Sep 30
The Hot Drop for 09-30-2026
Citrix NetScaler zero-days granted root access for weeks. Did you know WHIPSHOT and SLAPSHOT shells are already inside your network? With CISA mandating patches by September 30, are you patched or are you next?
Since the last show: 2 new · 8 developing · 4 dropped · 57% overlap with the previous show
Contents
- Citrix NetScaler Zero-Days Exploited for Weeks
- Citrix NetScaler Zero-Days Exploited for Root Access
- Citrix NetScaler Exploitation Confirmed
- Apple Patches CoreGraphics Zero-Day CVE-2026-86950 Exploited in Targeted Attacks
- Palo Alto Networks’ OperTraitor Exposes IBM Turbonomic RBAC Flaw
- XBOW AI Agent Discovers CVE-2026-72018: Linux Kernel Flaw Enables Local Root Escalation
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach Universities, FBI, and Nissan
- Sysdig documents JADEPUFFER, the first end-to-end AI-driven ransomware operation exploiting Langflow
- New Spectre v2 Variant Leaks Linux Root Hashes via JIT Engines
- Infostealers Drive 74% Surge in Cookie Theft
1. Citrix NetScaler Zero-Days Exploited for Weeks (Lead)
1 new indicator(s) observed
Citrix NetScaler appliances are under active attack from two critical zero-day flaws that have been exploited for weeks. On September twenty-seventh, Citrix patched eight vulnerabilities, including CVE-2026-88771 and CVE-2026-88772, which allow unauthenticated remote code execution. CISA immediately added these vulnerabilities to its Known Exploited Vulnerabilities catalog, mandating that federal agencies apply the patches by September 30, 2026. GreyNoise confirmed exploitation attempts on September twenty-fourth from IP 149[.]104[.]78[.]141, though reports conflict on the campaign’s start date, with some citing activity as early as January. Attackers use these flaws to gain root access, deploy webshells like WHIPSHOT and SLAPSHOT, and exfiltrate data to Hetzner servers. If you run NetScaler ADC or Gateway, verify you are on version 14.1-73.37 or 13.1-64.23 immediately. The primary signal to watch is any outbound connection to Hetzner infrastructure or the specific IP 149[.]104[.]78[.]141. The Dutch National Cyber Security Center and Citrix confirmed that APT groups and ransomware affiliates are actively exploiting NetScaler ADC appliances. Verification shows the flaws allow unauthenticated remote attackers to execute arbitrary commands without valid credentials or user accounts.
Attackers exploit CVE-2026-88771 in Citrix NetScaler ADC before version 14.1-73.37 to run arbitrary commands via improper input validation. NetScaler Gateway 14.1 misreads input past its buffer boundary when acting as an RDP Proxy. The weakness allows attackers to bypass standard access controls on these appliances, enabling unauthorized traffic manipulation. An attacker observes prior token values to calculate the exact next value, bypassing standard session validation without network access. Citrix NetScaler ADC before version 14.1-73.37 mishandles HTTP request smuggling, allowing attackers to inject unauthorized requests into back-end servers. An attacker exploits this weakness to bypass feature restrictions without needing prior authentication or privilege. The attack chain relies on improper input validation and memory overflow issues in the NetScaler client authentication process, which allow an attacker to bypass security restrictions and gain root access. Once initial access is achieved, the exploit enables the execution of arbitrary commands on the appliance, facilitating the deployment of webshells and data exfiltration. Citrix NetScaler ADC and Gateway versions before 14.1-73.37 face a feature policy bypass via improper HTTP URL expression. This out-of-bounds read exposes sensitive data with a CVSS 7.5 score, affecting only Gateway and AAA virtual servers. Today, NetScaler ADC and Gateway versions 14.1 through 73.32 remain exposed to CVE-2026-19490 within the broader set of ten related CVEs. Today’s Citrix NetScaler ADC update before 14.1-73.37 exposes CWE-342 via predictable session tokens, yielding high confidentiality impact. This unauthenticated command injection affects all NetScaler appliances in default configurations, enabling attackers to crash systems and consume critical CPU resources. This unauthenticated remote code execution grants full system control, enabling denial of service or data theft on affected appliances. This improper input validation flaw allows unauthenticated attackers to crash the device or elevate privileges on versions before 14.1-73.37. This weakness, tracked as CWE-444, specifically targets the NetScaler Gateway and ADC products running older Citrix releases. The scope of the impact includes all internet-facing Citrix NetScaler ADC and Gateway appliances running versions prior to the September 27, 2026, security updates. Consequences of successful exploitation include full system compromise, where attackers gain root access to deploy persistent webshells and exfiltrate sensitive data to external infrastructure. Attackers exploited Citrix NetScaler ADC and Gateway versions before 14.1-73.37 via remote code execution, achieving high impact without user interaction. Active exploitation by APT and ransomware groups has already compromised NetScaler instances, confirming internet-facing appliances are under direct attack. The vulnerabilities require only network access to execute arbitrary commands, so the absence of valid user credentials offers no defense. Defenders gain distinct value by isolating these NetScaler versions from the broader set of ten related CVEs affecting Citrix infrastructure. Attacker IP 149[.]104[.]78[.]141 probed and modified setuid bits, indicating a sophisticated post-exploitation phase that standard RCE monitoring misses. The remaining uncertainty is whether attackers established persistence via webshells, making forensic review of NetScaler logs for base64-encoded commands and verification of no active C2 connections the most useful investigation focus.
Operators must isolate affected NetScaler ADC versions today until the specific patch arrives. Verify your NetScaler inventory against the affected version ranges to confirm exposure status. Apply the Citrix security updates released on September 27, 2026, to all NetScaler ADC and Gateway appliances to close the remote code execution and denial-of-service vectors. Federal agencies must complete the installation of these mitigations by September 30, 2026, to comply with the CISA Known Exploited Vulnerabilities catalog mandate. Immediate patching to version 14.1-73.37 or later is the only effective mitigation for this critical command-injection flaw. This unauthenticated command injection allows full system compromise, so patching is urgent. No other mitigation exists for this active exploitation chain. Patch NetScaler Gateway before 14.1-73.37 immediately to stop this predictable value chain from leaking session data. Defenders must patch all NetScaler appliances to versions 14.1-73.37 or later to close the remote code execution path. Defenders must patch affected appliances immediately to stop the active exploitation chain targeting these critical remote code execution flaws.
Static analysis detects the flaw, but the exact patch release date remains unconfirmed. CISA lists this as known exploited, yet specific attack indicators for CVE-2026-88772 are unconfirmed in the current event set. Although the flaws require zero valid credentials, the scope of lateral movement and data exfiltration depends on the internal network configuration of the compromised appliance. The exact timeline of initial compromise for specific organizations is not established, as reports conflict on whether activity began in January or more recently.
Vulnerabilities
- CVE-2026-88771 — CVSS 9.8 (Critical) · CISA KEV · CWE-20 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
- CVE-2026-88772 — CVSS 8.1 (High) · CISA KEV · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
- CVE-2025-5777 — CVSS 7.5 (High) · CISA KEV · CWE-125 · NetScaler ADC; NetScaler Gateway. Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
- CVE-2026-88778 — CVSS 7.5 (High) · CWE-342 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
- CVE-2026-19490 — CVSS 0 (Low) · CISA KEV · NetScaler ADC; NetScaler Gateway. Vulnerability in NetScaler ADC and NetScaler Gateway.
- CVE-2026-88773 — CVSS 0 (Low) · CWE-444 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Inconsistent interpretation of HTTP requests (‘HTTP Request/Response smuggling’) vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
- CVE-2026-88774 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
- CVE-2026-88775 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
- CVE-2026-88776 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
- CVE-2026-88777 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
Techniques
- T1021.007 Cloud Services (Lateral Movement)
- T1087.001 Local Account (Discovery)
- T1133 External Remote Services (Persistence)
- T1136.001 Local Account (Persistence)
- T1190 Exploit Public-Facing Application (Initial Access)
- T1202 Indirect Command Execution (Stealth)
- T1203 Exploitation for Client Execution (Execution)
- T1204.002 Malicious File (Execution)
- T1210 Exploitation of Remote Services (Lateral Movement)
- T1211 Exploitation for Stealth (Stealth)
- and 4 more
Indicators
- 14 indicators on file
Coverage
- CVE-2026-88771: Citrix NetScaler: Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway
- Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772
- Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778
- CISA Warns of Citrix NetScaler 0-Day RCE Vulnerabilities Exploited in Attacks
- CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
- Citrix Products Multiple Vulnerabilities
- Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)
- GreyNoise Timeline: Citrix CVE-2026-88771
- Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771)
- Andrew Thompson (@ImposeCost) on X
-
[Kwetsbaarheden in Citrix NetScaler ADC en NetScaler Gateway: update nu NCSC](https://ncsc.nl/alerts/kwetsbaarheden-in-citrix-netscaler-adc-en-netscaler-gateway-update-nu) - Citrix urges immediate upgrades of NetScaler amid widespread exploitation attempts
- Swarming Against Citrix 0-Day Exploitation
- US, UK warn of exploited Citrix NetScaler zero-day bugs
- Citrix NetScaler Zero-Day Vulnerabilities FAQ: CVE-2026–88771 and CVE-2026–88772
- Citrix NetScaler RCE zero-day Vulnerabilities
- Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings
- Citrix NetScaler exploitation began days before public notification
- NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)
- Sept 28 Advisory: Citrix NetScaler ADC and NetScaler Gateway Zero-Day Remote Code Execution [CVE-2026-88771, CVE-2026-88772] - Censys
- Taking ‘execute logging’ a bit too literally - CVE-2026-88771
- Unit 42 (@Unit42_Intel) on X
- Citrix NetScaler Zero-Day Exploitation: How Attackers Weaponized CVE-2026–88771 and CVE-2026–88772…
- Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks
2. Citrix NetScaler Zero-Days Exploited for Root Access (Segment)
Event now covered by 4 outlets (was 3)
What changed
Mandiant and Google Threat Intelligence Group confirmed that unknown actors actively exploited two critical Citrix NetScaler zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, since early September 2026. The surge in mass exploitation peaked on September 28, with GreyNoise catching an attack from IP 149[.]104[.]78[.]141 installing a web shell three days before public disclosure. The attackers deploy two distinct tools: WHIPSHOT, a PHP web shell disguised as a Debian package, and SLAPSHOT, a Python tunneler used for internal reconnaissance. The fix involves a buffer size check in the NSPPE function to prevent oversized NSB chain copying. This is a high-severity threat listed in the CISA KEV catalog with a CVSS score of 9.8. You must investigate for modified Apache configurations and stolen credentials immediately. Watch for the specific IP 149[.]104[.]78[.]141 in your logs, and verify if any NetScaler gateways in your environment are running unpatched builds. Since early September, attackers have hit ADC and Gateway appliances in North America and Europe, bypassing authentication via a DTLS memory overflow to seize root access on FreeBSD systems. The threat actor leveraged lightweight installer web shells to assert the setuid bit on the /bin/sh executable, establishing persistent root-level execution on the compromised appliances. Researchers have verified that the attackers conducted credential theft and deployed custom malware to breach targets across multiple sectors.
How it works
Citrix NetScaler ADC versions before 14.1-73.37 allow unauthenticated attackers to run arbitrary commands through improper input validation. This weakness requires only high access complexity, enabling full system compromise without user interaction. The flaw lets adversaries observe prior values to derive the exact next token without network access. It also permits Cross Zone Scripting, where a zone-aware browser loads malicious content that bypasses security zone controls. Additionally, the software allows attackers to bypass feature policies by exploiting improper HTTP URL expression handling. A memory overflow causes denial of service when attackers trigger the overflow. An attacker triggers this overflow without authentication, causing unpredictable behavior in the gateway. Finally, attackers exploit a DTLS memory overflow in the Packet Processing Engine to bypass authentication, trigger unhandled termination, and seize root access on FreeBSD systems. Citrix NetScaler ADC versions prior to 14.1-73.37 face a high-severity remote code execution flaw, CVE-2026-88772, with a CVSS score of 8.1. The vulnerability allows attackers to predict session tokens via CWE-342, enabling Cross Zone Scripting and client-side injection-induced buffer overflow. This mechanism yields full compromise with a CVSS score of 9.8, granting complete control over the appliance without authentication. The flaw also enables privilege elevation through Cross Zone Scripting, causing crashes that consume critical CPU and memory resources. Attackers can access restricted features in older Gateway and ADC products and crash the system without prior authentication. The corruption affects organizations in North America and Europe across government, financial services, education, legal, and professional services sectors. The threat actor deployed multiple PHP web shells and a tunneler malware to proxy traffic into the victim network. This activity facilitated internal reconnaissance, lateral movement, and credential harvesting.
