Internet edge attacks spread through compromised NetScaler gateways

Internet edge attacks spread through compromised NetScaler gateways. Organizations have already been compromised through Internet-facing NetScaler ADC and Gateway appliances.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Wednesday, September 30th, 2026.

Organizations have already been compromised through Internet-facing NetScaler ADC and Gateway appliances. Attackers exploited two previously unknown issues, installed web shells and tunneling malware, gained root access, stole credentials, and moved toward internal systems. The campaign affected organizations in North America and Europe across government, finance, technology, education, legal, and professional services. Both issues entered CISA’s Known Exploited Vulnerabilities catalog.

These edge appliances are especially valuable targets because they face the Internet and may sit outside normal endpoint monitoring. Patching closes the known entry points, but it may not remove web shells or other persistence from an appliance that’s already compromised. Leaders should treat this as an incident-response priority, not a routine maintenance task. Defenders need to preserve evidence, run available compromise checks, inspect configurations and logs, and hunt for lateral movement before returning systems to service. The larger pattern is continued attacker focus on trusted infrastructure at the network boundary. Patch every affected appliance immediately, and investigate each previously exposed system for compromise before restoring normal service.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

Internet edge attacks spread through compromised NetScaler gateways
Broadcast by