I'm tired, boss.
A new #Citrix CVE affecting SAML IdP/SP-configured devices is out.

I'm tired, boss.
A new #Citrix CVE affecting SAML IdP/SP-configured devices is out.
The Shai-Hulud style attack on tensorlake has a nasty trick up its sleeve: try to cycle the stolen token, and it'll blow away your home folder, if you're not careful.
Chat, is it bad if your zero-trust VPN device forwards network requests without auth? Asking for thousands of friends.
SonicWall SMA1000 devices have a SSRF vulnerability that needs patching.
The TIIMA crop top was requested—nay, *demanded*. We have complied.
Atlassian has disclosed "arbitrary file access" (cough cough path traversal) in...basically everything. Patches available, but so now is a broad proof-of-concept. Not yet known-exploited, emphasis on "yet."
*Sigh*
The new reports of further exploitation of Citrix devices and all known observables have been added to our report/MISP feed.
Well would you look at that; it's Cisco 0-day o'clock again.
We've been continuously updating this post with the latest information—now including details on exploitation of CVE-2026-88772. And all relevant indicators have been added to our MISP feed.
We have updated our coverage of the new #Citrix #Netscaler vulnerabilities with the vendor's advisory.
We are tracking the story about undisclosed 0-days in Citrix Netscaler devices. We have confirmation from multiple source now about the veracity of the claims, although few details from Citrix themselves. This is a developing story.
The best time to block the finger protocol (port 79/tcp) outbound from your network was like…the second Clinton administration? But now's a good time too.
Completing our tour of new known-exploited vulns today, here is Arista's perfect-10.
When it rains, it pours. F5 BIG-IP APM also has an exploited CVE!
Two Check Point critical vulnerabilities are now listed as exploited in the wild.
Rust maintainers are targeted (again), but good news: the same defenses as always apply.
Based on a community tip (we love those!), we discovered yet another malware family that's bringing its own Python interpreter—and a few other tricks.
Bring-Your-Own-Python is *so hot right now*
The "Lorem Ipsum" malware family is still alive and kickin', delivered by our old pals ClickFix and Etherhiding.
Block abliteration[.]ai right now
The new BigBear2 reverse proxy phishing campaign has some interesting tricks up its sleeve.