What to do
Citrix NetScaler ADC before 14.1-73.37 is vulnerable to HTTP request smuggling, allowing attackers to inject unauthorized requests through the load balancer. This specific vulnerability is the second of eight related Citrix issues in the current event set, distinguishing it by its direct remote execution path. The confirmed deployment of PHP web shells and Python tunnelers on NetScaler appliances in North America and Europe indicates that compromised gateways are now serving as active proxies for internal reconnaissance and lateral movement. Because the threat actor uses these tools to harvest credentials and move laterally, the exposure extends beyond the initial appliance compromise to the entire internal network segment accessible from the gateway. Operators must patch versions prior to 14.1-73.37 immediately to stop the exploit chain that targets Citrix infrastructure. Apply the Citrix patch to update NetScaler ADC and Gateway appliances to version 14.1-73.37 or 13.1-64.23 to close the unauthenticated remote code execution vector defined in CVE-2026-88771. Investigate the appliances for modified Apache configurations and the presence of the WHIPSHOT PHP web shell or SLAPSHOT Python tunneler to identify and remove established persistence mechanisms before applying the patch. Operators must patch affected Citrix Gateways immediately to stop predictable token generation from enabling high-impact attacks. Defenders must patch versions before 14.1-73.37 immediately to prevent the high-impact resource consumption and privilege elevation. Defenders must apply the latest Citrix NetScaler Gateway 14.1-73.37 patch immediately to close this high-severity access path. Defenders must isolate the NetScaler Gateway and Gateway before 13.1-64.23 immediately, as the client-side injection indicator shows a crash after downloading code. Defenders must patch immediately to prevent resource exhaustion crashes, as static analysis tools can detect the missing validation logic in affected code paths. Defenders must patch immediately to prevent back-end servers from receiving secret malicious HTTP requests. Operators must upgrade affected Citrix NetScaler systems immediately to versions 14.1-73.37 or later to close this bypass vector. Immediate patching is required for all affected versions to stop the cross-zone scripting and client-side injection attacks.
Limits and watch
We cannot confirm a patch date yet, but unpatched systems remain exposed until Citrix releases the fix. It is not yet established which specific internal systems were accessed via the SLAPSHOT tunneler, meaning the extent of internal reconnaissance and data exfiltration across the affected government and financial sectors is currently unknown. Watch for inbound network access to remote service ports that correlates with near-time instability, such as crashes or abnormal restarts, in NetScaler daemons to detect potential exploitation of remote services for lateral movement.
Vulnerabilities
- CVE-2026-88771 — CVSS 9.8 (Critical) · CISA KEV · CWE-20 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
- CVE-2026-88772 — CVSS 8.1 (High) · CISA KEV · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
- CVE-2026-88778 — CVSS 7.5 (High) · CWE-342 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
- CVE-2026-88773 — CVSS 0 (Low) · CWE-444 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Inconsistent interpretation of HTTP requests (‘HTTP Request/Response smuggling’) vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
- CVE-2026-88774 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
- CVE-2026-88775 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
- CVE-2026-88776 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
- CVE-2026-88777 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
Techniques
- T1021.001 Remote Desktop Protocol (Lateral Movement)
- T1102 Web Service (Command And Control)
- T1133 External Remote Services (Persistence)
- T1190 Exploit Public-Facing Application (Initial Access)
- T1203 Exploitation for Client Execution (Execution)
- T1204.002 Malicious File (Execution)
- T1210 Exploitation of Remote Services (Lateral Movement)
- T1212 Exploitation for Credential Access (Credential Access)
- T1499.004 Application or System Exploitation (Impact)
- T1505.003 Web Shell (Persistence)
- and 3 more
Indicators
- 1 indicator on file
Coverage
- Here We Go Again (Citrix NetScaler DTLS Preauth Memory Overflow CVE-2026-88772)
- Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services
- Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances
- CVE-2026-88772: Citrix NetScaler: Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway
- GitHub - watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772
- Hackers exploit Citrix NetScaler zero-day to deploy web shells
- Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT
- Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)
- WHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaign
- Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution
- Hackers Exploit Citrix NetScaler Zero-Day to Gain Root Access and Deploy Web Shells
3. Citrix NetScaler Exploitation Confirmed (Segment)
Event first seen in a show
Threat actors are actively exploiting a critical insufficient input validation vulnerability in Citrix NetScaler ADC and NetScaler Gateway products. Researchers at watchTowr confirmed attacks began on March twenty-seventh, targeting CVE-2026-3055. watchTowr suggests the single CVE ID may mask multiple closely related flaws, including a race condition tracked as CVE-2026-4368. The lead sheet details the specific firmware versions and the CISA deadline. CISA added CVE-2026-3055 to its Known Exploited Vulnerabilities catalog, requiring Federal Civilian Executive Branch agencies to remediate by April 2. Watch for unauthorized session token generation or unexpected credential access logs on your NetScaler appliances. If you cannot patch right now, apply Global Deny List signatures on supported builds to mitigate without a reboot.
Yesterday’s NetScaler Gateway 14[.]1[.]66[.]54 update fixed a race condition in Gateway mode that caused user session mixup. An attacker triggers this by sending malformed SAML tokens that force the ADC to read past its buffer boundary. This out-of-bounds read occurs because the product reads data past the end of the intended buffer, a weakness classified as CWE-125. Because the gateway reads past its buffer limits when handling SAML tokens, attackers can now extract cryptographic keys. Because the product reads past its buffer boundaries, an adversary who influences the input can expose sensitive memory addresses or bypass ASLR protections. Attackers exploiting this weakness could impersonate users during SSL VPN or RDP Proxy sessions without needing prior access. The flaw affects NetScaler ADC and Gateway versions 14.1 and 13.1, including FIPS and NDcPP variants, specifically when configured as SAML Identity Providers. Successful exploitation exposes secret values such as cryptographic keys and PII, and can leak memory addresses that bypass ASLR protections.
