Urgent.News

What's breaking now, across thousands of outlets.

Tech

Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services

Two questions remain: who is abusing the CVEs? And why did Citrix take so long to disclose?

Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services

The unknown digital intruders have exploited CVE-2026-88771 and CVE-2026-88772, two critical vulnerabilities in Citrix NetScaler Gateway, to break into government agencies, financial services firms, education organizations, and professional services sectors across North America and Europe. The vendor took too long to disclose the security holes, according to GreyNoise and industry experts.

Citrix has a history of delaying the publication of vulnerabilities, even when they're being exploited in the wild and affecting customers. Google Threat Intelligence Group and Mandiant Consulting revealed that the exploitation campaign has been ongoing since early September, targeting organizations in various sectors. Custom malware, including WHIPSHOT and SLAPSHOT, was found to establish persistent root access and proxy traffic into internal corporate networks.

Google Threat Intelligence Group and Mandiant advised NetScaler customers to inspect their systems for compromise before upgrading/patching, as patching alone may not eradicate the threat actor from the environment.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech

Petrol, Diesel Get Cheaper Again

The federal government has decided to decrease the prices of motor spirit (MS) petrol and high-speed diesel (HSD) for the … Read More The post Petrol, Diesel Get Cheaper Again appeared first on…

More from Tuesday 29 September →