Weekly digest,
This week: Critical Citrix NetScaler Zero-Day Vulnerabilities… (+11 more)
Vulnerabilities
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited
In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, with a CVSS score of 9.5. Attackers utilized custom web shells named WHIPSHOT and SLAPSHOT to gain unauthorized access to affected systems. Organizations in sectors such as government, finance, and healthcare were particularly vulnerable. Citrix has since released patches for these vulnerabilities, but the urgency of the situation has raised concerns about the effectiveness of their response. The incidents highlight the ongoing risks associated with internet-exposed edge devices and the need for rapid incident response. As of October 4, 2026, the exploitation is confirmed to be ongoing, with significant operational and compliance risks reported.
Vulnerability · 9 sources · score 80 · CVE-2019-19781, CVE-2023-4966, CVE-2026-19489, CVE-2026-19490, CVE-2026-88771
Citrix Releases Emergency Patch for Exploited NetScaler Vulnerability
Citrix has issued emergency updates for a denial-of-service vulnerability in NetScaler, tracked as CVE-2026-88779, which is actively being exploited. The vulnerability, a memory buffer flaw, affects NetScaler ADC and Gateway appliances configured for SAML authentication. Citrix reported that targeted attacks have been observed, causing denial-of-service conditions on unmitigated deployments. The CVSS score for this vulnerability is 8.7, indicating a high risk. Affected versions include NetScaler ADC and Gateway 14.1 before 14.1-73.41 and 13.1 before 13.1-64.28. Citrix has also provided Global Deny Lists to block known malicious IP addresses. Organizations are urged to apply the patches immediately to mitigate risks. Some administrators have reported unexpected reboots of their appliances, raising concerns about potential remote code execution capabilities of the flaw.
Vulnerability · 3 sources · score 74 · CVE-2025-6543, CVE-2026-88779
Critical RCE Vulnerabilities in Gotenberg Exposed
Recent reports reveal critical unauthenticated remote code execution (RCE) vulnerabilities in Gotenberg versions 8.30.1 and earlier, specifically CVE-2026-40281 and CVE-2026-42589. These vulnerabilities allow attackers to inject commands via crafted metadata values sent to the /forms/pdfengines/metadata/write endpoint without requiring authentication. A proof-of-concept exploit was publicly released on October 2, 2026, enabling detection, single-command execution, and interactive shell access against vulnerable instances. Organizations using affected Gotenberg deployments are urged to upgrade to version 8.31.0 or later to mitigate these risks. The vulnerabilities were disclosed earlier this year, with CVE-2026-40281 receiving a CVSS score of 10.0, indicating a critical severity level. Both vulnerabilities exploit weaknesses in the metadata handling process of Gotenberg, which is a Docker-powered API for converting documents to PDF.
Vulnerability · 2 sources · score 70 · CVE-2026-40281, CVE-2026-42589
High Percentage of Critical Vulnerabilities Remain for Over 90 Days
Detectify's report reveals that 90% of critical and high-severity vulnerabilities across 1,300 organizations in the US, UK, and Nordics remain for over 90 days. The breakdown shows 97% in the Nordics, 92% in the UK, and 86% in the US. The report emphasizes that the longer vulnerabilities remain unaddressed, the more they are normalized within organizations, leading to a dangerous backlog. This situation is exacerbated by the rapid pace of software development and threat activity. Detectify's methodology confirms that these vulnerabilities are verified risks, not just false positives. Public sector organizations are particularly lagging, with only 8.3% of critical findings resolved within 90 days. The report suggests that organizational inertia and risk tolerance drift contribute to this issue, as teams may accept vulnerabilities as a norm without addressing them.
Vulnerability · 2 sources · score 68 · CVE-2026-88771
Critical GitLab AI Gateway Vulnerability Allows Command Execution
On October 2, 2026, GitLab disclosed a critical vulnerability (CVE-2026-90970) in its AI Gateway component, affecting self-hosted deployments with Duo AI features. The vulnerability, which has a CVSS score of 9.9, allows authenticated users with low privileges to execute arbitrary commands on the host by escaping a template sandbox via specially crafted flow configurations. GitLab has released patches in versions 19.2.4, 19.3.2, and 19.4.1, urging affected customers to upgrade immediately. There is currently no evidence of exploitation in the wild or public proof-of-concept code. The vulnerability is classified as CWE-1336, indicating improper neutralization of special elements in a template engine. Detection of potential exploitation involves monitoring unusual modifications to custom flows and unexpected process activity on the AI Gateway host.
Vulnerability · 2 sources · score 61 · CVE-2026-90970
US Air Force Withdraws Bombers Amid Terror Threat at RAF Fairford
All US Air Force bombers stationed at RAF Fairford have been withdrawn to the United States following a suspected terrorist threat linked to a security incident involving suspicious vehicles near the base. The alert was triggered by three suspicious vans observed near the perimeter, leading to the arrest of six individuals, including a dual UK-Iranian national. Counter Terrorism Policing is investigating potential foreign state involvement, particularly from Iran, amid heightened tensions in the region. No explosives were found in the vehicles, but petrol was discovered, raising concerns about possible attack preparations. The investigation remains complex, with authorities exploring multiple lines of inquiry. Prime Minister Andy Burnham indicated strong indications of Iranian involvement, while Israeli Prime Minister Netanyahu claimed Israel provided intelligence regarding the threat. The situation continues to evolve as authorities assess the implications for security at US military installations in the UK.