Because NetScaler appliances frequently sit in critical identity paths, the UK National Cyber Security Centre warns that widespread exposure allows attackers to retrieve session tokens and credentials through simple memory overreads. Update NetScaler ADC and Gateway instances to versions 14.1-66.59 or 13.1-62.23 to close the insufficient input validation flaw in SAML Identity Provider configurations. Operators must verify their appliance configuration matches the affected versions before applying the latest patch. Defenders must immediately validate all SAML inputs against known-good specifications to prevent this memory overread. Defenders must apply input validation to reject malformed SAML requests immediately to stop the overread.
WatchTowr analysis suggests the single CVE-2026-3055 identifier may mask multiple closely related memory leak flaws, complicating the scope of required remediation. The race condition tracked as CVE-2026-4368 affects specific Gateway and AAA virtual server configurations, meaning that patching only the SAML IDP flaw may leave session mixup vulnerabilities unaddressed. Check NetScaler access logs for abnormal request patterns to public endpoints that correlate with elevated 4xx or 5xx errors, indicating potential exploitation of the public-facing application.
Vulnerabilities
- CVE-2026-3055 — CVSS 9.8 (Critical) · CISA KEV · CWE-125 · NetScaler ADC; NetScaler Gateway. Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
- CVE-2026-4368 — CVSS 0 (Low) · NetScaler ADC; NetScaler Gateway. Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup
Techniques
- AML.T0106 Exploitation for Credential Access (Credential Access)
- T1190 Exploit Public-Facing Application (Initial Access)
- T1212 Exploitation for Credential Access (Credential Access)
- T1589.001 Credentials (Reconnaissance)
- T1590.006 Network Security Appliances (Reconnaissance)
- T1595.002 Vulnerability Scanning (Reconnaissance)
Indicators
- 1 indicator on file
Coverage
- Citrix NetScaler products confirmed to be under exploitation
- Citrix NetScaler bug may be multiple flaws in one
- Citrix Urges Immediate Patching for Critical NetScaler Vulnerabilities
4. Apple Patches CoreGraphics Zero-Day CVE-2026-86950 Exploited in Targeted Attacks (Segment)
CVE-2026-86950 added to CISA KEV catalog
What changed
Apple released emergency updates for iOS 26.7.1, iPadOS 26.7.1, and macOS on September 28, 2026, to close CVE-2026-86950. This zero-day out-of-bounds write vulnerability in the CoreGraphics framework enables arbitrary code execution when processing maliciously crafted files on devices ranging from iPhone 11 to the latest iPad models. Meta Product Security reported the bug, and exploitation was confirmed against specific individuals, including journalists and government officials, on iOS versions prior to iOS 27. CISA added this vulnerability to its Known Exploited Vulnerabilities catalog, requiring federal agencies to remediate it immediately under Binding Operational Directive 26-04. Apple confirmed that CVE-2026-86950 may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS versions prior to iOS 27. Check your endpoint logs for any CoreGraphics crashes or unusual file processing events from the past week. Focus your detection on the specific file types that trigger CoreGraphics parsing.
How it works
The attacker leveraged the missing bounds check by processing a malicious file to trigger arbitrary code execution with a CVSS score of 8.8, requiring only network access and no user interaction. The weakness stems from poor state management, allowing an adversary holding memory write privileges to corrupt the target process and execute their own payload. This vulnerability requires user interaction to open the crafted file, a precondition that aligns with the T1204.002 technique of user execution via malicious file download or open. The fix is available for iPhone 11 and later, iPad Pro models, iPad Air third generation and later, iPad eighth generation and later, and iPad mini fifth generation and later. Apple issued CVE-2026-86950 for a broader event, but this specific CVE targets high-value individuals through a sophisticated, pre-exploitation attack vector. Operators must distinguish this targeted event from the broader event involving CVE-2026-20700 because the access path and consequence differ significantly.
What to do
Because the flaw resides in CoreGraphics, any device processing a maliciously crafted file on an affected version is at risk of arbitrary code execution. Update macOS devices to Sequoia 15.8.1 or Tahoe 26.7.1 to ensure the improved bounds checking is active against malicious file processing.
Limits and watch
The evidence confirms exploitation against specific targeted individuals but does not specify the exact file types or delivery vectors used in the attacks. While CVE-2026-86950 is in the CISA KEV catalog, the related CVE-2026-20700 memory corruption issue has different access requirements and is not explicitly linked to the same targeted campaign. Watch for user execution of malicious files that trigger CoreGraphics parsing, specifically looking for file creation in user-controlled paths followed by unusual process spawns. Monitor for masquerading tactics where files use familiar naming conventions or password protection to increase the likelihood of user interaction with the malicious payload.
Vulnerabilities
- CVE-2026-86950 — CVSS 8.8 (High) · CISA KEV · Apple iOS and iPadOS; Apple macOS. An out-of-bounds write issue was addressed with improved bounds checking.
- CVE-2026-20700 — CVSS 7.8 (High) · CISA KEV · Apple iOS and iPadOS; Apple macOS; Apple tvOS. A memory corruption issue was addressed with improved state management.
Techniques
- T1204.002 Malicious File (Execution)
- T1213.005 Messaging Applications (Collection)
Indicators
- 1 indicator on file
Coverage
- Apple Fixes iOS Zero-Day Exploited in Sophisticated Targeted Attacks
- Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
- Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950), (Mon, Sep 28th)
- About the security content of iOS 26.7.1 and iPadOS 26.7.1 - Apple Support
- Critical Apple Zero-Day Vulnerability Actively Exploited in Attacks
- Apple patches CoreGraphics zero-day already exploited in targeted attacks
- Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950)
- Update your iPhone, iPad, or Mac: Flaw could run attackers’ code
- CISA Adds One Known Exploited Vulnerability to Catalog
5. Palo Alto Networks’ OperTraitor Exposes IBM Turbonomic RBAC Flaw (Segment)
Event first seen in a show
What changed
Palo Alto Networks released OperTraitor, an open-source tool that scans Kubernetes operator manifests to identify excessive role-based access control permissions. The tool immediately flagged a critical flaw in IBM’s Turbonomic Prometurbo agent, now tracked as CVE-2026-6389. IBM Turbonomic versions 8.16.0 through 8.17.6 carry a vulnerability rated 8.8 on the CVSS scale. IBM confirmed the issue and released version 8.18.0 as the fix. Researcher Lior Yakim reported the flaw to IBM in November 2025, with remediation confirmed in February 2026. Map your service accounts against their actual operational requirements using tools like OperTraitor. Watch for any Turbonomic instance running below version 8.18.0, particularly if it holds cluster-admin or broad secret-get permissions.
