{
  "id": 10754500,
  "title": "Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services",
  "url": "https://urgent.news/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-29T17:49:45.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/security/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-professional-services/5299867"
  },
  "original_language": "en",
  "account": "The unknown digital intruders have exploited CVE-2026-88771 and CVE-2026-88772, two critical vulnerabilities in Citrix NetScaler Gateway, to break into government agencies, financial services firms, education organizations, and professional services sectors across North America and Europe. The vendor took too long to disclose the security holes, according to GreyNoise and industry experts. Citrix has a history of delaying the publication of vulnerabilities, even when they're being exploited in the wild and affecting customers. Google Threat Intelligence Group and Mandiant Consulting revealed that the exploitation campaign has been ongoing since early September, targeting organizations in various sectors. Custom malware, including WHIPSHOT and SLAPSHOT, was found to establish persistent root access and proxy traffic into internal corporate networks. Google Threat Intelligence Group and Mandiant advised NetScaler customers to inspect their systems for compromise before upgrading/patching, as patching alone may not eradicate the threat actor from the environment.",
  "summary": "Two questions remain: who is abusing the CVEs? And why did Citrix take so long to disclose?",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register Science",
        "title": "Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services",
        "url": "https://urgent.news/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-10759359",
        "published": "2026-09-29T17:49:45.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}