⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
AI Summary
Multiple critical zero-day vulnerabilities were exploited in the wild this week, including CVE-2026-88779 in Citrix NetScaler ADC and Gateway, and CVE-2026-104286 in Fortinet FortiMail, both allowing remote code execution or arbitrary file writes. Russian state-sponsored group Star Blizzard deployed a new malware delivery technique called RedFlick to install the CosmicPulse backdoor via phishing. A Chinese-linked post-compromise malware, NeedyMantis, has been used in targeted operations since October 2025. Additionally, law enforcement disrupted the KillSec ransomware group and arrested members of ShinyHunters. A new Spectre v2 variant, BTR, enables rapid extraction of Linux root password hashes on Intel systems.
AI-extracted · verify before operational use