#2
CyberScoop
general
September 29, 2026 at 21:30 UTC
Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected
By Matt Kapko
AI Summary
Mandiant researchers confirmed that dozens of organizations were compromised via a Citrix NetScaler zero-day (CVE-2026-88771/CVE-2026-88772) for at least three weeks before detection, with attacks attributed to advanced and suspected state-sponsored threat groups. Attackers deployed web shells mapped to CSS-like URLs and created superuser accounts for persistent access. Mandiant expects additional exploitation waves as technical details are now public.
Relevance score: 91.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →