THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

4 min read

AI-assisted briefingHow we put it together ↗

AT A GLANCE

  • Two critical NetScaler vulnerabilities were exploited before Citrix’s September 27 disclosure; Rapid7 recommends emergency updates and compromise investigations.
  • Former U.S. soldier Cameron John Wagenius received a 70-month prison sentence in a data-theft campaign that also involved extortion and SIM-swapping fraud.
  • The reported RSA implementation demonstrates signature forgery, not private-key recovery, and applies only to signatures without formatting or padding.
01

Citrix NetScaler zero-days exploited before disclosure; emergency patching urged

Rapid7 reports that two critical NetScaler ADC and Gateway vulnerabilities, CVE-2026-88771 and CVE-2026-88772, were exploited in the wild before Citrix disclosed them; CISA added both to its Known Exploited Vulnerabilities catalog. The first can enable remote code execution in default configurations, while the second requires DTLS to be enabled. Rapid7 recommends urgently applying the available updates and investigating vulnerable appliances for signs of compromise.

What changed Citrix’s September 27 disclosure made the vulnerabilities public after attackers had already exploited both as zero-days.

Why it matters NetScaler operators cannot treat patching alone as incident closure: Rapid7 recommends also checking vulnerable appliances for evidence of compromise.

What to watch next Rapid7 expects authenticated vulnerability checks in its September 28 content release; availability is expected, not confirmed in this report.

Rapid7 ↗
02

Former U.S. soldier sentenced for telecom and Snowflake-linked data thefts

The Justice Department says Cameron John Wagenius, a former U.S. Army soldier, was sentenced to 70 months in prison and ordered to pay $294,978 in restitution for his role in a cybercrime campaign targeting telecommunications companies and Snowflake customers. Court documents say the group accessed data from more than 165 Snowflake customer organizations and conspired to extort at least 10 organizations. Wagenius and co-conspirators threatened to publish or sell stolen data, and some of it was used in other frauds, including SIM-swapping.

Why it matters The harm extended beyond ransom demands against organizations: some stolen data was sold or used in SIM-swapping fraud, exposing affected people to further abuse.

What to watch next Another hacker responsible for the Snowflake breaches, Connor Riley Moucka, is due to be sentenced on October 27.

HelpNet Security ↗
03

ETSI guidance warns QRNG output can leak clues despite passing statistical tests

A new ETSI technical report outlines security risks in quantum random number generators and their supporting systems, from the quantum source through delivery to applications. It warns that outputs may pass statistical tests yet still reveal clues about future numbers through predictable component noise or physical signals. The guidance recommends safeguards such as monitoring for unexpected patterns, protecting hardware and connections, and keeping records that trace generated output to its source.

Why it matters For organizations generating cryptographic keys, predictable QRNG output could weaken the protection those keys provide; evaluating randomness is therefore a security assurance task, not merely a performance check.

HelpNet Security ↗
04

Interview highlights exposed credentials and poisoning risks in AI agent memory

Vectorize CEO Chris Latimer told Help Net Security that coding agents may store API keys, credentials and sensitive documents in plain text on developer machines and cloud services. He warned that attackers could use unvetted plugins, skills or MCP integrations to plant poisoned memories or seek sensitive data. Latimer recommends auditing agent-memory use and says organizations should track where stored memories originated to support investigations.

Why it matters For development teams, agent memory can create additional plaintext copies of secrets outside the protections applied during software development, widening the set of locations that need protection.

What to watch next Whether memory products can enforce team-based and graduated access remains an unresolved enterprise requirement; Latimer says most products cannot yet provide the controls users expect.

HelpNet Security ↗
05

AWS report urges governance and human oversight as enterprise AI use grows

AWS’s Reimagine 2026 report draws on confidential interviews with 154 executives at 128 organizations and describes security, privacy and data leakage concerns as AI deployments expand. It cites a survey in which 24% of businesses had a documented approach to responsible AI use and 10% had a data governance strategy. The report recommends embedding controls in systems, keeping people accountable, and expanding agent autonomy only after demonstrating reliability.

Why it matters Enterprise security teams risk losing visibility when approval processes outlast AI experiments: the report describes teams bypassing permission rather than waiting for reviews.

HelpNet Security ↗
06

RSA signature-forgery implementation draws scrutiny over scope and novelty

Bruce Schneier says the RSA attack reported by Ars Technica is based on research dating to 2007, while the implementation is new. He characterizes it as a signature-forgery attack, not a method for recovering the private key, and says it applies only to unformatted, unpadded “pure” signatures. Schneier reports that forging messages for 1024-bit RSA required 1,380 CPU core-years, while noting the approach is somewhat faster than factoring.

What changed The new contribution is an implementation of research dating to 2007, not a newly discovered attack.

Why it matters For teams using formatted or padded RSA signatures, this report does not establish exposure to the demonstrated forgery technique; the stated scope is narrower than RSA use generally.

Schneier Blog ↗
Cybersecurity — September 28, 2026 | Briefing24