⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

⚡ Weekly Recap: 7M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats
This week’s roundup highlights active exploitation of Citrix NetScaler flaws, a major Bitget breach, and multiple campaigns abusing weak identities, phishing kits, and old vulnerabilities. It also shows how forgotten placeholder domains, exposed service accounts, and leaked GitHub App keys continue to create real attack paths for threat actors. #Citrix #NetScaler #Bitget #PamStealer #TeamFiltration #EvilTokens #Konni #Kimsuky #Ryuk #ScatteredSpider #GitHub

Keypoints

  • Citrix NetScaler ADC and Gateway flaws CVE-2026-88771 and CVE-2026-88772 are being actively exploited worldwide.
  • Bitget resumed withdrawals after a suspected North Korean breach that stole over $387 million.
  • Unused placeholder domains like third-party[.]com were registered and turned into malicious lure infrastructure.
  • TeamFiltration abused weak Microsoft 365 service accounts, exposing forgotten identities without MFA.
  • Law enforcement dismantled EvilTokens, while new campaigns from Konni and Kimsuky used LNK files and Git-based C2.

Read More: https://thehackernews.com/2026/09/weekly-recap-387m-crypto-hack-citrix.html