⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
Weekly recap: NetScaler and FortiMail 0-days exploited, AI coding leaks, Spectre v2, and ransomware arrests.
Summary
This week's security recap highlights actively exploited vulnerabilities in NetScaler ADC/Gateway (CVE-2026-88779) and FortiMail (CVE-2026-104286). Law enforcement made significant arrests, including two members of the ShinyHunters group and the suspected teenage mastermind behind the KillSec ransomware operation, which saw its leak site seized. The article also touches on broader themes of overlooked security basics and the increasing capability of some attacks.
Full text
⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests Ravie LakshmananOct 05, 2026Cybersecurity News / Hacking A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats keep finding leverage in small things that were easy to overlook. There are actively exploited bugs in the mix, cleaner intrusion paths, smarter automation, and a long patch list waiting behind them. Some attacks are getting more capable. Others are still getting in because the basics gave way first. Here’s what mattered this week. ⚡ Threat of the Week Citrix Warns of Newly Exploited NetScaler ADC and Gateway Flaw — Citrix released security updates for a high-severity security flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0. "CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific deployment conditions," Citrix said. "The issue affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met." Successful exploitation requires NetScaler ADC or NetScaler Gateway to be configured either as a SAML service provider (SP) or SAML identity provider(IdP). How Headspace Centralized AI Governance Across Teams Most teams are stuck choosing between speed and control. Headspace found a way to have both. Hear how Chris Oh, Senior Director of AI Enablement at Headspace, gives the org flexibility to build, while maintaining full visibility into what’s running and who owns it. Watch the On-Demand Webinar Here ➝ 🔔 Top News Critical FortiMail Zero-Day Flaw Exploited in Attacks — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned of active exploitation of a critical security flaw impacting Fortinet FortiMail. The flaw, CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. According to Fortinet, the vulnerability "may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests." Two ShinyHunters Members Arrested — Law enforcement agencies have arrested two members associated with the ShinyHunters digital extortion group. One of them is a 24-year-old Amsterdam man, who is believed to be Pepijn van der Stap, while the second individual is Saif al-Din Khader, who is said to have been detained by Jordanian authorities last week. ShinyHunters has drawn attention in recent weeks for hijacking the darknet website of Cl0p and its hack of the FBI's "apply.fbijobs[.]gov" portal. Authorities Arrest 16-Year-Old Mastermind Behind KillSec — Police in Spain apprehended a 16-year-old who is suspected to be the leader of the KillSec (aka Kill Security Ransomware Group) ransomware operation. According to Europol, authorities took control of KillSec's leak site on September 30, 2026, securing no less than 110 terabytes of data. As part of Operation KillSwitch, a total of three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain, and the U.K. One of the group’s accused members, Fouad Eltibrizi, was arrested in the U.K. and is awaiting extradition to the U.S. Since emerging in 2024, the group is estimated to have launched around 1,000 attacks, at least half of which were successful. "The group exploited software vulnerabilities and poorly secured access points, particularly to cloud storage, to gain access to organizations' systems," Europol said. "Its members then copied sensitive internal data to infrastructure under their control. Victims were named on the group's dark web leak site and threatened with publication of their data unless paid." Per Group-IB, which identified 274 publicly claimed victims, out of which most were U.S., Indian, and Brazilian organizations. "The group also sold stolen data outright, with asking prices ranging from USD 5,000 for a single company's records to USD 500,000 for the data it claimed to have taken from the global insurer, making KillSec as much a data broker as a ransomware operator," Group-IB said. New Spectre v2 Variant Leaks Linux Root Password Hash in Minutes — A new Spectre v2 attack variant called Branch Target Reuse (BTR) can recover root password hashes from Intel computers running Linux in just a few minutes. The attack exploits stale information in a processor's branch predictor after a just-in-time (JIT) engine reuses memory for new code. By tampering with this information, an attacker can trick the processor into temporarily executing wrong instructions and potentially expose sensitive data. "We evaluated the end-to-end exploit on both Raptor Cove and Lion Cove, and leaked the password within 3 and 5 minutes on average, respectively," researchers claimed. "Indirect branch prediction is inherent to modern CPUs, and BTR exploits the desynchronization between the branch predictor and the actual state of the code. No current CPU has a mechanism to keep the two in sync, so until vendors add one, your CPU is vulnerable." Star Blizzard Uses Fake Invites to Deploy CosmicPulse — The Russian state-sponsored threat actor known as Star Blizzard has employed a new malware delivery technique called RedFlick in attacks targeting Ukrainian individuals and institutions as well as international non-government organizations (NGOs), Western think tanks, governments, and other organizations associated with international policy. The end goal is to deploy a custom backdoor called CosmicPulse by setting up scheduled tasks using RedFlick through phishing emails masquerading as invitations. Once a victim responds to an initial phishing email, Star Blizzard typically sends a follow-up containing a password-protected archive that triggers the RedFlick chain. "This technique is a notable departure from the actor’s previous use of ClickFix-based infection chains which required victims to complete multiple actions before CosmicPulse could be installed," Microsoft said. "By contrast, the RedFlick infection flow only requires a single user interaction, reducing friction in the compromise process." NeedyMantis Malware Enables Persistent Network Access — A modular post-compromise malware family called NeedyMantis is being used by threat actors to maintain long-term stealth access and support post-compromise operations. Distributed by a two-stage loader and launched via DLL sideloading, the malware has been observed in a limited number of targeted operations affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. The activity aligns with operations that are associated with threat actors operating from China. The malware operation has been active since at least October 2025. "While NeedyMantis employs techniques commonly used by modern malware, its architecture combines multiple loaders, custom encrypted file archives, a custom executable file format, and modular components that enable operators to evade analysis and extend functionality through additional modules," Microsoft said. At least one threat actor has been linked to its use: Storm-3069, which is Microsoft's designation for the DAEMON Tools supply chain attack that took place in May 2026. RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims — The Android malware known as RatHat has been observed using Google Gemini to estimate each victim's bank balance and sorts the device into high-value and mid-value groups. "Gemini is used on both sides of the operation: the malware asks an LLM where to tap when its automation fails on an unfamiliar phone, and the panel uses one to estimate victims' bank balances from their SMS," Cleafy said. Ove
Indicators of Compromise
- cve — CVE-2026-88779
- cve — CVE-2026-104286