Technical write up of the latest Citrix Netscaler incident, which I’m calling PitScaler - you’ll find out why from this:
https://www.cert.europa.eu/blog/taking-execute-logging-a-bit-too-literally-cve-2026-88771
You may notice it matches the hunting hints earlier in this thread. Guess who found it first
It’s a really interesting vuln scenario. I’m tracking over 100 victim orgs now. Each one has a unique webshell which can’t be scanned for remotely unless you’re the attacker. It’s espionage.
/tmp/not_a_good_sanitation
Threat actor is correct
#PitScaler