importantSYS.SOURCE: The Hacker News• 2026-09-30T13:54:35+05:30
Exploitation of NetScaler Vulnerability CVE-2026-88772 for Root Access and Deployment of WHIPSHOT/SLAPSHOT Malware
Attackers exploited a critical NetScaler vulnerability (CVE-2026-88772) to gain root access, deploying custom web shells WHIPSHOT and tunneler SLAPSHOT for internal network reconnaissance. The campaign targeted multiple sectors through HTTP header-based payload delivery and configuration manipulations.
Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe.
The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has targeted government, financial services, technology, education, and legal and professional
*** END OF TRANSMISSION ***