NEWSLETTERIssue #38

Oct 6 Digest: Citrix's Third NetScaler Zero-Day, FortiBleed Still Active, AI Hits Korean Banks

This week: Citrix's third NetScaler zero-day in seven days, FortiBleed lockouts warn of ransomware, AI agents suspected in Korean bank hacks.

Dylan H.

CosmicBytez Labs

October 6, 2026
8 min read
Oct 6 Digest: Citrix's Third NetScaler Zero-Day, FortiBleed Still Active, AI Hits Korean Banks

This Week in Cybersecurity

Edge infrastructure took the hardest hits this week. Citrix disclosed its third actively exploited NetScaler zero-day in less than seven days, while the FBI and Secret Service issued a renewed warning that FortiBleed — far from dead — is still being used against 400,000+ internet-facing Fortinet devices, locking admins out before ransomware crews move in. Atlassian added to the patch pile with a critical, unauthenticated file-access flaw spanning eight Data Center products including Jira, Confluence, and Bitbucket.

The breach ledger stayed just as busy. South Korean officials now believe AI agents built on the Chinese Artex tool helped breach four major banks, exposing data on 68,000+ people — a preview of what automated intrusion tooling looks like at scale. Denmark confirmed attackers abused a company's lawful CPR register access for ten days, pulling identity records on 8.8 million people, and ASOS, Nikkei, Arizona's court system, and two healthcare firms all disclosed breaches of their own this week.

On the research side, Pwn2Own Ireland opened with 32 zero-days exploited on day one alone, and a three-year-old npm supply chain campaign (MALFEX) finally surfaced after quietly accumulating over 40,000 downloads across eight packages.


Top Stories

Citrix Discloses Third Actively Exploited NetScaler Zero-Day in Under a Week

CVE-2026-88779, a SAML-related flaw in Citrix NetScaler, is the third zero-day disclosed and actively exploited in the product line in less than seven days. Citrix's response was notably faster than prior incidents, limiting the exposure window, but three zero-days in one week against the same edge appliance line is a signal that NetScaler deployments are under sustained, targeted research — not opportunistic scanning.

Full story →

FBI and Secret Service: FortiBleed Is Still Active, Now Linked to 400,000+ Devices

FortiBleed was never fully contained. A fresh joint alert from the FBI and Secret Service ties the campaign to over 400,000 internet-exposed Fortinet devices, with victims reporting sudden account lockouts that precede full ransomware deployment. Treat any unexplained Fortinet admin lockout this week as a potential precursor event, not an IT glitch.

Full story →

Atlassian Warns of Critical File-Access Flaw Across Jira, Confluence, Bitbucket

CVE-2026-21589 (CVSS 9.3) lets unauthenticated attackers read arbitrary files across eight Atlassian Data Center products, including Jira, Confluence, and Bitbucket. Self-hosted Data Center instances — common in enterprises that avoided Atlassian Cloud for compliance reasons — are the direct target. Patch immediately; file-read primitives on issue trackers and wikis routinely yield credentials and internal documentation.

Full story →

South Korean Officials Believe AI Agents Hacked Several Banks

Investigators in South Korea believe autonomous AI agents built on the Chinese Artex tool were used to breach Shinhan, KB Kookmin, Hana, and Woori banks, exposing data on more than 68,000 people via credential stuffing at machine speed and scale. If confirmed, it's one of the clearest examples yet of AI-agent tooling operationalized for financial-sector intrusion rather than used experimentally.

Full story →

Denmark: Attackers Accessed CPR Data for 8.8 Million People via Company Account

Attackers abused a Danish company's lawful access to the national CPR register for ten days in September, extracting names, addresses, and ID numbers for 8.8 million people — nearly the entire population. The incident underscores third-party risk at its most extreme: the access itself wasn't a vulnerability, it was a legitimate business integration turned into a mass-exfiltration pipeline.

Full story →


Security Corner

10 new advisories published to the Security Advisories section this week — six rated Critical. Notable findings below.

CVE-2026-105740 / CVE-2026-105697 — Langflow MCP Stdio RCE Cluster (CVSS Critical ×2) Langflow's first fix for an MCP Stdio remote code execution flaw was incomplete — the same bash -c exec pattern stayed reachable through version 1.10.2. Only 1.10.3, which removes the shell entirely, closes it. Anyone who patched to 1.9.0 and stopped there is still exposed. CVE-2026-105740 → · CVE-2026-105697 →

CVE-2026-105215 / CVE-2026-105209 — ZITADEL Account Takeover Cluster (CVSS Critical ×2) Two distinct identity-provider flaws in ZITADEL: forged external IdP callbacks enable account pre-hijacking before a victim ever logs in, and a cross-organization bug lets low-privileged admins enroll passkeys on other orgs' accounts. Both hit the login/identity layer directly — patch before auditing anything downstream. CVE-2026-105215 → · CVE-2026-105209 →

