< ciso
brief />
Tag Banner

All news with #active exploitation tag

912 articles · page 2 of 46

Proof‑of‑Concept for Apple CoreGraphics Flaw Published

🛡️ Researchers published a public proof‑of‑concept for CVE‑2026‑86950, an Apple CoreGraphics vulnerability Apple says may have been used in targeted attacks. The trigger is a malicious PDF with a crafted embedded font that causes a crash on unpatched iPhones and Macs, though the published code demonstrates a crash, not full code execution. Apple patched the flaw on September 28 after crediting Meta Product Security, and CISA added it to its Known Exploited Vulnerabilities catalog with a federal remediation deadline of October 2.
read more →

Citrix NetScaler exploitation drops web shells, steals configs

🛡️ LevelBlue observed threat actors exploiting a critical pre-auth command injection in Citrix NetScaler ADC and NetScaler Gateway to deploy web shells and exfiltrate configuration data. The activity weaponizes CVE-2026-88771 and included attacker-supplied authentication strings, payload retrieval via curl/wget, and second-stage scripts that establish reverse shells, create privileged accounts, and upload archived configs. The incidents follow recent disclosures of CVE-2026-88771 and CVE-2026-88772 amid active exploitation reports.
read more →

Zimbra RCE Exploited to Deploy Web Shells and Steal Mail

🛡️ Microsoft found threat actors exploiting CVE-2026-73570 in Zimbra Collaboration Suite to deploy JSP web shells, establish reverse shells, escalate privileges, and exfiltrate mailbox data. The unauthenticated command injection flaw affected systems with SNMP notifications enabled and the optional zimbra-snmp package installed, and was patched in Zimbra 10.1.20 in July 2026. Attackers used varied persistence and lateral-movement techniques, including systemd services, cron jobs, SSH identity reuse, and custom Go-based tooling to harvest credentials and export mailbox databases. Organizations are urged to patch, remove the zimbra-snmp package if necessary, restrict SNMP/SMTP access, rotate secrets, and hunt for web shells and other artifacts.
read more →

Critical Cisco SD‑WAN Manager Zero‑Day Alert

🛡️ Cisco warned on September 30 that attackers are actively exploiting a critical zero‑day, CVE‑2026‑76504, in Catalyst SD‑WAN Manager that allows unauthenticated API access as the admin user. The flaw, tied to mishandled URI encoding in session login requests, scored 9.8/10 and has fixed releases available across affected release trains. Cisco confirmed active exploitation and advised upgrades; no workaround exists and internet‑exposed Managers are at highest risk.
read more →

Cisco warns of SD‑WAN authentication bypass zero‑day

🔒 Cisco released updates to address a critical zero-day in the Catalyst SD-WAN Manager (CVE-2026-76504) that is being actively exploited to gain admin privileges. The flaw affects API session-based authentication and allows unauthenticated remote access by bypassing an authentication rule via improper URI encoding. Cisco published IOCs and log locations for detection and urged customers to upgrade to fixed releases or open TAC cases for investigation. Multiple fixed releases are listed for affected versions.
read more →

Vulnerability Discovery and Exploitation Trends in AI Era

🔍 Google Threat Intelligence Group analyzes CVE disclosure and exploitation data from January 2025 through August 2026 to assess AI's impact on vulnerability trends. The report finds that disclosures and in-the-wild exploitations roughly doubled in 2026, AI-facilitated discovery surfaces proportionally more Moderate- and High-Risk issues and RCEs, and exploitation growth is concentrated in perimeter appliances and high-impact n-day weaponization. GTIG recommends threat-intelligence-driven triage and targeted remediation.
read more →

Unauthenticated command injection in Zimbra SNMP path

🔒 Microsoft Threat Intelligence tracked exploitation of CVE-2026-73570, an unauthenticated OS command-injection vulnerability in the Zimbra Collaboration Suite SNMP notification path. Exploitation occurs via specially crafted SMTP requests against internet-facing Zimbra servers with the optional zimbra-snmp package installed and SNMP notifications enabled. Observed impacts included JSP web shells, reverse shells, privilege escalation, persistent tooling, and exfiltration of email and authentication data. Activity spanned multiple regions and industries and combined automated probes with hands-on-keyboard operations.
read more →

Critical Citrix NetScaler DTLS Overflow Under Active Exploitation

🔒 Researchers disclosed details of a critical memory overflow in Citrix NetScaler ADC and Gateway, tracked as CVE-2026-88772 (CVSS 9.5). The flaw stems from improper DTLS fragment parsing in the NetScaler Packet Processing Engine, allowing crafted records to overflow a scratch buffer and enable remote code execution or denial-of-service. Vendor and researchers show how reassembly of many small fragments can produce a large NSB chain, enabling shellcode execution by bypassing NX protections with mprotect().
read more →

Automated AI agent breaches Dutch cybersecurity nonprofit

🔍 The Dutch Institute for Vulnerability Disclosure (DIVD) reported an autonomous, AI-driven intrusion that it described as “loud and very, very messy.” Evidence suggests a technical vulnerability was exploited to gain access, after which an automated AI agent carried out post-exploitation actions, often making obvious errors. DIVD has launched an investigation, notified authorities, and will publish further details on October 1 while working to identify and inform other potential victims.
read more →

