[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fbPSgzJss70cRS-5_6QQDXgCoe0jGqjntUic_80SdVtQ":3},{"article":4,"iocs":54},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":31,"category":32,"article_tags":36},"1a82364a-51f8-4ec5-b2fc-e8a5b052e8b2","⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats","weekly-recap-387m-crypto-hack-citrix-exploits-ai-agents-go-off-script-and-more-t-92a47b","A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface. Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work for attackers. Nothing","This week's recap highlights a significant $387 million hack of cryptocurrency exchange Bitget, suspected to be carried out by North Korean hackers. Citrix has warned of actively exploited vulnerabilities in its NetScaler ADC and Gateway products, urging immediate patching. Additionally, a commonly used placeholder domain, 'third-party[.]com', was registered by an attacker and used to serve malicious lures, impacting approximately 1,700 repositories.","Weekly recap covers $387M crypto hack, Citrix NetScaler exploits, and a placeholder domain used for attacks.","⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats Ravie LakshmananSep 28, 2026Cybersecurity News \u002F Hacking A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface. Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work for attackers. Nothing exotic. Mostly things nobody expected to matter anymore. Here’s the full recap of what mattered this week. ⚡ Threat of the Week Citrix Warns of Actively Exploited NetScaler ADC and Gateway Flaws — Citrix released patches to address multiple vulnerabilities, including CVE-2026-88771 and CVE-2026-88772, that have come under active exploitation. CVE-2026-88771 is an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands, while successful exploitation of CVE-2026-88772 could allow for remote code execution or denial-of-service. CISA said \"threat actors are actively exploiting these vulnerabilities globally,\" urging federal agencies to apply patches by Wednesday. Five Security Leaders. One Question: What Changes When Attackers Have AI? Mikko Hyppönen, Volkan Erturk, and security leaders from Chanel, the NFL, and Atlassian bring five distinct perspectives to The Validation Summit ’26. Hear what changed, what needs to change, and how leading teams are responding. Join the Summit ➝ 🔔 Top News Bitget Resumes Withdrawals After Hack — Cryptocurrency exchange Bitget resumed Bitcoin withdrawals in phases after suspected North Korean hackers breached its systems last week and stole over $387 million. \"At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving a limited number of hot wallets,\" Bitget said. \"Bitget's cold wallets and the overwhelming majority of platform assets remain secure and unaffected.\" According to a real-time fund tracing dashboard published by Coindesk, Circle and Tether have frozen stablecoins worth $339,100 linked to the hack. PamStealer Adds Live C2 Payload Decryption — A new version of PamStealer has been found to incorporate a new anti-analysis trick that ensures the main payload can only be recovered using a server-side decryption chain. The latest artifacts continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. \"Where earlier variants embedded their payload key material directly in the JXA source, it now fetches a purpose-built decryption utility and completes a key exchange with the server before the payload can be unwrapped,\" Jamf said. \"Without the server's cooperation, the payload cannot be recovered statically.\" Placeholder Domain Found References in ~1.7K Repos — The \"third-party[.]com\" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users. \"third-party[.]com has been a generic documentation placeholder for years, the same role example.com plays,\" Manifold Security said. \"Unlike 'example[.]com,' third-party[.]com is not IANA-reserved. Anyone could register it, and someone did. Every doc, test, and skill that hard-coded it now points readers at attacker infrastructure.\" As of writing, the domain has been marked as malicious and unsafe on both VirusTotal and Google's Safe Browsing list. Manifold also identified 13 more placeholder domains that are not IANA-reserved, with two of them – yoursite[.]com and your-domain[.]com – serving scams and scareware to macOS visitors and an ordinary parking page to other users. UNK_CondorFiltration Abuses TeamFiltration in New Campaign — An active TeamFiltration campaign codenamed UNK_CondorFiltration has targeted over 5,700 accounts across 28 Microsoft 365 tenants. The activity has primarily focused on Chilean retail and financial institutions. It originated from 1,487 unique AWS EC2 source IP addresses. \"The campaign compromised 7 accounts – all of which were unmanaged functional or service accounts rather than individual employee accounts – highlighting a critical exposure gap around forgotten, non-human identities carrying default or unrotated passwords and no MFA,\" Proofpoint said. The activity took place over three waves from