This week's threats found leverage in small, easily overlooked details: a blank field, a public repo, one reply to an email. Citrix warned that a high-severity NetScaler ADC and Gateway flaw, CVE-2026-88779, has been exploited in targeted zero-day attacks. The memory overflow issue carries a CVSS score of 8.7 and affects deployments configured as a SAML service provider or identity provider. Separately, CISA flagged active exploitation of a critical FortiMail vulnerability, CVE-2026-104286, which scores 9.8 and lets unauthenticated attackers write arbitrary files via crafted HTTP or HTTPS requests.
Researchers also detailed a new Spectre v2 attack variant called Branch Target Reuse (BTR) that can recover root password hashes from Intel Linux systems in minutes. The attack exploits stale branch predictor information after a JIT engine reuses memory, tricking the processor into executing wrong instructions. The researchers say no current CPU has a mechanism to keep the branch predictor and actual code state in sync, leaving the vulnerability open until vendors add one.
Law enforcement made notable arrests as well. Spanish police apprehended a 16-year-old suspected to be the leader of the KillSec ransomware group, with Europol seizing 110 terabytes of data from its leak site. Two members of the ShinyHunters extortion group were also arrested, one in Amsterdam and one in Jordan. The week also saw Russian state-sponsored actor Star Blizzard using fake invites to deploy the CosmicPulse backdoor, underscoring how phishing remains a reliable entry point even as attackers adopt more sophisticated techniques.