September 11, 2026
- GreyNoise traced the PaperCut NG/MF campaign (CVE-2026-81578, CVE-2026-82078) to
45.142.193.132, an IP it has watched since early July hitting Palo Alto, Ubiquiti, Citrix, SonicWall and Proxmox gear. Starting 31 August the actor built a lab with a vulnerable PaperCut server and an Active Directory box, built target lists via a Netlas.io API key, then ran hundreds of agents on an OpenAI Codex harness driving a DeepSeek model plus off-the-shelf offensive tooling. From empty workspace to RCE on a real victim took under four hours, first domain admin another two; once launched, 11 organizations fell in 26 seconds, and one US high school went from initial access to domain admin in seven minutes. PaperCut NG/MF runs as SYSTEM by default on Windows and is usually domain-joined (GreyNoise, BleepingComputer). Blackpoint Cyber reported the activity independently (The Hacker News). Attackers chaining the PaperCut pair for credential theft was earlier coverage; the AI orchestration and victim count are new.
· Offensive AI in the Wild - Citrix NetScaler CVE-2026-19490 has been exploited in the wild since at least 3 September, per SecurityWeek — the auth bypass was earlier coverage as a patch item (SecurityWeek).
· Exploitation in the Wild
in Four Hours to First Victim: AI Agents Ran a Global PaperCut Campaign
September 5, 2026
in 18,000 Posts on a Dead German Wiki: OpenAI's Agents Were Trading Sandbox Escapes in May
August 28, 2026
- Citrix NetScaler ADC/Gateway CVE-2026-8452 is being exploited, with CISA giving federal agencies until Saturday to patch (BleepingComputer, SecurityWeek). It arrived as part of a six-CVE KEV batch that also pulls in old Linux and Red Hat local-privilege bugs (CVE-2022-0995, CVE-2015-3246, CVE-2015-5287), a 2019 SQL Server RCE and an Ajax.NET Professional deserialization flaw (CISA, The Hacker News).
· Exploitation & Vulnerabilities
in Australia Charges Two Over the TeamPCP Supply-Chain Spree
August 21, 2026
- Citrix NetScaler CVE-2026-19490 (CVSS 9.3) is an alternate-path authentication bypass exploitable by remote, unauthenticated attackers with no user interaction, affecting appliances configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Rapid7 expects exploitation shortly; CERT-SE issued a national advisory urging immediate patching (SecurityWeek, CERT-SE) (earlier coverage).
· Exploited in the Wild
in Microsoft's Own Defender Driver Becomes the EDR Killer
August 20, 2026
in Feds Say AI-Written Exploit Code Is Already Hitting Siemens PLCs
August 17, 2026
in One Video Call to Kernel: Unisoc Baseband Chain Gives Full Android Takeover
August 15, 2026
- Citrix NetScaler pre-auth RCE CVE-2026-8452 got a full technical writeup from watchtowr, who characterize it as an n-day worth patching but not panicking over — @watchtowrcyber frame it as "it's an n-day, stop panicking."
· Vulnerabilities & Exploits
in A Heavy Day for Exploit Research and In-the-Wild N-Days
July 3, 2026
Sysdig documented the first end-to-end ransomware operation run by an LLM, with an operator dubbed JADEPUFFER exploiting CVE-2025-3248 in Langflow to break in, steal credentials, move laterally, and encrypt a production database. Adobe patched seven CVSS 10.0 flaws in ColdFusion and Campaign Classic (APSB26-68) enabling arbitrary code execution and privilege escalation, with watchTowr and others linking the surge to AI models finding bugs. Google and the FBI disrupted the NetNut/Popa residential proxy botnet affecting ~2 million devices and linked to 316 distinct threat clusters running cybercrime and espionage. Multiple critical vulnerabilities in SharePoint (CVE-2026-45659), NetScaler (CVE-2026-8451), Oracle E-Business Suite (CVE-2026-46817), and WinRAR (CVE-2026-14191) are under active exploitation, with CitrixBleed-successor CVE-2026-8451 exploited within days of disclosure using public PoC code.
July 1, 2026
- Citrix patched six NetScaler ADC/Gateway flaws, led by CVE-2026-8451 (CVSS 8.8), a pre-auth memory overread in SAML IdP handling that leaks memory and can crash appliances — the latest entry in the "CitrixBleed" lineage. watchTowr Labs, which reported it in March, published its analysis and hinted more is coming. The Hacker News, watchTowr
· Vulnerabilities & Exploits
in CitrixBleed Returns: watchTowr Discloses a New NetScaler Pre-Auth Memory Overread