late July to August 2026. EvilTokens Taken Down in Law Enforcement Action — A coalition of law enforcement and private-sector tech companies led by Microsoft dismantled the EvilTokens phishing service, arresting two suspected website admins, Felix Utomi and Waidi Segun Adams, taking down more than 50 websites, and notifying victims of compromised email accounts. Per Coinbase, the EvilTokens operators were said to be working on expanding the kit to target Gmail and Okta accounts at the time of the takedown. Microsoft attributes the development and support of the platform to Storm-2992. EvilTokens is the latest example of professionalization of cybercrime, allowing bad actors to mount phishing campaigns with little effort and at scale. EvilTokens' notable feature was the device code phishing flow, which took advantage of security gaps in devices that cannot support standard sign-in methods like smart TVs, printers, conferencing tools, and Teams devices. In these attacks, victims are sent a short code and are told to enter that code into a phishing page to complete authentication. The important aspect here is that instead of a legitimate device requesting access, the threat actor initiates the flow and provides the user with a code through a phishing lure. When the code is entered, victims unknowingly authorize the cybercriminals' session and grant them access without ever handing over their password. OpenAI Linked to More Website Hacks — AI research lab Transluce found three instances between May and June 2026 in which OpenAI's agents resorted to hacking when traditional methods failed. This included an attempt on an Australian government public health website. \"Notably, the agents did this while attempting mundane data retrieval tasks which were not cyber-related,\" Transluce said. \"This traffic goes back at least to March 6, 2026 and extends as recently as September 16, 2026, suggesting agents may still be exploiting these services to bypass restrictions.\" ‎️‍🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-77179 (Docker), CVE-2026-93485, CVE-2026-87902 (WordPress), CVE-2026-89775 (Linux kernel), CVE-2026-93616, CVE-2026-85102 (Check Point), CVE-2026-93952 (Arista VeloCloud Orchestrator), CVE-2026-90898 (Bifrost), CVE-2026-86555, CVE-2026-86554, CVE-2026-86553, CVE-2026-86552 (ZTE H188A\u002FH288A firmware), CVE-2026-94545 (Next.js), CVE-2026-94127 (F5 BIG-IP Access Policy Manager), CVE-2026-86296, CVE-2026-86510 (D-Link DIR-822A), CVE-2026-87900, CVE-2026-87899, CVE-2026-68490 (cPanel), CVE-2026-82356 (Imprivata Enterprise Access Management), CVE-2026-86867 (Cinnamon Kotaemon), CVE-2026-75682, CVE-2026-75684, CVE-2026-75686, CVE-2026-75689, CVE-2026-75697, CVE-2026-75698, CVE-2026-75745, CVE-2026-81995, CVE-2026-82000 (Adobe), CVE-2026-95350, CVE-2026-95357, CVE-2026-95339, CVE-2026-95281, CVE-2026-95313, CVE-2026-95349, CVE-2026-95284, CVE-2026-95322, CVE-2026-95329, CVE-2026-95356, CVE-2026-95310 (Google Chrome), CVE-2024-0244 (Canon MF753Cdw), CVE-2026-28324, CVE-2026-28325 (SolarWinds Observability Self-Hosted), CVE-2026-97359, CVE-2026-97360 (HFS2), CVE-2026-96560 (LightLLM), CVE-2026-80145, CVE-2026-80144, CVE-2026-80143 (Lantronix), CVE-2026-82987, CVE-2026-82988, CVE-2026-82989 (ViewSonic vCast), CVE-2026-","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fweekly-recap-387m-crypto-hack-citrix.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEh4-eWVCAN2nvZGZrKlwm-wminZE56MzJ_bVRK6CJfdBw9TXU4yQy6t9T0hDi0hSOskE9Xs6M-KCVEbVvBuL2DLDkew97W2iobOPZa9zqEBeGPWBnW8cftdD1FwzBLz7CIGVhJb1FwnS-35B62Jqc331zNQ67hZP-V2jKBT7yUxUV4rn8jMr27QCommYp-j\u002Fs1600\u002Fc-recap.jpg","2026-09-28T14:00:53+00:00","2026-09-28T18:00:47.47935+00:00",8,[18,21,24,27,29],{"name":19,"type":20},"North Korean hackers","threat_actor",{"name":22,"type":23},"Citrix","vendor",{"name":25,"type":26},"NetScaler ADC","product",{"name":28,"type":26},"NetScaler Gateway",{"name":30,"type":23},"Bitget","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":31,"icon":33,"name":34,"slug":35},null,"Threat Intelligence","threat-intelligence",[37,42,47,52],{"category":38},{"id":39,"icon":33,"name":40,"slug":41},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":43},{"id":44,"icon":33,"name":45,"slug":46},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":48},{"id":49,"icon":33,"name":50,"slug":51},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":53},{"id":31,"icon":33,"name":34,"slug":35},[55,59,62,66,69],{"type":56,"value":57,"context":58},"cve","CVE-2026-88771","Citrix NetScaler ADC and Gateway vulnerability allowing arbitrary command execution.",{"type":56,"value":60,"context":61},"CVE-2026-88772","Citrix NetScaler ADC and Gateway vulnerability allowing remote code execution or denial-of-service.",{"type":63,"value":64,"context":65},"domain","third-party.com","Placeholder domain registered and used for malicious lures.",{"type":63,"value":67,"context":68},"yoursite.com","Placeholder domain observed serving scams and scareware.",{"type":63,"value":70,"context":68},"your-domain.com"]