages contradicted the catalogue — Fortinet’s advisory still read “Known Exploited: No” four days after listing; Citrix’s bulletin does not mention exploitation at all; N-able’s status page says no exploitation confirmed while its own customer notice says the opposite.
  • 5,627 MikroTik RouterOS instances — exposed by South Africa to the internet, alongside 104 NetScaler instances; both verified counts.
  • 22 minutes apart — The Gentlemen listed Hollard Insurance Group at 21:56 UTC and LockBit 5.0 listed VSB Attorneys at 21:34 UTC on Sunday 7 September.
  • ~4 million policyholders — held by Hollard, the country’s largest privately owned insurer, with more than 4,000 staff. Both listings rated CLAIMED.
  • 4 victim confirmations — Bidvest Bank, EasyEquities, Cartrack and Rohloff Group; two of them for a supplier’s breach.
  • CVSS 10.0 — Cisco Secure FMC CVE-2026-20079, unauthenticated, reaches root; Cisco recorded active exploitation on 9 September.
  • 14 weeks — since the Information Regulator’s last register entry (corrected below).

Major Incidents: Who Was Hit and How

Bidvest Bank and EasyEquities — Both Through a Provider

Both institutions wrote to customers on Saturday 12 September saying a third-party service provider had suffered a cyber incident and that data held there should be treated as potentially affected. Neither named the provider. EasyEquities described its provider as the firm running its client verification checks; Bidvest Bank’s concerns a provider holding limited categories of bank data. Neither company could yet tell customers what was taken — and both wrote before the forensic result was in, which is the right order. These are the first public test of the question this report raised when the FSCA and Prudential Authority clock took effect on 1 September: what a regulated financial institution does when the material incident is a supplier’s.

Hollard and VSB Attorneys — Listed 22 Minutes Apart

The Gentlemen listed Hollard Insurance Group — South Africa’s largest privately owned insurer, with nearly four million policyholders and more than 4,000 staff — at 21:56 UTC on Sunday 7 September. LockBit 5.0 listed VSB Attorneys, a conveyancing and commercial practice in Alberton, at 21:34 UTC the same evening. Hollard says it is aware of the claims, has activated its incident response processes and cannot yet establish their validity, scope or impact; it has published nothing on its own site. Neither listing carries a data volume, a sample or a deadline, and both are rated CLAIMED. A conveyancing practice is a high-value target for a specific reason: it holds trust-account details and transfer instructions at the moment property money moves.

Citrix NetScaler — Patch Both HA Nodes, Then Hunt “anonymous”

CVE-2026-19490 was due 12 September, and a public exploit was published before exploitation attempts began on 3 September. Fixed builds are 14.1-73.32 and 13.1-63.21; 12.1 and 13.0 are end of life with no fix. Bishop Fox confirmed the flaw on 13.1-63.18, so a 13.1 appliance below 13.1-63.21 is exposed regardless of earlier patching. On builds before 14.1-43.56 and 13.1-61.28 every Gateway and AAA virtual server is affected whether or not SAML is configured. Patch both nodes of every HA pair, and check for sessions belonging to the user anonymous.

Cisco FMC and MikroTik — Check Before You Patch

Cisco Secure FMC CVE-2026-20079 is CVSS 10.0, unauthenticated, and reaches root; Talos ties one of three exploiting clusters to tradecraft consistent with Qilin affiliates. The check is one command in expert mode — zgrep for package_info and license across /var/log/messages — and a hit referencing /var/tmp/license.tmp means contact TAC rather than patch. VulnCheck’s finding that exploitation needs a stale post-reboot session makes the FMC nobody logs into the most exploitable one. For MikroTik RouterOS, 7.24.2, 7.23.4 or 6.49.21 closes the CERT Polska chain; a log line reading user ops added by ssh:-2 is the published compromise marker.

POPIA and Regulatory

A correction is owed to W37. That edition stated in three places that the Regulator’s enforcement-notices register carried nothing later than 16 April 2025. That was wrong — the 16 April date was read from the 2025 tab alone. The register’s 2026 tab carries three instruments: Central Johannesburg TVET College (POPIA section 95, 20 May), Sibanye Stillwater (PAIA section 77J, 2 June) and the Gauteng Department of Health notice (10 June). The W37 KPI was anchored on the June notice and stands, as does the finding that the SABS notice is absent from the register — nothing dated August or September 2026 appears there, two weeks after it was described at the briefing. The count moves to fourteen weeks, and this report will now record it without arguing it each week: the pattern is a communications practice rather than a backlog. Among the proposals the Regulator says it intends to submit to Parliament is replacing the grace period with an immediate fine on a finding of non-compliance; no Bill or draft text could be located. On the financial-sector side, Joint Communication 5 of 2026 requires initial notification within 24 ordinary hours of the institution classifying an incident as material, with no prescribed threshold, and states that outsourcing does not transfer the obligation — the Authorities expressly rejected the argument that an administrator’s notification could stand in for a fund’s.

Full Intelligence Report

The complete Week 38 technical report covers the Bidvest Bank and EasyEquities supplier notifications, the Hollard and VSB Attorneys listings, the Cartrack and Rohloff confirmations, all fourteen catalogue additions with fixed versions and the vendor-advisory discrepancies documented, the Citrix, Cisco FMC and MikroTik remediation sequences with compromise markers, the corrected Information Regulator register analysis, the 24-hour financial-sector notification regime, structured hunt missions with IOC tables and the full source list.

What Your Business Should Do Right Now

  • Patch Citrix NetScaler on both nodes of every HA pair, then hunt for “anonymous” sessions: CVE-2026-19490 was due 12 September and a public exploit preceded exploitation. Fixed builds are 14.1-73.32 and 13.1-63.21; 12.1 and 13.0 are end of life with no fix. A 13.1 appliance below 13.1-63.21 is exposed regardless of earlier patching.
  • Run the Cisco FMC log check before you patch: In expert mode, zgrep for package_info and license across /var/log/messages. A hit referencing /var/tmp/license.tmp means contact TAC, not apply the hot fix. The FMC nobody logs into is the most exploitable one, because exploitation needs a stale post-reboot session.
  • Patch MikroTik RouterOS and look for a user named “ops”: 7.24.2, 7.23.4 or 6.49.21 closes the CERT Polska chain. A log line reading “user ops added by ssh:-2” is the published compromise marker. South Africa exposes 5,627 RouterOS instances — this is the largest single edge population in the country.
  • Stop trusting vendor advisories as your exploitation signal: Three vendor pages contradicted the CISA catalogue in one week. Drive your prioritisation from the catalogue and from observed exploitation, and treat a vendor’s “not known exploited” as a statement about the vendor’s disclosure posture rather than about your risk.
  • Write to every provider that verifies, onboards or screens your customers: Ask two questions — does it hold your data in an environment shared with other clients, and how many hours will it take to tell you? Verification and KYC providers concentrate exactly the identity data that makes downstream fraud work.
  • Decide in writing, this week, when a supplier’s incident becomes material: The 24-hour clock under Joint Communication 5 of 2026 runs from your own classification, and there is no prescribed threshold. If you have not defined the trigger, you cannot demonstrate when the clock started.
  • Note that outsourcing does not transfer the obligation: The Authorities expressly rejected the argument that an administrator’s notification could stand in for a fund’s. Check whether your incident procedures quietly assume your administrator will handle it.
  • Follow the Bidvest and EasyEquities sequencing: Both notified customers before the forensic result was in. Telling people early that their data may be affected, and saying plainly what you do not yet know, is a stronger position than waiting for certainty that may take weeks.