How it works
Attackers exploit a flaw in IBM Turbonomic prometurbo agent versions 8.16.0 through 8.17.6 to gain unrestricted read access to all cluster secrets. The product grants excessive cluster-wide permissions, allowing privilege escalation from a low-trust operator to full cluster control. An attacker with any operator or service account access exploits the lack of access control to exfiltrate credentials and escalate privileges. Palo Alto’s analysis suggests that over five percent of examined operators requested privileges far beyond their operational needs, indicating a broader pattern of excessive RBAC permissions in Kubernetes environments.
What to do
The IBM Turbonomic flaw exposes a critical weakness where a compromised service account can exfiltrate cluster-wide secrets, leading to full cluster compromise. Because this weakness grants full cluster compromise, immediate architecture redesign to enforce separation of privilege is the only viable mitigation. While MFA and strict User Account Management policies are standard framework mitigations for account compromise, the evidence here shows that the immediate threat is the pre-existing over-privileged role binding itself, not just the authentication method. The uncertainty remains whether an adversary has already modified the service account to add additional roles or bindings, a change that could follow initial compromise to maintain persistent access. Therefore, the most useful decision priority is to map every service account against its actual operational requirements immediately, rather than waiting for a breach, because the tool’s findings suggest that the permission gap is the primary vector for the cluster-wide compromise. Re-install IBM Turbonomic Prometurbo agent version 8.18.0 or later to remediate the excessive cluster-wide permissions identified in CVE-2026-6389. Apply the latest patch immediately and enforce strict separation of privilege between operator and service accounts. Apply the principle of least privilege to service accounts to prevent adversaries from leveraging misconfigured access controls for privilege abuse. Manage trust zones explicitly and enforce separation of privilege to stop lower-privileged accounts from accessing sensitive resources.
Limits and watch
We cannot confirm if the current operator account is already misconfigured to allow unrestricted secret access. The CVSS score of 8.8 indicates a high severity, but the specific impact on your environment depends on whether the Turbonomic service account has been compromised. While the vulnerability allows for potential full cluster compromise, the evidence does not confirm active exploitation in your specific cluster. Watch for suspicious RoleBinding or ClusterRoleBinding assignments to service accounts, especially those coming from unknown IPs or outside CI/CD automation. Track Turbonomic instances running below version 8.18.0 that hold cluster-admin or broad secret-get permissions as a primary signal of exposure.
Vulnerabilities
- CVE-2026-6389 — CVSS 8.8 (High) · CWE-269 · IBM Turbonomic prometurbo agent. IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, including unrestricted read access to all secrets.
Techniques
- T1098.006 Additional Container Cluster Roles (Persistence)
- T1204.003 Malicious Image (Execution)
- T1548 Abuse Elevation Control Mechanism (Privilege Escalation)
Coverage
- Security Bulletin: IBM Turbonomic Prometurbo agent used by IBM Turbonomic Application Resource Management is affected by a single vulnerability (CVE-2026-6389)
- New OperTraitors Tool Reveals Dangerous Privilege Escalation Paths in Kubernetes Operators
- OperTraitor Finds Kubernetes Operators With Cluster-Wide Secret Access and Admin Paths
6. XBOW AI Agent Discovers CVE-2026-72018: Linux Kernel Flaw Enables Local Root Escalation (Segment)
Event first seen in a show
What changed
XBOW researchers disclosed CVE-2026-72018, an out-of-bounds write in the Linux kernel’s DIBS loopback driver that enables local privilege escalation to root. This finding is notable because human analysts previously dismissed the primitive as too weak, largely due to SMC-D code historically running on IBM Z mainframes with hardware protections. Proof-of-concept testing on Ubuntu 24.04 with mitigations disabled achieved successful privilege escalation in twenty-two of one hundred boot attempts, with the first success on the seventh try. Red Hat has warned of potential arbitrary code execution risks, though coverage is currently limited to XBOW and inoreader, so treat broader impact assessments as preliminary.
How it works
Today’s Linux kernel update resolves CVE-2026-72018 by adding a bounds check in the loopback move_data() function to prevent an out-of-bounds write when a peer-supplied offset or size exceeds the allocated DMB length. The vulnerability exists because the loopback move_data() function performs a memcpy into the registered DMB without checking whether the offset plus size exceeds the DMB length, unlike real ISM hardware which enforces memory region bounds natively. This lack of validation allows a peer-supplied out-of-bounds offset or oversized write to result in an out-of-bounds write past the allocated kernel buffer, enabling privilege escalation via the T1068 technique. This weakness allows an attacker with local access to trigger an out-of-bounds write past the kernel buffer, resulting in a high-impact compromise with a CVSS score of 7.8. The flaw affects standard x86 Linux systems by enabling SMC-D functionality through loopback networking, bypassing historical hardware-enforced protections found in mainframe environments. Successful exploitation allows local attackers with CAP_NET_ADMIN privileges to escalate to root, with consequences ranging from denial-of-service conditions to arbitrary code execution depending on the affected memory layout.
What to do
The dibs_loopback driver lacks bounds checking in move_data, exposing x86 Linux systems to root escalation for any local user holding CAP_NET_ADMIN. The exposure maps to T1068 Exploitation for Privilege Escalation, where a constrained 16-byte zero-write primitive corrupts kernel memory to gain root access without an information leak. This behavior resembles historical BYOVD campaigns, yet uncertainty remains whether the 22% success rate on Ubuntu 24.04 in proof-of-concept tests translates to real-world compromise without prior access. Mitigation via application control could block the exploit, but current evidence does not confirm if standard Linux distributions enforce these controls strictly enough to stop the 16-byte write. Watch for the first appearance of CAP_NET_ADMIN users on unpatched Linux 6.10 systems attempting to write to the DIBS loopback interface, which would confirm active exploitation. Apply the kernel patch that adds explicit bounds checks to the dibs_loopback move_data() routine to reject out-of-range offsets with -EINVAL, targeting Linux versions 6.10, 6.12.97, 6.18.40, 7.1.5, and 7.2. Implement application isolation and execution prevention controls to restrict code execution to trusted environments, limiting the ability of unauthorized processes to interact with the vulnerable kernel driver.
