Why Should I Care? โ 2026-09-29 | ๐ด 1 HIGH ยท ๐ก 0 MEDIUM ยท ๐ต 20 RADAR ยท โช 100 FILTERED
๐ Briefing โ 2026-09-29
21 vendor intel items scanned | ๐ด 1 HIGH | ๐ก 0 MEDIUM | ๐ต 20 RADAR | โช 100 FILTERED
๐ด Critical โ action required:
- Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (CVE-2026-88771, CVE-2026-88772) โ Yes, if you run any version of NetScaler ADC or NetScaler Gateway: these vulnerabilities allow unauthenticated attackers to execute remote code or cause a denial of service.
Everything else can wait.
๐ต 15 items on the radar โ see below โ
Why Should I Care? ๐ด HIGH โ Handle Now
Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild
Palo Alto Unit 42 [CISA KEV] | CVSS 9.5 | CVE-2026-88771, CVE-2026-88772
โ Why Should I Care?
Yes, if you run any version of NetScaler ADC or NetScaler Gateway: these vulnerabilities allow unauthenticated attackers to execute remote code or cause a denial of service.
๐ฏ Affected versions: All versions of NetScaler ADC and NetScaler Gateway
๐ญ In plain English:
These vulnerabilities allow attackers to take control of your NetScaler devices or crash them, which can disrupt your network services. For example, an attacker could remotely execute commands to steal sensitive data or shut down your network.
๐ง Prerequisites:
- Unpatched NetScaler ADC or NetScaler Gateway devices
- No authentication required
โฑ Urgency: High urgency due to active exploitation in the wild, which can lead to full system compromise or service disruption.
๐ก Context: The vulnerabilities stem from improper input validation and memory handling in the NetScaler software.
Why Should I Care? ๐ก MEDIUM (0)
None.
Why Should I Care? ๐ต On the Radar (20)
- CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally (The Hacker News) โ Two critical vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited. These flaws can allow attackers to execute arbitrary commands or cause a denial of service.
- Times Car confirms data breach affecting 6.6 million user accounts (BleepingComputer) โ Times Car, a major Japanese car-sharing service, suffered a data breach affecting 6.6 million user accounts. Sensitive information like full names, addresses, and driver's license details were compromised. This impacts users' privacy and security.
- Japan's Keio confirms ransomware attack disrupted business systems (BleepingComputer) โ Keio Corporation, a major Japanese railway operator, was hit by a ransomware attack that disrupted some of its business systems, particularly affecting its hospitality division. This highlights the vulnerability of critical infrastructure to cyber attacks.
- Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M (The Hacker News) โ A hacker stole $388 million from Bitget by exploiting a flaw in a third-party security product. This shows that third-party security tools can have vulnerabilities that attackers can exploit, putting your systems at risk.
- Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent (The Hacker News) โ A new botnet, Carbonato, is targeting Docker daemons to deploy an AI agent called Hermes, which can execute tasks and collect credentials. This is a significant threat to any infrastructure using Docker without proper authentication.
- 80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking (BleepingComputer) โ Over 80,000 organizations have had their AI logins stolen, exposing sensitive data and potentially allowing attackers to act as employees. This affects major companies and can lead to data breaches, unauthorized access, and financial loss.
- JadePuffer agentic AI attacks target Azure, destroy cloud resources (BleepingComputer) โ JadePuffer, an AI-driven ransomware, is attacking Azure tenants by stealing credentials and destroying core components. This attack can disrupt your services and cause data loss.
- JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources (The Hacker News) โ A threat actor named JADEPUFFER used compromised service principals to delete Azure resources, including storage accounts, SQL databases, and more. This attack shows how critical it is to secure your service principals and monitor for unauthorized activity.
- CISA orders feds to patch exploited Citrix flaws by Wednesday (BleepingComputer) โ CISA has ordered U.S. government agencies to patch two critical Citrix NetScaler vulnerabilities by Wednesday to prevent remote code execution attacks. This affects all NetScaler ADC and Gateway deployments with default configurations.
- Misconfigured Supabase apps expose data in over 16,000 databases (BleepingComputer) โ Over 16,000 Supabase databases were found to be misconfigured, exposing sensitive data including PII, passwords, and auth tokens. This affects various industries and services, from valet services to government consulates.
- Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI (The Hacker News) โ AI agents are increasingly being used in production environments, but many organizations lack the proper controls to manage them effectively. This can lead to excessive access and security risks. The webinar offers practical guidance on how to govern AI agents and reduce these risks.
- โก Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats (The Hacker News) โ This week saw several cybersecurity threats, including Citrix vulnerabilities, a massive crypto hack, and placeholder domains being exploited. If you use Citrix products or have placeholder domains in your repositories, you're at risk.
- Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks (The Hacker News) โ NeedyMantis malware used in targeted intrusions.
- Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks (The Hacker News) โ Apple patches a CoreGraphics flaw.
- RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims (The Hacker News) โ News article reporting on a malware-as-a-service model for Android banking trojan RatHat.
โช 100 low-priority items filtered.
๐ฆ Aggregated and triaged by Donna AI | Sources: 8 vendor feeds | CISA KEV