CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
Attackers are actively exploiting Citrix NetScaler flaws CVE-2026-88771 and CVE-2026-88779, reportedly chaining them in customer-managed deployments and planting web shells and privileged accounts. Ransomware operators are also abusing TeamCity CVE-2026-63077 to execute operating-system commands and extract AWS credentials, while Cling operators are exploiting a 2021 Realtek flaw across internet-facing IoT devices.
CVE-2026-88771 demands more than a version check: TENEX found web shells, reverse shells, privileged accounts and other implants that can survive installation of patched builds. CVE-2026-88779 adds repeated gateway crashes and reported chaining, while suspected state-linked actors have deployed Whipshot and Slapshot web shells. A clean IOC scan does not conclusively exclude compromise.
A malicious contract admitted to a Base investment vault’s permission list enabled the theft of 1,783 wstETH, worth about $6 million; valid multisig signatures removed and re-added it within roughly a minute. Immediate priorities include hunting for persistent NetScaler implants, updating TeamCity to 2025.11.7 or 2026.1.3, and investigating who authorized vault whitelist changes with valid signatures.
Editorial: Recommended Actions
01
PRIORITY
Patch affected Citrix NetScaler ADC and Gateway appliances immediately, then investigate them for web shells, reverse shells, privileged accounts, and other implants. Attackers are actively exploiting CVE-2026-88771 and CVE-2026-88779, reportedly chaining the flaws against customer-managed and SAML-configured deployments. Do not treat either a clean IOC scan or installation of a patched build as proof that an appliance is uncompromised: observed persistence can survive patching, and a clean scan does not conclusively exclude intrusion.
02
PRIORITY
Upgrade JetBrains TeamCity On-Premises to 2025.11.7 or 2026.1.3 immediately, prioritizing internet-accessible instances running 2025.11.6, 2026.1.2, or earlier. Ransomware operators are actively exploiting unauthenticated CVE-2026-63077 to execute operating-system commands and have reportedly extracted AWS credentials from compromised environments. Examine affected servers for unauthorized command execution and replace any AWS credentials that may have been exposed.
03
PRIORITY
Upgrade Rejetto HFS deployments to version 3.2.1 or later and remove vulnerable servers from internet exposure until remediation is complete. CVE-2026-61500 affects versions 3.0.0 through 3.2.0 and is under active exploitation after publication of a Python proof of concept. Attackers can reconstruct predictable session-key state, forge an administrator session cookie, and use administrative access to execute arbitrary server-side JavaScript; U.S. systems have already been targeted.
04
PRIORITY
Identify and remediate FortiMail 7.2.0–7.2.9, 7.4.0–7.4.8, 7.6.0–7.6.6, and 8.0.0–8.0.1 deployments without delay. Fortinet reports active exploitation of CVE-2026-104286, which allows unauthenticated attackers to write arbitrary files through crafted HTTP or HTTPS requests. Restrict web access to affected appliances while remediation is pending and investigate them for unexpected file writes rather than relying on patching alone.
05
PRIORITY
Revoke or replace the Safe signing keys controlling the affected Base investment vault, suspend whitelist changes, and secure the approximately $31.7 million reportedly still under the same Safe’s control. An attacker drained about $6 million in wstETH after a malicious contract was removed and re-added to the whitelist within roughly one minute using valid multisig signatures. Evidence points to at least three potentially compromised signing keys or signer collusion, not a flaw in Aave V3 or Base.
ROUNDTABLE
Expert Panel Discussion
12 AI experts analyzed this briefing across 3 turns of structured debate
12Agents16Messages25mDuration
→
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_