The Matthew Chapman Podcast

Citrix NetScaler SAML Zero-Day Hits KEV Ahead of Wednesday

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 4:25
Here is your briefing for Monday, October fifth, twenty twenty-six. Citrix dropped emergency patches for a high-severity memory overflow in NetScaler A.D.C. and Gateway, tracked as C.V.E. twenty twenty-six dash eighty-eight thousand seven hundred seventy-nine, after targeted zero-day attacks against customer-managed boxes configured as a SAML service provider or identity provider. C.I.S.A. put it in the Known Exploited Vulnerabilities catalog with a Wednesday, October seventh deadline for federal agencies. WatchTowr reproduced the flaw within hours of honeypot crashes, and researchers are still arguing whether it stops at denial of service or stretches into remote code execution the way earlier NetScaler bugs did. If you run SAML on NetScaler, this is not a wait-and-see patch. VulnCheck is seeing live exploitation of C.V.E. twenty twenty-six dash sixty-one thousand five hundred, a critical nine-point-three in Rejetto H.T.T.P. File Server versions three point zero through three point two. The cookie signing key comes from JavaScript Math.random, and that same weak generator leaks enough bits during login for an attacker to forge an admin session and run server-side code. Horizon three used Anthropic's Mythos model to find the bug, a public proof of concept landed late September, and VulnCheck says a China-based actor started hitting real U.S. hosts the next day. The fix shipped in three point two point one back in July. If you still have an old H.F.S. box on the internet, pull it or patch it. Apple says it will tighten Full Disk Access on macOS because some apps, especially AI agents, are using that permission to read mail, messages, files, and browsing history without users really understanding the blast radius. Full Disk Access has been the quiet skeleton key since Mojave, and Apple wants an explicit user action before anything gets that deep. The timing is not subtle. Meta's Muse agent needed Full Disk Access plus a Messages connector to read iMessages, Patrick Wardle showed how Muse's Mac app could amplify local malware, and OpenAI's ChatGPT Mac app just ate a similar chat-log flaw. Agents with god-mode permissions are the new privileged process. Reuters reports that a ShinyHunters operator known as Rey, identified as Saif al-Din Khader, was detained in Jordan on September twenty-ninth and is cooperating with the F.B.I. to name other members. Krebs previously flagged Rey as one of the administrators of Scattered LAPSUS$ Hunters and a former BreachForums admin. This lands right after the Dutch arrest of Pepijn van der Stap, alleged Umbreon, and after ShinyHunters hit Clop's leak site and an F.B.I. jobs portal. F.B.I. leadership is already talking about more leads and more arrests. The brand keeps reshuffling, but the people behind it are getting a lot less anonymous. Proofpoint is tracking a China-aligned group it calls T.A. four nineteen that has been phishing A.I. policy experts at U.S. think tanks, universities, and law firms. One lure impersonated an Anthropic employee with the subject line Request for Feedback on Military Integration of Claude. After a polite first email, the follow-up drops a shortened link through Cloudflare Turnstile into a OneDrive adversary-in-the-middle page using Frameless BitB, so the Microsoft sign-in succeeds while session cookies get stolen in the background. Passkeys help. Unsolicited A.I. policy outreach does not get a free click. From NetScaler and H.F.S. under active exploit, to Apple slamming the brakes on agent disk access, to ShinyHunters losing another name and Chinese spies fishing A.I. policy staff, identity and privileged automation keep showing up as the real battlefield. Patch the edge, distrust the agent permission prompts, and verify who is asking for your login. That's the briefing. Stay sharp, keep your systems patched, and we'll see you tomorrow.

Kindle: https://www.amazon.com/dp/B0HHMH88H9 
Apple Books: https://books.apple.com/us/book/local-ai-on-the-mac/id6807243472

https://mattchapman.net

Support the show