ITsecurity Daily
Daily Briefing
Citrix NetScaler flaw is being exploited now — CISA lists it, Google ships five critical Chrome fixes the same day
Good morning. CISA lists CVE-2026-88779 on its Known Exploited Vulnerabilities catalog and states it is known to be exploited. Citrix's advisory covers NetScaler ADC; the affected range is citrix-adc 13.1 up to the fix in 13.1-37.282. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H for a base score of 7.5 — network-reachable, no privileges or user interaction, impact to availability only. Move to the fixed release 13.1-37.282 per Citrix's advisory; CISA directs stakeholders to apply mitigations under BOD 26-04 and to evaluate each asset's internet exposure.
Google's stable channel update for desktop fixes five flaws Google tracks as CVE-2026-106419, CVE-2026-106417, CVE-2026-106414, CVE-2026-106401 and CVE-2026-106382, each with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H and a base score of 9.6 — each requires user interaction and crosses a scope boundary to full compromise. All are fixed in Chrome 155.0.8059.39. Update to that build.
BleepingComputer reports threat actors are exploiting one critical and one medium-severity vulnerability still unpatched in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners. Help Net Security reports that Lava found a high-severity flaw in NVIDIA's DCGM Exporter that lets unauthenticated attackers crash the GPU monitoring service, with hundreds of internet-exposed GPU servers open to it; Lava reported it to NVIDIA.
Zoom out: Friday pairs flaws already being exploited — one on CISA's catalogue, one still unpatched — with a run of law-enforcement arrests against ransomware and extortion crews.
Vulnerability in focus
CVE-2026-88779 — Citrix. CVSS 7.5 CISA lists it as known to be exploited.
Affected: citrix-adc.
What to do: Follow the vendor advisory for the fixed release and any interim mitigation.
Elsewhere
- BleepingComputer: Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks Read it
- The Register: AWS AgentCore security undone by prompt requesting credentials Read it
- BleepingComputer: Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto Read it
- The Hacker News: P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands Read it
- The Record: Leader of vast money mule operation that laundered cybercriminal proceeds pleads guilty Read it
- The Hacker News: Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge Read it
- The Hacker News: Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects Read it
- The Hacker News: Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access Read it
- The Hacker News: TP-Link Sued by Four More U.S. States Over Router Security and China Ties Read it
- The Hacker News: Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies Read it
- Help Net Security: High-severity NVIDIA vulnerability lets unauthenticated attackers crash GPU monitoring Read it
- BleepingComputer: Max severity SonicWall SMA1000 flaw now exploited in attacks Read it
Sources
- Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks BleepingComputer
- AWS AgentCore security undone by prompt requesting credentials The Register
- Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories The Hacker News
- Japan confirms arrest of Russian Qilin operative, extradition to Germany The Record
- High-severity NVIDIA vulnerability lets unauthenticated attackers crash GPU monitoring Help Net Security
- In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 Years SecurityWeek
- FBI Arrests Another ShinyHunters Suspect Reportedly Involved in Its Jobs Portal Hack The Hacker News
- Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto BleepingComputer
- FBI arrests another suspected ShinyHunters hacker after agency breach BleepingComputer
- P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands The Hacker News
- Hundreds of thousands impacted by data breach at biosensor firm iRhythm The Record
- Leader of vast money mule operation that laundered cybercriminal proceeds pleads guilty The Record
- FBI touts another ShinyHunters arrest in response to data breach The Record
- Germany arrests alleged core Qilin ransomware member after extradition BleepingComputer
Share this issue
Facebook · X · Reddit · LinkedIn · WhatsApp · Email · Bluesky
Every briefing is on the site, with the advisory record behind it. All briefings