Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Beyond the Scanner: How Verified PoC exploits Prove True Business Risk

On September 1, OpenAI announced that its new model, GPT-6 Astra, had become the first to cross the “Critical” cybersecurity threshold in the company’s Preparedness Framework. Most coverage focused on the safety implications, and fairly so, but buried in the announcement sits a benchmark result that should change how every security leader reads their next vulnerability report.

FBI Winter SHIELD's Cybersecurity Controls Are Worth a Second Look

AI adoption is making everyone faster, including the attackers we as cybersecurity practitioners are competing with. While the attackers are getting faster thanks to AI, it’s not changing why most preventable breaches happen. That part is remaining consistent, for better or worse.

Detectify Cyber Hygiene Index Report reveals that most critical vulnerabilities sit unfixed for months

The Detectify Cyber Hygiene Index Report H2 2026 measures something most reports ignore: not what happened after an attack, but what’s exposed right now, before one occurs. We analyzed anonymized data from a sample of +1290 organizations across the US, UK, and Nordics to understand how effectively they’re finding, monitoring, and closing vulnerabilities across their external attack surfaces.

CVE-2026-88771 and CVE-2026-88772: Two Critical Citrix NetScaler Flaws Under Active Exploitation

Citrix disclosed two critical vulnerabilities in NetScaler ADC and NetScaler Gateway that are already being exploited in the wild. CVE-2026-88771 allows unauthenticated attackers to run commands on an affected appliance, while CVE-2026-88772 can lead to remote code execution or denial of service when DTLS is turned on. Both received a CVSS v4.0 score of 9.5, and CISA added them to its Known Exploited Vulnerabilities catalog.

Hunting Citrix NetScaler Zero-Days with Corelight

Citrix’s security bulletin CTX697096, the NetScaler security blog, and WatchTowr’s vulnerability FAQ describe an urgent situation for organizations using NetScaler ADC and NetScaler Gateway. Two vulnerabilities (CVE-2026-88771 and CVE-2026-88772) are known to be exploited. CISA confirms active exploitation globally and has added both to its Known Exploited Vulnerabilities catalog.

Citrix NetScaler vulnerabilities (CVE-2026-88771, CVE-2026-88772) in active exploitation

On September 27, 2026, Citrix disclosed eight vulnerabilities affecting NetScaler Application Delivery Controller (ADC) and NetScaler Gateway. Two of these vulnerabilities are critical (CVSS score of 9.5) and can allow an unauthenticated remote attacker to execute code: Citrix has observed exploitation against unmitigated NetScaler deployments, and the U.S.

Keep your Qualys vulnerability scanner: Fix what it finds with Patch Manager Plus

Most organizations that run a vulnerability scanner have already made a significant investment. They chose Qualys, Tenable, Rapid7, or CrowdStrike based on their detection needs, their compliance requirements, and the way their security team works. That scanner is embedded in their workflows, audit processes, and reporting chain. Then they look at their vulnerability remediation times and realize the problem is not on the scanning side.

Your Vulnerability Backlog Is No Longer Technical Debt, It's an Attack Surface

Every security program has one: a queue of a few thousand findings, or a few hundred thousand, that nobody has worked through and nobody expects to. Most teams file it under technical debt, a cost carried on purpose, paid down when there is room, and tolerable because the interest rate stays low. That accounting held for a long time, because it rested on a single assumption: almost nothing in the queue would ever be reached, or exploited, by anyone.

What CVE-2026-20079 Means for Every Network Team

On September 9, Cisco confirmed what earlier warning signs had already hinted at: a security flaw in its Secure Firewall Management Center (Secure FMC) software, the tool that configures and controls Cisco firewalls across a network, is being actively exploited. The flaw, tracked as CVE-2026-20079, received a maximum severity score of 10.0 on the CVSS scale, the industry-standard scale used to rate how serious a vulnerability is.

Automate Vulnerability Reporting for Auditors Without Creating More Work

Anyone who has participated in a cybersecurity audit knows the drill and has likely asked the same question. “Is there a way to automate any of this?” When an auditor requests evidence that vulnerabilities are being identified, prioritized, remediated, and tracked according to policy, the automation question is a fair one.