Cookie Consent by Free Privacy Policy Generator

Cyber Brief: Citrix flaws, AI vulnerabilities, and crypto theft

Today's brief reflects a pattern UK organisations will recognise: the need to respond quickly to known vulnerabilities whilst understanding how the broader threat landscape is shifting. The NCSC has issued urgent guidance on actively exploited Citrix flaws, Google has published research showing how AI is changing vulnerability discovery, a major cryptocurrency exchange has confirmed a zero-day attack, and MetaMask is managing an ongoing security incident. Together, these stories highlight the importance of timely patching, understanding emerging attack methods, and maintaining clear incident response ownership.

NCSC urges UK organisations to patch actively exploited Citrix vulnerabilities

The National Cyber Security Centre has issued urgent guidance calling on UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway. The NCSC reports that two of the vulnerabilities are being actively exploited in the wild. Citrix NetScaler products are widely deployed across UK enterprise networks to manage application delivery and remote access, making them high-value targets for attackers seeking initial access to corporate environments. The NCSC has not provided specific details about the nature of the exploitation activity but has made clear that organisations should treat this as a priority patching requirement.

For UK businesses, this is a familiar but critical scenario. Citrix infrastructure often sits at the perimeter, handling authentication and access control for remote workers, third-party users and cloud applications. When vulnerabilities in these systems are actively exploited, the operational risk is immediate: attackers may gain authenticated access to internal networks, bypass multi-factor authentication controls or move laterally to more sensitive systems. The fact that the NCSC has issued specific guidance rather than relying on vendor advisories alone suggests that UK organisations are being targeted or that exploitation is sufficiently widespread to warrant direct intervention. This is not theoretical risk; it is confirmed attacker activity affecting technology that many organisations depend on daily.

Why it matters

For UK businesses running Citrix NetScaler ADC or Gateway, this is a prompt to review whether patches have been applied, whether these systems are included in routine vulnerability scanning, and who owns responsibility for maintaining them. Many organisations discover during incidents that perimeter appliances have unclear ownership between network, security and infrastructure teams, leading to delays in patching or monitoring.

Source: NCSC UK

Google research shows AI-discovered vulnerabilities more likely to enable remote code execution

Google Threat Intelligence Group has published research examining vulnerability disclosure and exploitation trends between January 2025 and August 2026. The research found that monthly CVE disclosures doubled during this period, rising from 5,045 in January to 10,740 in August. Whilst only 0.23% of disclosed vulnerabilities were exploited, the research identified a notable pattern: vulnerabilities discovered using AI research methods are significantly more likely to enable remote code execution compared to those found through traditional methods. Google also reported that attackers exploited one AI-discovered vulnerability within four days of its public disclosure, suggesting that the pace of exploitation is accelerating alongside the pace of discovery.

This matters operationally because it changes the assumptions organisations can make about vulnerability management. Traditionally, security teams have relied on the fact that most disclosed vulnerabilities are never exploited, allowing them to prioritise patching based on CVSS scores, asset criticality and known exploitation. If AI tools are discovering vulnerabilities that are both more severe and more likely to be exploited quickly, then the window for defensive action is narrowing. For UK businesses, this reinforces the importance of having mature vulnerability management processes that can respond to disclosures within days rather than weeks, particularly for internet-facing systems. It also highlights the need to understand which vulnerabilities are being prioritised by attackers and why, rather than treating all high-severity CVEs as equally urgent.

Why it matters

For many organisations, this is a prompt to review whether vulnerability management processes are designed to handle faster disclosure-to-exploitation timelines. It is worth checking whether security teams have the tools, authority and support needed to patch critical systems within 72 hours of a disclosure, and whether that expectation is clearly understood across IT, development and leadership teams.

Source: Help Net Security

Bitget confirms zero-day vulnerability behind $387.5 million cryptocurrency theft

Cryptocurrency exchange Bitget has confirmed that attackers who stole $387.5 million last week exploited a zero-day vulnerability in third-party security products. The confirmation follows an ongoing investigation conducted with blockchain security firm SlowMist, which identified malicious activity involving the third-party tools and recovered a customised tool used by the attacker. Bitget has not disclosed which third-party security product was affected, but the incident highlights the operational risk that organisations face when relying on external security tooling, particularly in high-value environments such as cryptocurrency exchanges where attackers are highly motivated and well-resourced.

