Future TechnologyFuture Technology
← Back to archive
Security Digest

[Cybersecurity Digest] The login screen you can skip

28 August 2026

CISA does not tell agencies to drop everything and patch very often. This week it did, over a Citrix bug that lets an attacker walk past the login screen entirely.


The Big 3

1. CISA orders emergency patching after a NetScaler login you can just skip

CVE-2026-19490 is an authentication bypass in Citrix NetScaler ADC and NetScaler Gateway, the appliances thousands of companies use for remote access and load balancing. It scores 9.3 on CVSS v4.0, and the bug is almost comically simple: request an alternate path and the login check never fires. No credentials, no user interaction, just the right URL.

Why it matters: NetScaler sits at the internet-facing edge of the network, so every unpatched box is a discoverable, scannable target, and CISA telling agencies to patch now rather than on the usual cycle tells you exploitation is expected fast.

Read more at SecurityWeek

2. Cl0p's leak site now names Shell, Philips and GE

More than 40 organisations have turned up on Cl0p's extortion site following a campaign against PTC's Windchill and FlexPLM, the product lifecycle management platforms manufacturers use to track CAD files and supply chain data. The playbook is the same one Cl0p ran with MOVEit in 2023: quietly exploit one widely used platform across as many victims as possible, then extort via a leak site instead of live ransomware.

Why it matters: PLM software holds design files and supplier data, not just customer records, so a mass exploitation event here hits intellectual property that took years to build, at companies with serious security budgets.

Read more at The Hacker News

3. A Windows zero-day is planting kernel rootkits for North Korea

CVE-2026-68820 was already being exploited when Microsoft shipped its 421-fix August Patch Tuesday. The flaw sits in AFD.sys, the WinSock driver, and lets a low-privileged attacker jump straight to SYSTEM. Check Point ties active exploitation to a new wave of Operation Dream Job, the North Korean campaign that lures targets in defence, aerospace and crypto with fake recruiter messages.

Why it matters: once the rootkit lands in kernel mode it is very hard to find from user space, and the entry point is still a person opening the wrong message from a fake recruiter.

Read more at Help Net Security


Quick Hits

1.6 million RingCentral accounts: the ShinyHunters extortion group stole personal data after breaching RingCentral in July, the theft only surfacing this week.

678,000 taxpayers exposed: France's tax authority, the DGFiP, confirmed an attacker accessed reference income, family quotient and withholding data for individuals and business registration details for companies.

659 live Stripe keys leaked: a forum listing published working API keys for 659 merchant accounts alongside roughly 35GB of customer and payment data pulled through them.

AI agents cracked 85 accounts on their own: researchers documented a multi-agent AI framework that enumerated 21 government systems in Asia, cracked 85 accounts and exfiltrated over 2,500 personnel records with minimal human steering.


Tool of the Week

YubiKey 5 NFC is a physical hardware key that replaces SMS codes and authenticator apps with a tap, so a stolen password alone cannot get an attacker into your accounts.

Good for anyone who has an account tied to a breach this week (RingCentral, Trezor's shipping partner, or anywhere else) and wants a second factor that cannot be phished the way a text message code can.

Check YubiKey 5 NFC on Amazon


Protect Yourself

This week's breach list (RingCentral, Trezor's shipping partner ShipMonk, France's DGFiP) all trace back to a vendor or third party being compromised rather than the company itself. Go into your account settings for anything you use regularly and look for a "connected apps," "trusted devices" or "active sessions" page. Revoke anything you don't recognise, and anything you haven't used in the last six months.


Forwarded this? Get your own cybersecurity briefing at futuretechnologyhq.com/newsletter

Stay safe out there. Nath, Future Technology

Some links in this newsletter may be affiliate links. We only recommend products we genuinely think are worth your time.