⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests

⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests

A vacant field. An open repository. A single response to an email. An unprotected box. None of these scenarios seem particularly alarming, which is part of the issue. This week’s threats continue to exploit minor details that are often easily missed.

There are vulnerabilities currently being exploited, more streamlined intrusion methods, advanced automation, and a lengthy list of patches awaiting attention. Some attacks are becoming increasingly sophisticated, while others are still succeeding due to basic security measures being compromised first.

Here’s what was significant this week.

⚡ Threat of the Week

Citrix Issues Warning About Newly Exploited NetScaler ADC and Gateway Vulnerability — Citrix has issued security updates for a critical vulnerability in NetScaler ADC and NetScaler Gateway that has been targeted in zero-day attacks. The flaw, identified as CVE-2026-88779, has a CVSS score of 8.7 out of 10.0. According to Citrix, “CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can result in denial-of-service under certain deployment conditions.” The issue impacts customer-managed NetScaler deployments running affected supported versions when specific preconditions are met. Successful exploitation necessitates that NetScaler ADC or NetScaler Gateway be set up as either a SAML service provider (SP) or SAML identity provider (IdP).

How Headspace Centralized AI Governance Across Teams

Many teams find themselves having to choose between speed and control. However, Headspace has discovered a method to achieve both. Learn how Chris Oh, Senior Director of AI Enablement at Headspace, provides the organization with the flexibility to innovate while ensuring complete oversight of what is operational and who is responsible for it.

Watch the On-Demand Webinar Here ➝

🔔 Top News

– Critical FortiMail Zero-Day Vulnerability Under Attack — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has alerted about the active exploitation of a severe security flaw affecting Fortinet FortiMail. The vulnerability, CVE-2026-104286 (CVSS score: 9.8), permits unauthenticated attackers to write arbitrary files on the underlying system. Fortinet stated that the vulnerability “may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.”

– Two Members of ShinyHunters Arrested — Law enforcement has detained two individuals linked to the ShinyHunters digital extortion group. One is a 24-year-old man from Amsterdam, believed to be Pepijn van der Stap, while the other, Saif al-Din Khader, was reportedly arrested by Jordanian authorities last week. ShinyHunters has gained notoriety recently for taking over the darknet site of Cl0p and for hacking the FBI’s

Source: Original article

Leave a Reply

Your email address will not be published. Required fields are marked *

Back To Top