Citrix's two NetScaler zero-days were exploited for close to a month before disclosure, which means the patch customers rushed to apply this week closed a door attackers had already walked through.
CISA added four actively exploited, unauthenticated network-edge vulnerabilities from three different vendors to its KEV catalog on the same day, and the clustering says more about where attackers are hunting than any single flaw does.
Volexity's research on UTA0560/BlueMoon turns a Monday footnote into a live espionage campaign, and it shows exactly how much lead time a well-resourced actor gets from the gap between a fix landing in a code repository and that fix reaching a user's machine.
A coordinated password spray campaign exploited the deprecated ROPC OAuth flow to bypass MFA and Conditional Access across 64 organizations, while a CVSS 10.0 RMM auth bypass hit its federal remediation deadline today with payloads already targeting cloud and AI API keys.