ITsecurity Daily
Daily Briefing
Citrix NetScaler flaw under active attack leads a day dominated by Chrome fixes, arrests and AI-agent abuse
Good morning. CISA's Known Exploited Vulnerabilities catalog lists CVE-2026-88779 in Citrix NetScaler ADC as known to be exploited. The flaw carries CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, a base score of 7.5 — a network-reachable, no-privileges, no-interaction availability impact. Citrix's advisory lists citrix-adc 13.1 up to the fix in 13.1-37.282 as affected. Act on this first: apply the fixed release named by Citrix, follow any interim mitigation in the vendor advisory, and apply mitigations in line with CISA's BOD 26-04 guidance referenced in the KEV catalog. Because it is on KEV, treat exposed, internet-facing NetScaler as a priority.
Google's Chrome stable channel advisory records five flaws — CVE-2026-106419, CVE-2026-106417, CVE-2026-106414, CVE-2026-106401 and CVE-2026-106382 — each CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H, base score 9.6, requiring user interaction and crossing a security boundary. Google lists Chrome up to the fix in 155.0.8059.39 as affected. Update to 155.0.8059.39. None of the five is on CISA KEV.
On law enforcement, Krebs on Security reported the FBI arrested the co-founder of a Canadian cybersecurity firm in connection with an investigation into the ShinyHunters group, which Krebs reported recently took sensitive data on thousands of FBI agents. BleepingComputer identified the arrested executive as Edward Dubrovsky, detained in Pennsylvania. SecurityWeek reported a former core infrastructure engineer who deleted admin accounts, reset hundreds of passwords and demanded 20 bitcoin was sentenced to prison. The Record reported Raheim Hamilton, co-creator of the Empire Market dark web marketplace, received a 40-year sentence, and that Japan's National Police Agency confirmed the arrest and extradition to Germany of a Russian national accused of involvement in the Qilin ransomware gang.
Zoom out: Several of the day's reports — AWS AgentCore, malicious GitHub Actions workflows, fake Claude installers and AI-assisted attacks on banks — center on the security of AI agents and the software supply chain.
Vulnerability in focus
CVE-2026-88779 — Citrix. CVSS 7.5 CISA lists it as known to be exploited.
Affected: citrix-adc.
What to do: Follow the vendor advisory for the fixed release and any interim mitigation.
Elsewhere
- BleepingComputer: Cyber exec arrested in case allegedly tied to ShinyHunters hackers Read it
- BleepingComputer: Hacker used ARTEX AI and Claude agents to target South Korean banks Read it
- BleepingComputer: Criminal IP Introduces AITEM as the Next Evolution of Attack Surface Management Read it
- The Hacker News: The Third-Party Agent Problem: Why Security Built for AI You Chose Misses the Agents You Didn't Read it
- SecurityWeek: Insider Cyber Extortion Plot Against Industrial Firm Lands Engineer in Prison Read it
- The Hacker News: Anthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection Flaws Read it
Sources
- Cyber exec arrested in case allegedly tied to ShinyHunters hackers BleepingComputer
- The Third-Party Agent Problem: Why Security Built for AI You Chose Misses the Agents You Didn't The Hacker News
- Insider Cyber Extortion Plot Against Industrial Firm Lands Engineer in Prison SecurityWeek
- Co-creator of Empire Market dark web marketplace given 40-year sentence The Record
- FBI Arrests Founder of Ransomware Negotiation Firm Krebs on Security
- AWS AgentCore security undone by prompt requesting credentials The Register
- Hacker used ARTEX AI and Claude agents to target South Korean banks BleepingComputer
- Criminal IP Introduces AITEM as the Next Evolution of Attack Surface Management BleepingComputer
- Anthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection Flaws The Hacker News
- Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks BleepingComputer
- Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories The Hacker News
- Japan confirms arrest of Russian Qilin operative, extradition to Germany The Record
Share this issue
Facebook · X · Reddit · LinkedIn · WhatsApp · Email · Bluesky
Every briefing is on the site, with the advisory record behind it. All briefings