Limits and watch
Watch for unusual process or token behavior after exploitation attempts on vulnerable kernel drivers, which signals privilege escalation via T1068.
Vulnerabilities
- CVE-2026-72018 — CVSS 7.8 (High) · Linux Linux; Linux Linux. In the Linux kernel, the following vulnerability has been resolved: dibs: loopback: validate offset and size in move_data() The loopback move_data() performs a memcpy into the registered DMB without checking whether…
Techniques
- T1068 Exploitation for Privilege Escalation (Privilege Escalation)
Indicators
- 3 indicators on file
Coverage
- Linux Kernel CVE-2026-72018 Flaw Lets Local Attackers Gain Root Access
- AI Agent Finds Linux Kernel Bug That Turns a Tiny Memory Write Into Root Access
- No Time to Pwn: CVE-2026-72018
7. ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach Universities, FBI, and Nissan (Segment)
Now attributed to malware: Umbreon
What changed
ShinyHunters, tracked as UNC6240, breached over one hundred organizations by exploiting a critical zero-day in Oracle PeopleSoft. The group targeted the Environment Management Hub endpoint between May twenty-seventh and June ninth. Victims include the University of Nottingham, which exposed roughly four hundred fifty-five thousand email addresses, and Nissan Americas, which confirmed data theft affecting employees in the US, Canada, Mexico, and Brazil. The FBI is currently investigating a claimed breach of its job application portal. Dutch authorities recently arrested a former ShinyHunters member on suspicion of aiding these operations. Google’s Mandiant and Threat Intelligence Group confirmed the exploitation of the zero-day in Oracle PeopleSoft. The campaign targeted Oracle PeopleSoft servers using an unpatched zero-day, exposing roughly four hundred fifty-five thousand email addresses at the University of Nottingham. Nissan Americas confirmed data theft affecting employees in the US, Canada, Mexico, and Brazil, while new attacks target agriculture, government, and healthcare. After Oracle patched on June tenth, attackers adapted by URL-encoding the PSEMHUB path to bypass detection. Verify WAF rules cover percent-encoded variants of the PSEMHUB endpoint. Block attacker infrastructure domains like azurenetfiles[.]net and winmanage-me[.]network.
How it works
An unauthenticated attacker with network access via HTTP can trigger this CVSS 9.8 flaw without authentication or physical presence. The weakness allows an attacker with network access to compromise the BI Publisher Integration component without requiring any prior authentication. This technique allows the threat actor to target PeopleSoft servers that had not applied security updates by using percent-encoded or mixed-case variants of the vulnerable endpoint. The ShinyHunters extortion crew exploited the unpatched flaw to break into enterprise systems, steal data, and demand payment to keep it private, with the University of Nottingham being one of the first confirmed victims. Oracle’s Security Alert Advisory addresses the remote, authentication-less exploitability of the flaw in PeopleSoft PeopleTools, urging immediate action for affected customers under Premier or Extended Support.
What to do
Unlike the other CVE in this set, this vulnerability allows full takeover of PeopleSoft Enterprise PeopleTools, making immediate patching of versions 8.61 and 8.62 the only viable defense. Because this event pairs CVE-2025-61882 with CVE-2026-35273, defenders gain clarity on how a CVSS 9.8 baseline drives coordinated exploitation across the suite. Because UNC6240 modified its exploit to bypass WAF rules blocking the PSEMHUB endpoint, standard perimeter defenses no longer guarantee protection against this specific zero-day. Apply the Oracle Emergency Security Update for CVE-2026-35273 immediately to all PeopleSoft PeopleTools 8.61 and 8.62 instances to close the remote code execution vector. Update WAF signatures to explicitly block percent-encoded and mixed-case variants of the /PSEMHUB/ path to counter the specific bypass technique used by UNC6240.
Limits and watch
The specific technical details of the zero-day vulnerability remain unconfirmed, as ShinyHunters leveraged an unspecified flaw in the PeopleSoft environment. It is not yet established whether the breach of FBI employee personal information is a direct result of the PeopleSoft exploit or a separate operational failure. Check web server logs for unexpected file creation in web directories followed by web server processes spawning command shells or script interpreters, which indicates web shell deployment.
Vulnerabilities
- CVE-2025-61882 — CVSS 9.8 (Critical) · CISA KEV · Oracle Corporation Oracle Concurrent Processing. Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration).
- CVE-2026-35273 — CVSS 9.8 (Critical) · CISA KEV · Oracle Corporation PeopleSoft Enterprise PeopleTools. Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management).
Techniques
- AML.T0000 Search Open Technical Databases (Reconnaissance)
- AML.T0006 Active Scanning (Reconnaissance)
- AML.T0049 Exploit Public-Facing Application (Initial Access)
- AML.T0050 Command and Scripting Interpreter (Execution)
- AML.T0055 Unsecured Credentials (Credential Access)
- AML.T0072 Reverse Shell (Command And Control)
- T1005 Data from Local System (Collection)
- T1016 System Network Configuration Discovery (Discovery)
- T1018 Remote System Discovery (Discovery)
- T1027 Obfuscated Files or Information (Stealth)
- and 10 more
Named actors and malware
- ShinyHunters (actor)
- Neo-reGeorg (malware)
- Umbreon (malware)
- TeamPCP (actor)
- Umbreon. (malware)
Indicators
- 22 indicators on file
Coverage
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities
- Oracle Security Alert Advisory - CVE-2026-35273
- ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
- ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft
- Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
- ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
- Oracle PeopleSoft Servers Targeted Again as ShinyHunters Expands Extortion Operations
- Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
- Oracle PeopleSoft Zero-Day RCE Vulnerability Exploited by ShinyHunters
- Oracle Emergency Security Update to Fix Critical RCE Vulnerability
- ShinyHunters Bypasses WAF Protections to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
- Oracle PeopleSoft 0-Day RCE Vulnerability Exploited in Attacks by ShinyHunters
- Nissan Confirms Data Breach Following Oracle PeopleSoft 0-Day Attacks
- FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day
- Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
- ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns
- Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation
8. Sysdig documents JADEPUFFER, the first end-to-end AI-driven ransomware operation exploiting Langflow (Segment)
Event first seen in a show
What changed
Sysdig researchers documented JADEPUFFER as the first confirmed ransomware operation orchestrated entirely by an autonomous large language model. The attack began by exploiting CVE-2025-3248 in an internet-facing Langflow instance to harvest cloud credentials. An AI agent moved laterally to an Alibaba Nacos service, deploying over six hundred payloads across two machines. It encrypted one thousand three hundred forty-two configuration items, deleted database schemas, and left Bitcoin ransom notes. Microsoft tracked related destructive activity under the alias Storm-3168, involving Azure resource deletion using compromised service principals. Sysdig’s analysis highlights the agent’s ability to self-correct code errors and adapt tactics in real-time. The evidence includes self-narrating code comments and the use of a canonical Bitcoin address found in the model’s training data. The same Langflow instance was subsequently targeted a second time using a compiled Go-based ransomware strain codenamed ENCFORGE. Check your Langflow instances for CVE-2025-3248 exposure immediately. Watch for AI Agent Tool Invocation and OS Credential Dumping techniques.
