TL;DR for CISOs: Citrix has patched a third NetScaler flaw to be exploited within days, this one in SAML-configured appliances, and attackers reportedly hit systems that had just been updated. Separately, Symantec and The Hacker News describe a ransomware group using SharePoint flaws and a vulnerable driver to disable security tools on dozens of hosts at once, and reporting says a suspected ShinyHunters administrator is cooperating with the FBI.
- Internet-facing gateways are being attacked in waves. A team that patched NetScaler last week may need to patch again this week, so the process has to assume repeat cycles rather than a single event.
- Ransomware crews still win on known flaws. The SharePoint vulnerabilities in the Warlock reporting have had patches available for over a year.
- An arrest does not return stolen data. Treat extortion exposure from groups like ShinyHunters as continuing until your own review says otherwise.
Lead story: Citrix patches a third exploited NetScaler flaw in days, this time in SAML deployments
CRITICAL · ACTIVELY EXPLOITEDVulnerability: CVE-2026-88779, a memory overflow in NetScaler ADC and NetScaler Gateway, CVSS 8.7 as reported by BleepingComputer
Affected configuration: Appliances configured as a SAML service provider or SAML identity provider
Citrix assessment: Targeted attacks on unmitigated deployments can cause denial of service; Citrix reports no evidence of data integrity compromise (as reported by SecurityWeek)
Unconfirmed claim: BleepingComputer cites researchers who say crafted authentication requests tried to download and run payloads, which would point beyond denial of service. Citrix has not confirmed this
Fixed builds: 14.1-73.41 and 13.1-64.28
CISA: Added to the Known Exploited Vulnerabilities catalog on October 4, with a federal remediation date of October 7 (as reported by BleepingComputer). SecurityWeek counts it as the sixth NetScaler flaw added to the catalog in 2026
Context: It follows CVE-2026-88771 and CVE-2026-88772, both exploited before patches were available
What happened
Citrix released fixed NetScaler builds for CVE-2026-88779 on October 3 or 4; Tenable and BleepingComputer give different dates. The flaw affects appliances that handle SAML sign-in, a common setup for single sign-on to internal applications.
SecurityWeek reports that researcher Kevin Beaumont observed exploitation attempts against fully updated honeypot instances. In other words, the attempts were aimed at systems that had absorbed the patches issued days earlier for the two prior NetScaler flaws. Tenable's timeline places those earlier patches on September 27 and says Mandiant and Google Threat Intelligence Group put exploitation of CVE-2026-88772 at early September at the latest.
Tenable lists confirmed compromises from earlier in the sequence across government, education, technology, financial services and legal organizations in North America, Europe and Australia. Those compromises relate to the earlier flaws, not necessarily this one. SecurityWeek also notes that the previous two flaws strained vendor support, with long queues and interim mitigations that did not always prevent crashes.
Evidence
Verified against independently fetched sources:
1. BleepingComputer, Citrix patches NetScaler SAML zero-day exploited in attacks
2. SecurityWeek, Exploitation of Citrix NetScaler zero-day hits appliances patched days earlier
3. Tenable, Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities
What this means for your team
The risk here is less any single CVE than the cadence. Three exploited flaws in one product within a few weeks means a patch window that closes on Friday can reopen on Monday. If your change process needs a week of approvals for an edge appliance, it is slower than the attackers' release cycle.
Whether the flaw stops at denial of service or reaches code execution matters for how you triage, but you do not need to settle it before acting. A SAML-configured NetScaler is an authentication front door. If it is unstable or compromised, your single sign-on path is affected either way. Treat the unconfirmed execution claim as a reason to review logs, not as a reason to wait.
Also check your assumptions about what "patched" means. Teams that applied the September fixes may still be exposed here, so confirm build numbers directly on the appliances instead of relying on a ticket status.
- Inventory every NetScaler ADC and Gateway, then check each for a SAML service provider or identity provider profile in its configuration.
- Upgrade affected appliances to a fixed build (14.1-73.41 or 13.1-64.28) and confirm the running version on the device, not only in change records.
- Review appliance logs for unexpected reboots, crashes and unusual SAML authentication requests since early September, and escalate to Citrix support if you find them.
- Agree in advance who can approve emergency edge-device patches outside the normal window, so the next cycle takes hours rather than days.
Warlock ransomware operators keep using SharePoint flaws and a vulnerable driver against critical infrastructure
HIGH · RANSOMWAREActor: Tracked by Symantec as Longlegs and also known as Storm-2603; the group deploys Warlock ransomware and is described by The Hacker News as China-linked
Victims reported: At least four organizations over roughly two months, including critical infrastructure operators, mainly in Portuguese- and Spanish-speaking regions
Initial access: Exploitation of on-premises SharePoint Server flaws, including the ToolShell chain, with a web shell dropped in the LAYOUTS directory and stolen machine keys used to forge payloads
Defense evasion: The vulnerable K7RKScan driver (CVE-2025-1055) used to disable security software; in one intrusion, tools were pushed to about 40 hosts within roughly two hours, followed by ransomware on at least 33 hosts
Spread: Ransomware staged in the SYSVOL domain share; Visual Studio Code tunnels used for persistent access
Reported: Symantec, October 1; The Hacker News, October 3
What happened
Symantec's threat hunters describe intrusions in which the attackers reach an unpatched on-premises SharePoint server, place a web shell, and use extracted ASP.NET machine keys to run code. From there they move to domain-level tooling.
