Overview
Description
Statistics
- 29 Posts
- 110 Interactions
Fediverse
Technical write up of the latest Citrix Netscaler incident, which I’m calling PitScaler - you’ll find out why from this:
https://www.cert.europa.eu/blog/taking-execute-logging-a-bit-too-literally-cve-2026-88771
You may notice it matches the hunting hints earlier in this thread. Guess who found it first :annoyingdog:
It’s a really interesting vuln scenario. I’m tracking over 100 victim orgs now. Each one has a unique webshell which can’t be scanned for remotely unless you’re the attacker. It’s espionage.
Ah Citrix. My favourite VM access app….bane of my professional life.
(How are they even still in business???)
A timeline of Citrix NetScaler CVE-2026-88771, from the CVE reservation on Sep 10 to public disclosure on Sep 27, including the exploitation attempts GreyNoise observed on Sep 24.
🔗 Full analysis: https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation
CVE-2026-88771: Detection Artifact Generator for Citrix NetScaler
GitHub: https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88771
CVE-2026-88771 is a Citrix NetScaler command injection exploited in the wild. Details and a PoC are public. Patch NetScaler to 14.1-73.37 now.
#Citrix #NetScaler #CVE202688771 #CommandInjection #ZeroDay #ExploitedInTheWild #PoC #PatchNow
(CISA TS+SOC) CVE-2026-88771 – Citrix NetScaler Input Validation RCE Briefing
Active exploitation of CVE-2026-88771 in Citrix NetScaler requires immediate patch deployment and forensic triage. Review integrated TSUITE + SOC intelligence assets....
Citrix says attackers are exploiting two critical NetScaler flaws. CVE-2026-88771 allows unauthenticated command execution and affects default configurations. CVE-2026-88772 can lead to remote code execution or denial of service when DTLS is enabled.
Both score 9.5 under CVSS 4.0. If you manage NetScaler, identify affected appliances and install the fixed builds.
https://support.citrix.com/external/article/CTX697096
#Cybersecurity #NetScaler #Citrix
Mandiant and Google Threat Intelligence Group describe in-the-wild exploitation CVE-2026-88771 and CVE-2026-88772 against Citrix NetScaler ADC and NetScaler Gateway appliances globally. Indicators of compromise and YARA rules are included.
📰 Citrix Patches Two Critical NetScaler Zero-Days Under Active Attack
Critical Alert: Two Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) are under active global attack. Flaws allow unauthenticated RCE. CISA KEV listed. Patch and hunt for compromise now! #Citrix #NetScaler #CyberSecurity #CVE
Two critical Citrix NetScaler zero-day flaws, rated 9.5 on CVSS 4.0, are under attack. See the fixed builds and how to respond.
#Citrix #NetScaler #ZeroDay #CVE202688771 #CVE202688772 #RCE #VPN #CISAKEV
https://meterpreter.org/citrix-netscaler-zero-day/?utm_source=mastodon&utm_medium=jetpack_social
Recent global developments highlight escalating cybersecurity risks and geopolitical tensions. AI-powered attacks are rapidly exploiting vulnerabilities, with threat actors leveraging agentic workflows for credential harvesting. In response, Nvidia has launched its Open Agent Safety Platform to manage rogue AI agents. Meanwhile, CISA has issued a critical warning regarding actively exploited Citrix NetScaler zero-day flaws (CVE-2026-88771, CVE-2026-88772).
On the geopolitical front, a new US-Saudi civilian nuclear pact has raised significant proliferation concerns, as Saudi Arabia has not ruled out developing nuclear weapons.
🚨RAPID RESPONSE: Two critical Citrix NetScaler vulnerabilities are being actively exploited as zero-days.
CVE-2026-88771 and CVE-2026-88772 can each lead to remote code execution.
Censys currently observes 42,735 Internet-exposed NetScaler ADC or Gateway hosts. Censys ARC breaks down the exposed population, exploitation status, patches, and guidance for defenders.