How it works
An AI agent exploited Langflow versions before 1.3.0 by sending unauthenticated requests to /api/v1/validate/code to run arbitrary Python code. The flaw exploits the AuthFilter servlet to skip checks, enabling attackers to execute any administrative task without valid credentials. The missing authentication on the /api/v1/validate/code endpoint allowed attackers to assume privileged identities, ranging from data access to full host control. This flaw enabled scanning for cloud credentials across Chinese providers like Aliyun and Tencent. In one Microsoft Azure environment, two compromised service principals were used for reconnaissance and destructive actions across multiple subscriptions.
What to do
Nacos servers on version 1.4.0 or lower let attackers bypass authentication using a spoofed user-agent header to seize full administrative control. The JADEPUFFER operation shows an autonomous LLM agent executing a complete ransomware lifecycle, from initial access to destructive impact, without human intervention. This capability shifts the threat model from discrete human-led attacks to continuous, self-correcting automated campaigns that adapt tactics in real-time. Verify Nacos instance versions and restrict server access to prevent authentication bypass. Upgrade Alibaba Nacos to 1.4.1 or higher to eliminate the user-agent spoofing backdoor.
Limits and watch
The backdoor mechanism is unique to the Nacos platform’s authentication filter, even though the event includes CVE-2025-3248. We do not know the extent of data exfiltration before encryption, as evidence points to destructive actions and credential harvesting rather than data theft. It remains unclear whether the LLM agent’s self-correction capabilities are unique to this model or represent a broader trend in autonomous threat actor tooling. Watch for manual penetration testing results that identify unauthenticated endpoints in custom authentication mechanisms, since automated tools may miss these critical gaps.
Vulnerabilities
- CVE-2025-3248 — CVSS 9.8 (Critical) · CISA KEV · CWE-306 · langflow-ai langflow. Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint.
- CVE-2021-29441 — CVSS 8.6 (High) · CWE-290 · alibaba nacos. Nacos is a platform designed for dynamic service discovery and configuration and service management.
Techniques
- AML.T0006 Active Scanning (Reconnaissance)
- AML.T0010.001 AI Software (Initial Access)
- AML.T0016.002 Generative AI (Resource Development)
- AML.T0053 AI Agent Tool Invocation (Execution)
- AML.T0054 LLM Jailbreak (Defense Evasion)
- AML.T0090 OS Credential Dumping (Credential Access)
- AML.T0098 AI Agent Tool Credential Harvesting (Credential Access)
- AML.T0102 Generate Malicious Commands (Ai Attack Staging)
- AML.T0108 AI Agent (Command And Control)
- T1059.009 Cloud API (Execution)
- and 3 more
Indicators
- 3 indicators on file
Coverage
- JADEPUFFER: First End-to-End AI-Driven Ransomware Operation
- JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
- This AI agent autonomously hacked a network, adapted on the fly, and demanded a ransom
- JadePuffer ransomware used AI agent to automate entire attack
- JadePuffer agentic attacks now target AI model data with ransomware
- Smooth AI criminal drives ‘first’ end-to-end agentic ransomware attack
9. New Spectre v2 Variant Leaks Linux Root Hashes via JIT Engines (Segment)
Event now covered by 3 outlets (was 2)
What changed
VUsec and Scuola Superiore Sant’Anna researchers disclosed Branch Target Reuse, a new Spectre v2 variant identified as CVE-2026-64507 and CVE-2026-64508, which exploits stale indirect branch prediction entries in JIT engines. The attack targets the interplay between self-modifying code and indirect branch prediction in Linux cBPF, Oracle GraalVM, and Firefox SpiderMonkey, leaking sensitive data including root password hashes on modern Intel, AMD, and Arm processors. Proof-of-concept exploits recovered these hashes within minutes on fully patched systems, bypassing mitigations like FineIBT. While Linux kernel patches and Oracle’s code-cache randomization are deployed, Mozilla prioritizes site isolation. Measured leakage rates hit approximately 5.7 kilobytes per second on Intel Raptor Cove chips and 5.4 on Lion Cove processors. Standard Spectre mitigations are not sufficient against this specific JIT engine vector. The research is set for publication at the CCS 2026 conference in The Hague.
How it works
In the Linux kernel, the BPF JIT allocator reuses space within larger executable allocations, allowing indirect jumps into fresh code to reuse branch predictions left behind by previous programs. Today’s Linux kernel update resolves CVE-2026-64507 by forcing an Instruction Buffer Privilege Bypass flush specifically when the BPF JIT allocator reuses memory after Spectre-v2 mitigations are active. The update also resolves CVE-2026-64508 by adding a static call to flush indirect branch predictors before reusing JIT memory allocations. The vulnerability affects Linux kernel versions 5.18, 6.1.183, 6.6.145, 6.12.97, 6.18.39, 7.1.4, and 7.2, as well as specific commits, where the BPF JIT is in use. This fix protects systems running Linux versions 5.18 through 7.2 from exploits that leverage stale branch predictions to execute arbitrary code via BPF JIT spraying. Successful exploitation allows adversaries to recover root password hashes, which can then be cracked offline to gain access to systems and services where the account has privileges. This fix applies only to systems running Linux versions 5.18 through 7.2 with BPF-JIT enabled, leaving older kernels and disabled JIT paths unaffected by this specific hardening.