Kiteworks lifts shutdown warning after patching flaw

🔔 Kiteworks, formerly Accellion, notified customers to temporarily shut down systems after receiving an intelligence warning of an imminent cyberattack, then restored hosted systems after patching a critical vulnerability and finding no evidence of compromise. The company said the flaw affected less than 1% of customers and urged self-hosted Advanced Forms users to contact support. Continuous monitoring reportedly showed no abnormal activity, and no CVE has been assigned yet.
read more →

Active exploitation of Citrix NetScaler ADC and Gateway

🛡️ Mandiant and Google Threat Intelligence Group identified active exploitation of a zero-day (CVE-2026-88772) affecting Citrix NetScaler ADC and Gateway appliances starting in early September 2026, with evidence of impact across government, finance, education and professional services in North America and Europe. The campaign bypasses authentication by corrupting the NetScaler Packet Processing Engine (NSPPE) during DTLS handshake parsing, leading to root execution and installation of PHP web shells and a Python tunneler. Observed tooling includes WHIPSHOT (PHP web shell) and SLAPSHOT (Python proxy) that facilitate persistence, internal reconnaissance, and credential theft. Citrix has published updates and guidance; defenders are urged to review vendor guidance and apply patches and containment steps.
read more →

Weekly recap: major hacks, flaws, and service abuse

🛡️ This week’s recap highlights a string of practical, opportunistic attacks—placeholder domains turned malicious, service-account compromises, and active exploitation of Citrix NetScaler ADC and Gateway bugs. Vendors and defenders are urged to patch high-risk CVEs and review forgotten non-human identities. The incidents include a $387M crypto theft, new evasive stealer techniques, and law enforcement takedowns of phishing infrastructure.
read more →

Critical NetScaler zero-days demand immediate patch

🔒 Citrix has confirmed two critical unauthenticated remote code execution zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway that are under active exploitation and must be patched immediately. Citrix released fixes in versions 14.1-73.37 and later and 13.1-64.23 and later, and urged customers to install updates as soon as possible. The US CISA added both to its KEV catalog while Citrix published additional mitigations, IOCs and fixes for six other related vulnerabilities.
read more →

Citrix issues urgent patches for critical NetScaler flaws

🔐 Citrix has released updates addressing eight vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway, including two critical zero-days that were actively exploited. The most severe issues — CVE-2026-88771 and CVE-2026-88772 — enable unauthenticated remote code execution in default deployments and in DTLS-enabled configurations respectively. Agencies including CISA and the ACSC have issued emergency patching guidance, and Citrix urges customers to install updates immediately.
read more →

CISA Adds Two Critical Citrix NetScaler Flaws to KEV

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical Citrix NetScaler ADC and Gateway vulnerabilities to its Known Exploited Vulnerabilities (KEV) list after reports of active exploitation. Both issues carry CVSS scores of 9.5 and can lead to remote command execution or denial-of-service; one requires DTLS to be enabled. Citrix has released patched versions and provided IoCs through the NetScaler Console to help customers detect compromises.
read more →

Two Unpatched Citrix NetScaler Zero-Days Exploited

🔔 Security firm watchTowr reported on September 26 that two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway allow remote code execution and are being actively exploited. Citrix has not confirmed the flaws or released a fix, and some administrators have taken appliances offline as a precaution. The vulnerabilities are distinct from the earlier CVE-2026-19490 authentication bypass patched on August 19.
read more →

Attackers Bypass WAFs to Exploit Oracle PeopleSoft

🛡️ Google warns of renewed mass exploitation of a critical Oracle PeopleSoft flaw (CVE-2026-35273, CVSS 9.8) by activity linked to ShinyHunters/UNC6240. The campaign weaponizes a modified exploit that URL-encodes the character "P" to bypass WAF rules, targeting multiple sectors globally and deploying web shells, trojanized installers, and backdoors. Affected organizations are urged to apply patches, disable or remove the PSEMHUB component, inspect logs and web directories, rotate credentials, and hunt for signs of data exfiltration and persistence.
read more →

Elementor CSRF Flaw Lets Attackers Create Admins

🔒 A high-severity CSRF vulnerability in the Elementor Website Builder (versions 4.3.0 and 4.3.1) allows an unauthenticated attacker to coerce logged-in users into performing REST API actions, including creating rogue administrator accounts. Patchstack reported the issue, which affects over 2 million installations of those versions and has a CVSS score of 8.8. The flaw stems from the Editor Events module skipping CSRF checks when "elementor/v1/events/" appears in the request URI. Elementor addressed the bug in version 4.3.2 following disclosure by researcher "Saggre," and users are urged to update immediately.
read more →

CISA Adds SharePoint and MikroTik Flaws to KEV List

🔐 CISA has added two actively exploited vulnerabilities—CVE-2026-65660 in Microsoft SharePoint and CVE-2026-67279 in Mikrotik RouterOS—to its Known Exploited Vulnerabilities catalog. Microsoft updated its advisory to reflect that the SharePoint issue can be leveraged for remote code execution, while CERT Polska and researchers linked RouterOS flaws to a full administrative takeover exploit called MikroTrick. Federal agencies must patch these issues by September 28, 2026.
read more →

AI-powered attack campaign compromises retailers cheaply

🔒 Research from Israeli security firm Gambit shows attackers used open-source AI tools to target 105 online retailers over five days, successfully compromising 27 of them. The campaign used tools named Strix, Cairn, and Hermes to find vulnerabilities, exploit them autonomously, and orchestrate operations. The attacker acquired AI model access via OpenRouter and spent roughly $7,005 over four weeks — about $25 per attack — while harvesting hundreds of thousands of credit card details and installing skimmer scripts.
read more →