{"id":306,"date":"2026-10-02T04:47:59","date_gmt":"2026-10-02T04:47:59","guid":{"rendered":"https:\/\/managedt.com\/blog\/security-roundup-september-30-citrix-netscaler-unsloth\/"},"modified":"2026-10-02T04:48:00","modified_gmt":"2026-10-02T04:48:00","slug":"security-roundup-september-30-citrix-netscaler-unsloth","status":"publish","type":"post","link":"https:\/\/managedt.com\/blog\/security-roundup-september-30-citrix-netscaler-unsloth\/","title":{"rendered":"Security Roundup, September 30: Citrix NetScaler Exploit and Unsloth Studio Flaw"},"content":{"rendered":"<p>Two pre-authentication flaws put enterprise gateways and AI development environments at the top of this week&#8217;s patch list. A new Spectre v2 variant can pull Linux root password hashes in minutes, and a wave of older unpatched vulnerabilities is still sitting exposed on thousands of internet-facing systems.<\/p>\n<h2>Citrix NetScaler CVE-2026-88772: pre-auth path to shellcode<\/h2>\n<p>A critical flaw in Citrix NetScaler ADC and NetScaler Gateway gives attackers a pre-authentication route to shellcode execution on the appliance. The issue sits in the management interface and does not require a valid user session, so any NetScaler exposed to the internet is a candidate target. Once code runs on the appliance, the attacker typically gains a stable foothold that can be used to reach back-end services and harvest credentials.<\/p>\n<p>NetScaler appliances are common in front of business applications, so the blast radius extends well past the device itself. IT teams running NetScaler should confirm they are on a fixed build, restrict the management interface to trusted networks or jump hosts, and review logs for unusual requests against the management endpoint.<\/p>\n<h2>Unsloth Studio: inspecting a model is enough to run code<\/h2>\n<p>A vulnerability in the Web UI front end for Unsloth, a popular open-weight library for fine-tuning and quantizing large language models, allowed arbitrary Python code execution simply by selecting a model. The malicious code shipped inside the model&#8217;s Hugging Face repository and ran during a routine metadata read of the model&#8217;s config file, before any weights were loaded or inference was attempted. The flaw has since been fixed.<\/p>\n<p>Because the code ran with the permissions of the user inspecting the model, an attacker targeting an enterprise AI development environment could reach proprietary training data, model artifacts, and credentials tied to the process, including cloud logins and SSH keys. Teams using Unsloth Studio should update to the patched release, audit which models were inspected in the affected window, and rotate any secrets stored on machines used for model selection.<\/p>\n<h2>Spectre v2 Branch Target Reuse: root password hash in minutes<\/h2>\n<p>Researchers have published Branch Target Reuse (BTR), a new Spectre v2 variant that recovers root password hashes from Intel systems running Linux in just a few minutes. The attack exploits stale indirect branch prediction entries that survive after a just-in-time engine rewrites code at the same memory address. By misdirecting speculative execution, the attacker can read kernel memory through a side channel.<\/p>\n<p>The team behind the work evaluated the technique against Linux cBPF, Oracle&#8217;s GraalVM runtime, and SpiderMonkey in Firefox, and built two end-to-end exploits against the Linux kernel. The issues are tracked as CVE-2026-64507 and CVE-2026-64508, and fixes have been merged into the Linux kernel. The same class of attack also affects AMD and Arm CPUs, since the underlying prediction behaviour is shared. Linux administrators should apply the kernel patches as they reach their distribution channels and review cBPF exposure in container and sandbox setups.<\/p>\n<h2>South Africa air traffic control cyberattack<\/h2>\n<p>South Africa&#8217;s state-owned air traffic operator has asked for international help after a cyberattack on aviation systems. A ransomware toolkit was installed on at least one operational network, and the incident is part of a wider pattern of attacks on aviation infrastructure. The country is working with external responders to contain the intrusion and restore services.<\/p>\n<p>Organizations that depend on South African airspace or route data should watch for flight disruption updates and review any integrations that pull from affected systems. Aviation-adjacent businesses should also revisit segmentation between IT and operational technology networks.<\/p>\n<h2>NeedyMantis malware framework<\/h2>\n<p>A previously unidentified malware family is giving a China-based threat actor long-term stealth access to networks it has already compromised. Microsoft observed the framework, tracked as NeedyMantis, in targeted intrusions against telecommunications providers, universities, medical organizations, and government-related bodies. The toolset is designed to persist quietly after the initial break-in, which creates a blind spot for defenders who focus only on entry-point detection.