Skip to content

Home/Digest/Past issues

Daily digest,

Citrix NetScaler Zero-Day Exploitation Targets Multiple Sectors (+7 more)

Vulnerabilities

Citrix NetScaler Zero-Day Exploitation Targets Multiple Sectors

Cyber attackers are exploiting two critical zero-day vulnerabilities in Citrix NetScaler, identified as CVE-2026-88771 and CVE-2026-88772, to deploy web shells and gain unauthorized access to systems. The attacks have impacted government agencies, financial services, education, and professional services across North America and Europe. Exploitation began as early as September 2026, with attempts detected on September 24, just days before Citrix's public disclosure on September 27. The vulnerabilities allow for remote code execution and memory overflow, posing significant risks to unpatched systems. Citrix has released patches and advised customers to check for signs of compromise before applying updates. Cybersecurity firms have confirmed ongoing exploitation, and CISA has added these CVEs to its Known Exploited Vulnerabilities catalog. Organizations are urged to act quickly to mitigate risks.

Vulnerability · 4 sources · score 75 · CVE-2026-88771, CVE-2026-88772, Slapshot, Whipshot, Citrix NetScaler

New Spectre v2 Variant BTR Exposes CPUs to Data Leaks

Researchers from VUSec and Scuola Superiore Sant'Anna disclosed a new Spectre v2 variant named Branch Target Reuse (BTR) that affects Intel, AMD, and Arm CPUs. This attack targets just-in-time (JIT) compilers in operating systems, web browsers, and language runtimes, allowing attackers to steal sensitive data from memory, including password hashes. The BTR exploit leverages stale indirect branch prediction entries that persist after code modifications, enabling speculative execution attacks. Two end-to-end exploits have been developed against the Linux kernel, successfully leaking the root password hash at a rate of 8 bytes per second. The vulnerabilities have been assigned CVE-2026-64507 and CVE-2026-64508, with fixes already merged into the Linux kernel. The researchers have notified affected vendors, and while exploits are confirmed for Linux, a complete browser exploit is still under development. The attack demonstrates that self-modifying code can still be exploited despite previous assumptions of impracticality.

Vulnerability · 4 sources · score 73 · CVE-2026-64507, CVE-2026-64508, CVE-2026-65660, Spectre

Vega II Launches Amid Active Exploitation of CVE-2026-86950

On September 29, 2026, Vega introduced Vega II, an agentic cyber defense platform designed to enhance security operations centers (SOCs) by integrating advanced AI capabilities. This launch coincides with the active exploitation of CVE-2026-86950, a zero-day vulnerability that was published on September 28, 2026, and added to the CISA KEV list on the same day. The Vega II platform aims to overcome legacy SIEM limitations by enabling real-time detection, triage, and investigation of threats across all enterprise data sources. The platform is expected to significantly reduce investigation times and operational costs for security teams. As organizations face increasing threats from sophisticated attackers leveraging AI, Vega II seeks to empower defenders with a more effective toolset. The urgency of the situation is heightened by the rapid adoption of frontier AI by adversaries, making the need for advanced defensive measures critical.

APT · 3 sources · score 70 · CVE-2026-86950, ShinyHunters

Critical Out-of-Bounds Write Vulnerability in FastStone Image Viewer

A vulnerability, CVE-2026-101203, has been identified in FastStone Image Viewer versions up to 8.3, specifically in the 1bpp RLE Decoder component. This out-of-bounds write vulnerability allows remote attackers to manipulate the application by sending specially crafted image files that require user interaction to open. The attack can lead to memory corruption, potentially compromising the application's integrity and availability. The vendor has been contacted but has not responded to the disclosure. The vulnerability was published on September 28, 2026, and is rated with a CVSS score of 6.3, indicating a high risk if left unpatched. Organizations are advised to avoid opening untrusted image files and to update the application once a patch is available. Currently, there is no evidence of public proof-of-concept exploitation. The attack complexity is low, and no privileges are required for exploitation.

