Enterprise Cybersecurity IntelligenceLocal day

An enterprise cybersecurity intelligence company.For security and technology leaders.

Security.io — Enterprise Cybersecurity Intelligence

Security.io Intelligence

What changed, why it matters,
and how it evolved.

Today's audio briefing

Listen to today’s briefing

5 min audio summaryFreeNo signup required

Daily intelligence

NetScaler zero-days turn patching into an incident-response decision

Mandiant’s newly published incident evidence shows exploited NetScaler appliances receiving root-level persistence, custom web shells and an internal tunnelling capability, making clean-build verification and compromise assessment inseparable.

What changed

Citrix confirms active exploitation of CVE-2026-88771 and CVE-2026-88772. Mandiant now provides evidence of root access, custom WHIPSHOT and SLAPSHOT malware, credential-focused internal reconnaissance and hunt-ready artefacts, so patch completion alone is not defensible closure. CVE-2026-88771 permits unauthenticated command execution and applies to default customer-managed NetScaler ADC and Gateway deployments.

Read the full story →
759Source References to Date
275Public Intelligence Briefings
55Daily Editions Published
5Today’s Daily Headlines

Public record through 2026-09-30. Source references count citations across published briefings, including repeated sources. Explore the record and its limits →

What We Publish / What We Sell

Free · Public

The Daily

Five evidence-backed selections for security leaders, every weekday.

  • Lead decision and analysis
  • Key developments and briefs
  • Free public audio briefing
Read today’s edition →
Free · The Record

Security.io Intelligence

The longitudinal record of material cybersecurity change and its decision context.

  • Progression and related developments
  • Evidence and analytical history
  • Emerging Risks and reports
Explore the record →
Commercial · Enterprise

Enterprise Intelligence

Customer-specific intelligence applied to declared context and priorities.

  • Customer Applicability
  • Third-party and dependency intelligence
  • Decisions, owners and time horizons
Explore Enterprise Intelligence →

Signal desk

Security.io editorial score

NetScaler response priority

Security.io scores each dimension from 0–100. Exposure reflects deployment reach and privileged network placement; Urgency reflects exploitation tempo and remediation window; Business consequence reflects credential access, persistence and potential interruption. Exposure: 94. Urgency: 98. Business consequence: 93. Focus the chart and use the up and down arrow keys for detail. Source: Security.io editorial assessment based on Citrix, Mandiant and CERT-EU evidence.

Explore the signal desk →