<\/p>\n<p>Defenders in the named sectors should hunt for unusual service account activity, unexpected scheduled tasks, and outbound traffic to unfamiliar infrastructure. Long-running investigations of past intrusions in these verticals may also benefit from a re-review with the new indicators in mind.<\/p>\n<h2>French tax data theft: stolen staff passwords, seven weeks undetected<\/h2>\n<p>An attacker used stolen credentials belonging to staff at France&#8217;s tax administration, the DGFIP, to take data on roughly 350,000 individuals and 250,000 businesses in June and July. Neither the tax administration nor France&#8217;s national cybersecurity agency, ANSSI, saw the data leave. ANSSI&#8217;s report attributes the success of the attack to weak login protection, poor network segmentation, and gaps in monitoring.<\/p>\n<p>The compromised data came from E-Contact, the messaging tool on impots.gouv.fr, and does not include taxpayer passwords or the ability to log in to user accounts. For affected individuals, the exposed fields include tax ID, contact details, family situation, reference taxable income, and tax withholding rate. The incident is a useful reminder that strong authentication on staff accounts, including phishing-resistant multi-factor authentication, and proper separation between administrative systems and public-facing services are not optional.<\/p>\n<h2>Unpatched vulnerability backlog: most critical flaws are over 90 days old<\/h2>\n<p>Exposure data from 1,293 organizations in the US, the UK, and the Nordics shows that most critical and high-severity vulnerabilities still open on internet-facing systems have been exposed for more than 90 days. The share of old critical or high findings was 97% in the Nordics, 92% in the UK, and 86% in the US. The findings are payload-verified, so the backlog represents issues a scanner judged exploitable rather than theoretical matches.<\/p>\n<p>Public-sector organizations resolved the fewest of their critical and high findings, at 8.3% within 90 days, compared with 46.2% for consumer packaged goods and brand companies, 37.4% for technology, 30.6% for financial and banking, and 23.9% for manufacturing. Consumer brands had the worst overall hygiene score at 56.2, driven by the size of their backlogs. Even where most findings close quickly, a few long-lived legacy issues can dominate a snapshot, so each aged item is worth a deliberate accept-risk decision rather than silent drift.<\/p>\n<h2>Former US Air Force members sentenced for BEC scams<\/h2>\n<p>Two former US Air Force service members stationed at Dover Air Force Base in Delaware were sentenced to a combined 189 months in federal prison for a multi-year business email compromise scheme. They stole employee email credentials through spam and phishing campaigns, then used spoofed addresses that mimicked business partners to redirect payments to accounts controlled by co-conspirators in the United States and abroad.<\/p>\n<p>Documented losses include a wire of more than $1.68 million from a victim in Iowa City, Iowa, and another of more than $720,000 from a victim in Ohio, among many other attempts. One defendant received 111 months and $366,617.59 in restitution; the other received 78 months and $995,680.45. Finance teams should treat any out-of-band request to change payment details as high risk and require a second verification channel before approving changes.<\/p>\n<h2>Custom ChatGPTs pushing ClickFix to deploy RATs<\/h2>\n<p>Custom ChatGPT variants promoted through sponsored Google search results have been redirecting users to malicious Google Sites pages that run ClickFix social engineering. One malicious model, named Plus 5.6, displayed a fake Cloudflare check and instructed visitors to run a PowerShell command, which installed a signed MSI that side-loaded a modified DLL. The payload is a remote access trojan with capabilities for remote desktop, audio and camera capture, file search, host reconnaissance, and running additional payloads, and it persists via a Run key and scheduled task named Canon Configuration Reader. OpenAI has retired the custom GPTs feature, with shutdown scheduled for December 11.<\/p>\n<p>Security teams should block or alert on PowerShell invocations originating from browser-launched instructions, watch for the Canon Configuration Reader persistence indicators, and brief users that any prompt asking them to paste commands into a terminal is a red flag, even when the page sits on a trusted domain.<\/p>\n<h2>What to do this week<\/h2>\n<ul>\n<li>Patch Citrix NetScaler ADC and Gateway to a fixed build for CVE-2026-88772 and restrict the management interface.<\/li>\n<li>Update Unsloth Studio, audit which models were inspected recently, and rotate secrets on affected developer machines.