September 27, 2026
Why this day matters
- A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.
- Kosovo national Ardit Kutleshi pleaded guilty to running Rydox, a cybercrime marketplace that sold stolen identities and credentials for years.
Enriched source records
Luna-generated claims retained by the evidence and claim-validation gates. Automated validation does not imply human review. A record does not need a CVE to be included.
Luna-enriched source article · the hacker newsWarning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
Two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances reportedly allow remote code execution and were being actively exploited in the wild as of September 26, according to security firm watchTowr.
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
Two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances reportedly allow remote code execution and were being actively exploited in the wild as of September 26, according to security firm watchTowr.
Source published Sep 27, 2026, 7:47 AM UTC · Evidence retrieved Sep 27, 2026, 1:23 PM UTC
What happened
Two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances reportedly allow remote code execution and were being actively exploited in the wild as of September 26, according to security firm watchTowr. [1]
Citrix had not confirmed the vulnerabilities or published a fix at the time described. [2]
Some generated claims did not pass validation and were omitted. Only retained claims are shown.
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr said on September 26.
- [2]
Citrix has not confirmed the flaws or published a fix.
Luna-enriched source article · securityaffairsRydox Admin Faces 20 Years After Selling Stolen Data and Fraud Tools
Kosovo national Ardit Kutleshi pleaded guilty in the Western District of Pennsylvania to aggravated identity theft and money-laundering conspiracy for building and running Rydox.
Rydox Admin Faces 20 Years After Selling Stolen Data and Fraud Tools
Kosovo national Ardit Kutleshi pleaded guilty in the Western District of Pennsylvania to aggravated identity theft and money-laundering conspiracy for building and running Rydox.
Source published Sep 27, 2026, 9:27 AM UTC · Evidence retrieved Sep 27, 2026, 2:51 PM UTC
What happened
Kosovo national Ardit Kutleshi pleaded guilty in the Western District of Pennsylvania to aggravated identity theft and money-laundering conspiracy for building and running Rydox. [1] [2] [3] [4]
Active since February 2016, Rydox facilitated more than 7,600 transactions involving stolen PII, access devices, identification means, and cybercrime tools or services, generating at least $232,000. [5] [6] [7]
The marketplace listed more than 321,000 products for about 18,000 users, including names, Social Security numbers, and hacking tools; thousands of U.S. victims were affected. [8] [9] [10]
Authorities seized the Rydox domain, servers in Kuala Lumpur, and $225,000 in cryptocurrency during an international investigation involving U.S., Kosovar, Albanian, and Malaysian authorities. [11] [12] [13] [14]
Kutleshi faces a mandatory minimum of two years for aggravated identity theft and up to 20 years for money laundering; sentencing is scheduled for February 9, 2027. [4] [15] [16]
Why it matters
The FBI characterized the marketplace as enabling cybercriminals to buy information and tools for further online crime, while the U.S. attorney said these crimes cause financial and ongoing psychological harm to victims. [17] [18] [19] [20] [21]
The source reports that identity-theft effects can persist through credit checks, background checks, and account recovery for years, beyond the initial fraudulent charge. [22] [23]
Interpretation: The case indicates that an overseas operating location did not prevent U.S. prosecution, but the source does not establish that this outcome applies to all cybercriminals operating abroad. [13] [24]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Kosovo national Ardit Kutleshi pleaded guilty to running Rydox, a cybercrime marketplace that sold stolen identities and credentials for years.
- [2]
Ardit Kutleshi , 28 years old and a citizen of Kosovo, pleaded guilty last week to building and running the cybercrime marketplace Rydox.
- [3]
“Kutleshi pleaded guiltyin the District Court for the Western District of Pennsylvania to aggravated identity theft and money laundering conspiracy.
- [4]
Kutleshi pleaded guilty in the Western District of Pennsylvania to aggravated identity theft and money laundering conspiracy.
- [5]
The Rydox marketplace has been active since February 2016; it facilitated over 7,600 sales of stolen PII, access devices, and cybercrime tools, generating $230,000 since 2016.
- [6]
“According to court documents, since at least 2016, Rydox conducted over 7,600 transactions involving stolen personally identifiable information (PII), stolen access devices, means of identification, and cybercrime tools and services, receiving at least $232,000 in revenue.
