⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

🇧🇷 PT 🇺🇸 EN

Mon, 28 Sep 2026

← Back

Executive Summary

A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface. Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work for attackers.

Nothing exotic. Mostly things nobody expected to matter anymore. Here’s the full recap of what mattered this week. Citrix Warns of Actively Exploited NetScaler ADC and Gateway Flaws — Citrix released patches to address multiple vulnerabilities, including CVE-2026-88771 and CVE-2026-88772, that have come under active exploitation.

CVE-2026-88771 is an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands, while successful exploitation of CVE-2026-88772 could allow for remote code execution or denial-of-service. CISA said "threat actors are actively exploiting these vulnerabilities globally," urging federal agencies to apply patches by Wednesday. Mikko Hyppönen, Volkan Erturk, and security leaders from Chanel, the NFL, and Atlassian bring five distinct perspectives to The Validation Summit ’26. Hear what changed, what needs to change, and how leading teams are responding.

Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being...

Details

A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface. Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work for attackers.

Nothing exotic. Mostly things nobody expected to matter anymore. Here’s the full recap of what mattered this week. Citrix Warns of Actively Exploited NetScaler ADC and Gateway Flaws — Citrix released patches to address multiple vulnerabilities, including CVE-2026-88771 and CVE-2026-88772, that have come under active exploitation.

CVE-2026-88771 is an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands, while successful exploitation of CVE-2026-88772 could allow for remote code execution or denial-of-service. CISA said "threat actors are actively exploiting these vulnerabilities globally," urging federal agencies to apply patches by Wednesday. Mikko Hyppönen, Volkan Erturk, and security leaders from Chanel, the NFL, and Atlassian bring five distinct perspectives to The Validation Summit ’26. Hear what changed, what needs to change, and how leading teams are responding.

Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-77179 (Docker), CVE-2026-93485, CVE-2026-87902 (WordPress), CVE-2026-89775 (Linux kernel), CVE-2026-93616, CVE-2026-85102 (Check Point), CVE-2026-93952 (Arista VeloCloud Orchestrator), CVE-2026-90898 (Bifrost), CVE-2026-86555, CVE-2026-86554, CVE-2026-86553, CVE-2026-86552 (ZTE H188A/H288A firmware), CVE-2026-94545 (Next.js), CVE-2026-94127 (F5 BIG-IP Access Policy Manager), CVE-2026-86296, CVE-2026-86510 (D-Link DIR-822A), CVE-2026-87900, CVE-2026-87899, CVE-2026-68490 (cPanel), CVE-2026-82356 (Imprivata Enterprise Access Management), CVE-2026-86867 (Cinnamon Kotaemon), CVE-2026-75682, CVE-2026-75684, CVE-2026-75686, CVE-2026-75689, CVE-2026-75697, CVE-2026-75698, CVE-2026-75745, CVE-2026-81995, CVE-2026-82000 (Adobe), CVE-2026-95350, CVE-2026-95357, CVE-2026-95339, CVE-2026-95281, CVE-2026-95313, CVE-2026-95349, CVE-2026-95284, CVE-2026-95322, CVE-2026-95329, CVE-2026-95356, CVE-2026-95310 (Google Chrome), CVE-2024-0244 (Canon MF753Cdw), CVE-2026-28324, CVE-2026-28325 (SolarWinds Observability Self-Hosted), CVE-2026-97359, CVE-2026-97360 (HFS2), CVE-2026-96560 (LightLLM), CVE-2026-80145, CVE-2026-80144, CVE-2026-80143 (Lantronix), CVE-2026-82987, CVE-2026-82988, CVE-2026-82989 (ViewSonic vCast), CVE-2026-75907 (Norwegian Cruise Line door access controller), CVE-2026-18311, CVE-2026-18312, CVE-2026-18320 (Readwise Reader for Android), CVE-2026-88771, and CVE-2026-88772 (Citrix NetScaler ADC and Gateway). 📰 Around the Cyber World The common thread this week was not sophistication.

It was neglect. Forgotten accounts, stale assumptions, old flaws, exposed services, and tooling that keeps getting more capable faster than the controls around it. That is usually how these weeks land: the dramatic stories get attention, but the quieter failures keep doing the real work underneath. The patch nobody rushed, the identity nobody owned, the placeholder nobody questioned, the service nobody hardened.

That’s it for this week. Patch the obvious stuff, check the forgotten stuff, and assume somebody else already noticed it too. AI agents are already operating inside enterprises with growing access to sensitive systems and data—while security teams still lack the visibility, controls, and governance to keep that access in check. Attackers are using AI to accelerate reconnaissance, compromise identities and escalate access.

See how security teams can fight back with runtime identity controls. Get the latest news, expert insights, exclusive resources, and strategies from industry leaders, all for free.