<\/li>\n<li>Apply Linux kernel patches for CVE-2026-64507 and CVE-2026-64508 as they reach your distribution, and review cBPF exposure.<\/li>\n<li>Enforce phishing-resistant multi-factor authentication on all administrative accounts and segment admin systems from public services.<\/li>\n<li>Review every open critical or high finding older than 90 days and make a written accept-risk decision for each.<\/li>\n<li>Require a second verification channel for any payment detail change, and brief finance teams on BEC patterns.<\/li>\n<li>Alert on PowerShell launched from browser prompts, the Canon Configuration Reader persistence artifacts, and outbound traffic to unfamiliar infrastructure.<\/li>\n<li>Hunt for indicators of NeedyMantis in telco, university, medical, and government networks.<\/li>\n<\/ul>\n<h2>FAQ<\/h2>\n<h3>What is CVE-2026-88772 in Citrix NetScaler?<\/h3>\n<p>It is a critical flaw in Citrix NetScaler ADC and NetScaler Gateway that gives attackers a pre-authentication path to shellcode execution on the appliance through the management interface.<\/p>\n<h3>How does the Unsloth Studio vulnerability work?<\/h3>\n<p>Selecting a malicious model in Unsloth Studio&#8217;s Web UI causes the application to read the model&#8217;s config.json and run Python code embedded in that file, triggering arbitrary code execution before any weights are loaded.<\/p>\n<h3>What is Branch Target Reuse and which CPUs does it affect?<\/h3>\n<p>Branch Target Reuse is a new Spectre v2 variant that reuses stale branch prediction entries after a JIT engine rewrites code, allowing attackers to leak sensitive data such as Linux root password hashes. It affects systems running Intel, AMD, and Arm CPUs and is tracked as CVE-2026-64507 and CVE-2026-64508.<\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What is CVE-2026-88772 in Citrix NetScaler?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"It is a critical flaw in Citrix NetScaler ADC and NetScaler Gateway that gives attackers a pre-authentication path to shellcode execution on the appliance through the management interface.\"}},{\"@type\":\"Question\",\"name\":\"How does the Unsloth Studio vulnerability work?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Selecting a malicious model in Unsloth Studio's Web UI causes the application to read the model's config.json and run Python code embedded in that file, triggering arbitrary code execution before any weights are loaded.\"}},{\"@type\":\"Question\",\"name\":\"What is Branch Target Reuse and which CPUs does it affect?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Branch Target Reuse is a new Spectre v2 variant that reuses stale branch prediction entries after a JIT engine rewrites code, allowing attackers to leak sensitive data such as Linux root password hashes. It affects systems running Intel, AMD, and Arm CPUs and is tracked as CVE-2026-64507 and CVE-2026-64508.\"}}]}]}<\/script><\/p>\n<hr style=\"margin:2.5em 0 1em;opacity:.35\" \/>\n<p style=\"font-size:.85em;opacity:.7\">This article summarizes reporting from <a href=\"https:\/\/thehackernews.com\/2026\/09\/citrix-netscaler-cve-2026-88772-exploit.html\" target=\"_blank\" rel=\"nofollow noopener\">thehackernews.com<\/a>, <a href=\"https:\/\/thehackernews.com\/2026\/09\/citrix-netscaler-cve-2026-88772-exploit.html\" target=\"_blank\" rel=\"nofollow noopener\">thehackernews.com<\/a>, <a href=\"https:\/\/twitter.com\/thehackersnews)[_\uf0e1_](https:\/\/www.linkedin.com\/company\/thehackernews\/)[_\uf09a_](https:\/\/www.facebook.com\/thehackernews)\" target=\"_blank\" rel=\"nofollow noopener\">twitter.com<\/a>, <a href=\"http:\/\/localhost\/5c34172ae87fab3ecb77bf8cfaf83e48)](https:\/\/thehackernews.com\/)\" target=\"_blank\" rel=\"nofollow noopener\">localhost<\/a>, <a href=\"https:\/\/thehackernews.com\/2026\/09\/ci\" target=\"_blank\" rel=\"nofollow noopener\">thehackernews.com<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>September 30 security roundup: Citrix NetScaler pre-auth exploit, Unsloth Studio code execution flaw, Spectre v2 BTR leaks, and more.<\/p>\n","protected":false},"author":3,"featured_media":305,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-306","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/306","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/comments?post=306"}],"version-history":[{"count":1,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/306\/revisions"}],"predecessor-version":[{"id":307,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/306\/revisions\/307"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media\/305"}],"wp:attachment":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media?parent=306"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/categories?post=306"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/tags?post=306"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}