
Inside the Citrix NetScaler Zero Day Saga
This case is yet another reminder just how important vendor communication is in such incidents and how much uncertainty can hamper security.

This case is yet another reminder just how important vendor communication is in such incidents and how much uncertainty can hamper security.
September 29, 2026 | 1 min read

On Saturday, researchers from watchTowr Labs said they had credible information that attackers were exploiting an unknown RCE vulnerability in Citrix NetScaler boxes.
September 29, 2026 | 3 min read

This vulnerability allows for unauthenticated remote code execution and shows how a missing bounds check—a classic programming error.
September 24, 2026 | 3 min read
Inside the Citrix NetScaler Zero Day Saga
September 29, 2026 | 1 min read
Researchers Warn of Citrix NetScaler Exploitation
September 29, 2026 | 3 min read
F5 CVE-2026-94127 Targeted in Active Attacks
September 24, 2026 | 3 min read
September 29, 2026 | 1 min read
September 29, 2026 | 1 min read
On Saturday, researchers from watchTowr Labs said they had credible information that attackers were exploiting an unknown RCE vulnerability in Citrix NetScaler boxes.
This vulnerability allows for unauthenticated remote code execution and shows how a missing bounds check—a classic programming error.
Cisco Talos researchers identified ClosedQuorum, a Windows implant that uses multiple LLMs to autonomously select attack actions. The catch: there’s no confirmation that it’s actually been deployed in the wild.
Read More Researchers Find Windows Malware With Autonomous C2 Functionality
Attackers impersonated LastPass Authenticator on fake GitHub pages to deliver the Rapuncel infostealer in a campaign involving 40 fake brands.
Read More Fake LastPass Authenticator Pages Deliver Rapuncel Infostealer
Let’s ask a simple question that seems to be getting lost in all of the credulous fervor around AI: How’s this working out for everyone?
Read More ‘We Have Enough AI’: Realism in a Time of Relentless Hype
Active since at least August 2025, the malware represents a functional pivot from the threat actor’s existing SparrowDoor backdoor.