ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
Board › Newsletters › Past editions › ITsecurity Daily — Saturday, 10 October 2026: Citrix NetScaler flaw under active attack leads a day dominated by Chrome fixes, arrests and AI-agent abuse

ITSECURITY.GURU

ITsecurity Daily

Daily Briefing

Citrix NetScaler flaw under active attack leads a day dominated by Chrome fixes, arrests and AI-agent abuse

Good morning. CISA's Known Exploited Vulnerabilities catalog lists CVE-2026-88779 in Citrix NetScaler ADC as known to be exploited. The flaw carries CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, a base score of 7.5 — a network-reachable, no-privileges, no-interaction availability impact. Citrix's advisory lists citrix-adc 13.1 up to the fix in 13.1-37.282 as affected. Act on this first: apply the fixed release named by Citrix, follow any interim mitigation in the vendor advisory, and apply mitigations in line with CISA's BOD 26-04 guidance referenced in the KEV catalog. Because it is on KEV, treat exposed, internet-facing NetScaler as a priority.

Google's Chrome stable channel advisory records five flaws — CVE-2026-106419, CVE-2026-106417, CVE-2026-106414, CVE-2026-106401 and CVE-2026-106382 — each CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H, base score 9.6, requiring user interaction and crossing a security boundary. Google lists Chrome up to the fix in 155.0.8059.39 as affected. Update to 155.0.8059.39. None of the five is on CISA KEV.

On law enforcement, Krebs on Security reported the FBI arrested the co-founder of a Canadian cybersecurity firm in connection with an investigation into the ShinyHunters group, which Krebs reported recently took sensitive data on thousands of FBI agents. BleepingComputer identified the arrested executive as Edward Dubrovsky, detained in Pennsylvania. SecurityWeek reported a former core infrastructure engineer who deleted admin accounts, reset hundreds of passwords and demanded 20 bitcoin was sentenced to prison. The Record reported Raheim Hamilton, co-creator of the Empire Market dark web marketplace, received a 40-year sentence, and that Japan's National Police Agency confirmed the arrest and extradition to Germany of a Russian national accused of involvement in the Qilin ransomware gang.

Read the full briefing →

Zoom out: Several of the day's reports — AWS AgentCore, malicious GitHub Actions workflows, fake Claude installers and AI-assisted attacks on banks — center on the security of AI agents and the software supply chain.

Vulnerability in focus

CVE-2026-88779 — Citrix. CVSS 7.5 CISA lists it as known to be exploited.

Affected: citrix-adc.

What to do: Follow the vendor advisory for the fixed release and any interim mitigation.

Elsewhere

  • BleepingComputer: Cyber exec arrested in case allegedly tied to ShinyHunters hackers Read it
  • BleepingComputer: Hacker used ARTEX AI and Claude agents to target South Korean banks Read it
  • BleepingComputer: Criminal IP Introduces AITEM as the Next Evolution of Attack Surface Management Read it
  • The Hacker News: The Third-Party Agent Problem: Why Security Built for AI You Chose Misses the Agents You Didn't Read it
  • SecurityWeek: Insider Cyber Extortion Plot Against Industrial Firm Lands Engineer in Prison Read it
  • The Hacker News: Anthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection Flaws Read it

Sources

Every briefing is on the site, with the advisory record behind it. All briefings

You are receiving this because you subscribed at itsecurity.guru.

Headlines from other outlets belong to them; each one credits its outlet and leads to their own report.

All past editions · Get them by email