Security news.
Critical edge infrastructure faces active zero-day exploitation this week, with CISA ordering emergency remediation for multiple Citrix NetScaler flaws under active attack. Meanwhile, threat actors are leveraging WAF-bypass techniques against enterprise platforms and deploying autonomous AI tools to compromise cloud and container environments. IT teams should prioritize perimeter patching and audit privileged service identities across hybrid environments.
CISA Warns of Active Exploitation in Critical Citrix NetScaler Flaws
CISA added two critical NetScaler ADC and Gateway zero-days (CVE-2026-88771 and CVE-2026-88772) to its Known Exploited Vulnerabilities catalog following widespread global attacks that allow unauthenticated remote code execution.
ShinyHunters Exploiting Oracle PeopleSoft via WAF Bypass
The extortion syndicate has modified its attack chain with URL-encoding evasion techniques to bypass web application firewalls and exploit remote code execution flaw CVE-2026-35273 across enterprise targets.
Microsoft SharePoint Code Injection Flaw Added to CISA KEV
Federal agencies face an urgent patching mandate after CISA confirmed active exploitation of CVE-2026-65660, a high-severity code injection vulnerability impacting SharePoint deployments.
Storm-3168 Hijacks Azure Service Principals for Cloud Destruction
Attackers tied to JADEPUFFER compromised privileged cloud service principals to conduct automated reconnaissance and mass-delete resources within victim Microsoft Azure tenants.
Cloudflare Patches Cross-Tenant Isolation Flaw in Containers
A resolved vulnerability in Cloudflare Containers and Sandboxes allowed paid Workers accounts to recover residual execution data belonging to co-located customer containers on shared physical hardware.
Carbonato Botnet Exploits Docker Daemons to Deploy AI Implants
Adversaries are targeting exposed Docker engines to deploy Hermes AI agent frameworks modified via injected system prompts to run tasks commanded through Telegram.
Kiteworks Advises Server Shutdowns Over Advanced Forms Vulnerability
Kiteworks issued precautionary shutdown guidance to enterprise customers while addressing a newly discovered security flaw within its Advanced Forms server platform.
Bitget Resumes Operations Following $387 Million Cyber Heist
Crypto exchange Bitget restored Bitcoin withdrawals after suspected North Korean threat actors breached internal infrastructure and siphoned over $350 million in assets.