Applied cybersecurity, ph.d, cissp, riss, team enu, team v, mws, ntv, samurai kids, enlightened, team valor. My opinions are my own, not views of my belonging.
On September 24, GreyNoise observed zero-day exploitation attempts against Citrix NetScaler Gateway, now tracked as CVE-2026-88771. Existing GreyNoise detections flagged the source IP as malicious within seconds, three days before the vulnerability was publicly disclosed.
The attacker's post-exploitation payload and IOCs: https://t.co/8E2AWwepXN
#GreyNoise #Citrix #Netscaler #CVE202688771 #Cybersecurity #0day #Vuln
‼️ WARNING — Citrix NetScaler is facing two unpatched RCE 0-days under active exploitation.
Researchers at watchTowr say the flaws are being exploited in the wild. Citrix has not confirmed them or released a patch, affected-version guidance, workaround, or indicators of compromise.
What defenders should know now: https://t.co/12vsIOYaWc
After the Hugging Face incident, we committed to conducting a much broader review of actions taken by our models during training and evaluation and to being transparent about our findings. This is an extensive review that is ongoing.
The vast majority of actions we’ve reviewed were completions of mundane research tasks, such as accessing publicly available web content to answer questions. Our investigation focuses on instances where agents interacted with third-party websites in ways that went beyond their assigned tasks or intended methods. Most cases identified so far have been lower severity, with limited or no evidence of meaningful impact to the third-party service.
While our review is underway, we want to share more about this work and make sure people understand our disclosure process and notifications to affected third parties.
Given the scale of the review required, and the need to assess each case, we expect this work will take months to complete.
https://t.co/IH4TkS72Vh
🚨 On 9/22/26, #F5 published a security advisory for CVE-2026-94127 – a critical heap-based buffer overflow vuln. affecting F5 BIG-IP APM.
An unauth. attacker with network access to an affected virtual server may be able to achieve RCE. More in our blog: https://t.co/ueLzxdbkLu
Cisco Talos is proud to introduce CAIRN, a new metadata-first research toolkit designed to scale the hunting and classification of AI-integrated malware without defenders needing to download binaries: https://t.co/MZZO3qYS8p
📉 Decreased HTTP traffic in AS174 (Cogent Communications) starting at 20:00 UTC amidst reports of a fiber cut in New Jersey, a critical region for fiber interconnects.
https://t.co/okmS9ckIif