ITsecurity Daily
Daily Briefing
Three actively exploited flaws land on CISA's KEV list — Citrix, Apple patch now
Good morning. Start with the vulnerabilities that attackers are already using. CISA's Known Exploited Vulnerabilities catalog lists CVE-2026-88771 in Citrix NetScaler ADC as known to be exploited. The flaw carries a CVSS base score of 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) — reachable over the network, no authentication and no user interaction required. CISA also lists CVE-2026-88772 in the same product as exploited; it scores 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). Citrix's advisory names the fixed release as 13.1-64.23 for the 13.1 branch. Citrix's security bulletin (CTX697096) covers both. Move NetScaler ADC to 13.1-64.23 per the vendor advisory.
CISA's catalog also lists CVE-2026-86950 in Apple macOS as exploited, scoring 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), with user interaction required. Apple's advisory gives the fix in macOS 15.8.1. Apply it.
Google's Chrome release note addresses three flaws — CVE-2026-102331, CVE-2026-102316 and CVE-2026-102309 — each scoring 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H), fixed in Chrome 154.0.8037.92. These are not on CISA's KEV list. Update to 154.0.8037.92.
Zoom out: Several of the day's reports touch China — Warlock's SharePoint campaign is attributed to a suspected China-linked actor, MI5 named China's state security service, and The Register reported exploitation attempts from a China-hosted IP.
Vulnerability in focus
CVE-2026-86950 — Apple. CVSS 8.8 CISA lists it as known to be exploited.
Affected: macos.
What to do: Follow the vendor advisory for the fixed release and any interim mitigation.
Elsewhere
- BleepingComputer: ShinyHunters hacker reportedly detained in Jordan, aiding FBI Read it
- The Register: Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows Read it
- The Hacker News: Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware Read it
- SecurityWeek: doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures Read it
- SecurityWeek: Fortra Patches Critical Vulnerabilities in BoKS Read it
- The Hacker News: The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations Read it
Sources
- ShinyHunters hacker reportedly detained in Jordan, aiding FBI BleepingComputer
- Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows The Register
- MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics The Hacker News
- doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures SecurityWeek
- Judge dismisses spyware case brought by Salvadoran journalists targeted with Pegasus The Record
- Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware The Hacker News
- Danish university DTU breach exposes data of up to 200,000 people BleepingComputer
- Fortra Patches Critical Vulnerabilities in BoKS SecurityWeek
- The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations The Hacker News
- Frontline Education breach exposes school district employee data BleepingComputer
- Warlock ransomware breach SharePoint in water, telecom operator attacks BleepingComputer
Share this issue
Facebook · X · Reddit · LinkedIn · WhatsApp · Email · Bluesky
Every briefing is on the site, with the advisory record behind it. All briefings