The reported speed is the notable part. In one case the group disabled endpoint protection across about 40 machines in around two hours and then launched ransomware on at least 33. Symantec says it stages the payload in SYSVOL, the share that domain controllers replicate to member machines, which lets it spread without a separate delivery step.
Evidence
Verified against independently fetched sources:
1. Symantec Threat Intelligence, Warlock Ransomware Attackers Hit Water and Telecom Operators
2. The Hacker News, Warlock exploits SharePoint flaws to deploy ransomware
What this means for your team
This is a case for treating on-premises SharePoint as an internet-facing risk until its patch level is proven. The vulnerabilities involved date from 2025, so exposure now reflects a patching and inventory gap rather than a new weakness.
The second lesson is about endpoint tooling. If an attacker with administrative rights can load a signed but vulnerable driver and switch off your agents, the agent is not a control you can rely on in isolation. Driver blocking and monitoring of changes to security tooling need to sit alongside it.
- Confirm patch status for CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771 on every on-premises SharePoint server, and rotate ASP.NET machine keys where compromise is possible.
- Check SharePoint LAYOUTS directories for unexpected files and review web server logs for the same period.
- Alert on new files in SYSVOL and on endpoint agent stops or removals across multiple hosts in a short window.
- Enable vulnerable driver blocking and verify that security software has tamper protection turned on.
A suspected ShinyHunters administrator is reportedly detained in Jordan and cooperating with the FBI
NOTABLE · REPORTED, NOT OFFICIALLY CONFIRMEDReported event: A suspected member of the extortion group was detained in Jordan, with the detention dated to September 29 by The Hacker News
Sourcing: Both outlets attribute the account to Reuters and unnamed sources; neither reports an official statement confirming the cooperation
Reported role: Described by The Hacker News as one of three administrators of the combined Scattered LAPSUS$ Hunters collective
Scale cited: The Hacker News reports that FBI officials say the group has breached more than 140 organizations and extorted at least $70 million
Context: Follows the arrest of a 24-year-old in Amsterdam on September 15 or 16, depending on the account
What happened
Reuters, as relayed by BleepingComputer and The Hacker News, reports that a suspected administrator of the group has been detained in Jordan and is helping investigators identify others. BleepingComputer adds that signs of disruption, including the group's leak site going offline, appeared around the same time. These details come from unnamed sources and have not been independently confirmed by authorities.
Evidence
Verified against independently fetched sources:
1. BleepingComputer, ShinyHunters hacker reportedly detained in Jordan, aiding FBI
2. The Hacker News, ShinyHunters suspect reportedly detained in Jordan, assisting investigators
What this means for your team
Enforcement news changes the odds of future attacks, but not the status of data already taken. If your organization was touched by a ShinyHunters-linked incident, assume stolen data can still be sold, leaked or used for follow-on fraud.
The group's reported pattern centers on persuading people and abusing connected SaaS access, so the useful response is on the identity side: who can reset credentials, and who can approve new integrations.
- Re-confirm help desk verification steps for password resets and multi-factor enrollment changes.
- Review OAuth grants and API tokens on core SaaS platforms and remove any you cannot attribute to an owner.
- Keep monitoring for leaked credentials and customer data tied to any prior incident, even if the group goes quiet.
Also notable
- Technical University of Denmark: DTU said attackers used compromised credentials to reach its identity management system and download personal data, with up to 200,000 current and former users potentially affected, including Danish civil registration numbers. The attacker is not identified. Single source, not yet independently verified: BleepingComputer.
- Fortra BoKS: Fortra patched critical flaws that could allow authentication bypass, shell command execution and memory corruption. Single source: SecurityWeek.
Frequently asked questions
What is CVE-2026-88779?
A memory overflow in NetScaler ADC and Gateway appliances configured for SAML authentication. Citrix says attacks on unmitigated systems can cause denial of service, and CISA lists it as exploited.
Which NetScaler builds fix it?
BleepingComputer reports builds 14.1-73.41 and 13.1-64.28. Confirm against Citrix's own bulletin for your release.
Does it allow remote code execution?
Citrix describes denial of service. BleepingComputer cites researchers who saw requests trying to download and run payloads, which Citrix has not confirmed.
Who is affected by the Warlock campaign?
Organizations running unpatched on-premises SharePoint Server. Reported victims so far are mostly in Portuguese- and Spanish-speaking regions.
Is the ShinyHunters detention confirmed?
It is reported by Reuters through BleepingComputer and The Hacker News, citing unnamed sources. Authorities have not published confirmation in the sources we reviewed.
What should a CISO do first this week?
Check NetScaler SAML configurations and build numbers, verify SharePoint patch levels, and confirm who can approve emergency patching of edge devices.
Curated by Pritha Aash, Community Head, CISO Platform
Subscribe to the weekly newsletter
More from the Breach Intelligence hub, identity security and ransomware coverage on CISO Platform.
Corrections and takedown requests: CISO Platform is committed to accuracy and fairness. If any detail in this briefing is inaccurate, or if you represent an affected organization and would like a correction or removal, please contact us at pritha.aash@cisoplatform.com and we will review your request promptly.

Comments