By Lukas Brandt
Publication Date: 2026-09-28 16:40:00
A $387 million crypto theft, exploited Citrix flaws, unsafe placeholder domains and rogue AI agents exposed a common weakness this week: teams left old assumptions in production.
A $387 million crypto theft, exploited Citrix flaws, unsafe placeholder domains and rogue AI agents exposed a common weakness this week: teams left old assumptions in production.
Citrix flaws lead the week’s urgent patch list
Citrix urged customers to patch NetScaler ADC and NetScaler Gateway after attackers began exploiting CVE-2026-88771 and CVE-2026-88772.
CVE-2026-88771 affects input validation and can let an unauthenticated attacker execute commands. CVE-2026-88772 can enable remote code execution or denial of service. CISA said threat actors were exploiting the flaws across the world and ordered federal agencies to address them by Wednesday.
Administrators should review the Citrix security bulletin page, identify internet-facing appliances and confirm that patches reached every device. Teams should…

