Home/Digest/Technology/Past issues
Technology digest,
Technology: Critical NetScaler Vulnerabilities Exploited for Remote… (+4 more)
Vulnerabilities
Critical NetScaler Vulnerabilities Exploited for Remote Code Execution
Threat actors are exploiting two critical vulnerabilities, CVE-2026-88771 and CVE-2026-88772, in Citrix NetScaler ADC and Gateway appliances, allowing unauthenticated remote code execution. CVE-2026-88771, identified as a pre-authentication RCE flaw, has been since at least September 21, 2026, while CVE-2026-88772, a memory overflow bug, was also weaponized in September 2026. Attackers are deploying PHP web shells and a Go-based command-and-control framework named Platypus to maintain persistence and facilitate further intrusions. The vulnerabilities affect critical sectors including government and finance, with over 50,000 exposed instances of NetScaler appliances globally. Patches have been released, but the rapid weaponization indicates a significant risk for organizations that have not yet updated their systems.
Vulnerability · 2 sources · score 73 · CVE-2026-19490, CVE-2026-88771, CVE-2026-88772, Platypus, Slapshot
High Percentage of Critical Vulnerabilities Remain for Over 90 Days
Detectify's report reveals that 90% of critical and high-severity vulnerabilities across 1,300 organizations in the US, UK, and Nordics remain for over 90 days. The breakdown shows 97% in the Nordics, 92% in the UK, and 86% in the US. The report emphasizes that the longer vulnerabilities remain unaddressed, the more they are normalized within organizations, leading to a dangerous backlog. This situation is exacerbated by the rapid pace of software development and threat activity. Detectify's methodology confirms that these vulnerabilities are verified risks, not just false positives. Public sector organizations are particularly lagging, with only 8.3% of critical findings resolved within 90 days. The report suggests that organizational inertia and risk tolerance drift contribute to this issue, as teams may accept vulnerabilities as a norm without addressing them.
Vulnerability · 2 sources · score 68 · CVE-2026-88771
Threat actors and malware
China-Aligned TA419 Targets US AI Experts in Phishing Campaign
In July 2026, the China-aligned threat actor TA419 conducted credential phishing campaigns targeting AI policy experts in the U.S. by impersonating prominent figures, including Lynne Parker and Heidi Crebo-Rediker. The attackers sent benign emails inviting recipients to join a fictitious AI Policy Advisory Committee, which led to a multi-stage URL redirection to a credential phishing page designed to steal login credentials. This operation is part of a broader intelligence-gathering effort by China amid ongoing competition over AI technology. Proofpoint has tracked TA419's activities since April 2025, noting that the group has previously targeted individuals in U.S. and Japanese think tanks, defense contractors, and universities. The phishing method utilized a modified version of the Frameless BitB tool, which creates a deceptive login interface. The campaign's impact is still being assessed, with no confirmed account compromises reported.
APT · 20 sources · score 60 · TA419
New Linux Malware Mimics Asian Email Security Appliances
Researchers have uncovered sophisticated Linux malware that closely imitates Korean and Taiwanese network edge appliances, making detection challenging. The malware includes backdoors such as BPFdoor and Rekoobe, which disguise themselves as legitimate processes, specifically targeting the popular SpamSniper anti-spam software used by over 6,000 organizations. Another tool, AVERAT, is linked to attacks on Taiwanese mail security vendor ShareTech Information. These backdoors exploit TCP Port 25 to blend command-and-control traffic with normal email communications, complicating detection efforts. The campaigns are characterized by their advanced mimicry techniques, replicating filenames and operational habits of the legitimate software they impersonate. The threat landscape is particularly concerning for organizations in the Asia-Pacific region, where these appliances are prevalent. Current status indicates ongoing research and monitoring of these threats.
Malware · 2 sources · score 51 · BPFDoor, Rekoobe, SpamSniper, Korea Campaign, Taiwan Campaign
Also worth knowing
European Intelligence Warns of Espionage Risks from Connected Vehicles
European intelligence agencies, including the Dutch AIVD, have issued warnings about the security vulnerabilities of modern connected vehicles, which can potentially be exploited for espionage. The AIVD's notice advises against treating cars as private spaces due to risks of remote activation of microphones and cameras. Although the warning does not explicitly name China, it coincides with MI5's announcement regarding the China General Technology Research Institute's ties to Chinese intelligence. The AIVD urges users to avoid confidential conversations near their vehicles and to limit sensitive data entry into onboard systems. The warnings reflect broader concerns about data security and technological dependence on Chinese manufacturers as their electric vehicles gain market presence in Europe. The implications extend beyond vehicles to university partnerships and semiconductor research, highlighting a complex trade-off for European governments between security and economic interests.
Other Threats · 3 sources · score 60
New on leak sites
29 victims listed on ransomware leak sites by 20 groups in the 7 days before this issue. The most active:
Get the next one by email
The technology digest is free and arrives on Tuesdays. One click to leave.
Subscribe to the technology digest
A free account turns the digest into a personal watchlist: choose what you want to follow.