Researchers disclosed technical details of a recently patched critical vulnerability in Citrix NetScaler ADC and Gateway that is under active exploitation in the wild. The vulnerability is identified as CVE-2026-88772, has a CVSS score of 9.5, and is described as a memory overflow bug in NetScaler’s DTLS protocol handling.
Why it matters
Technical disclosure alongside reported active exploitation makes this relevant beyond a theoretical vulnerability report.
Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily
Exploitation · Securityaffairs
What happened
Apple patched CoreGraphics zero-day CVE-2026-86950 in iOS, iPadOS and macOS; the flaw is an out-of-bounds write that can enable arbitrary code execution when processing a specially crafted file. Apple said it was aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals using iOS versions before iOS 27.
Why it matters
Apple has not disclosed who was targeted, how many people were affected, whether the attacks succeeded, when exploitation began, or how attackers delivered the malicious files.
Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily
Incident · The Hacker News
What happened
An attacker used stolen passwords belonging to France’s tax-administration staff to access tax data on hundreds of thousands of taxpayers and businesses during June and July. ANSSI characterized the attack as not sophisticated, according to a report published Tuesday.
Why it matters
Neither the tax administration nor France’s national cybersecurity agency, ANSSI, detected the data leaving the organization.
Known limitation: This item is supported by one source record and has not been independently corroborated here.
Evidence is visible. Uncertainty stays visible too.
Baitaphish separates source records from interpretations, labels AI-assisted enrichment, and avoids turning ingestion volume into unsupported claims about threats, prevalence, or risk.