Last week’s security news was dominated by active exploitation of multiple zero-days in Citrix NetScaler, Apple, Cisco SD-WAN, and FortiMail, alongside a major breach of OpenInfra Europe’s JFrog Artifactory and a reported FBI portal compromise linked to ShinyHunters. The roundup also highlighted growing AI-related risks, including malicious Custom GPT abuse, leaked company screenshots from coding agents, and research showing AI systems can expose secrets and weaken security controls. #Citrix #NetScaler #Apple #Cisco #FortiMail #OpenInfraEurope #JFrogArtifactory #ShinyHunters #DIVD #KillSec
Keypoints
- Citrix NetScaler zero-days were exploited globally to plant webshells.
- Apple patched an actively exploited Core Graphics zero-day in iOS and macOS.
- Attackers also used a new Cisco SD-WAN zero-day and a FortiMail zero-day.
- OpenInfra Europe confirmed a breach of its self-hosted JFrog Artifactory instance.
- AI systems and coding agents are increasingly leaking secrets, screenshots, and credentials.