
Exploited NetScaler Zero-Days, AI Agent Safety, And Cloud Updates
Coverage: 28 Sept 2026 (UTC)
< view all daily briefs >Urgent security fixes for widely deployed network appliances dominated the day, alongside a wave of measures aimed at governing autonomous AI systems and strengthening cloud resilience. Vendors introduced new safeguards for agentic AI, while hyperscalers rolled out model updates, data‑protection features, and infrastructure lifecycle clarity. Separately, investigators detailed an AI‑driven cloud attack and a major crypto theft, underscoring the need for rapid patching, rigorous governance, and tested recovery plans.
Patch Now: NetScaler Zero‑Days Exploited
Citrix customers running NetScaler ADC and NetScaler Gateway face active exploitation of two critical flaws, with patches now available and urgent remediation advised, according to CSO. CVE-2026-88771 (CVSS 9.5) is an unauthenticated remote code execution issue stemming from improper input validation that affects all deployments, including default configurations. CVE-2026-88772 (CVSS 9.5) is a memory overflow that can enable remote code execution or denial of service when DTLS is enabled, which is the default on many VPN virtual servers. Citrix issued fixes across supported 14.1 and 13.1 builds (including FIPS and NDcPP variants) and provided generic indicators of compromise via the NetScaler Console to help assess exposure; CISA has added both CVEs to its KEV catalog. The advisory also addresses six additional issues whose impact varies by configuration: HTTP request smuggling (CVE-2026-88773, 9.3), a URL-handling feature-policy bypass (CVE-2026-88774, 7.0), three memory overflows (CVE-2026-88775/76/77, each 8.8), and a TCP ISN prediction weakness (CVE-2026-88778, 8.8) that can be mitigated by enabling Enhanced ISN Generation. Organizations using NetScaler for VPN, remote access, or application delivery are advised to apply patches immediately and consider isolating affected appliances while performing compromise assessments.
Governing Autonomous AI Agents
NVIDIA introduced the Open Agent Safety Platform to address risks from autonomous AI agents that can bypass application‑layer controls, pairing the open‑source OpenShell runtime with an optional hardware enforcement layer called Sentry, per InfoSecurity. OpenShell traces agent actions, enforces policies, and controls access to systems, data, and services with sandboxed execution, kernel‑level controls, and credential management. Sentry leverages BlueField‑4 DPUs as an out‑of‑band watchdog in an isolated trust domain, able to quarantine or stop agents within milliseconds when policy limits are exceeded. NVIDIA says OpenShell can extend to third‑party compute platforms, and more than 100 organizations are engaging with the initiative.
Palo Alto Networks and NVIDIA outlined a reference design to enforce Zero Trust for agentic AI across the stack, combining NVIDIA’s accelerated computing and BlueField DPUs with governance and runtime controls in Prisma AIRS, according to Palo Alto. Prisma AIRS AI Gateway verifies agent identities, enforces least‑privilege access, redacts sensitive data, and blocks unauthorized actions before they reach hosts or cloud endpoints, while an AI Runtime firewall running on BlueField creates a tamper‑resistant boundary for AI factory and edge traffic. Future plans include integrating OpenShell with IDIRA’s Agent Identity Security to reduce standing credentials and prevent privilege escalation.
Threat activity shows the stakes of unmanaged autonomy: Microsoft-tracked campaign Storm‑3168, dubbed JadePuffer, used agentic AI to automate reconnaissance, credential theft, lateral movement, and destructive actions across Azure tenants in minutes, as reported by BleepingComputer. Operators leveraged compromised service principals for discovery and destructive operations, attempting to delete over 100 Storage accounts and other resources, while also removing recovery protections. Recommended mitigations include scanning for exposed secrets, enforcing least‑privilege RBAC, reviewing service principal usage, and enabling cloud workload protections.
New Frontier Models on AWS
AWS Bedrock added support for SpaceXAI Grok 4.7, a frontier model tuned for coding, agentic workflows, and general knowledge work. Enhancements over prior versions include improved handling of mixed documents, more reliable repository‑scale coding via integrated planning and error recovery, and better browser‑agent behaviors for form completion and portal navigation. The model is offered with US Geo and Global cross‑Region inference options and can be accessed via the Bedrock console or APIs.
AWS Sonnet 5.5 is now available, delivering faster performance and lower cost per task for coding and knowledge work versus previous versions. Access is offered through two paths: Amazon Bedrock for integrated governance controls such as Guardrails and Knowledge Bases with regional data residency, and the Claude Platform on AWS, which provides Anthropic’s native console and APIs with AWS billing and authentication.
GovCloud Sonnet 5.5 is also available in AWS GovCloud (US), bringing upgraded model capabilities to customers with sensitive or regulated workloads. Delivery through Amazon Bedrock helps maintain data within AWS infrastructure while layering operational controls to support compliant use.
Cloud Resilience and Platform Updates
To demonstrate the independence of its European sovereign operations, AWS Sovereign Cloud will conduct a controlled exercise on October 24, disconnecting the sovereign region from the AWS Global Network backbone and routing operations over European ISP links. An EU‑resident operational team will use only in‑EU hardware and software while disabling systems that normally handle limited transfers of AWS operational data. AWS anticipates no service availability impact within the sovereign cloud and plans to share results with regulators and customers.
AWS Backup added logically air‑gapped vault support for Amazon FSx for NetApp ONTAP, enabling immutable, encrypted backups that can be stored in the same or different accounts and Regions with AWS‑owned or customer‑managed keys. In parallel, DocumentDB 8.0.2 expanded MongoDB API compatibility and resiliency with retryable writes, five additional aggregation stages, enhanced change streams (including large‑event splitting and DDL visibility), and query planner optimizations for lower latency and resource usage.
Microsoft formalized its Azure blog Virtual Machine lifecycle policy across VM families, defining Current, Extended, End of Life, and Retired stages with recommendations, availability and quota expectations, and purchasing implications. The policy is paired with tooling such as Azure Advisor and Service Health, with AI‑augmented modernization assistance to improve migration planning and execution.
Google Cloud’s storage‑optimized Z4D machine family is generally available for Compute Engine VMs, with bare‑metal instances in preview, according to Google Cloud. Powered by 5th Gen AMD EPYC processors and Titanium SSDs, Z4D offers up to 384 vCPUs, 3,072 GiB RAM, and as much as 84,000 GiB of local SSD, targeting IO‑intensive workloads like databases, vector stores, analytics, and distributed file systems. Google cites up to 40% higher throughput than prior Z3 instances, with doubled network throughput up to 400 Gbps; bare‑metal options remove the hypervisor layer for lower latency and support custom hypervisors and licensing needs.