Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
Citrix confirmed on September 27 that two critical flaws in NetScaler ADC and NetScaler Gateway, CVE-2026-88771 and CVE-2026-88772 (both CVSS v4 9.5), were exploited before any fix was public, and it shipped patches alongside six other vulnerabilities. The first lets an unauthenticated attacker run arbitrary commands on any deployment of an affected version, while the second is a memory overflow reachable when DTLS is enabled, which is the default for VPN virtual servers. Appliances already updated for August’s authentication bypass still fall in the affected range, the 13.1 branch fix lands after its end of maintenance, and because exploitation predates the patch, admins are urged to preserve evidence, hunt for compromise, and rotate secrets rather than treat updating as the end of the job.
US soldier gets 70 months in prison for extorting 10 tech, telecom firms
Former U.S. Army soldier Cameron John Wagenius, known online as “kiberphant0m,” has been sentenced to 70 months in prison and ordered to pay nearly $295,000 in restitution for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024. While on active duty, he and accomplices used a brute-force tool he helped build to steal network credentials, then threatened to leak or sold stolen data on forums like BreachForums and XSS, attempting to extort at least $1 million in total. His co-conspirators were tied to the 2024 Snowflake data theft campaign that affected AT&T, Ticketmaster, Santander, and more than 160 other organizations.
New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
A threat actor calling itself WraithTools is selling access to a Windows botnet called x47.c that uses xAI’s Grok model to pick persistence actions such as startup entries and scheduled tasks on infected hosts, falling back to local actions if the AI call fails. Beyond 18 DDoS methods, SOCKS5 proxying, and credential and cookie theft, the botnet offers an “AI drain” mode that burns through a victim’s paid OpenAI, xAI, or compatible API credits using a stolen key, leaving the target’s website online while its AI features quietly run out of funds. The full package sells for $950, with a C2 panel that supports fast-flux infrastructure and a rootkit module for clearing out rival malware.
MacSync info-stealing malware hides malicious commands in an iCloud calendar
A new version of the MacSync macOS infostealer is spreading through a fake crypto wallet app called Toria, and in at least one sample it hid its next-stage commands inside the description field of a public iCloud calendar that is piped line by line into the zsh shell. The malware has moved from AppleScripts to compiled Swift and Objective-C droppers, shows a fake password prompt and verifies it using the PAM API, and then steals browser data, Keychain files, crypto wallets, Telegram data, and SSH, AWS, Kubernetes, and Git configurations. A backdoor disguised as Finder persists through a LaunchAgent, shell profile edits, and Git hooks, and kills macOS notification processes so the user never sees the new login item, making developers and crypto users the clear targets.
Kiteworks Systems Went Offline After Federal Threat Warning
Secure file-sharing vendor Kiteworks has lifted its unusual recommendation that customers worldwide take their systems offline for a nine-hour window over the weekend, a precaution it issued after federal intelligence authorities warned that a threat actor might attempt to target some Kiteworks deployments. The company says it has found no evidence that its own systems or customer environments were compromised and that all currently known vulnerabilities are addressed in version 9.5.1, so customers can now bring systems back online. The episode stands out given the company’s history as Accellion, whose legacy file transfer appliance was mass-exploited in 2020 and 2021, and it shows how seriously vendors now treat advance warnings of attacks on file-transfer platforms.