Vulnerability · 5 sources · score 55 · CVE-2026-101203, CVE-2026-95509, CVE-2026-96420, CVE-2026-96421, CVE-2026-96422

Breaches

Dodo Pizza Cyberattack Exposes Customer Data of 68 Million

Dodo Pizza confirmed a cyberattack on its IT systems, revealing that hackers gained access to personal data of its customers. The compromised information may include names, addresses, email addresses, phone numbers, dates of birth, and order history. The hacking group DataSuckers claimed responsibility, alleging they stole 2-3 TB of data affecting approximately 68 million customers across multiple countries. Dodo Pizza reported that it does not store payment information, so financial data was not compromised. The company has blocked access to the affected systems and is conducting an internal investigation. They have notified the Russian communications regulator, Roskomnadzor, about the incident. The claims made by DataSuckers regarding the scale of the breach and the data stolen remain unverified by independent sources.

APT · 3 sources · score 61 · Datasuckers

Ledyard Terminates Flock Camera Use After Data Breach

The Town of Ledyard, Connecticut, has decided to terminate its relationship with Flock after a security incident involving a data breach. Flock informed Ledyard Police Chief Ken Creutz that a malicious actor published a website containing sensitive customer device information, including device names, locations, and types. This breach raised significant concerns regarding privacy, security, and transparency. In light of these developments, Chief Creutz recommended that the town cease using Flock cameras, which had been installed to assist in crime-solving. The town council unanimously voted to stop data collection and sharing by the cameras. Ledyard had four Flock cameras, which have now been covered, and the town is willing to pay approximately $12,000 to exit the contract with Flock. The police chief has requested that the cameras be removed but has not received a response from Flock.

Breach · 3 sources · score 54

DIVD Hit by Agentic AI-Powered Cyberattack

The Dutch Institute for Vulnerability Disclosure (DIVD) reported a cyberattack attributed to an agentic AI, marking a significant breach after seven years of operation without incident. The attack was characterized as 'loud and very, very messy,' with the AI agent autonomously executing actions that left substantial evidence for investigation. DIVD has initiated a forensics investigation and informed relevant authorities, including the police and the National Cyber Security Centre. The exact impact and purpose of the attack remain unclear, but it exploited a technical vulnerability in an undisclosed system, which has not been identified as Citrix NetScaler. DIVD is treating the situation as a worst-case scenario and is focused on securing its infrastructure and supporting its volunteers. A public update is expected on October 1, 2026.

Breach · 3 sources · score 52

Threat actors and malware

Cybercriminals Exploit ChatGPT Custom GPTs for ClickFix RAT Attacks

A new ClickFix campaign has been discovered that exploits ChatGPT Custom GPTs to impersonate legitimate products, luring users into executing malicious code. Cybersecurity firm Huntress reported that at least 40 users have been infected, with two confirmed incidents linked to Custom GPT instances. The attackers created Custom GPTs that directed victims to a Google Sites link, leading to a malicious page that instructed users to run PowerShell commands to download a malicious MSI file. This file then deployed a remote access trojan (RAT) by sideloading malicious DLLs using legitimate Canon and Stardock executables. OpenAI took down the first Custom GPT on September 25, but a second one was discovered shortly after. The campaign highlights the ongoing abuse of AI platforms for social engineering attacks.

Vulnerability · 4 sources · score 70 · CVE-2025-25249, CVE-2026-86950, ClickFix, NeedyMantis, Rapuncel

New on leak sites

30 victims listed on ransomware leak sites by 16 groups in the 24 hours before this issue. The most active:

Also moving

  • CVEs: CVE-2026-86950, CVE-2026-88771, CVE-2026-88772, CVE-2026-53131, CVE-2026-53221
  • APT groups: ShinyHunters
  • Vulnerabilities: Citrix NetScaler, Path Traversal

Get the next one by email

The digest is free and arrives every morning. One click to leave.

Subscribe to the digest

A free account turns the digest into a personal watchlist: choose what you want to follow.