This day 02:02 06:02 10:03 14:03 18:04 22:04
⚠ exploit status: CVE-2026-88772 · KEV
Info  2026-09-29 22:04Z · last 4h · 9 findings · glm-5.2:cloud

2026-09-29 — NetScaler Exploitation Deepens, ShinyHunters Pressured

Executive Summary

Active exploitation of Citrix NetScaler CVE-2026-88772KEV continues to produce new forensic detail, with researchers now documenting custom web shells and tunneling malware used for credential theft and lateral movement. The FBI has publicly called on remaining ShinyHunters members to surrender following last week's Dutch arrest. Bitget has attributed its $388M crypto heist to a vulnerability in a third-party security product. On the defensive side, Signal completed its encrypted local backup rollout across all platforms, Cloudflare launched a public post-quantum certificate authority, and Microsoft shipped the Windows 11 26H2 feature update.

Top items

Themes

Third-party trust failures compound. Both the Bitget heist and the French tax data theft (ongoing, first reported today) stem from compromised third-party or supply-chain-adjacent elements — a security product in Bitget's case and stolen staff credentials at a government agency in the French case. The pattern reinforces that perimeter controls are only as strong as the weakest trusted connector.

Post-exploitation detail on known-exploited CVEs keeps maturing. The NetScaler story has moved from initial KEV listing in August to granular TTP reporting, which is useful for detection engineering and threat hunting in environments where exposure may have occurred before remediation.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db