Security teams faced a familiar mix this week: known vulnerabilities, forgotten infrastructure, and weak service accounts. Citrix released patches for two NetScaler ADC and Gateway flaws, CVE-2026-88771 and CVE-2026-88772, that are already under active exploitation. CISA said threat actors are exploiting the bugs globally and gave federal agencies a Wednesday deadline to patch.

On the financial side, cryptocurrency exchange Bitget resumed Bitcoin withdrawals after a suspected North Korean intrusion that stole more than $387 million. The exchange said its security systems detected unauthorized transfers from a limited number of hot wallets on September 24, while cold wallets and most platform assets remained safe. Circle and Tether have frozen about $339,100 in stablecoins linked to the heist, according to a CoinDesk tracing dashboard.

Attackers also turned documentation assumptions into live attack surface. The placeholder domain third-party[.]com, used in roughly 1,700 repositories, was registered and is now serving a ClickFix lure to Windows browsers while showing a harmless decoy to other users. Unlike example.com, the domain is not IANA-reserved, so anyone could register it. Manifold Security identified 13 more non-reserved placeholder domains, with two already serving scams and scareware to macOS visitors.

Other findings included a TeamFiltration campaign that targeted over 5,700 accounts across 28 Microsoft 365 tenants, compromising seven unmanaged service accounts with default passwords and no MFA. Law enforcement also dismantled the EvilTokens phishing service, arresting two suspects and taking down more than 50 websites. The week's pattern, as the source notes, is less about exotic attacks and more about forgotten assumptions that attackers are happy to exploit.