What to do
The Branch Target Reuse attack bypasses existing Spectre-v2 mitigations like FineIBT to leak root password hashes on fully patched Intel systems. This exposure is critical because the attack recovers sensitive credentials in minutes, rendering standard kernel protections insufficient for JIT engine environments. The attacker behavior of password cracking via recovered hashes maps directly to the framework mitigation of Multi-Factor Authentication, which remains ineffective if the root password hash is already exfiltrated. This creates a decision priority where standard credential monitoring is insufficient; instead, responders should examine system logs for rapid hash recovery attempts or unauthorized access using the leaked root credentials. Uncertainty remains regarding the specific target of the attack and whether the leaked hashes have been used for further compromise, so the watch item is any anomalous login activity from the compromised host or evidence of the hash being passed to a cracking tool. Operators must verify their kernel version matches the affected baseline and confirm the bpf_arch_pred_flush_enabled static key is active before deploying today’s patch. Apply the Linux kernel patches for CVE-2026-64507 and CVE-2026-64508 to enable IBPB flush on BPF JIT allocation and harden against JIT spraying. Verify that the BPF dispatcher is using a retpoline sequence or that the bpf_arch_pred_flush static key is active to ensure indirect branch predictors are flushed on memory reuse.
Limits and watch
The kernel fix for CVE-2026-64507 only applies when BPF-JIT is in use and is guarded by CONFIG_BPF_JIT, leaving systems with this configuration disabled without this specific hardening. The predictor flush in CVE-2026-64508 does not cover allocations larger than a pack, relying on the assumption that cBPF programs remain bounded below that size. Watch for high CPU usage or GPU invocation via unsigned binaries accessing password hash files, which signals the use of password cracking techniques to recover usable credentials.
Vulnerabilities
- CVE-2026-64507 — CVSS 0 (Low) · Linux Linux; Linux Linux. In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Enable IBPB flush on BPF JIT allocation Enable hardening against JIT spraying when Spectre-v2 mitigations are in use.
- CVE-2026-64508 — CVSS 0 (Low) · Linux Linux; Linux Linux. In the Linux kernel, the following vulnerability has been resolved: bpf: Support for hardening against JIT spraying The BPF JIT allocator packs many small programs into larger executable allocations and reuses space…
Techniques
- T1110.002 Password Cracking (Credential Access)
Coverage
- New Spectre v2 attack variant leaks Linux root password hash in minutes
- Branch Target Reuse: Spectre-v2 Attacks in JIT Engines
- New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses
- Spectre bug is back, this time to haunt JIT engines
10. Infostealers Drive 74% Surge in Cookie Theft (Segment)
Event now covered by 5 outlets (was 4); Now attributed to malware: LockBit
What changed
NordStellar data reveals a surge in leaked browser cookies from fifty-four billion to nearly ninety-four billion, with the United States ranking fourth globally at over three billion leaked tokens. Lumma, RedLine, and Vidar harvest session tokens and API keys from developer workstations. Five independent outlets, including NordSecurity and WeLiveSecurity, identify these three families as responsible for eighty-five point seven percent of detected incidents. KELA unmasked the Hellcat hacking group as a distributor of these tools, identifying key operators Rey and Pryx. NordVPN reports a seventy-four percent year-over-year surge in leaked cookies, placing the United States fourth globally among two hundred and fifty-three countries.
How it works
Stolen cookies let attackers bypass multi-factor authentication entirely, granting direct access to AWS, Azure, and Google Cloud environments without requiring user login credentials. Stolen data is rapidly validated and resold within hours to access brokers and ransomware operators who monetize verified enterprise access through mature malware-as-a-service ecosystems. Approximately ninety percent of organizations breached in 2024 had their credentials leaked for sale on dark web marketplaces, a statistic largely driven by infostealer malware such as RedLine Stealer and its successor Lumma Stealer. This surge from fifty-four billion to ninety-four billion leaked cookies shows session hijacking is the primary vector for bypassing multi-factor authentication in enterprise cloud environments. The stolen data allows immediate impersonation of authenticated users, creating uncertainty about which specific cloud accounts are currently active and accessible.
What to do
Implement application isolation and sandboxing to restrict infostealer execution, blocking access to sensitive browser resources and critical operations on developer workstations. Integrate secure coding practices into the software development lifecycle to mitigate exploitation of vulnerabilities used to collect credentials and forge authentication tickets.
Limits and watch
While infostealer malware can expose an organization’s entire database of digital credentials, the specific scope of data exfiltration varies depending on whether the infection originates from compromised software or direct workstation compromise. The attribution of specific infostealer incidents to individual operators like Rey remains limited to OSINT traces and law enforcement sharing, meaning the full extent of their operational reach across different sectors is not fully established. Watch for abnormal LSASS memory access and forged Kerberos tickets to spot credential validation exploitation before session tokens are harvested.
Techniques
- T1005 Data from Local System (Collection)
- T1027.014 Polymorphic Code (Stealth)
- T1195 Supply Chain Compromise (Initial Access)
- T1212 Exploitation for Credential Access (Credential Access)
- T1219 Remote Access Tools (Command And Control)
- T1528 Steal Application Access Token (Credential Access)
- T1539 Steal Web Session Cookie (Credential Access)
- T1550.004 Web Session Cookie (Lateral Movement)
- T1552.004 Private Keys (Credential Access)
- T1555.005 Password Managers (Credential Access)
- and 8 more
Named actors and malware
- LockBit (malware)
- Lumma Stealer (malware)
- RedLine Stealer (malware)
- Lumma (malware)
- RedLine (malware)
Indicators
- 5 indicators on file
Coverage
- Lumma, RedLine and Vidar Infostealers Fuel Cloud Credential Theft Campaigns
- From 54 billion to 94 billion: Cookie theft skyrockets as hackers exploit your browser
-
[Infostealer Malware: The Silent Threat to Your Digital Credentials - Managed IT Services & Technology Consulting OSIbeyond](https://osibeyond.com/blog/infostealer-malware-the-silent-threat-to-your-digital-credentials) -
[UPDATE: Hellcat Hacking Group Unmasked: Investigating Rey and Pryx KELA Cyber](https://kelacyber.com/blog/hellcat-hacking-group-unmasked-rey-and-pryx) - Stay informed with ESET’s threat reports