By BigGo Finance
Publication Date: 2026-09-30 18:29:00
Unknown attackers have been exploiting a critical flaw in Citrix NetScaler appliances to gain root access and plant custom malware inside government agencies, banks, and professional services firms across North America and Europe, according to security researchers tracking the campaign.
The intrusions, observed in September 2026 by Mandiant Consulting and Google Threat Intelligence Group (GTIG), weaponized CVE-2026-88772 — a memory overflow vulnerability in the Datagram Transport Layer Security (DTLS) protocol handling — to bypass authentication and seize control of the underlying FreeBSD operating system.
The attacks delivered a post-exploitation toolkit that includes two previously unreported pieces of malware: WHIPSHOT, a PHP web shell disguised as a Debian software package, and SLAPSHOT, a Python-based TCP tunneling tool used to bridge into internal networks.
Citrix disclosed the flaw on Sunday alongside seven other vulnerabilities. The two most severe issues,…



