Techradar Critical Citrix NetScaler Zero-Days Exploited Amid $387M Crypto Hack
Article Content
- •Two critical zero-day vulnerabilities in Citrix NetScaler are actively exploited.
- •CISA has issued a patch deadline of September 30, 2026, for affected systems.
- •Bitget suffered a $387 million breach attributed to North Korean hackers.
Citrix has confirmed that two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in its NetScaler ADC and Gateway products are being actively exploited. These vulnerabilities allow unauthenticated attackers to execute arbitrary commands and potentially disrupt services. CISA has added these flaws to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to apply patches by September 30, 2026. The vulnerabilities were disclosed on September 27, 2026, and are rated critical with a severity score of 9.5/10. In a separate incident, cryptocurrency exchange Bitget resumed withdrawals after a breach attributed to North Korean hackers resulted in the theft of over $387 million. The attack involved unauthorized transfers from hot wallets, while cold wallets remained secure. The situation highlights ongoing threats from both state-sponsored actors and opportunistic cybercriminals targeting critical infrastructure and financial systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track Clop, Kimsuky and PamStealer in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical…
ShinyHunters Hack Exposes Sensitive FBI Employee Data On September 23, 2026, the FBI disclosed an investigation into a data breach by the hacking group ShinyHunters, which claims to have stolen sensitive personal information of approximately 38,000 FBI employees and job applicants. The stolen data reportedly includes names, addresses, phone numbers, Social Security…