Search
Find merged stories by title or summary.
🏴☠️ N0n has just published a new victim : PayPal support operations (Transcom WorldWide)
Outsourced customer support / financial services • Netherlands / Tunisia • 86.7M connection records: daily support-agent sessions into PayPal corporate Citrix/AAA systems; Complete infrastructure map: internal AD, PKI, Netskope/Zscaler tenants, all 8 sites • All 8 sites are enforcing a network blackout until settlement. • [ACTIVE: deadline 2026-09-21 03:01 UTC]
Security Affairs newsletter Round 594 by Pierluigi Paganini – INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open Internet Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware UK Council Attack Linked to Mass Exploitation of SonicWall Flaw U. S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog More Capable AI, Not Enough Guardrails A New Claude ‘s Sandbox Failure Shows How AI Can Rationalize Real-World Harm U. S.
U.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : • CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability • CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability • CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability • CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-20079 (CVSS score of 10. 0) is an authentication bypass issue.
CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
The U. S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities are listed below - CVE-2026-20079 (CVSS score: 10.0) - An authentication
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability • CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability • CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability • CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.
CVE-2026-19490 - Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.
RMM-ber this ransomware. [Research Saturday]
Ismael Valenzuela , Vice President of Labs, Threat Research and Intelligence at Arctic Wolf , sits down with Dave to discuss their work tracking Anubis. Arctic Wolf Labs details a series of 2026 Anubis ransomware intrusions, revealing affiliates using stolen VPN credentials and exploiting CitrixBleed 2 to gain initial access. Attackers then blended into legitimate IT activity by deploying RMM tools, using RDP and PsExec for lateral movement, stealing credentials, and establishing tunnels and proxies for persistence and exfiltration. The research highlights a repeatable attack chain defenders can disrupt before encryption, from suspicious remote access and unauthorized RMM deployment to credential theft, security-tool tampering, and ransomware execution.
Critical Citrix NetScaler auth bypass now leveraged in attacks
Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. [... ]
Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Unpatched Zimbra servers are falling to CVE-2026-73570 attacks At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. AI supply chain risk is showing up in developer workflows first In this Help Net Security interview, Dr. Jaushin Lee, CEO of Zentera Systems, discusses where AI supply chain risk shows up. … More → The post Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited appeared first on Help Net Security .
U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Red Hat, Linux Kernel, Ajax. NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U. S.
CISA Warns of Citrix NetScaler ADC and Gateway Vulnerability Exploited in Attacks
The U. S. Cybersecurity and Infrastructure Security Agency has added a critical Citrix NetScaler ADC and NetScaler Gateway security flaw, tracked as CVE-2026-8452 , to its Known Exploited Vulnerabilities catalog after confirming exploitation in attacks. The vulnerability was added on August 26, 2026, and federal civilian executive branch agencies must apply the vendor-recommended mitigations by August 29, 2026. CISA’s listing signals that the issue presents an immediate operational risk, particularly for organizations that expose NetScaler appliances to the internet. CVE-2026-8452 is an improper restriction of operations within the bounds of a memory buffer vulnerability, classified as CWE-119. The flaw affects Citrix NetScaler ADC and NetScaler Gateway products. It can allow an unauthenticated attacker to trigger a denial-of-service condition.
Critical Citrix NetScaler Memory-Overflow Vulnerability
Citrix initially described it as capable of causing unpredictable behavior or denial-of-service conditions, while research by WatchTowr[1] demonstrated that it can potentially be exploited for unauthenticated remote code execution. For successful exploitation it must be a Citrix NetScaler running a vulnerable version and must be configured as either a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or a AAA virtual server. CVE CVE-2026-8452 Affected Products NetScaler ADC and NetScaler Gateway 14. 1 BEFORE 14. 1-72. 61 NetScaler ADC and NetScaler Gateway 13. 1 BEFORE 13. 1-63. 18 NetScaler ADC FIPS BEFORE 14. 1-72. 61 FIPS NetScaler ADC FIPS and NDcPP BEFORE 13. 1-37. 272 Exploitation CVE-2026-8452 has recently been added to the CISA database of known exploited vulnerabilities[2].
CISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix Products
CISA added six new bugs to its Known Exploited Vulnerabilities catalog on August 26, showing signs of active exploitation in the wild
Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452)
CISA added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a previously patched Citrix NetScaler ADC and Gateway flaw, tracked as CVE-2026-8452, that is being exploited in the wild. The agency published the alert on August 26 and gave federal agencies until August 29 to remediate it. About CVE-2026-8452 Citrix disclosed the issue on June 30, 2026, describing CVE-2026-8452 as a “memory overflow vulnerability leading to unpredictable or erroneous behavior and denial … More → The post Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452) appeared first on Help Net Security .
CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday
CISA has ordered U. S. government agencies to patch their Citrix NetScaler appliances against an actively exploited remote code execution vulnerability by Saturday. [... ]
CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
The U. S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2019-1068 - A remote code execution vulnerability in
Recent Citrix NetScaler Vulnerability Exploited in the Wild
CISA is urging government agencies to immediately patch the Citrix NetScaler vulnerability tracked as CVE-2026-8452. The post Recent Citrix NetScaler Vulnerability Exploited in the Wild appeared first on SecurityWeek .
CISA Adds Six Known Exploited Vulnerabilities to Catalog
CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability • CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability • CVE-2019-1068 Microsoft SQL Server Remote Code Execution Vulnerability • CVE-2021-23758 Ajax.NET Professional Deserialization of Untrusted Data Vulnerability • CVE-2022-0995 Linux Kernel Out-of-Bounds Write Vulnerability • CVE-2026-8452 Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
CVE-2026-8452 - Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.
Citrix UniconOS dual boot turns Windows endpoints into their own recovery device
Citrix announced Citrix UniconOS dual boot, a new endpoint resiliency capability designed to help organizations recover access to work in minutes — without spare hardware, central reimaging or prolonged business downtime. Available now as part of Citrix UniconOS Release 7 2607, dual boot turns every compatible Windows endpoint into its own recovery device: an isolated, hardened Citrix UniconOS environment that runs alongside Windows on the device and can reconnect users to their applications via Citrix … More → The post Citrix UniconOS dual boot turns Windows endpoints into their own recovery device appeared first on Help Net Security .
Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)
Citrix has patched two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw tracked as CVE-2026-19490, and is urging customers to upgrade affected appliances as soon as possible. “We strongly recommend that customers review the official NetScaler ADC and NetScaler Gateway security bulletin, assess whether their deployments are affected, and upgrade impacted appliances to the recommended builds as soon as possible,” Anil Shetty, senior VP of Engineering with Cloud Software Group … More → The post Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490) appeared first on Help Net Security .
The robots have gone bananas.
Federal agencies warn of an active campaign targeting critical infrastructure. Citrix races to patch critical NetScaler flaws. More than 50,000 exposed Stripe API keys raise fraud concerns. Black Hat and DEF CON attendees are targeted in a new social engineering campaign. Atlassian, Splunk, and Cisco fix hundreds of vulnerabilities. A new Android banking trojan adds an unusual twist. A healthcare breach impacts 3. 8 million people. SilkParasite expands cyberespionage in Central Asia. And CISA eyes a major overhaul of federal cyber software procurement. Our guest is Chris Wallis, founder and CEO of Intruder, on how AI agents killed the annual pentest and are reshaping exposure management. AI powered robots find bananas quite appealing. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode?
Citrix issues critical security updates for its NetScaler devices
Citrix is urging its NetScaler ADC and NetScaler Gateway customers to quickly patch two critical security holes, one involving a memory overflow vulnerability leading to unpredictable behavior or denial of service, and the other allowing authentication bypass. Citrix said in an advisory that supported versions of customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds, as well as SecurAccess ZTNA Hybrid (formerly Secure Private Access Hybrid) deployments that use customer-managed NetScaler instances, are affected. Citrix-managed cloud services and Citrix-managed Adaptive Authentication have already been updated. However, it added, “at this point [August 19] the NetScaler images available on cloud marketplaces (AWS, Azure, GCP) have not been updated.
Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability. According to the cloud computing and virtualization technology company, the issues affect customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds, as well as SecurAccess
Citrix urges admins to patch new NetScaler flaws as soon as possible
Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances. [... ]
Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler
Remote, unauthenticated attackers could exploit the critical-severity flaw without user interaction. The post Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler appeared first on SecurityWeek .
Citrix security advisory (AV26-833)
Serial Number: AV26-833 Date: August 19, 2026 As of August 19, 2026, NetScaler is affected by vulnerabilities in the following products: • NetScaler ADC and NetScaler • Version 13.1 prior to or equal to 13.1-63.21 • Version 14.1 prior to or equal to 14.1-73.32 • NetScaler ADC FIPS • Prior to 14.1-73.32 FIPS • NetScaler ADC FIPS and NDcPP • Prior to 13.1-37.277 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. • NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490 • Citrix Security Advisories Citrix security advisory (AV26-833) - Canadian Centre for Cyber Security
Critical Citrix NetScaler Flaw Lets Remote Attackers Bypass Authentication Without Credentials
Cloud Software Group has issued a critical security bulletin warning customers of two serious vulnerabilities affecting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). Tracked as CVE-2026-19489 and CVE-2026-19490, the flaws could allow attackers to trigger denial-of-service conditions or bypass authentication entirely on unpatched appliances, putting enterprise remote access infrastructure at significant risk. Critical Citrix NetScaler Vulnerability The more severe of the two, CVE-2026-19490, carries a CVSS v4. 0 base score of 9. 3 and is classified under CWE-288, Authentication Bypass Using an Alternate Path. This flaw allows an attacker to circumvent authentication controls on NetScaler appliances configured as a Gateway for SSL VPN, ICA Proxy, CVPN, or RDP Proxy, or as an AAA virtual server.
CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
Overview On August 19, 2026, a security advisory was published for CVE-2026-19490 , a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4. 0 base score of 9. 3 and can be exploited remotely by an unauthenticated attacker over the network without user interaction or elevated privileges. NetScaler ADC and NetScaler Gateway are widely deployed enterprise networking products commonly positioned at or near the network perimeter. NetScaler ADC provides application delivery, traffic management, load balancing, SSL/TLS offloading, and application security capabilities, while NetScaler Gateway provides secure remote access and VPN functionality.
Citrix NetScaler Heap Overflow Flaw Lets Remote Attackers Execute Code as Root – PoC Released
A working proof-of-concept (PoC) exploit demonstrating how a pre-authentication heap overflow in Citrix NetScaler ADC and NetScaler Gateway can be turned into unauthenticated root-level remote code execution (RCE). The vulnerability was originally addressed in Cloud Software Group’s June 30 security bulletin CTX696604, where Citrix described CVE-2026-8452 as a memory overflow that could result in denial-of-service (DoS) or “unpredictable behavior.” However, independent analysis confirms that the flaw is far more severe, granting remote attackers direct control over the core packet-processing engine that runs with root privileges. Addressing recurring Citrix NetScaler vulnerabilities remains essential for securing enterprise perimeter infrastructure.
Citrix expands Platform Flex with observability and secure developer services
Citrix has announced new services for Citrix Platform Flex, extending its flexible credit model with additional options for delivering, monitoring and securing digital work environments. The new offerings include Citrix Experience Insights Flex, a Citrix-managed observability service powered by Splunk Cloud Platform that turns high-resolution workspace telemetry into operational insights, and Citrix SecurSpaces Flex, a hosted cloud platform for code development and agentic workloads that provides secure development environments without requiring enterprises to build and … More → The post Citrix expands Platform Flex with observability and secure developer services appeared first on Help Net Security .
CitrixBleed 2 (CVE-2025-5777) 7Steps to Dragonforce Ransomware | Huntress
Huntress has observed a series of strikingly similar intrusions beginning with CitrixBleed 2 exploitation, employing novel local privilege escalation techniques, and ending in Dragonforce ransomware.
The AI lock comes off.
The US restores exports of Anthropic’s most advanced AI models. Adobe and Citrix rush out critical patches. RustDuck emerges as a fast-evolving DDoS threat. The Gentlemen raise the stakes with a new EDR-killing exploit. Rocket lab bets big on Iridium. Researchers unveil browser-only ransomware. New Zealand faces questions about its cyber readiness. Iran’s long-running cyber espionage campaign is back in the spotlight. Our guest is Donald Codling, CISO and senior advisor to REGO on cybersecurity and data privacy matters, to discuss the importance of tying security by design to psychological safety and digital trust. VIP backstage access, courtesy of Claude. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing , and you’ll never miss a beat .
Water sector feels the pressure.
Iranian-linked hackers warn of possible “irreparable” attacks on U. S. water systems. CISA pushes urgent fixes for a critical Citrix flaw. The Dutch Finance Ministry takes systems offline after a breach. Space Force may scrap next-gen GPS control software. Attackers exploit a Fortinet server bug. Lloyds exposes customer transaction data. AI and regulation reshape cyber careers. The FTC settles with a dating app over data sharing. Sam Rubin, SVP, Palo Alto Networks Unit 42 Consulting and Threat Intelligence, discusses Iran's shift to identity weaponization. Wikipedia wrestles with a wayward writer. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing , and you’ll never miss a beat . And be sure to follow CyberWire Daily on LinkedIn .
Inbox intrusion hits FBI chief.
Iran-linked hackers claim a breach of the FBI director’s personal email. ShinyHunters hit the European Commission. F5 and Citrix warn of actively exploited flaws. A WordPress plugin exposes hundreds of thousands of sites. Infinity Stealer targets macOS users. A Russian APT adopts a new iOS exploit kit. Treasury weighs a cyber insurance backstop. DHS clears suspended CISA staff. Our guest is Brian Long, CEO and Co-Founder of Adaptive Security, discussing deepfake job hires and the new identity attack surface. Bureaucrats bless a black-box behemoth. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing , and you’ll never miss a beat . And be sure to follow CyberWire Daily on LinkedIn .
You've reached the end of current stories for this search.
