Security news.
Critical zero-day exploitation headlines today's brief as CISA mandates urgent remediation for actively abused Citrix NetScaler vulnerabilities. Meanwhile, high-impact cyber incidents include a massive $388 million cryptocurrency theft and agentic AI-driven destruction of enterprise cloud infrastructure. Security teams should also review configurations following mass database and credential exposure reports.
CISA Adds Actively Exploited Citrix NetScaler Zero-Days to KEV Catalog
Attackers are actively targeting two critical vulnerabilities, CVE-2026-88771 and CVE-2026-88772, in Citrix NetScaler ADC and Gateway to achieve remote code execution. CISA has added both flaws to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch immediately.
Bitget Suffers $388 Million Heist via Third-Party Security Vulnerability
Cryptocurrency exchange Bitget revealed that an attacker leveraged a security flaw in a third-party product to harvest high-level credentials and execute unauthorized withdrawals totaling $388 million.
JadePuffer Deploys Agentic AI to Destroy Azure Cloud Environments
The threat actor tracked as JadePuffer (Storm-3168) used compromised service principals and autonomous agent-driven attacks to conduct automated reconnaissance, harvest credentials, and delete enterprise Azure infrastructure.
Misconfigured Supabase Applications Expose Over 16,000 Databases
Security researchers uncovered more than 16,000 publicly accessible Supabase databases exposing sensitive information, including user credentials, authentication tokens, and personally identifiable data, due to insecure default configurations.
Dutch Authorities Arrest Suspect in ShinyHunters Extortion Investigation
Police in the Netherlands detained a 24-year-old in connection with data theft and extortion operations orchestrated by the notorious ShinyHunters hacking collective.
Cloudflare Patches Cross-Tenant Data Isolation Flaw in Containers
A resolved issue in Cloudflare Containers and Sandboxes allowed paid Workers accounts to retrieve residual, co-located data belonging to other tenants running on the same underlying physical host.
Infostealer Logs Reveal Stolen AI Account Credentials Across 80,000 Organizations
Analysis of malware log caches identified compromised AI service logins spanning tens of thousands of business domains, leaving organizations vulnerable to LLMjacking and conversational data exfiltration.