ITsecurity Daily
Daily Briefing
FBI, CISA and researchers flag three edge-device flaws under active attack as Citrix NetScaler bug lands on KEV
Good morning. Patch internet-facing gateways first. CISA lists CVE-2026-88779 in Citrix NetScaler ADC as known to be exploited; the flaw is listed at CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, base score 7.5, and affects citrix-adc 13.1 up to the fix in 13.1-37.282. Citrix's advisory directs administrators to the fixed release and any interim mitigation, and CISA directs stakeholders to evaluate each asset's internet exposure and follow its BOD 26-04 patching guidance.
Help Net Security reported that attackers have begun exploiting a critical arbitrary file access vulnerability in Atlassian's self-managed Data Center products, one day after Atlassian released patches and a few hours after watchTowr researchers published a technical rundown of the flaw. BleepingComputer reported the FBI is warning that FortiBleed attacks remain ongoing, targeting exposed Fortinet FortiGate firewalls and SSL VPN gateways and locking out legitimate administrators.
Two more critical patches landed. The Hacker News reported SonicWall released hotfixes for four flaws in its SMA1000 remote-access appliances, the most serious a pre-authentication SSRF that lets an attacker without a login send requests through the appliance to reach internal functions. Google's stable channel update fixes CVE-2026-106419, CVE-2026-106417, CVE-2026-106414, CVE-2026-106401 and CVE-2026-106382 in Chrome, each listed at CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H, base score 9.6, with the fix in version 155.0.8059.39.
Zoom out: Three separate perimeter products — Citrix, Atlassian and Fortinet — were reported under active exploitation, alongside an attack on the certificate layer that produced unauthorized certificates for Google domains.
Vulnerability in focus
CVE-2026-88779 — Citrix. CVSS 7.5 CISA lists it as known to be exploited.
Affected: citrix-adc.
What to do: Follow the vendor advisory for the fixed release and any interim mitigation.
Elsewhere
- BleepingComputer: Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland Read it
- Help Net Security: How AI can fix cybersecurity compliance: From dashboards to continuous execution Read it
- Help Net Security: The people who know passkeys best are still typing passwords Read it
- Help Net Security: Java library vulnerabilities: IBM and Red Hat fix 400+ previously unknown flaws Read it
- BleepingComputer: FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins Read it
- The Register: Attackers hijacked top-level domains, minted fake security certs for Google and other orgs Read it
- The Record: $11 million plan for psychological support at Cyber Command gets fresh boost from lawmakers Read it
- The Hacker News: SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances Read it
- The Register: AWS launches open-source AI agent sandbox to prevent YOLO mode disasters Read it
- The Hacker News: Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely Read it
- Help Net Security: Exploitation attempts against critical Atlassian flaw have begun (CVE-2026-21589) Read it
- The Record: Cyber experts call on CISA to create mandatory federal OT rules Read it
Sources
- Ransomware recovery CEO charged over secret ransom payments BleepingComputer
- US posts $10 million reward for accused Chinese ‘Hafnium’ hacker The Record
- Attackers hijacked top-level domains, minted fake security certs for Google and other orgs The Register
- Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains The Hacker News
- Exploitation attempts against critical Atlassian flaw have begun (CVE-2026-21589) Help Net Security
- Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts SecurityWeek
- ShinyHunters Extorted Boeing Spin-off Prior to Arrests Krebs on Security
- FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins BleepingComputer
- Hackers hijack Google domains after breaching ccTLD registries BleepingComputer
- $11 million plan for psychological support at Cyber Command gets fresh boost from lawmakers The Record
- Arizona courts say hackers stole info on more than 1.3 million people The Record
- Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer The Hacker News
- AWS launches open-source AI agent sandbox to prevent YOLO mode disasters The Register
- SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances The Hacker News
Share this issue
Facebook · X · Reddit · LinkedIn · WhatsApp · Email · Bluesky
Every briefing is on the site, with the advisory record behind it. All briefings