Follow the latest coverage, related explainers and connected technology stories.
Attackers exploited two zero-day vulnerabilities in Citrix NetScaler appliances to install PHP backdoors and a network tunneling tool, gain root privileges, steal credentials, and move within networks. Citrix released security updates, while Mandiant warned that disabling DTLS addresses only one of the vulnerabilities.
GreyNoise detected a campaign conducted by a Chinese-speaking threat actor that exploited vulnerabilities in WordPress and a wide range of technologies, compromising 49 organizations in 29 countries and 996 devices, and stealing 18,566 records from an SQL server belonging to a Western government entity.
CISA added CVE-2026-7273 in Zyxel GS1900 switches to its catalog of exploited vulnerabilities and ordered U.S. federal civilian agencies to address it by Thursday. GreyNoise says attackers exploited the vulnerability to compromise 996 switches in 48 countries.