ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)
Attackers exploited Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-88772, disclosed Sunday, to gain root access and deploy WHIPSHOT and SLAPSHOT malware. Mandiant says intrusions began in early September, hitting government, financial, education, legal and professional services organizations across North America and Europe. GreyNoise saw exploitation on September 24, three days before public disclosure. Citrix released patches; defenders should hunt for.ctxs.receiver files and modified /bin/sh permissions.
Tap to vote and see what everyone thinks.
Summary by ByteBrief