CVE-2026-88395 — GouGuOA Unauthenticated SQL Injection (CVSS 9.8 Critical) Unauthenticated SQL injection via the keywords parameter in GouGuOA ≤6.0.5, enabling full database compromise with no credentials required. Full advisory →

CVE-2026-79820 — HPE iLO 7 Remote Authentication Bypass (CVSS 9.0 Critical) A remote user-validation failure in HPE Integrated Lights-Out 7 firmware can hand attackers full administrative control of the BMC — and by extension, the host it manages. Full advisory →

CVE-2026-88391 — Northstar Exposed H2 Console with Default Credentials → RCE dromara/northstar ships an unauthenticated H2 Console reachable with default sa credentials, letting network attackers run arbitrary SQL and escalate to remote code execution. Full advisory →

Also this week:

  • CVE-2026-105182 — Unauthenticated SQL injection in SourceCodester Online Reviewer Management System via the Title parameter →
  • CVE-2026-105221 — The gist RubyGem disables TLS certificate validation on every HTTPS connection before 6.1.0, exposing GitHub OAuth tokens to on-path attackers →
  • CVE-2026-105158 — Unauthenticated SQL injection in RainyGao DocSys via its database-management component →

Quick Takes

  • MALFEX npm Campaign Surfaces After 3 Years, 40,767 Downloads: Checkmarx traced a long-running supply chain campaign across 8 npm packages spreading the Overlord RAT and Movinlike infostealer — live and collecting downloads the entire time. Read more →
  • Ninja Forms + WPC Product Bundles Flaws Backdoor 530,000+ WordPress Sites: Attackers are chaining stored XSS bugs in two popular plugins to plant hidden admin accounts and backdoors at scale. Read more →
  • Pwn2Own Ireland Day One: 32 Zero-Days, $388,500 Paid Out: Researchers hit the Samsung Galaxy S26 twice among 32 successful exploits on the competition's opening day. Read more →
  • Rejetto HFS Servers Actively Scanned for Weak Signing-Key RCE: CVE-2026-61500 enables session forgery and remote code execution; mass scanning is already underway. Read more →
  • ASOS Confirms Breach After "HACKED" Push Notifications: Attackers sent unauthorized in-app alerts claiming compromise of ASOS's Snowflake environment; the company has now confirmed the breach. Read more →
  • Arizona Court Breach Hits Over 1.3 Million People, Records Span 30 Years: The state Supreme Court confirmed the September cyberattack exposed decades-old records including Social Security numbers. Read more →
  • Nikkei Discloses Breach of Employee M365, Google Workspace Accounts: One compromised account was used to send roughly 9,000 phishing emails to staff and sources. Read more →
  • Osaka Metropolitan University Cancels Classes After Suspected Ransomware Attack: ~500 servers went down, exposing data on 130,000+ students and staff. Read more →
  • FBI Fires Accenture Contractor Over Patch Failure Behind ShinyHunters Breach: A skipped required patch on an Oracle PeopleSoft flaw let ShinyHunters into the FBI's jobs portal. Read more →
  • Engineer Sentenced to 32 Months for Locking 3,000+ Employer Devices: Daniel Rhyne demanded $750,000 in bitcoin after locking out servers and workstations network-wide. Read more →
  • 250,000 Impacted by Healthcare Breaches in New Jersey, Texas: Clover Health Investments and AngMar Management Services separately disclosed breaches exposing PII and PHI. Read more →
  • Google Pauses OSS Bug Bounty Payouts After Flood of Invalid AI-Generated Reports: A surge in low-quality automated submissions to Go, Angular, and Bazel forced a payout pause starting October 1. Read more →
  • Critical Healthcare Systems Aren't Quantum-Ready: A Forescout study of 2.5 million healthcare devices found only 6% of IoMT and 16% of OT devices are prepared for post-quantum cryptography. Read more →
  • Former NSA Chief Nakasone: Agency Overhaul "Probably Needed": Paul Nakasone backs a reported five-center NSA reorg to keep pace with AI-driven threats, while warning an aging workforce could undercut execution. Read more →
  • Fake ChatGPT, Gemini, and Claude Ad Portals Steal Logins and MFA Codes: A human-operated phishing platform impersonates AI-provider ad portals to harvest credentials and bypass MFA. Read more →

Upcoming

Citrix's track record this week suggests more NetScaler disclosures could land before the dust settles — keep patch cadence tight and watch CISA's KEV catalog for a formal addition. Pwn2Own Ireland continues through the rest of the week, with day-two and day-three results typically surfacing additional zero-days in IoT, mobile, and enterprise targets worth tracking for your own exposure. Atlassian Data Center admins should treat CVE-2026-21589 remediation as this week's top patch-management priority, and Fortinet admins should audit for unexplained lockouts rather than assume a benign cause. We'll have the full picture — plus whatever Pwn2Own turns up next — in next week's digest.


CosmicBytez Labs — IT & Cybersecurity Intelligence Hub

Unsubscribe · Privacy Policy · View in browser