This website uses cookies

Read our Privacy policy and Terms of use for more information.

Summary: Citrix released emergency patches in security bulletin CTX697096 for eight NetScaler ADC and Gateway flaws after confirming active exploitation of two critical remote code execution vulnerabilities: CVE-2026-88771 and CVE-2026-88772 (both CVSS 9.5). CVE-2026-88771 is an improper input validation issue allowing unauthenticated command execution on all deployments, including default configurations. CVE-2026-88772 is a memory overflow leading to RCE or DoS when DTLS is enabled (default on VPN virtual servers).

Fixed builds are 14.1-73.37 and later, and 13.1-64.23 and later (plus corresponding FIPS/NDcPP versions). CISA added both to its KEV catalog and ordered Federal Civilian Executive Branch agencies to patch by September 30, 2026, citing global exploitation reports.

Key takeaway / Actionable note: Immediately upgrade NetScaler ADC/Gateway appliances, check for IoCs via NetScaler Console before patching if possible, and isolate any compromised devices.

Summary: The Cybersecurity and Infrastructure Security Agency added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalog on September 27 and published an alert confirming threat actors are actively exploiting the flaws worldwide. CISA noted that updating NetScaler appliances can be complex and may require downtime, urging organizations to assess exposure and prioritize mitigation.

Federal agencies face a September 30 deadline. Citrix provided generic indicators of compromise and recommended steps including preserving evidence, isolating devices, rotating credentials and KEKs, and rebuilding from known-good backups.

Key takeaway / Actionable note: Treat this as an emergency: inventory all NetScaler instances, apply the fixed builds without delay, and review connected systems for lateral movement.

Summary: Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals that were suspended after suspected North Korean hackers breached its systems and stole over $350 million (later revised to approximately $387.5 million) from hot and warm wallets. The attack involved unauthorized transfers that did not require private-key compromise; attackers instead abused backend systems to trigger legitimate-looking internal transfers.

Bitget’s CEO cited IP addresses and on-chain patterns matching known DPRK groups, with external firms including Elliptic assessing the activity as highly likely linked to North Korean actors. The exchange’s User Protection Fund is covering customer losses.

Key takeaway / Actionable note: Crypto platforms should continue hardening hot-wallet controls and monitoring for forged internal transfer patterns associated with nation-state actors.

Summary: Former U.S. Army soldier Cameron John Wagenius, 22 (online as kiberphant0m), was sentenced to 70 months in prison and ordered to pay nearly $295,000 in restitution for hacking and extorting at least 10 technology and telecommunications companies between April 2023 and December 2024 while on active duty.

He and co-conspirators obtained network credentials (including via a custom SSH Brute tool), stole call-detail records and other sensitive data, and threatened public leaks on cybercrime forums unless ransoms totaling over $1 million were paid. The scheme included data affecting more than 100 million AT&T customers’ metadata.

Key takeaway / Actionable note: Enforce MFA and credential hygiene on cloud storage platforms such as Snowflake, and monitor for credential-stuffing or brute-force activity against telecom infrastructure.

Summary: Researchers disclosed Carbonato, a botnet targeting Docker daemons exposed without authentication on port 2375. It launches privileged containers for host access, establishes persistence (cron, systemd, reverse SSH), and deploys the unmodified open-source Hermes Agent AI framework. Operators overwrite the SOUL.md persona file with a 39-line prompt that renames the agent GH0ST and directs it to execute Telegram commands, maintain persistence, and prioritize theft of AI API keys from providers including OpenAI, Anthropic, and Google. The campaign has been active since at least October 2024 and includes worm-like scanning of adjacent networks.

Key takeaway / Actionable note: Never expose Docker APIs without authentication; immediately audit and lock down port 2375, rotate any exposed AI API keys, and hunt for Hermes Agent or GH0ST indicators.

Summary: Google issued a warning that the ShinyHunters extortion group has modified its exploit technique in new attacks targeting the Oracle PeopleSoft vulnerability CVE-2026-35273. The group continues to pursue high-value data for extortion following earlier claims involving government and enterprise systems.

Key takeaway / Actionable note: Prioritize patching of PeopleSoft instances and monitor for web-shell deployment or unusual authentication activity associated with known ShinyHunters TTPs.

Summary: CISA added the Microsoft SharePoint vulnerability CVE-2026-65660 to its KEV catalog, with a federal patching deadline of September 28, 2026, after confirming active exploitation. The flaw enables remote code execution under certain conditions and has been observed in real-world attacks.

Key takeaway / Actionable note: Apply the available SharePoint security updates immediately and review logs for indicators of compromise related to this CVE.

Summary: Attackers exploited a GlobalProtect vulnerability to breach business networks, steal customer records, and use the data to generate approximately 2.4 million convincing fraudulent messages as part of a campaign referred to as Operation Master.

Key takeaway / Actionable note: Ensure Palo Alto Networks GlobalProtect is fully patched and monitor for anomalous outbound messaging or data-exfiltration patterns.

Also Noted:

Bottom line: The weekend’s dominant story remains the Citrix NetScaler zero-days under active exploitation; every organization running ADC or Gateway appliances must treat patching as an emergency priority before the CISA federal deadline.

Parallel activity from suspected North Korean actors against crypto infrastructure and the emergence of AI-agent-driven botnets targeting cloud hosts underscore the continued pressure on both perimeter appliances and cloud identity/API surfaces. Maintain heightened monitoring for NetScaler IoCs and exposed Docker endpoints.

Reply

Avatar

or to participate