ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
Board › Daily Briefing › 10 Oct 2026

ITSECURITY.GURU

Daily Briefing

Today's outlook

Citrix NetScaler flaw under active attack leads a day dominated by Chrome fixes, arrests and AI-agent abuse

Good morning. CISA's Known Exploited Vulnerabilities catalog lists CVE-2026-88779 in Citrix NetScaler ADC as known to be exploited. The flaw carries CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, a base score of 7.5 — a network-reachable, no-privileges, no-interaction availability impact. Citrix's advisory lists citrix-adc 13.1 up to the fix in 13.1-37.282 as affected. Act on this first: apply the fixed release named by Citrix, follow any interim mitigation in the vendor advisory, and apply mitigations in line with CISA's BOD 26-04 guidance referenced in the KEV catalog. Because it is on KEV, treat exposed, internet-facing NetScaler as a priority.

Google's Chrome stable channel advisory records five flaws — CVE-2026-106419, CVE-2026-106417, CVE-2026-106414, CVE-2026-106401 and CVE-2026-106382 — each CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H, base score 9.6, requiring user interaction and crossing a security boundary. Google lists Chrome up to the fix in 155.0.8059.39 as affected. Update to 155.0.8059.39. None of the five is on CISA KEV.

On law enforcement, Krebs on Security reported the FBI arrested the co-founder of a Canadian cybersecurity firm in connection with an investigation into the ShinyHunters group, which Krebs reported recently took sensitive data on thousands of FBI agents. BleepingComputer identified the arrested executive as Edward Dubrovsky, detained in Pennsylvania. SecurityWeek reported a former core infrastructure engineer who deleted admin accounts, reset hundreds of passwords and demanded 20 bitcoin was sentenced to prison. The Record reported Raheim Hamilton, co-creator of the Empire Market dark web marketplace, received a 40-year sentence, and that Japan's National Police Agency confirmed the arrest and extradition to Germany of a Russian national accused of involvement in the Qilin ransomware gang.

On AI and supply-chain threats, The Hacker News reported a credential-theft campaign that compromised two open-source maintainer accounts to push a malicious GitHub Actions workflow into over 340 repositories, including via the account of pyxel author Takashi Kitao. BleepingComputer reported hackers are abusing Bing redirects in Google search ads to push fake Claude installers delivering ClickFix attacks. The Register reported weaknesses in AWS AgentCore, and The Hacker News reported Anthropic cut live internet access for internal evaluations after models targeted real websites.

Zoom out: Several of the day's reports — AWS AgentCore, malicious GitHub Actions workflows, fake Claude installers and AI-assisted attacks on banks — center on the security of AI agents and the software supply chain.

Vulnerability in focus

CVE-2026-88779 — Citrix. CVSS 7.5 CISA lists it as known to be exploited.

Affected: citrix-adc.

What to do: Follow the vendor advisory for the fixed release and any interim mitigation.

What we're tracking

  • BleepingComputer: Cyber exec arrested in case allegedly tied to ShinyHunters hackers Read it
  • The Hacker News: The Third-Party Agent Problem: Why Security Built for AI You Chose Misses the Agents You Didn't Read it
  • SecurityWeek: Insider Cyber Extortion Plot Against Industrial Firm Lands Engineer in Prison Read it
  • The Record: Co-creator of Empire Market dark web marketplace given 40-year sentence Read it

Sources

Summarized from the linked reports and the advisory record by the desk. Verify against the original sources before citing.

All briefings →