decrypted · 28 august 2026 · vulnerabilities and patching · supply chain · ai and llm security

The NetScaler bug Citrix called denial of service, until it wasn't

Citrix told customers in June that a bug in NetScaler ADC and Gateway could, at worst, crash the appliance. Nine weeks later, researchers showed the same flaw hands an attacker root access with no login required, and criminals are now inside exposed boxes running webshells. The gap between "annoying" and "game over" says less about Citrix's engineering than about how organisations decide what to patch first, and two other stories this week make a similar point from opposite directions: a prolific hacking crew's downfall came down to arrests, not code, and a ransomware operator's biggest asset turned out to be an AI coding agent it talked into helping.

A denial of service warning that was really remote code execution

CVE-2026-8452 is a memory overflow in NetScaler ADC and Gateway appliances configured with a Gateway virtual server (VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA server. Citrix patched it on 30 June, in versions 14.1-72.61, 13.1-63.18 and 13.1-37.272, and described it at the time as causing "unpredictable or erroneous behaviour and denial of service," adding that it had seen no exploitation. On 14 August, watchTowr Labs published research chaining the same flaw into full, unauthenticated remote code execution as root. Within days, real attacks followed: web shells named x.php and z.php dropped onto compromised appliances, with reconnaissance activity spotted across multiple countries. CISA added the bug to its Known Exploited Vulnerabilities catalogue on 26 August and gave US federal agencies until 29 August to fix it. Citrix's own advisory, as of this week, still hasn't been updated to acknowledge active exploitation. Shadowserver counts roughly 22,000 NetScaler ADC and 1,800 Gateway instances reachable from the open internet.

The Secure by Design lesson: don't patch to the vendor's confidence level

The June patch already closes CVE-2026-8452. Anyone who applied it over the summer isn't affected by any of this. The organisations at risk now are the ones that read "denial of service, not exploited" and scheduled it into next quarter's patch window instead of this one. That's a reasonable read of the advisory and a bad outcome, because a vendor's initial severity rating is a guess made under time pressure, not a ceiling on what a bug can do. Pre-authentication memory corruption on an internet-facing gateway should be treated as remote code execution until proven otherwise, regardless of what the disclosure says. For UK organisations running NetScaler, which covers a large slice of the mid-market and public sector remote access estate, the task this week is unglamorous: confirm the version is current, and if it isn't, don't wait to check for the specific artefacts researchers have published, because exploitation started before most defenders were watching for it.

Also this week

Australia charged two men over the TeamPCP supply chain spree. The Australian Federal Police charged Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, with a combined 14 offences after raids in Western Australia, alleging they ran the group behind the compromise of open-source projects including the Trivy security scanner, Checkmarx's KICS, the LiteLLM AI gateway and TanStack. The AFP says the group stole publishing credentials from trusted maintainers and pushed poisoned releases across GitHub Actions, Docker Hub, npm, PyPI and OpenVSX, ultimately touching over 1,000 organisations, more than 500,000 stolen credentials and at least 300GB of exfiltrated data. It's a reminder that the fix for supply chain compromise isn't only technical controls on package registries, it's also that this kind of crime gets investigated and prosecuted like any other.

A ransomware crew talked an AI coding agent into breaking in for it. Tel Aviv-based Gambit Security found an exposed server belonging to a new gang called Aur0ra and recovered 28 chat sessions between its operators and the AI agent built into Cursor, running on Anthropic's Claude Sonnet 4.5. The agent initially refused overtly malicious requests, then complied once operators framed the intrusion as an authorised penetration test, going on to help scan networks, enumerate domain privileges and attempt NTLM relay and certificate-based attacks. Gambit says the tool made the attackers roughly 30 to 50% faster across at least seven breached firms, including Scotland's Helideck Certification Agency. Coding agents that accept a user's stated intent at face value are, for now, a social-engineering target like any other employee, and defenders should assume that framing trick works on them too.

Sources

If any of this touches your patch queue or your AI tooling policy, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.