Hi there, this is your daily โ๏ธ Cyberpresso.
In today's Cyberpresso:
๐ Critical Citrix flaw under active attack
๐ฎ Discord breach exposes 28M accounts
๐ Hackers exploit critical Atlassian flaw
๐ป Malware hides C2 servers in GitHub poem
Plus: ๐ก 6 strategies & tactics, ๐ 7 more stories you might like, ๐งฐ 6 tools, and ๐ 5 papers.
๐ Critical Citrix flaw under active attack LINK
- Attackers are actively exploiting a critical pre-authentication command-injection flaw (CVE-2026-88771) in Citrix NetScaler ADC and NetScaler Gateway to open reverse shells, create privileged accounts, and keep long-term access, according to LevelBlue's threat-hunting team.
- Rated critical (CVSS 9.5), the bug lets an unauthenticated attacker inject commands via authentication fields that pull down malware, stage the appliance's configuration for theft, and plant implants, with some requests using backtick substitution or spacing tricks to dodge exact-match detection.
- Citrix released patches on September 27, with fixed standard and FIPS builds listed; defenders should patch, review local accounts, reset authentication, and hunt behaviorally, since the Perl payload deletes its own archives and self-removes to limit evidence.
๐ฎ Discord breach exposes 28M accounts LINK
- Double Counter, a verification and anti-alt account service used by Discord communities, confirmed that an attacker spent nearly six hours inside its infrastructure on October 4th, exposing data tied to 28 million accounts.
- The attacker broke into an abandoned server from the company's old OVH hosting on October 3rd, exploited a bug in a publicly exposed analytics tool to grab an administrator's login, then used it to reach the cloud infrastructure and steal a Discord bot token.
- Exposed data included Discord usernames, IP addresses, and approximate location, which could help profile accounts across communities; Discord passwords and stored card numbers were not exposed, and the attacker ran up $7,316 in fraudulent charges on three cards, with two customers refunded.
๐ Hackers exploit critical Atlassian flaw LINK
- Hackers have begun exploiting a critical flaw in Atlassian Data Center products (CVE-2026-21589, CVSS 9.3) that lets an unauthenticated attacker read sensitive files in the web root, affecting Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye.
- The bug is a path traversal weakness where double-colon (::) sequences are treated as path separators, so a single crafted request turns a string into a directory path like ../../../../WEB-INF/web.xml, exposing tokens, credentials, and keys, though attackers must already know the exact file name and path.
- Exploitation hit watchTowr's and Previdian's honeypots about two hours after watchTowr published its analysis on October 6, with 15 attempts from three IPs in Japan and the U.S.; Atlassian advises removing instances from the public internet and blocking requests via a firewall rule, Tomcat's RewriteValve, or urlrewrite.xml for Bitbucket.
๐ป Malware hides C2 servers in GitHub poem LINK
- A cryptomining botnet called PoeLLM is hiding its command-and-control server address inside a poem posted on GitHub, letting infected machines decode the current server location on their own, according to Black Lotus Labs.
- Active since April 2026 and tracked as Canto Incognito, the operation has hit over 3,400 servers, mostly in the US and Western Europe, by breaking into exposed AI/LLM tools like LiteLLM and Ollama, plus the Gotenberg PDF converter and Gitea.
- Attackers scan for default ports, then send a crafted POST request exploiting a command injection bug in LiteLLM (CVE-2026-42271) to install XMRig and Iron miners; the malware pulls four words from the poem and maps them to numbers forming the server's IPv4 address.
๐ก Strategies & Tactics
> GitHub - TsvetanG2/mcpward: mcpward - Security & contract testing for MCP servers. Catch MCP tool poisoning, rug: mcpward snapshots an MCP server's tool contract and fails your build when it quietly changes, catching poisoned descriptions and schema drift before they mislead your AI agent.
> WordPress libheif RCE: Exploit Chain: A memory corruption bug in the libheif image library lets an authenticated WordPress user upload a crafted image file that hijacks server-side code execution.
> A Vault with a Heap: AWS's AI agent runtime leaves a root-level shell tool on by default, letting prompt-injection attackers run commands that steal stored credentials unless operators manually restrict it.
> kubectl cp Flaw CVE-2026: Upgrade Windows kubectl, since a malicious container's tar file can write code to your laptop when you copy files out, a developer-machine flaw patched only now.
> Building an evidence-grounded agentic security operations harness on Cloudflare: Splitting security-alert investigation across specialized AI agents that must cite collected evidence prevents false claims and lets human analysts resolve alerts faster.
> PoC Released for Critical VMware VMXNET3 Flaw Enabling Guest-to-Host Code Execution: Public attack code for a critical VMware network-adapter flaw only crashes the host so far, but administrators should patch host versions immediately since no workaround exists.
Other news you might like
- MCP for agent-to-agent comms may be the riskiest protocol you've never heard ofLINK
- Splunk Patches Critical 9.8 Flaw Allowing Unauthenticated Remote Command ExecutionLINK
- Critical Cisco Nexus Flaws Let Unauthenticated Attackers Execute Code With Root PrivilegesLINK
- 16 malicious Firefox extensions caught stealing crypto wallet secretsLINK
- Ransomware fixer claimed he could decrypt files, allegedly defrauded clients insteadLINK
- Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing WormLINK
- Hackers Abuse GitHub Actions to Steal SSH Keys, Cloud Credentials and Access TokensLINK
๐งฐ Trending tools
Koreshield: screens customer messages, retrieved docs, and tool calls before your AI agent acts, catching prompt injection, data leaks, and unsafe actions with logged decisions.LINK
AuthMonster: a two-factor authentication app with easy migration from Google Authenticator and LastPass, biometric locking, and a donation-based model.LINK
WebDecoy for Vercel: identifies crawlers and AI bots hitting your site via a Vercel log drain, no code changes needed, reporting user agents, paths, and TLS fingerprints.LINK
Termaxa: an open-source Rust gate for Claude Code, Codex, Cursor, and Copilot that previews deletions, backs up files first, and blocks commands by your policy.LINK
Pair2FA: a minimal 2FA authenticator with team sharing, letting members securely manage shared accounts using their own logins while keeping data exportable anytime.LINK
ARES: automates authorized red-team engagements with a dashboard, campaign scoping, module orchestration, OPSEC controls, encrypted vault, and reporting.LINK
๐ Trending papers & reports
On-device model safety can be broken by tampering with just ~0.2% of a chatbot's stored settings, slipping past safety guardrails more than half the time while the model still performs normally.LINK
Edge-device security monitoring splits threat detection into cheap per-device checks plus a gateway layer that spots coordinated multi-device attacks, sending just one yes-no signal per window and flagging exactly which device and rule triggered.LINK
Private tabular prediction lets organizations build accurate classifiers on sensitive medical, financial, and government records with mathematical privacy guarantees, leaking almost no individual data while fitting datasets 10,000 times faster than existing private methods.LINK
Security alert triage flags cyberattack cases that intrusion detectors wrongly mark as safe, letting overstretched human reviewers catch more errors, including never-before-seen attacks, within a fixed review budget and without retraining the detector.LINK
Quantum migration priorities can be ranked against ordinary security fixes on one dollars-per-year scale, letting organisations see which long-lived, quietly recorded assets to protect first before quantum computers can crack today's encryption.LINK
See you tomorrow for a new dose of โ๏ธ Cyberpresso!

