Geek Guy

CVE-2026-88779: Citrix NetScaler Zero-Day Exploited Against SAML Deployments

Only days after Citrix addressed actively exploited NetScaler flaws CVE-2026-88771 and CVE-2026-88772, defenders faced another urgent security issue. A newly disclosed vulnerability tracked as CVE-2026-88779 has been exploited in targeted attacks against customer-managed NetScaler ADC and NetScaler Gateway appliances configured for SAML authentication. Citrix rates the vulnerability as high severity with a CVSS v4.0 score…

CVE-2026-104286: Critical FortiMail Zero-Day Exploited for Unauthenticated File Writes

Fortinet has disclosed a critical FortiMail zero-day vulnerability that attackers are already exploiting in the wild. Tracked as CVE-2026-104286 and rated 9.8 on the CVSS scale, the flaw enables an unauthenticated remote attacker to write arbitrary files to the underlying system by sending specially crafted HTTP or HTTPS requests. The vulnerability poses a significant risk…

Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users’ Mailboxes

Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system. “Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a

CISA flags new exploited NetScaler flaw as attackers crash appliances (CVE-2026-88779)

CISA has added another Citrix NetScaler vulnerability to its Known Exploited Vulnerabilities catalog on Sunday: CVE-2026-88779, a memory overflow bug that may cripple vulnerable NetScaler ADCs and Gateways. “Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service. If the condition is triggered repeatedly, the service may remain unavailable,”…

5th October – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 5th October, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Arizona’s state court system has suffered a phishing-led cyberattack after an employee clicked a malicious link. Attackers copied backup files containing protective-order records and more than 150,000 Foster Care Review Board reports…

LTM launches BlueVerse AgenTraceIQ to monitor AI agents and reverse unintended actions

LTM has announced the launch of BlueVerse AgenTraceIQ, an offering designed to help organizations securely adopt and scale agentic AI. Combining Rubrik Agent Cloud with LTM’s AI governance and managed services expertise, the offering enables organizations to monitor AI agents, establish guardrails, and rewind unintended agent actions across business-critical environments. As part of Rubrik’s Project…

U.S. CISA adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Citrix NetScaler flaw tracked as CVE-2026-88779 (CVSS score of 8.7), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Gateway…

Citrix warns of actively exploited NetScaler flaw days after zero-day patch rush

Citrix has warned customers about another high-severity vulnerability in its NetScaler ADC and NetScaler Gateway products, just days after the company urged them to fix a separate batch of flaws that included two actively exploited zero-days. The new vulnerability, tracked as CVE-2026-88779, is a memory-overflow issue that can cause a denial-of-service (DoS) condition on affected…

Deeper Network Promo Deeper Network Promo Deeper Network Promo Image

Introducing the New Small Business Cybersecurity Support Program Finder

For small businesses who are often confronted with limited resources, knowing how to get started and where to find support with planning, implementing, or evaluating a cybersecurity risk management strategy can be challenging — sometimes making cybersecurity feel like an insurmountable hurdle. However, there is good news. Many non-profit organizations across the United States have…

The Credential Layer Is Expanding Faster Than Security Teams Can See It

Every modern enterprise depends on credentials. This is how humans, systems, and now AI, all connect to data, services, and each other securely. GitGuardian helps secure that credential layer through three connected capabilities: Detect, Remediate, and Prevent. The journey starts with detection, because organizations first need to understand what credentials exist, where they live, and…

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. “Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel,” Nozomi Networks said in…

Out-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940)

Microsoft has pushed out an out-of-band security update for Exchange Server that fixes a high-severity vulnerability (CVE-2026-96940) that may allow authenticated attackers to read emails and attachments of other users in the same organization, but “does not allow access across tenant boundaries.” CVE-2026-96940 was discovered internally and, according to the Exchange Server Team, they “are…

DC Power Reshapes AI Data Center Infrastructure for Partners

AI infrastructure is reshaping more than the servers inside data center racks. As GPU-intensive workloads push rack densities higher, Eaton, NVIDIA, Google, Microsoft and others are advancing direct-current power architectures designed to deliver more power with fewer conversion stages and less physical infrastructure. For solution providers, integrators and infrastructure partners, that shift could broaden the…

Should the CISO role be split in two?

In its roughly 30-year history, the CISO role has been reshaped by waves of new technology and rising cyber threats. In many organizations, CISOs now own risk reporting, information risk management, threat monitoring, cyber risk accountability and governance, and security strategy. And as AI and digital dependence grow, the CISO’s remit is growing beyond security…

doxx.net opens Agentic Defined Networking public beta, raises $38 million

doxx.net has launched the open beta of its Agentic Defined Networking (ADN) platform, which lets people and their agents create their own private, secure networks, communicate with no servers in the middle, and get started with no personal information required. The platform gives agents an environment with defined connectivity and built-in threat protection, helping prevent…

A week in security (September 28 – October 4)

Last week on Malwarebytes Labs: Fake xStocks, Pendle, and other sites bait crypto users with rewards votes Shadow AI explained: The work shortcut that could leak your company’s secrets Convincing Free Mobile phishing emails appear after data breach Malwarebytes earns another Top Product award in independent testing Pentagon breach exposes Social Security numbers and military…

A week in security (September 28 – October 4)

Last week on Malwarebytes Labs: Fake xStocks, Pendle, and other sites bait crypto users with rewards votes Shadow AI explained: The work shortcut that could leak your company’s secrets Convincing Free Mobile phishing emails appear after data breach Malwarebytes earns another Top Product award in independent testing Pentagon breach exposes Social Security numbers and military…

Deeper Network Promo Deeper Network Promo Deeper Network Promo Image

New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

Citrix has released security updates for a high-severity security flaw in NetScaler ADC and Citrix NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0. “CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway…

SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 2

Security Affairs AI-CYBERSECURITY newsletter includes a collection of the best articles and research on AI in the international landscape Artificial intelligence is rapidly changing cybersecurity, reshaping both the techniques used by attackers and the tools available to defenders. AI agents can automate tasks, analyze large amounts of data, discover vulnerabilities and accelerate offensive operations. At…

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 117

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Lunex Unmasked: A New Information Stealer Deployed Through BYOVD   Storm-3168: Agentic-driven cloud attacks using compromised service principals   Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties  …

Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploited

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: 16-year-old researcher breaks into Microsoft analytics service with access to 17 trillion rows of data A flaw in Titan, an internal Microsoft analytics service, could have let an attacker read employee records and Bing search analytics, a 16-year-old security researcher…

Security Affairs newsletter Round 598 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Fake Zoom installer hides macOS backdoor CloudSyncD CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed Antino Backdoor Lets…

Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

Warlock ransomware continues to exploit unpatched SharePoint flaws to breach water utilities, telecoms, governments, and universities worldwide. Warlock ransomware made headlines back in mid-2025 for exploiting a chain of SharePoint zero-days collectively dubbed ToolShell. More than a year later, the same group is still using that door, and it’s still getting in. Symantec tracks the…