Skip to content

Home/Digest/Past issues

Daily digest,

Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching… (+5 more)

Vulnerabilities

Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required

Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated federal agencies to patch by September 30. Reports indicate that these vulnerabilities have been actively exploited since September 3, 2026, by a suspected state-backed group using custom web shells. Organizations in sectors such as banking, healthcare, and government are urged to update their systems immediately and conduct forensic checks for prior exploitation. The situation is critical, as failure to patch could lead to significant control over affected devices. The vulnerabilities allow for remote code execution and other severe impacts.

Vulnerability · 2 sources · score 86 · CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775

Rising Vulnerabilities and AI Exploitation Threaten Cybersecurity

In the first half of 2026, Kaspersky reported 5,200 critical vulnerabilities, a 50% increase from the previous year. The gap between vulnerability disclosure and exploitation is shrinking, with AI accelerating exploit generation. Many attacks exploit known vulnerabilities rather than zero-days, as attackers monitor vulnerability disclosures closely. Organizations struggle to manage vulnerabilities effectively due to delays in remediation and prioritization issues. The reliance on vulnerability scanners without robust management processes leaves systems exposed. Deloitte emphasizes the need for faster decision-making and remediation to counteract AI-driven threats. The current cybersecurity landscape demands immediate action to address these vulnerabilities and improve defenses.

Vulnerability · 2 sources · score 60

Breaches

Australia Ranks Third for North Korean Cyber Attacks

According to Microsoft's 2026 Digital Defense Report, Australia has become the third-largest target globally for North Korean hackers, accounting for 5% of their attacks. The report highlights that Australian organizations are experiencing a significant volume of cyber intrusions, ranking 11th overall for state- and criminal cyber threats. The report indicates that North Korean hackers have evolved their tactics, leveraging AI to enhance their operations and conduct more persistent campaigns. Microsoft recorded 27 cyber threats in Australia involving foreign nation-states. The report comes amid heightened awareness of cyber risks in Australia, particularly following a recent incident involving unauthorized access to a Medicare statistics portal. The increasing sophistication of North Korean cyber operations poses a growing concern for both public and private sectors in Australia.

Breach · 2 sources · score 60

McMinnville City Data Breach Exposes Sensitive Records

The City of McMinnville reported a data breach that exposed sensitive information, including Social Security and driver's license numbers, affecting individuals whose data was accessed between June 1 and July 18, 2026. The breach was discovered on July 15, but formal notification to affected individuals was delayed until September 29, exceeding the 45-day legal requirement in Oregon. A ransomware group named RansomHouse claimed responsibility for the attack, which involved unauthorized access to various city records, including police and human resources information. Local cybersecurity expert Chuck Dornon confirmed the ease of accessing these records on the dark web, describing it as a 'treasure trove of information.' The city has since begun notifying affected individuals and is enhancing its data protection policies.

Ransomware · 2 sources · score 52 · RansomHouse

Threat actors and malware

87% of Retailers Report Cyber Incidents Amid Rising Threats

A Kaspersky survey reveals that 87% of retailers experienced cyber incidents in the past year, with phishing being the most common attack vector, affecting over 20% of respondents. The retail sector, which handles vast amounts of personal data, is increasingly targeted by cybercriminals, leading to significant consequences such as data theft (28%) and financial losses (25%). Internal factors like insufficient IT expertise and risky behaviors, such as using personal devices for work, contribute to these vulnerabilities. In response, 82% of retailers have increased their IT security budgets, with many opting to outsource security functions. The findings highlight the urgent need for enhanced cyber awareness programs and advanced endpoint protection solutions as AI integration grows in retail.

Malware · 2 sources · score 52 · Magecart

Also worth knowing

AI-Driven Cyber Scams Target 90% of Americans, Consumer Reports Reveals

A new report from Consumer Reports indicates that 90% of Americans have encountered a cyber scam or attack, with 17% reporting financial losses. The study, conducted in March and April 2026, highlights the role of artificial intelligence in facilitating these scams, allowing criminals to create personalized attacks using stolen personal data. Consumer confidence in data privacy has significantly declined, with only 32% of respondents feeling secure about their personal information, down from 48% in 2025. The report emphasizes the urgent need for accountability from companies and government regulations to combat this growing threat. Experts warn that AI is making fraud more accessible and sophisticated, impacting even tech-savvy individuals. The findings are based on surveys of nearly 5,000 U.S. adults.

Other Threats · 2 sources · score 52

New on leak sites

31 victims listed on ransomware leak sites by 17 groups in the 24 hours before this issue. The most active:

Also moving

  • CVEs: CVE-2026-86950, CVE-2026-88772, CVE-2020-1472, CVE-2023-54404, CVE-2024-58388
  • Vulnerabilities: XSS, Authentication Bypass Via Session Handling, Authorization Bypass Through User-Controlled Key, Citrix NetScaler, Credential Disclosure
  • APT groups: APT27, APT31, CamoFei, ChamelGang, CL-CRI-1040
  • Malware: Borat, Borat RAT

Get the next one by email

The digest is free and arrives every morning. One click to leave.

Subscribe to the digest

A free account turns the digest into a personal watchlist: choose what you want to follow.