#7
The Hacker News
general
September 30, 2026 at 08:24 UTC
Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT
By [email protected] (The Hacker News)
AI Summary
Mandiant and Google GTIG observed threat actors deploying novel post-exploitation payloads dubbed WHIPSHOT and SLAPSHOT after exploiting the Citrix NetScaler pre-auth flaw against government, financial services, technology, education, and legal organizations in North America and Europe throughout September 2026. The attackers also mapped web shells to CSS-like URLs to evade detection and created superuser accounts. The suspected state-sponsored attribution and breadth of targeted sectors make this a high-priority incident for network defenders.
Relevance score: 81.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →