Weekly Threat Recap: Citrix Flaws Under Active Attack, Plus a $387M Crypto Heist
Citrix has released urgent patches for two vulnerabilities in its NetScaler ADC and Gateway products that are already being exploited by attackers worldwide. CVE-2026-88771 is an input validation flaw that could let an unauthenticated attacker run arbitrary commands on affected systems, while CVE-2026-88772 could lead to remote code execution or a denial-of-service condition. The US Cybersecurity and Infrastructure Security Agency (CISA) confirmed active exploitation and directed federal agencies to patch immediately.
This was one of several stories in a broader weekly recap that highlighted how attackers continue to succeed not through exotic new techniques, but by exploiting old bugs, weak service accounts, exposed systems, and forgotten infrastructure. One notable example involved a placeholder domain used in roughly 1,700 code repositories, which was later registered by an attacker and turned into a tool for serving malicious content, a reminder that outdated assumptions can quietly become live attack surfaces.
The recap also referenced a $387 million cryptocurrency hack and other emerging threats, underscoring that this was a particularly active week across multiple areas of the threat landscape, from infrastructure exploitation to AI-related risks.