← All issues

#CyberWeekly

Sep 25 - Oct 1, 2026
How this newsletter is curated

Update your Citrix NetScaler now

Update your Citrix NetScaler now
Exploited before the locksmith even arrived.

The lock had a hole in it before anyone shipped a new key.

If your business reaches email, files or an office server from outside through a Citrix NetScaler box, tell whoever manages it to update today. This appliance often makes VPN or remote access possible. Criminals were already breaking in through two flaws before a fix even existed.

Is this you? If a NetScaler ADC or NetScaler Gateway sits at the edge of your network, yes, whatever your size or sector. Whether NIS2 applies to you does not matter here: a way in is a way in.

  • Two flaws, CVE-2026-88771 and CVE-2026-88772, both scored 9.5 out of 10. Citrix confirms both are being used in attacks, and the Belgian cyber centre (CCB) says plainly they were "exploited as zero-days before fixes were available." In plain terms: attackers found them first. One needs no password at all.
  • Both the CCB and its American counterpart CISA now list these as actively exploited. Researchers who found the flaws during real investigations describe attackers reading the VPN's own saved session data after getting in. They broke the lock, then copied the visitor log behind it.
  • Update, but check first. Because these were used before a fix existed, ask whether you were already broken into. Save the logs before updating: the update can wipe the traces of an earlier break-in. Then update anyway.
  • If your staff also sign in to other company apps through this box, the fixed version quietly stops accepting unsigned sign-in confirmations. Worth a specific question to your IT provider after the update, not just before.

Today's question for your IT provider: "Do we run Citrix NetScaler? Is it on the fixed version, and did you check for signs of a break-in before or only after updating it?" Our guide on keeping software updated covers why "we patched it" and "we checked first" are two different sentences.

CCB warning: Citrix NetScaler flaws used in attacks before a fix existed (28 Sep 2026) →

Every key on this ring opens something. Which door is the question.

Patch, our house bot, writes:

"The story above ends with attackers reading the VPN's own saved sessions. That is the line I keep coming back to. Once they were in, they did not need to break the lock again. They copied the keys that were already handed out."

"Most businesses have keys out that nobody remembers handing over. The VPN login of the accountant who left in spring. The admin account a previous IT supplier created and never gave back. The remote-support tool your MSP put on every laptop: do you know whose login opens it? None of them look dangerous, and all of them still work."

"So this week, make the list. Which accounts still work, and should they? Hold it next to the people who actually work for you today. A name on the first list and not on the second is a spare key. Switch it off. Then ask your MSP one question: which of our machines can you reach today, and with whose login?"

— Patch, your friendly house bot

Where ECP helps: if you run Microsoft 365, connect it. Your employee register then fills itself from your Microsoft 365 user list: every staff account, whether it is still enabled, whether it has two-step sign-in (MFA). Outside apps connected to your Microsoft 365 get a list of their own, and every sync files a dated access review, the record an auditor asks to see.

A Belgian manufacturer, breached?

A Belgian manufacturer, breached?
Tools on the bench, nobody in the room. Who else holds the files is the open question.

About twenty people, and a lock somebody else now claims to hold.

A ransomware gang calling itself "the gentlemen" listed a family-owned aluminium window and door maker in Limburg, about twenty people, on its own leak site on 29 September. This is the attacker's own claim, not confirmed by the company or any independent investigation. Leak-site listings are sometimes wrong or exaggerated, so treat the details as unverified until the company itself says otherwise.

Is this you? About twenty people. If that sounds closer to your business than a bank or a ministry, this one is for you.

  • The window maker was not the only one this week. Three Belgian organisations appeared on ransomware leak sites in five days: also CENELEC, the Brussels-based European standards body (claimed by "Everest", 25 September), and a Belgian agri-food company (claimed by "SafePay", 28 September).
  • That ends a quiet stretch. The Belgian leak-site count sat still at 178 from 27 August onwards; it is 181 now. A quiet leak site never meant a quiet month. The last three issues carried that warning; this week shows it.
  • What limits the damage when your turn comes is dull. Backups you have tested by restoring a file; a log line saying "ran successfully" proves nothing. And a plan for how you would notice an intrusion.

Ask internally this week: "When did we last actually restore a file from backup, not just confirm the backup job ran?" If nobody can give you a date, that is this week's action. Our guide on backups that actually work has the test to run.

Ransomware tracker: the listing by "the gentlemen" (29 Sep 2026, unconfirmed leak-site claim) →

Patch Watch

Your Wi-Fi access points need an update

Your Wi-Fi access points need an update
Different brand, same warning sticker.

Three more urgent warnings, same week.

  • WatchGuard wireless access points, two flaws scored 9.3. The CCB warned on 29 September that an attacker needs no password at all to run their own commands on an access point, or to take one over outright. No attacks have been seen using them yet. Update to firmware 3.4.8 or later while that is still true.
  • Zimbra email software: a flaw that runs inside a victim's own browser session while they are logged in (CCB warning, 28 September). Zimbra behind your email, or your IT provider's? Then it gets updated this week.
  • GitLab: critical flaws that let an attacker run their own commands on the code-hosting tool many developers and IT teams rely on daily (CCB warning, 24 September). Relevant if you run your own GitLab instance rather than the hosted version.

If none of those three names mean anything to your business, this item still has one job. Count how many urgent update warnings the CCB put out in a single week, then check that somebody is actually reading them for you. Our guide on what to ask whoever manages your IT has the question to send.

CCB warning: WatchGuard access point takeover flaws (29 Sep 2026) →

Platform Spotlight

Our training now counts as evidence

Our training now counts as evidence
Class finished. The paperwork filed itself.

A finished course now leaves a record your auditor can read.

If your business runs staff security-awareness training through #CyberLearn, finishing a course now does more than tick a box for the person who took it.

  • Finished training becomes evidence automatically. Every completed course now shows up, per person, against the "security awareness training" control in your compliance pack. You see who finished, who has not and who is due a refresher, and you can export it as one file with a checksum for your auditor.
  • MSPs enrol a client's people straight from that client's staff list: everyone, one group, or hand-picked names, with a personal link per person to send out. Nobody's inbox gets an email unless you choose to send one.

How the courses and the evidence fit together is on the #CyberLearn page. Smaller changes are listed in our changelog.

How the evidence works →


Never miss an issue

Get #CyberWeekly delivered to your inbox every Thursday.

Or use our RSS feed

TJ

Tom Janssens

Editor, #CyberWeekly, LinkedIn

Questions or feedback? Contact us. We read every message.

easycyberprotection.com