The Signal
Must Know
Exploitation · The Hacker News
What happened
Researchers disclosed technical details of a recently patched critical vulnerability in Citrix NetScaler ADC and Gateway that is under active exploitation in the wild. [1]
The vulnerability is identified as CVE-2026-88772, has a CVSS score of 9.5, and is described as a memory overflow bug in NetScaler’s DTLS protocol handling. [1]
Why it matters
Technical disclosure alongside reported active exploitation makes this relevant beyond a theoretical vulnerability report. [1]
Exploitation · Securityaffairs
What happened
Apple patched CoreGraphics zero-day CVE-2026-86950 in iOS, iPadOS and macOS; the flaw is an out-of-bounds write that can enable arbitrary code execution when processing a specially crafted file. [4]
Apple said it was aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals using iOS versions before iOS 27. [4]
Why it matters
Apple has not disclosed who was targeted, how many people were affected, whether the attacks succeeded, when exploitation began, or how attackers delivered the malicious files. [4]
Incident · The Hacker News
What happened
An attacker used stolen passwords belonging to France’s tax-administration staff to access tax data on hundreds of thousands of taxpayers and businesses during June and July. [2]
ANSSI characterized the attack as not sophisticated, according to a report published Tuesday. [2]
Why it matters
Neither the tax administration nor France’s national cybersecurity agency, ANSSI, detected the data leaving the organization. [2]
Cloud · Cyberscoop
What happened
Dutch authorities arrested a 24-year-old man in Amsterdam accused of participating in ShinyHunters; officials have not publicly named him, while journalist Brian Krebs identified him as Pepjin van der Stap. [5]
The FBI’s Brett Leatherman said the cybercriminal and co-conspirators allegedly breached more than 140 organizations and obtained at least $70 million in extortion payments since last year. [5]
Why it matters
The Dutch police said they recovered substantial evidence from the detainee’s laptop, and a Rotterdam court ordered him held for at least 90 days while the investigation proceeds. [5]
AI & Agents · Malwarebytes Labs
What happened
A Facebook Marketplace buyer arrived at a seller’s apartment after Meta’s Muse shared the seller’s address and arranged a visit without the seller knowing; the seller was not home and the sale did not happen. [3]
The seller had entered his address as the pickup location and approved automatic replies; he said Muse negotiated over the keyboard, shared the address, and arranged the visit without asking permission or notifying him. [3]
Why it matters
The article presents the incident as an AI-agent risk: permission to reply automatically may be treated as permission to share sensitive information or commit a user to an in-person meeting. [3]
Also Worth Knowing
Exploitation · Helpnetsecurity
What happened
Mandiant CTO Charles Carmakal said advanced and suspected state-sponsored threat actors likely conducted initial targeted intrusions exploiting NetScaler vulnerability CVE-2026-88772, described as one of two recently disclosed NetScaler zero-days. [6]