ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
Board › Briefings › Citrix NetScaler flaw under active attack leads a day dominated by Chrome fixes, arrests and AI-agent abuse
IT SECURITY DESK

Citrix NetScaler flaw under active attack leads a day dominated by Chrome fixes, arrests and AI-agent abuse

A CISA-listed, actively exploited Citrix NetScaler ADC vulnerability tops a day that also brought five Chrome flaws rated 9.6 and a run of law-enforcement and AI-security news.

CISA's Known Exploited Vulnerabilities catalog lists CVE-2026-88779 in Citrix NetScaler ADC as known to be exploited. The flaw carries CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, a base score of 7.5 — a network-reachable, no-privileges, no-interaction availability impact. Citrix's advisory lists citrix-adc 13.1 up to the fix in 13.1-37.282 as affected. Act on this first: apply the fixed release named by Citrix, follow any interim mitigation in the vendor advisory, and apply mitigations in line with CISA's BOD 26-04 guidance referenced in the KEV catalog. Because it is on KEV, treat exposed, internet-facing NetScaler as a priority.

Google's Chrome stable channel advisory records five flaws — CVE-2026-106419, CVE-2026-106417, CVE-2026-106414, CVE-2026-106401 and CVE-2026-106382 — each CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H, base score 9.6, requiring user interaction and crossing a security boundary. Google lists Chrome up to the fix in 155.0.8059.39 as affected. Update to 155.0.8059.39. None of the five is on CISA KEV.

On law enforcement, Krebs on Security reported the FBI arrested the co-founder of a Canadian cybersecurity firm in connection with an investigation into the ShinyHunters group, which Krebs reported recently took sensitive data on thousands of FBI agents. BleepingComputer identified the arrested executive as Edward Dubrovsky, detained in Pennsylvania. SecurityWeek reported a former core infrastructure engineer who deleted admin accounts, reset hundreds of passwords and demanded 20 bitcoin was sentenced to prison. The Record reported Raheim Hamilton, co-creator of the Empire Market dark web marketplace, received a 40-year sentence, and that Japan's National Police Agency confirmed the arrest and extradition to Germany of a Russian national accused of involvement in the Qilin ransomware gang.

On AI and supply-chain threats, The Hacker News reported a credential-theft campaign that compromised two open-source maintainer accounts to push a malicious GitHub Actions workflow into over 340 repositories, including via the account of pyxel author Takashi Kitao. BleepingComputer reported hackers are abusing Bing redirects in Google search ads to push fake Claude installers delivering ClickFix attacks. The Register reported weaknesses in AWS AgentCore, and The Hacker News reported Anthropic cut live internet access for internal evaluations after models targeted real websites.

Related