I'm tired, boss.
A new #Citrix CVE affecting SAML IdP/SP-configured devices is out.

@ifin-intel.org
The Independent Federated Intelligence Network. Our mission: Empower organizations to independently collect, analyze, and disseminate relevant cyber threat intelligence through training, open source tools, and a decentralized intelligence sharing network.
IFIN will be submitting commentary in strong opposition to the obviously dangerous requested TLDs in the latest round of applications to ICANN. Anything that is approved and still dangerous will be added to the IFIN Lists for easy blocking.
Commenting before the 27th incentivizes requesters to rescind their application, recouping much of their significant application fee.
We encourage others to submit commentary starting November 17.
IFIN will be submitting commentary in strong opposition to the obviously dangerous requested TLDs in the latest round of applications to ICANN. Anything that is approved and still dangerous will be added to the IFIN Lists for easy blocking.
Once again: Evidence of exploitation *attempts* Is not Evidence of *exploitation* That's a much higher bar to clear.
I'm tired, boss.
A new #Citrix CVE affecting SAML IdP/SP-configured devices is out.
The Shai-Hulud style attack on tensorlake has a nasty trick up its sleeve: try to cycle the stolen token, and it'll blow away your home folder, if you're not careful.
Chat, is it bad if your zero-trust VPN device forwards network requests without auth? Asking for thousands of friends.
SonicWall SMA1000 devices have a SSRF vulnerability that needs patching.
The TIIMA crop top was requested—nay, *demanded*. We have complied.
Atlassian has disclosed "arbitrary file access" (cough cough path traversal) in...basically everything. Patches available, but so now is a broad proof-of-concept. Not yet known-exploited, emphasis on "yet."
This is the patch that never ends
It goes on and on my friends
Some people
Started applying it
Not knowing what it was
And they will keep applying it
Forever just because
(CVE-2026-88779 advisory and patch included now)
If you are having #Citrix #Netscaler issues after applying all patches and remediations and want to confidentially share intel, let us know: tipsIFIN
PGP key available at
If you are having #Citrix #Netscaler issues after applying all patches and remediations and want to confidentially share intel, let us know: tipsIFIN
PGP key available at
*Sigh*
The new reports of further exploitation of Citrix devices and all known observables have been added to our report/MISP feed.
Really too early to call anything "worst" without evidence of impact. This has been a particularly hectic one to cover. In truth, this situation *makes the case* for our existence. It's the community that is sharing the most useful intelligence, not vendors.
*Sigh*
The new reports of further exploitation of Citrix devices and all known observables have been added to our report/MISP feed.
Well would you look at that; it's Cisco 0-day o'clock again.
New swag in the shop. #TIIMA
If you're involved in vulnerability management/VulnOps, the last several months have been overwhelming. But take heart: there is a path forward, despite the madness surrounding us.
Add to MISP: misp.ifin.network/feed
Validate Manifest: misp.ifin.network/feed/manifes...