Read the advisory: https://censys.com/advisory/cve-2026-10747-2/
#Cybersecurity #Citrix #NetScaler #VulnerabilityManagement #CensysARC
Bluesky
Overview
Description
Statistics
- 28 Posts
- 35 Interactions
Fediverse
We've been continuously updating this post with the latest information—now including details on exploitation of CVE-2026-88772. And all relevant indicators have been added to our MISP feed.
https://ifin.network/t/multiple-citrix-netscaler-0-days-exploited/867
Citrix shenanigans from @watchTowr
We had first POC yes, but what about second POC? watchTowr breaks down CVE-2026-88772 and provides a "detection artifact generator"
Citrix says attackers are exploiting two critical NetScaler flaws. CVE-2026-88771 allows unauthenticated command execution and affects default configurations. CVE-2026-88772 can lead to remote code execution or denial of service when DTLS is enabled.
Both score 9.5 under CVSS 4.0. If you manage NetScaler, identify affected appliances and install the fixed builds.
https://support.citrix.com/external/article/CTX697096
#Cybersecurity #NetScaler #Citrix
Mandiant and Google Threat Intelligence Group describe in-the-wild exploitation CVE-2026-88771 and CVE-2026-88772 against Citrix NetScaler ADC and NetScaler Gateway appliances globally. Indicators of compromise and YARA rules are included.
📰 Citrix Patches Two Critical NetScaler Zero-Days Under Active Attack
Critical Alert: Two Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) are under active global attack. Flaws allow unauthenticated RCE. CISA KEV listed. Patch and hunt for compromise now! #Citrix #NetScaler #CyberSecurity #CVE
Two critical Citrix NetScaler zero-day flaws, rated 9.5 on CVSS 4.0, are under attack. See the fixed builds and how to respond.
#Citrix #NetScaler #ZeroDay #CVE202688771 #CVE202688772 #RCE #VPN #CISAKEV
https://meterpreter.org/citrix-netscaler-zero-day/?utm_source=mastodon&utm_medium=jetpack_social
Recent global developments highlight escalating cybersecurity risks and geopolitical tensions. AI-powered attacks are rapidly exploiting vulnerabilities, with threat actors leveraging agentic workflows for credential harvesting. In response, Nvidia has launched its Open Agent Safety Platform to manage rogue AI agents. Meanwhile, CISA has issued a critical warning regarding actively exploited Citrix NetScaler zero-day flaws (CVE-2026-88771, CVE-2026-88772).
On the geopolitical front, a new US-Saudi civilian nuclear pact has raised significant proliferation concerns, as Saudi Arabia has not ruled out developing nuclear weapons.
🚨RAPID RESPONSE: Two critical Citrix NetScaler vulnerabilities are being actively exploited as zero-days.
CVE-2026-88771 and CVE-2026-88772 can each lead to remote code execution.
Censys currently observes 42,735 Internet-exposed NetScaler ADC or Gateway hosts. Censys ARC breaks down the exposed population, exploitation status, patches, and guidance for defenders.
Read the advisory: https://censys.com/advisory/cve-2026-10747-2/
#Cybersecurity #Citrix #NetScaler #VulnerabilityManagement #CensysARC
Bluesky
Overview
Description
Statistics
- 15 Posts
- 13 Interactions
Fediverse
Apple Notfall-Update
Apple veröffentlicht Notfall-Flicken für sämtliche Systeme. In den neueren (27) werden "nur" zwei Fehler behoben, die mit dem Update-Paket vor zwei Wochen eingeführt wurden (ja, nicht nur Microsoft - Apple kann das auch). Dringender sind die Updates für alle älteren Systeme. In denen steckt die Sicherheittslücke CVE-2026-86950 im Grafiksystem, die bereits für Angriffe ausgenutzt wird (Zero-Day). Die Schwachstelle entsteht dadurch, dass passend präparierte Dateien jenseits der vorgesehenen Grenzen in den Arbeitsspeicher schreiben können. Da hatte wohl jemand bei der Programmierung "vergessen", eine entsprechende Prüfung einzubauen. Alle ... Weiterlesen:
https://www.pc-fluesterer.info/wordpress/2026/09/29/apple-notfall-update-3/
#0day #apple #cybercrime #exploits #sicherheit #spionage #UnplugApple #UnplugTrump #zeroday
Apple released updates to patch a zero-day vulnerability tracked as CVE-2026-86950 linked to an extremely sophisticated attack.