Vulnerability · 2 sources · score 60
CVE-2026-105123: Remote Code Execution in vincent-peugnet/wcms
A remote code execution vulnerability, CVE-2026-105123, has been identified in vincent-peugnet/wcms versions up to 3.18.0. This flaw allows authenticated editors to upload arbitrary files, including .php files, by exploiting an unvalidated path in the upload API. Attackers can also use encoded ../ sequences to write outside the media directory and delete files via a specific DELETE request. The risk is particularly high for internet-facing CMS instances with editor accounts, especially those with multiple contributors. The exploitation status remains unconfirmed, and no proof-of-concept (PoC) or exploitation in the wild has been reported yet. Administrators are urged to review upload API logs and restrict access to trusted networks. The vendor has released a fix, and immediate application is recommended to mitigate risks.
Vulnerability · 2 sources · score 58 · CVE-2026-105123
Ransomware
Slate Valley School District Declines Ransom Payment Amid Data Breach Threat
The Slate Valley Unified School District in Vermont experienced a ransomware attack in early September 2026, compromising personal information of over 1,500 teachers. The district's internet system was breached, leading to a demand for hundreds of thousands of dollars in ransom from the Kairos ransomware group. Superintendent Brooke Olsen-Farrell confirmed that the district's server was hacked, and the board voted on October 2 to decline the ransom payment. The hackers claimed to possess sensitive data, including Social Security numbers and addresses, threatening to leak it. The district is currently investigating the incident with assistance from the FBI and cybersecurity firms. As of October 2, the district has restored its internet services but has not confirmed whether any student data was compromised. The ongoing investigation aims to determine the extent of the breach and the identity of the attackers.
Ransomware · 2 sources · score 52 · Kairos Ransomware Group
Breaches
Bitget Hack Attributed to North Korean Actors: $387 Million Stolen
On September 24, 2026, the crypto exchange Bitget experienced a significant hack, resulting in the theft of approximately $387 million in various cryptocurrencies. The attack was attributed to North Korean-linked actors by Chainalysis, which noted that the stolen funds were transferred across 23 transactions within three hours. Initially estimated at $351.6 million, the total loss increased as more stolen assets were identified. The breach involved unauthorized transfers from Bitget's hot and warm wallets, with the attackers using techniques consistent with previous DPRK hacking incidents. Chainalysis developed AI tools to trace the stolen funds across multiple blockchains, significantly reducing the time needed for tracking from over 20 hours to under 10 minutes. This incident marks a continuation of North Korea's aggressive cyber theft strategy, which has reportedly exceeded $1 billion in crypto thefts for 2026 alone.
Breach · 2 sources · score 76
Threat actors and malware
China-Nexus UAT-11587 Uses Antino Backdoor for Cyber-Espionage
A newly identified cyber-espionage campaign attributed to the China-nexus group UAT-11587 is actively exploiting Microsoft 365 services, specifically Outlook and OneDrive, to deploy the Antino backdoor. This sophisticated attack targets government and policy organizations across Asia and the Middle East. The campaign utilizes multi-stage infection chains, including spear-phishing emails that deliver malicious payloads via trusted cloud services. The Antino backdoor, developed in Rust, allows for stealthy command-and-control operations by embedding malicious traffic within legitimate cloud activity. The threat actor employs advanced techniques such as DLL sideloading and social engineering to evade detection. Current mitigation strategies are being discussed to counteract this ongoing threat.
APT · 2 sources · score 78 · Cl-sta-0049, Earth Alux, Ink Dragon, Jewelbug, UNC6384
Bitget Suffers $388M Hack Attributed to North Korean Lazarus Group
On September 24, 2026, Bitget reported a significant security breach resulting in the theft of approximately $388 million from its hot and warm wallets. The attackers exploited a vulnerability in a third-party security product to gain internal access credentials and issued fraudulent withdrawal commands. Bitget's cold wallets remained secure, and private keys were not compromised. The incident has been linked to North Korea's Lazarus Group, known for previous cyberattacks. Following the breach, Bitget temporarily suspended withdrawals and has since resumed them in phases, with a protection fund covering customer losses. Investigations by security firms Mandiant and SlowMist are ongoing, focusing on the attack's methods and tracing the stolen funds, which have begun moving through various mixers and exchanges. As of October 1, 2026, some funds remain unspent, providing a target for ongoing investigations.
APT · 5 sources · score 76 · Lazarus Group
ShinyHunters Hacker Detained in Jordan, Assists FBI Investigation
Saif al-Din Khader, a suspected member of the ShinyHunters hacking group, was detained in Jordan this week and is reportedly cooperating with the FBI. The group claims to have stolen data on every FBI employee, including sensitive personal information. Khader is providing investigators with access to his electronic devices and digital communications to help identify other members of the group. The FBI has not confirmed the specifics of Khader's detention but continues to investigate the incident. This breach has drawn comparisons to the 2015 OPM hack, which exposed sensitive information of millions of Americans. The ShinyHunters group has faced disruptions, including the disappearance of their dark web site following the breach announcement. FBI Director Kash Patel has indicated that more arrests may follow Khader's detention, as the bureau actively pursues leads.
APT · 12 sources · score 55 · CVE-2026-35273, ShinyHunters, HellCat, Shinysp1d3r
New on leak sites
228 victims listed on ransomware leak sites by 47 groups in the 7 days before this issue. The most active:
Get the next one by email
The digest is free and arrives once a week. One click to leave.
A free account turns the digest into a personal watchlist: choose what you want to follow.