Cybersecurity Weekly Recap: NetScaler and FortiMail Zero-Days, AI Data Leaks, Spectre v2 and Ransomware Arrests
Cybersecurity weekly recap covering exploited NetScaler and FortiMail zero-days, AI coding-agent data leaks, the new Spectre v2 BTR attack, PaperCut exploitation, RatHat malware and ransomware arrests.

The first week of October 2026 brought another wave of major cybersecurity developments, ranging from actively exploited NetScaler and FortiMail vulnerabilities to AI-related data exposure, a new Spectre v2 attack technique and international operations against ransomware groups.
Here are the key developments security teams should know.
Citrix NetScaler Zero-Day Exploited in Targeted Attacks
Citrix disclosed CVE-2026-88779, a high-severity memory overflow vulnerability affecting NetScaler ADC and NetScaler Gateway.
The vulnerability carries a CVSS score of 8.7 and has been exploited in targeted zero-day attacks. Exploitation requires affected customer-managed NetScaler deployments to be configured as either a SAML service provider or SAML identity provider.
Organizations running vulnerable configurations should prioritize Citrix's security updates and review exposed appliances for evidence of compromise.
Critical FortiMail Zero-Day Under Active Exploitation
Fortinet disclosed CVE-2026-104286, a critical FortiMail vulnerability with a CVSS score of 9.8.
The flaw combines path traversal and improper handling of NULL characters, potentially allowing an unauthenticated attacker to write arbitrary files to the underlying system through specially crafted HTTP or HTTPS requests.
CISA added the vulnerability to its Known Exploited Vulnerabilities catalog following confirmed exploitation. Until patched versions are available across affected branches, Fortinet recommends disabling IBE support and preventing internet access to the FortiMail management interface.
AI Coding Agents Expose Thousands of Corporate Screenshots
Research from Glow Labs uncovered more than 13,000 sensitive screenshots associated with software projects from 343 companies in public GitHub repositories.
The research, dubbed PixelLeak, found cases where AI coding agents generated screenshots to demonstrate visual changes and made those images accessible through public repositories.
The incidents highlight an emerging AI security problem: an agent does not need to be malicious to create a data leak. Poorly constrained autonomous actions can unintentionally expose internal applications, development environments and sensitive information.
New Spectre v2 Attack Can Leak Linux Secrets
Researchers demonstrated a new Spectre v2 technique called Branch Target Reuse (BTR).
The attack abuses stale branch-prediction information after a just-in-time engine reuses memory for new code. Researchers reported successfully recovering a Linux root password hash from tested Intel systems within approximately three to five minutes.
The research demonstrates that speculative-execution attacks continue to evolve despite years of hardware and software mitigations.
KillSec Ransomware Infrastructure Seized
International law enforcement also disrupted the KillSec ransomware operation.
As part of Operation KillSwitch, authorities provisionally arrested three suspects, including a 16-year-old suspected of playing a leading role, searched eight properties and seized KillSec infrastructure.
Law enforcement secured more than 110 TB of data and took control of the group's leak site. Investigators are examining roughly 1,000 suspected attacks, with around half currently assessed as successful.
Two Suspected ShinyHunters Members Arrested
Law enforcement operations also targeted individuals allegedly connected to the ShinyHunters cybercrime and extortion ecosystem.
Two suspected members were reported arrested separately in the Netherlands and Jordan as authorities continue investigations into the group's activities.
The arrests follow a period of increased attention around ShinyHunters-linked extortion and data-theft activity.
PaperCut Exploits Used to Deploy AdaptixC2
Researchers also disclosed additional details about attacks exploiting CVE-2026-82078 and CVE-2026-81578 in PaperCut MF.
Attackers used the vulnerabilities to deploy an in-memory Java loader and web shell before delivering a trojanized Microsoft Copilot executable containing an AdaptixC2 implant.
In one intrusion, the attackers reportedly stole a token belonging to a domain-privileged service account, moved laterally to a domain controller and attempted to obtain Active Directory credential hashes from the NTDS.dit database.
AI-Powered Android Malware Identifies High-Value Victims
The Android malware RatHat has also incorporated generative AI into its operations.
Researchers reported that the malware ecosystem uses Google's Gemini to help estimate victims' bank balances from SMS messages and categorize devices based on their perceived financial value.
AI is also reportedly used when malware automation encounters unfamiliar device interfaces, helping determine where interactions should occur.
Google Pauses OSS VRP Product Vulnerability Submissions
Google stopped accepting new Open Source Software Vulnerability Rewards Program (OSS VRP) product vulnerability submissions from October 1.
Google attributed the decision to a substantial increase in automated submissions, most of which it said were invalid.
The company plans to revise the program and provide another update in the first quarter of 2027.
Security Takeaway
This week's developments highlight four areas security teams should prioritize:
Internet-Facing Systems → Patch actively exploited vulnerabilities quickly.
AI Agents → Treat autonomous coding and productivity agents as potential data-exposure paths.
Identity & Privileges → Monitor privileged service accounts and unusual authentication activity.
Incident Response → Patching alone may not be enough after exploitation; organizations should actively hunt for persistence and post-exploitation activity.
The combination of zero-day exploitation, AI-enabled threats and traditional ransomware operations shows that organizations increasingly need both rapid vulnerability management and strong detection capabilities rather than relying on either one alone.
Related reporting
LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Execute Code Without Macro Warnings
Critical LibreOffice and Apache OpenOffice vulnerabilities allow malicious spreadsheets to execute Java code without macro warnings. LibreOffice users should update, while OpenOffice users should disable Java until a fix is released.
Google Pauses Open-Source Product Bug Bounties After Surge in Invalid Automated Reports
Google pauses product vulnerability submissions to its OSS bug bounty program after a surge in invalid automated reports, while supply-chain reports and existing submissions remain unaffected.
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Files Across Eight Products
Atlassian patches CVE-2026-21589, a critical CVSS 9.3 flaw allowing unauthenticated attackers to access known files across Jira, Confluence, Bitbucket and five other Data Center products.


