ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
Board › Briefings › Citrix NetScaler flaw is being exploited now — CISA lists it, Google ships five critical Chrome fixes the same day
IT SECURITY DESK

Citrix NetScaler flaw is being exploited now — CISA lists it, Google ships five critical Chrome fixes the same day

An actively exploited Citrix NetScaler ADC denial-of-service flaw leads Friday's reporting, alongside a Chrome release closing five 9.6-rated bugs and unpatched AhsayCBS flaws already being exploited.

CISA lists CVE-2026-88779 on its Known Exploited Vulnerabilities catalog and states it is known to be exploited. Citrix's advisory covers NetScaler ADC; the affected range is citrix-adc 13.1 up to the fix in 13.1-37.282. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H for a base score of 7.5 — network-reachable, no privileges or user interaction, impact to availability only. Move to the fixed release 13.1-37.282 per Citrix's advisory; CISA directs stakeholders to apply mitigations under BOD 26-04 and to evaluate each asset's internet exposure.

Google's stable channel update for desktop fixes five flaws Google tracks as CVE-2026-106419, CVE-2026-106417, CVE-2026-106414, CVE-2026-106401 and CVE-2026-106382, each with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H and a base score of 9.6 — each requires user interaction and crosses a scope boundary to full compromise. All are fixed in Chrome 155.0.8059.39. Update to that build.

BleepingComputer reports threat actors are exploiting one critical and one medium-severity vulnerability still unpatched in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners. Help Net Security reports that Lava found a high-severity flaw in NVIDIA's DCGM Exporter that lets unauthenticated attackers crash the GPU monitoring service, with hundreds of internet-exposed GPU servers open to it; Lava reported it to NVIDIA.

On the campaign side, The Hacker News reports a credential-theft operation compromised two open-source maintainer accounts — including that of Takashi Kitao, author of the 18,400-star pyxel engine — to push a malicious workflow into over 340 repositories. BleepingComputer reports attackers are abusing Bing search-result redirects inside Google search ads to push fake Claude installers delivering ClickFix attacks. The Register reports weaknesses in AWS AgentCore, including tokens transmitted in metadata and weak VM isolation.

In law enforcement: The Record reports Japan's National Police Agency confirmed the arrest and extradition to Germany of a Russian national accused of involvement in the Qilin ransomware gang, and BleepingComputer reports Germany arrested the suspected leading member after that extradition. FBI Director Kash Patel said on October 9, per The Hacker News and BleepingComputer, that the FBI arrested another suspected ShinyHunters co-conspirator tied to the breach of the FBI's jobs portal. The Record reports Oleg Korniev, a 42-year-old dual Ukrainian-Russian citizen and principal of "Your Mule Cashout," pleaded guilty. The Record also reports hundreds of thousands were impacted by a summer data breach at biosensor firm iRhythm. The Hacker News reports a new P7 variant of the DarkSword iOS exploit kit adds on-device keychain and crypto-wallet theft and two-way C2.

Related