daily cyber × ai intelligence

index

tagged

[citrix]

9 editions · 9 items

September 11, 2026

  • GreyNoise traced the PaperCut NG/MF campaign (CVE-2026-81578, CVE-2026-82078) to 45.142.193.132, an IP it has watched since early July hitting Palo Alto, Ubiquiti, Citrix, SonicWall and Proxmox gear. Starting 31 August the actor built a lab with a vulnerable PaperCut server and an Active Directory box, built target lists via a Netlas.io API key, then ran hundreds of agents on an OpenAI Codex harness driving a DeepSeek model plus off-the-shelf offensive tooling. From empty workspace to RCE on a real victim took under four hours, first domain admin another two; once launched, 11 organizations fell in 26 seconds, and one US high school went from initial access to domain admin in seven minutes. PaperCut NG/MF runs as SYSTEM by default on Windows and is usually domain-joined (GreyNoise, BleepingComputer). Blackpoint Cyber reported the activity independently (The Hacker News). Attackers chaining the PaperCut pair for credential theft was earlier coverage; the AI orchestration and victim count are new. · Offensive AI in the Wild
  • Citrix NetScaler CVE-2026-19490 has been exploited in the wild since at least 3 September, per SecurityWeek — the auth bypass was earlier coverage as a patch item (SecurityWeek). · Exploitation in the Wild

in Four Hours to First Victim: AI Agents Ran a Global PaperCut Campaign

August 28, 2026

  • Citrix NetScaler ADC/Gateway CVE-2026-8452 is being exploited, with CISA giving federal agencies until Saturday to patch (BleepingComputer, SecurityWeek). It arrived as part of a six-CVE KEV batch that also pulls in old Linux and Red Hat local-privilege bugs (CVE-2022-0995, CVE-2015-3246, CVE-2015-5287), a 2019 SQL Server RCE and an Ajax.NET Professional deserialization flaw (CISA, The Hacker News). · Exploitation & Vulnerabilities

in Australia Charges Two Over the TeamPCP Supply-Chain Spree

August 21, 2026

  • Citrix NetScaler CVE-2026-19490 (CVSS 9.3) is an alternate-path authentication bypass exploitable by remote, unauthenticated attackers with no user interaction, affecting appliances configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Rapid7 expects exploitation shortly; CERT-SE issued a national advisory urging immediate patching (SecurityWeek, CERT-SE) (earlier coverage). · Exploited in the Wild

in Microsoft's Own Defender Driver Becomes the EDR Killer

July 3, 2026

Ransomware on Autopilot, and a Pile of Critical Bugs Under Fire

Sysdig documented the first end-to-end ransomware operation run by an LLM, with an operator dubbed JADEPUFFER exploiting CVE-2025-3248 in Langflow to break in, steal credentials, move laterally, and encrypt a production database. Adobe patched seven CVSS 10.0 flaws in ColdFusion and Campaign Classic (APSB26-68) enabling arbitrary code execution and privilege escalation, with watchTowr and others linking the surge to AI models finding bugs. Google and the FBI disrupted the NetNut/Popa residential proxy botnet affecting ~2 million devices and linked to 316 distinct threat clusters running cybercrime and espionage. Multiple critical vulnerabilities in SharePoint (CVE-2026-45659), NetScaler (CVE-2026-8451), Oracle E-Business Suite (CVE-2026-46817), and WinRAR (CVE-2026-14191) are under active exploitation, with CitrixBleed-successor CVE-2026-8451 exploited within days of disclosure using public PoC code.