NetScaler zero-days turn patching into an incident-response decisionOpenAI disclosure makes agent boundaries and notification clocks…Hasbro vishing disclosure puts identity verification and rebuild…Phishing campaign turns two legitimate RMM tools into redundant access
NetScaler zero-days turn patching into an incident-response decision
Mandiant’s newly published incident evidence shows exploited NetScaler appliances receiving root-level persistence, custom web shells and an internal tunnelling capability, making clean-build verification and compromise assessment inseparable.
Security.io Intelligence Desk · Wednesday, 30 September 2026
Executive consequence
Citrix confirms active exploitation of CVE-2026-88771 and CVE-2026-88772. Mandiant now provides evidence of root access, custom WHIPSHOT and SLAPSHOT malware, credential-focused internal reconnaissance and hunt-ready artefacts, so patch completion alone is not defensible closure.
Decision today
Inventory every customer-managed NetScaler, including HA peers, FIPS, NDcPP, VPX and hybrid instances.
Read the full decision briefPrimary reporting: Citrix Security Bulletin CTX697096 · Mandiant and Google Threat Intelligence Group · CERT-EU
Decision intelligence, not a headline feed.Every edition ranks what security leaders should read first, assign today and monitor next.
Daily executive briefing
Security.io Daily Headlines
Five equally weighted stories: what happened and the leadership decision each creates.
CVE-2026-86950 is an exploited CoreGraphics out-of-bounds write addressed in iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. CISA added it to KEV, while Apple has not published actor attribution, victim identities or compromise indicators.
Do today
Query MDM for every affected iOS, iPadOS and macOS branch.
Security.io scores each dimension from 0–100. Exposure reflects deployment reach and privileged network placement; Urgency reflects exploitation tempo and remediation window; Business consequence reflects credential access, persistence and potential interruption. Source: Security.io editorial assessment based on Citrix, Mandiant and CERT-EU evidence.
Back page
Daily comic · Circuit Chuckles
A brief pause after the intelligence
Secrets Management
Glitch reports that the administrator secret changed, but Rusty reveals his “managed” vault is full of labeled envelopes containing office rumors and gossip.