Citrix NetScaler Reboots After Emergency 0-Day Patch: What Teams Need to Know

Citrix NetScaler Reboots After Emergency 0-Day Patch: What Teams Need to Know

Citrix released emergency builds to address two actively exploited zero-day vulnerabilities in NetScaler appliances, but some organizations report that the patched appliances are repeatedly rebooting. What began as a rapid mitigation effort to stop remote command execution and DTLS-related attacks has morphed into an availability problem for some deployments—raising the difficult question defenders must balance: is this an operational outage

Antino: A Stealthy Backdoor That Hides in Outlook and OneDrive

Antino: A Stealthy Backdoor That Hides in Outlook and OneDrive

A new espionage campaign tracked by Cisco Talos has exposed a sophisticated Windows backdoor, nicknamed Antino, that uses Microsoft 365 services as its covert communications channel. Targeting government and policy organizations across Asia — including Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar — the activity centers on highly tailored spear‑phishing lures and a multi-stage infection chain that culminates

Akira Ransomware Uses Windows Safe Mode to Shut Down EDR Before Launching Encryptor

Akira Ransomware Uses Windows Safe Mode to Shut Down EDR Before Launching Encryptor

Akira’s latest tactics expand the ransomware playbook: instead of relying solely on kernel drivers or signed binaries to disable protections, an affiliate in a recent intrusion rebooted a compromised host into Safe Mode with Networking to silence endpoint defenses while keeping network access for remote control and exfiltration. The operation began with a successful credential-spraying attack against an exposed SonicWall

2.86 Billion Credentials Flood Criminal Markets — How Infostealers and Initial-Access Brokers Are Reshaping Risk

2.86 Billion Credentials Flood Criminal Markets — How Infostealers and Initial-Access Brokers Are Reshaping Risk

Stolen login data has become a commodity so abundant that it’s now cheap to buy in bulk — and alarmingly effective when attackers use it to pivot into corporate environments. In 2025, researchers reported roughly 2.86 billion compromised credentials traded across underground markets. That scale changes the calculus of identity: a correct username and password no longer prove much when

Amazon Faces Months of Repairs After Drone Strikes Cripple Middle East Data Centers

Amazon Faces Months of Repairs After Drone Strikes Cripple Middle East Data Centers

Amazon Web Services says recovery from drone strikes that hit its data centers in the United Arab Emirates and Bahrain will be measured in months, leaving customers in the region facing prolonged disruption and prompting a broader rethink of investments in Middle East infrastructure. The attacks, part of a wider bout of regional hostilities, knocked core compute racks offline, triggered

Meta inks deal for solar power at night, beamed from space

Meta inks deal for solar power at night, beamed from space

The race to keep massive AI workloads powered around the clock has led Meta to sign a capacity reservation agreement with Overview Energy, a startup developing spacecraft that collect solar energy in space and convert it to near-infrared light beamed at large terrestrial solar farms. The deal — for up to 1 gigawatt of capacity — is a notable early