CRITICALZero Day
Global

Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected

·Source: CyberScoop

Updated:

Executive Summary

Mandiant researchers said dozens of organizations have been impacted by attacks attributed to advanced and suspected state-sponsored threat groups. They expect more attacks to come. The post Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected appeared first on CyberScoop .

Analysis

Mandiant researchers said dozens of organizations have been impacted by attacks attributed to advanced and suspected state-sponsored threat groups. They expect more attacks to come. The post Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected appeared first on CyberScoop .
Source Attribution

Originally published by CyberScoop on Sep 29, 2026.

Related Threats

CRITICALZero Day

The AI app builder your team trusts has a root-level backdoor

The fastest-growing category of enterprise software right now is also the least scrutinized from a security standpoint. AI application platforms — tools that let teams build, connect and automate AI-powered workflows without writing much code — are landing in production environments faster than security teams can assess them. They connect to your APIs, your databases, your cloud credentials and yo

CVE-2026-0768CVE-2026-0769
CSO Online
CRITICALZero Day

ShinyHunters’ exploitation of a new PeopleSoft zero-day hole threatens to change enterprise risk dynamics

A recent compromise of PeopleSoft by hacking group ShinyHunters is causing new concerns for enterprise users of the Oracle product, with analysts recommending extreme measures in response. Law enforcement has made some progress in its pursuit of the cyber criminals involved. On Saturday, Reuters reported that a suspected member of ShinyHunters had been arrested by the FBI and has been cooperating

CVE-2026-35273
CSO Online
CRITICALZero Day

Despite ShinyHunters arrests after FBI jobs data breach, enterprises still have no answers about PeopleSoft risks

The theft of FBI employee data by hacking group ShinyHunters, and the subsequent shutdown of the FBI’s Peoplesoft-based jobs portal , is causing concern for enterprise users of the Oracle product, with analysts recommending extreme measures in response. Law enforcement has made some progress in its pursuit of the cyber criminals involved, but there has still been no official word from either the F

CVE-2026-35273
CSO Online