- [7]
These transactions involved the sale of PII stolen from victims located in the United States.” reads the DoJ’s press release .
- [8]
It offered over 321,000 products to 18,000 users, including names, social security numbers, and hacking tools.
- [9]
Thousands of U.S.
- [10]
victims were affected.
- [11]
authorities seized the Rydox domain in 2025, a coordinated operation by the FBI and Royal Malaysian Police seized servers in Kuala Lumpur, Malaysia, that hosted the illicit marketplace.
- [12]
The US authorities also seized $225,000 in cryptocurrency.
- [13]
The FBI arrested Kutleshi in Kosovo in December 2024, seized the Rydox.cc domain at the same time, and extradited him to the US in 2025.
- [14]
Coordination on this case included Kosovo’s Special Prosecution Office and Cybercrime Investigation Directorate, Albania’s anti-corruption body, and Malaysia’s Royal Police and Attorney General’s office, which is a genuinely international lineup for what was, at its core, a website selling other people’s information.
- [15]
He faces a mandatory minimum of two years on the identity theft count and up to 20 years on the money laundering charge.
- [16]
Sentencing is scheduled for February 9, 2027.
- [17]
The FBI’s cyber division assistant director put the harm in plain terms.
- [18]
Rydox, he said, put “Cybercriminals Ardit Kutleshi and his brother Jetmir — who pleaded guilty and was sentenced in December 2025 prior to his deportation back to Kosovo — operated the Rydox marketplace for their own gain, making hundreds of thousands of dollars from the marketplace where cyber criminals could purchase information and tools to effect and further their online crime,” said U.S.
- [19]
Attorney Troy Rivetti of the Western District of Pennsylvania.
- [20]
“These types of cybercrimes cause not only financial loss, but also ongoing psychological harm to the victims who lose both money as well as trust in institutions and the online market infrastructure.
- [21]
Our office will continue to work with our law enforcement partners to find and prosecute individuals who attempt to profit from the illegal sharing and sale of other people’s personal information and access devices, and related cybercrime.” That second part is easy to undercount.
- [22]
Identity theft isn’t a one-time event that ends when the fraudulent charge gets reversed.
- [23]
It follows people through credit checks, background checks, and account recovery processes for years, and the damage to how someone trusts systems they have to keep using is harder to quantify than the dollar figure prosecutors cite in press releases.
- [24]
His extradition from Kosovo also shows that operating outside the United States does not necessarily protect cybercriminals from US prosecution.
Additional source records
Threat and risk signalsMicrosoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
Securityweek published details for CVE-2026-65660.
Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
Securityweek published details for CVE-2026-65660.
What happened
Securityweek published details for CVE-2026-65660.
Why it matters
A reviewed impact interpretation has not been published for this record.
Structured associations
Reviewed next steps
- Check asset inventory and patch status for CVE-2026-65660.
Evidence
- Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks Securityweek · Published 2026-09-27T09:23:09Z · Retrieved Sep 27, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Incidents and exposureSecurity Affairs newsletter Round 597 by Pierluigi Paganini – INTERNATIONAL EDITION
Securityaffairs published a source item for review.
Security Affairs newsletter Round 597 by Pierluigi Paganini – INTERNATIONAL EDITION
Securityaffairs published a source item for review.
What happened
Securityaffairs published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Security Affairs newsletter Round 597 by Pierluigi Paganini – INTERNATIONAL EDITION Securityaffairs · Published 2026-09-27T13:40:23Z · Retrieved Sep 27, 2026, 2:51 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Incidents and exposureWeek in review: Gyazo breach exposes 23.6M user data, TASK#STOMP steals documents
Helpnetsecurity published a source item for review.
Week in review: Gyazo breach exposes 23.6M user data, TASK#STOMP steals documents
Helpnetsecurity published a source item for review.
What happened
Helpnetsecurity published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Week in review: Gyazo breach exposes 23.6M user data, TASK#STOMP steals documents Helpnetsecurity · Published 2026-09-27T08:00:49Z · Retrieved Sep 27, 2026, 8:51 AM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.