CyberSecurity News
Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT
AI summary
Unknown threat actors are exploiting a recently patched vulnerability in Citrix NetScaler appliances to gain root access and deploy malware. The targeted organizations are primarily located in North America and Europe, and span multiple sectors including government, finance, and education. The exploitation was observed by Mandiant Consulting and Google's Threat Intelligence Group in September 2026. The attackers are using the vulnerability to deploy WHIPSHOT and SLAPSHOT, although details of these malware tools are not specified. The activity suggests that the threat actors are highly motivated and capable of exploiting newly discovered flaws quickly. Organizations using Citrix NetScaler ADC and NetScaler Gateway appliances are being targeted.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

