Daily Digest

Citrix, Cisco Zero-Days Exploited; AI Fuels Attack Surge

October 1, 2026
9 articles (6 new, 3 updated)
27 min read

Summary

Critical Vulnerabilities Under Active Exploitation:

  • Citrix NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772) Actively Exploited: Analysis reveals sophisticated threat actors, potentially state-sponsored, have been exploiting two critical NetScaler zero-days since at least August 21, 2026. Attacks involve custom malware, including a PHP web shell with RC4-encrypted C2, and leverage techniques like DTLS packet manipulation and log poisoning for RCE/DoS and privilege escalation. Exploitation has been ongoing for weeks prior to public disclosure, targeting high-value government and financial organizations. A temporary mitigation of disabling DTLS is suggested if patching is not immediately feasible.
  • Cisco SD-WAN Auth Bypass Zero-Day (CVE-2026-76504): Cisco has patched a critical authentication bypass vulnerability in its Catalyst SD-WAN Manager. This zero-day, rated CVSS 9.8, allows unauthenticated remote attackers to gain administrative access due to improper URI handling. CISA has added this to its Known Exploited Vulnerabilities catalog, emphasizing the need for immediate patching as no workarounds are available.

New Threats and Advisories:

  • Dutch Security Institute Hacked via AI-Powered Zammad Zero-Days: The Dutch Institute for Vulnerability Disclosure (DIVD) experienced a compromise attributed to an "agentic AI-powered attack." This intrusion utilized two zero-day vulnerabilities in Zammad helpdesk software (CVE-2026-102489 and CVE-2026-102490) to achieve remote code execution and full system control, resulting in a data breach.
  • Russian APT Star Blizzard Evolves Phishing with 'RedFlick' Technique: The Russian APT group Star Blizzard has implemented a new malware delivery technique called "RedFlick." This method streamlines phishing campaigns against targets in Ukraine, including NGOs and journalists, by requiring only a single user interaction to initiate the CosmicPulse backdoor infection chain.
  • Data Breaches at Healthcare & Professional Services Firms Disclosed: Several US-based organizations, including Modoc Medical Center and Blanchard Training & Development, have disclosed data breaches that occurred earlier in 2026. These incidents exposed sensitive personal, financial, and protected health information (PHI) affecting thousands of individuals across the healthcare, legal, and professional services sectors.

Industry Trends and Guidance:

  • Industry Leaders Warn AI-Powered Attacks Are Outpacing Defenses: A report from Google's Threat Intelligence Group (GTIG) indicates a significant increase in AI's impact on cybersecurity, with a more than 100% rise in disclosed vulnerabilities and a 241% surge in high-risk disclosures in the first eight months of 2026. AI is accelerating the exploitation of N-day vulnerabilities, particularly targeting network edge and security appliances, thereby compressing the 'patch gap'.
  • Gartner Advises CISOs to Prioritize AI Risks, Preemptive Security: Gartner has issued new guidance for CISOs, recommending the prioritization of AI-related risks, investment in preemptive security capabilities, and treating all frontier AI models as potential insider risks. This advice is driven by the acceleration of AI-augmented attacks and the resulting reduction in defender response times.
  • Europol Dismantles KillSec Ransomware; Teenager Suspected Leader: An international law enforcement operation, Operation KillSwitch, has successfully dismantled the infrastructure of the KillSec ransomware group. The operation, led by German authorities with Europol's support, resulted in the seizure of the group's darknet leak site and 110 TB of stolen data. A 16-year-old is suspected of being the primary operator.

Filter by Category

New Articles (6)

Updated Articles (3)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.