For UK businesses, this incident is a reminder that supply chain risk extends beyond software development dependencies to include the security products organisations use to protect themselves. Many organisations deploy third-party security tools for endpoint protection, network monitoring, identity management or cloud security without fully understanding how those tools are maintained, how vulnerabilities are disclosed, or what happens if the tool itself becomes the attack vector. In this case, the attackers appear to have identified and exploited a previously unknown flaw in a product that Bitget relied on for security, turning a defensive control into an entry point. Whilst the financial services and cryptocurrency sectors face particularly sophisticated threats, the lesson applies broadly: security tooling is software, and software has vulnerabilities.

Why it matters

For UK businesses, this is a prompt to review whether third-party security products are included in vulnerability management processes, whether vendors provide timely security updates, and whether there is a clear process for responding if a security tool is found to be compromised. It is also worth considering whether over-reliance on any single security product creates a concentration of risk that could be exploited.

Source: The Hacker News

MetaMask responds to ongoing security incident affecting infrastructure

MetaMask has confirmed it is responding to an ongoing security incident affecting part of its infrastructure. The software cryptocurrency wallet maker stated it is actively addressing and remediating the issue internally, in coordination with external partners and security advisors. MetaMask has said it has identified no immediate threat to MetaMask wallets at this time, and has prompted the exit of affected Ethereum validators as a precautionary measure. The company has not disclosed the nature of the incident, the scope of the infrastructure affected, or how the issue was detected, but the public acknowledgment and coordinated response suggest the incident is being managed as a live operational event.

For UK businesses, this incident is a useful example of how organisations communicate during an active security event. MetaMask has confirmed the incident is ongoing, acknowledged it is working with external partners, and provided an initial assessment of user impact whilst making clear that the situation is still being investigated. This approach reflects mature incident response practice: acknowledge what is known, explain what is being done, and avoid over-reassuring or speculating beyond confirmed facts. Many UK organisations struggle with this balance, either staying silent too long or providing incomplete information that creates more uncertainty. The decision to exit affected validators also demonstrates a willingness to take disruptive action to contain risk, even when the immediate threat to end users is unclear.

Why it matters

For UK businesses, this is a prompt to review whether incident response plans include clear guidance on external communication, whether there is agreement on what constitutes an incident that requires public acknowledgment, and whether technical teams have the support and authority needed to take containment actions that may affect service availability. Incidents rarely wait for convenient moments, and the quality of the response often depends on decisions made well before the incident occurs.

Source: The Hacker News

Today's Key Actions

  • Check whether Citrix NetScaler ADC and Gateway systems have been patched in line with NCSC guidance, and confirm who is responsible for maintaining these systems and monitoring for exploitation activity.
  • Review whether your vulnerability management process can respond to critical disclosures within 72 hours, particularly for internet-facing systems, and whether security teams have the tools and authority needed to meet that expectation.
  • Ensure third-party security products are included in vulnerability management processes, and confirm whether vendors provide timely security updates and clear disclosure practices.
  • Review whether incident response plans include guidance on external communication during live security events, and whether technical teams have the support needed to take containment actions that may affect service availability.
  • Make sure ownership of perimeter systems, vulnerability management, third-party security tooling and incident response is clearly assigned and understood across IT, security and leadership teams.

Secarma Insight

Good security practice is built on habits that are already in place before incidents happen: knowing which systems you run, who is responsible for maintaining them, how quickly you can patch when it matters, and how you will communicate when something goes wrong. The stories in today's brief reflect challenges that most organisations will face at some point - urgent patching requirements, faster exploitation timelines, supply chain risk in security tooling, and the need to manage incidents whilst they are still unfolding. The organisations that handle these situations well are the ones that have already worked through the ownership questions, the communication plans and the technical processes needed to respond with confidence rather than improvisation.

News and blog posts
Today's brief reflects a pattern UK organisations will recognise: the need to...
The National Cyber Security Centre has issued urgent guidance calling on UK...
Google Threat Intelligence Group has published research examining vulnerability...
Cryptocurrency exchange Bitget has confirmed that attackers who stole $387.5...