Security news.
Today's security updates are dominated by zero-day exploitation targeting Citrix NetScaler deployments alongside newly reported in-the-wild attacks on Rejetto HTTP File Server. High-profile law enforcement actions also take center stage, including the arrest of an alleged ShinyHunters extortionist and the developer behind Ploutus ATM malware. In addition, organizations face newly documented Linux backdoors and targeted spear-phishing campaigns hitting the AI research sector.
CISA Adds Exploited Citrix NetScaler Zero-Day to KEV Catalog
CISA has mandated federal remediation for CVE-2026-88779 (CVSS 8.7), a memory overflow flaw in Citrix NetScaler ADC and Gateway actively leveraged in targeted attacks against SAML deployments.
Attackers Target Rejetto HFS Flaw to Achieve Admin Access and RCE
Threat actors are actively exploiting CVE-2026-61500 (CVSS 9.3), a session forgery vulnerability caused by weak PRNG implementations that allows attackers to forge administrative cookies and execute arbitrary code.
ClingSTUN Linux Backdoor Exploits Multiple Flaws and Abuses STUN Protocol
A newly discovered backdoor dubbed ClingSTUN leverages the Session Traversal Utilities for NAT (STUN) protocol to configure back-connect proxies, establish persistence, and self-propagate across network assets.
Alleged ShinyHunters Extortion Group Member Arrested in Jordan
A suspected member of the prolific data theft and extortion syndicate known online as "Rey" has been detained in Jordan and is reportedly assisting the FBI in tracking other members of the group.
DOJ Announces Arrest of Alleged Ploutus ATM Malware Developer
Federal authorities have taken into custody the suspected creator behind the Ploutus malware family, which has been deployed to facilitate millions in ATM jackpotting heists across the United States.
China-Linked TA419 Targets U.S. AI Policy Experts in AitM Phishing Push
Cyber espionage operators have orchestrated adversary-in-the-middle credential phishing attacks impersonating high-profile researchers, think tank leaders, and Anthropic staff to compromise key AI policymakers.
GitLab Fixes Critical Command Execution Flaw in AI Gateway
A high-severity vulnerability carrying a 9.9 CVSS score could allow authenticated users with Duo Agent Platform access to execute unauthorized commands on self-hosted AI Gateway instances.
Google Halts Open Source Bug Bounty Submissions Over AI Spam Surge
Google has temporarily suspended inbound vulnerability submissions to its Open Source Software Vulnerability Rewards Program after an influx of low-quality, automated AI-generated vulnerability reports overwhelmed triage teams.