Source: SecurityWeek
https://www.securityweek.com/apple-patches-meta-reported-zero-day-linked-to-extremely-sophisticated-attack/
Apple patched an exploited Apple zero-day vulnerability. Learn how this Apple zero-day vulnerability impacts devices and install emergency updates now.
#Apple #iOS #macOS #CVE202686950 #ZeroDay #Cybersecurity #InfoSec
Learn about the critical CVE-2026-86950 zero-day vulnerability patched in iOS 26.7.1. Discover how this CoreGraphics flaw could lead to malicious code execution.
Apple kiadott frissítést egy CoreGraphics-ben lévő CVE-2026-86950 out-of-bounds memóriaírás hibára, amit célzott támadásoknál kihasználhattak. Mely eszközeid érintettek; telepítetted már a javítást? Ne halogasd, olvasd el a részleteket:
https://linuxmint.hu/hir/2026/09/celzott-tamadasban-is-kihasznalhattak-az-apple-serulekenyseget
#Apple #iOS #iPadOS #macOS #CVE-2026-86950 #CoreGraphics #sebezhetőség #biztonságifrissítés #kibervédelem #NKI
‼️ Apple patched a new CoreGraphics flaw that may have been exploited in targeted iOS attacks.
CVE-2026-86950 can trigger arbitrary code execution when a maliciously crafted file is processed. Fixes are available for affected older iOS, iPadOS, and macOS releases.
Read: https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html
Apple Patches CoreGraphics Zero-Day Linked to Sophisticated Targeted Attacks
Bluesky
Overview
Description
Statistics
- 5 Posts
- 2 Interactions
Fediverse
ShinyHunters PeopleSoft attacks are back. A one-letter WAF bypass lets the group exploit CVE-2026-35273 and plant web shells on unpatched servers.
#ShinyHunters #PeopleSoft #WAFBypass #CVE202635273 #UNC6240 #Oracle #DataExtortion #CyberSecurity
Discover how ShinyHunters uses URL encoding to bypass WAF defenses, aggressively exploiting the critical CVE-2026-35273 Oracle PeopleSoft vulnerability.
#ShinyHunters #OraclePeopleSoft #WAFBypass #CyberSecurity #ZeroDay
Bluesky
Overview
Description
Statistics
- 4 Posts
Fediverse
Tracked as CVE-2026-20700, this flaw stems from an out-of-bounds write weakness discovered by Meta Product Security in CoreGraphics. https://www.bleepingcomputer.com/news/security/apple-patches-coregraphics-zero-day-flaw-exploited-in-attacks/
Bluesky
Overview
Description
Statistics
- 2 Posts
- 8 Interactions
Fediverse
Podman 6.1.3 and v5.8.8 have both been released and are making their way to Fedora and other distros. These releases address CVE-2026-94603. Details: https://github.com/podman-container-tools/podman/releases/tag/v6.1.3, https://github.com/podman-container-tools/podman/releases/tag/v5.8.8 #podman #opensource
Overview
Description
Statistics
- 2 Posts
Fediverse
https://ptswarm.com/blog/cve-2026-43783-repair-permissions-get-root-lpe-via-desktopserviceshelper-in-macos-26-5/
Overview
Description
Statistics
- 2 Posts
Fediverse
A critical MikroTik RouterOS vulnerability, CVE-2026-84411 (CVSS 9.8), lets unauthenticated attackers run code as root. Update RouterOS now.
#MikroTik #RouterOS #CVE202684411 #RCE #NetworkSecurity #CISA #RouterSecurity #PatchNow
Overview
Description
Statistics
- 2 Posts
Bluesky
Overview
- Python Software Foundation
- CPython
Description
Statistics
- 2 Posts
- 7 Interactions