Security news.
Active zero-day exploitation and critical edge-device vulnerabilities dominate today's briefing, with CISA issuing emergency directives for Citrix NetScaler appliances. Meanwhile, threat actors continue to weaponize enterprise collaboration tools and Kubernetes environments for initial access and lateral movement. Defenders are urged to prioritize external-facing appliance patches and review privileged service accounts.
CISA Adds Actively Exploited Citrix NetScaler Flaw to KEV
CISA has added CVE-2026-88779, a critical memory buffer boundary vulnerability affecting Citrix NetScaler appliances, to its Known Exploited Vulnerabilities catalog following confirmed in-the-wild exploitation.
Dell Patches Maximum-Severity Flaws in Container Storage Modules
Dell resolved multiple critical bugs, including CVE-2026-63688 (CVSS 10.0), that allow unauthenticated remote attackers to bypass authentication and gain root-level execution across Kubernetes cluster nodes.
GitLab Resolves Critical RCE in Duo AI Gateway Service
A critical 9.9 CVSS vulnerability in self-hosted GitLab AI Gateway instances enabled authenticated users with Duo access to execute arbitrary system commands on underlying host environments.
Warlock Threat Group Targets SharePoint in Ransomware Intrusions
The China-linked threat group Warlock is actively weaponizing Microsoft SharePoint vulnerabilities to bypass endpoint security controls and deploy ransomware against government and critical infrastructure targets.
China-Aligned TA419 Targets AI Policy Experts with AitM Phishing
Espionage group TA419 launched targeted adversary-in-the-middle phishing attacks against think tanks and policymakers by impersonating prominent AI researchers and Anthropic staff.
ShinyHunters Extortion Suspect Detained in Jordan
A key ShinyHunters member known as "Rey" (Saif al-Din Khader) was arrested by Jordanian authorities and is reportedly aiding the FBI in tracking other members of the data extortion syndicate.
Fortra Patches Authentication Bypass and Shell RCE in BoKS
Fortra delivered urgent security updates for its BoKS Server product to resolve high-severity flaws that could allow attackers to bypass central authentication controls and execute shell commands.