FBI, CISA and researchers flag three edge-device flaws under active attack as Citrix NetScaler bug lands on KEV
Active exploitation hit Citrix, Atlassian and Fortinet gateways, fresh critical patches landed for SonicWall and Chrome, and attackers obtained unauthorized certificates for Google domains by hijacking national domain registries.
Patch internet-facing gateways first. CISA lists CVE-2026-88779 in Citrix NetScaler ADC as known to be exploited; the flaw is listed at CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, base score 7.5, and affects citrix-adc 13.1 up to the fix in 13.1-37.282. Citrix's advisory directs administrators to the fixed release and any interim mitigation, and CISA directs stakeholders to evaluate each asset's internet exposure and follow its BOD 26-04 patching guidance.
Help Net Security reported that attackers have begun exploiting a critical arbitrary file access vulnerability in Atlassian's self-managed Data Center products, one day after Atlassian released patches and a few hours after watchTowr researchers published a technical rundown of the flaw. BleepingComputer reported the FBI is warning that FortiBleed attacks remain ongoing, targeting exposed Fortinet FortiGate firewalls and SSL VPN gateways and locking out legitimate administrators.
Two more critical patches landed. The Hacker News reported SonicWall released hotfixes for four flaws in its SMA1000 remote-access appliances, the most serious a pre-authentication SSRF that lets an attacker without a login send requests through the appliance to reach internal functions. Google's stable channel update fixes CVE-2026-106419, CVE-2026-106417, CVE-2026-106414, CVE-2026-106401 and CVE-2026-106382 in Chrome, each listed at CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H, base score 9.6, with the fix in version 155.0.8059.39.
On the trust layer, The Hacker News reported that Google said on October 6 that attackers compromised the country-code registries for Ghana (.gh), Sierra Leone (.sl) and American Samoa (.as) and obtained unauthorized HTTPS certificates for several Google domains; Google said its own systems were not breached. BleepingComputer reported the hijack followed the compromise of third-party operators and the modification of authoritative DNS records. The Register reported the fake certificates present without the usual browser certificate warnings.
On breaches, SecurityWeek reported Southern Company is notifying 400,000 Georgia Power and Alabama Power accounts of accessed utility account information, and The Record reported Arizona courts say hackers stole information on more than 1.3 million people via the FARE program. The Hacker News reported CloudSEK and Checkmarx disclosed eight malicious npm packages, downloaded 40,767 times, delivering the Overlord RAT and a stealer in a campaign codenamed MALFEX.
On enforcement, The Record reported U.S. officials posted a $10 million reward for accused Hafnium hacker Zhang Yu; Krebs on Security reported a teenager in Amman suspected of leading ShinyHunters was detained; and BleepingComputer reported MonsterCloud's owner was charged over secretly paying attackers while claiming proprietary recovery technology.
Sources
- BleepingComputer — Ransomware recovery CEO charged over secret ransom payments
- The Record — US posts $10 million reward for accused Chinese ‘Hafnium’ hacker
- The Register — Attackers hijacked top-level domains, minted fake security certs for Google and other orgs
- The Hacker News — Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains
- Help Net Security — Exploitation attempts against critical Atlassian flaw have begun (CVE-2026-21589)
- SecurityWeek — Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts
- Krebs on Security — ShinyHunters Extorted Boeing Spin-off Prior to Arrests
- BleepingComputer — FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins
- BleepingComputer — Hackers hijack Google domains after breaching ccTLD registries
- The Record — $11 million plan for psychological support at Cyber Command gets fresh boost from lawmakers
- The Record — Arizona courts say hackers stole info on more than 1.3 million people
- The Hacker News — Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer
- The Register — AWS launches open-source AI agent sandbox to prevent YOLO mode disasters
- The Hacker News — SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances