Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Government must stop dithering over energy bill support for the vulnerable | Energy bills

    September 30, 2026

    Factory CEO just accused his VC board advisor of spying for Cognition

    September 30, 2026

    Russian state hackers use new RedFlick technique to push malware

    September 30, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Government must stop dithering over energy bill support for the vulnerable | Energy bills
    • Factory CEO just accused his VC board advisor of spying for Cognition
    • Russian state hackers use new RedFlick technique to push malware
    • UK Brings Crypto Under Full FCA Oversight For The First Time
    • Mulberry may reshape gut bacteria and influence metabolism
    • New releases a leap forward for endangered frog in southern California
    • A proportional representation voting system could spell disaster for Labour | Electoral reform
    • Ethiopia fighting escalates in Tigray killing 52 civilians in Alamata, medic tells the BBC
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 30
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 30, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Google’s Mandiant and Threat Intelligence Group (GTIG) have published details on attacks exploiting the NetScaler zero-days that Citrix patched over the weekend.

    The vulnerabilities are tracked as CVE-2026-88771 and CVE-2026-88772, and they affect NetScaler ADC and NetScaler Gateway instances. Attackers can exploit these critical flaws for unauthenticated remote code execution. 

    Before Citrix released patches, government cybersecurity agencies and security firms took the rare step of urging administrators to disconnect affected NetScaler appliances from the internet immediately while zero-day exploitation investigations were ongoing.

    Mandiant and GTIG, whose report focuses on the exploitation of CVE-2026-88772, spotted attacks in late September. However, their investigation found that the zero-day campaign has been “ongoing since at least early September.”

    The attacks likely impacted organizations in North America and Europe. These organizations are in the government, financial services, education, legal, and professional services sectors.

    The attackers exploited the vulnerability to gain root access to NetScaler ADC and Gateway appliances. They then changed the appliance’s web server configuration so they could plant web shells and run them with root privileges.

    Advertisement. Scroll to continue reading.

    Mandiant found previously unseen malware in the attacks, including a PHP web shell named WHIPSHOT and a Python-based tunneling tool named SLAPSHOT. The two work together to give the attackers a path from the compromised appliance into the victim’s internal network.

    According to Mandiant, the tools enable internal reconnaissance, lateral movement and credential theft. In at least one intrusion, the hackers used the tunnel to manually explore the internal network and steal credentials.

    Mandiant also saw signs that the threat actor may be managing similar web shells in multiple compromised environments.

    Mandiant CTO Charles Carmakal noted that dozens of organizations have been hit, including by suspected state-sponsored threat actors. 

    “We expect broad and opportunistic exploitation of CVE-2026-88772 and CVE-2026-88771 by a variety of threat actors in the near term,” Carmakal warned.

    Cybersecurity expert Kevin Beaumont reported being aware of more than 100 victim organizations as of Tuesday, noting that the attacks appear to be part of an espionage campaign. 

    Security firm WatchTowr, one of the first to confirm in-the-wild exploitation, has released technical details on both CVE-2026-88772 and CVE-2026-88771.

    Threat intelligence company GreyNoise observed zero-day exploitation attempts on September 24, several days before the flaws were disclosed and patched. 

    “The [malicious cyber actor] attempted to set both the Set User ID (setuid) and Set Group ID (setgid) bits on /bin/sh to obtain a root shell and install a password-protected webshell that accepts communication by the cookie value sent by the adversary. This may be to avoid persisting their commands in web logs,” GreyNoise explained.

    Palo Alto Networks reported that there had been roughly 50,000 potentially exposed NetScaler instances as of September 27.

    Related: Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

    Related: Apple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’

    Related: New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks

    attacks Finance government NetScaler orgs targeted weekslong ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Government must stop dithering over energy bill support for the vulnerable | Energy bills

    Russian state hackers use new RedFlick technique to push malware

    WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

    Cisco warns of new SD-WAN zero-day exploited in attacks

    CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS

    The MFA you have isn’t the MFA you think you have

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Government must stop dithering over energy bill support for the vulnerable | Energy bills

    September 30, 2026

    Factory CEO just accused his VC board advisor of spying for Cognition

    September 30, 2026

    Russian state hackers use new RedFlick technique to push malware

    September 30, 2026

    UK Brings Crypto Under Full FCA Oversight For The First Time

    September 30, 2026
    Latest Posts

    Don Lemon Accuses Justice Dept. of Vindictive Prosecution in Church Protest Case

    August 7, 2026

    Kemi Badenoch pens letter to Clacton voters ahead of by-election

    August 7, 2026

    Thetford residents remain on edge after days of ‘mob rule’ over asylum plans | Norfolk

    August 7, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Government must stop dithering over energy bill support for the vulnerable | Energy bills

    September 30, 2026

    Factory CEO just accused his VC board advisor of spying for Cognition

    September 30, 2026

    Russian state hackers use new RedFlick technique to push malware

    September 30, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.