Tech Infrastructureโ€ขโ€ข5 min readโ€ข909 words

๐Ÿš€ Security - Citrix NetScaler Zero-Days Exploited for Unauthenticated RCE

โšกDirect Technical Summary

Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) were exploited to achieve unauthenticated RCE on internet-facing appliances, allowing threat actors to pivot to internal

๐Ÿš€ Security - Citrix NetScaler Zero-Days Exploited for Unauthenticated RCE

Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) were exploited to achieve unauthenticated RCE on internet-facing appliances, allowing threat actors to pivot to internal segments and establish persistent C2.

Key Points:

  • Zero-Day Exploitation: Attackers exploited two critical Citrix NetScaler zero-days to achieve unauthenticated RCE.

  • Pivot to Internal Segments: Threat actors pivoted to internal segments after compromising these network gateways.

  • Establish Persistent C2: Established persistent C2 to maintain control over compromised systems.

๐Ÿ”— Resources:


๐Ÿšจ Security - Former U.S. Army Soldier Used SSH Brute Force Tools to Breach Telecom Giants

TRC analysis shows former U.S. Army soldier used SSH brute force tools to breach telecom giants including AT&T and Verizon, moving laterally to exfiltrate terabytes of customer data for $1M+ extortion campaign.

Key Points:

  • SSH Brute Force Tools: Former U.S. Army soldier used SSH brute force tools to breach telecom giants.

  • Lateral Movement: Moved laterally to exfiltrate terabytes of customer data.

  • Extortion Campaign: Exfiltrated data for $1M+ extortion campaign.

๐Ÿ”— Resources:


๐Ÿšจ Security - North Korean Hackers Compromised Bitget's Backend Wallet Infrastructure

North Korean hackers compromised Bitget's backend wallet infrastructure and moved laterally across seven blockchain networks to exfiltrate $387.5M in cryptocurrency.

Key Points:

  • Backend Wallet Infrastructure: North Korean hackers compromised Bitget's backend wallet infrastructure.

  • Lateral Movement: Moved laterally across seven blockchain networks.

  • Exfiltration of Cryptocurrency: Exfiltrated $387.5M in cryptocurrency.

๐Ÿ”— Resources:


๐Ÿ“š Literature - Quote from 1851 Novel

"however baby man may brag of his science and skill โ€ฆ for ever and for ever, to the crack of doom, the sea will insult and murder him."

Key Points:

  • Quote from 1851 Novel: Quote from 1851 novel that flopped so badly its author spent the rest of their life in poverty.

  • Author's Struggle: Author's struggle to make a living from their writing.

๐Ÿ”— Resources:


๐Ÿšจ Security - Attackers Harvested AI Platform Credentials from 80,000+ Organizations

TRC analysis shows attackers harvested AI platform credentials from 80,000+ organizations using commodity infostealers, then replayed stolen session cookies to bypass MFA and access corporate accounts.

Key Points:

  • AI Platform Credentials: Attackers harvested AI platform credentials from 80,000+ organizations.

  • Infostealers: Used commodity infostealers to harvest credentials.

  • Bypass MFA: Bypassed MFA using stolen session cookies.

๐Ÿ”— Resources:


๐ŸŽต Music - The Power of Music Videos

Been ages since I last saw a music video but it's amazing the power they can have. Watching the Yung Lean video is mesmerizing but the song is terrible. Would he have had any success without that video?

Key Points:

  • Music Videos: Music videos have the power to make or break an artist's success.

  • Yung Lean Video: Yung Lean's music video is mesmerizing but the song is terrible.

  • Success without Video: Would Yung Lean have had any success without that video?

๐Ÿ”— Resources:


๐Ÿšจ Security - Attackers Exploited CVE-2026-88771 in Citrix NetScaler Gateways

Attackers are exploiting CVE-2026-88771 in Citrix NetScaler gateways to achieve unauthenticated root access through command injection. TRC analysis shows threat actors then pivot through internal networks accessible via the compromised appliance.

Key Points:

  • CVE-2026-88771: Attackers are exploiting CVE-2026-88771 in Citrix NetScaler gateways.

  • Command Injection: Achieved unauthenticated root access through command injection.

  • Pivot through Internal Networks: Pivoted through internal networks accessible via the compromised appliance.

๐Ÿ”— Resources:


๐Ÿšจ Security - JadePuffer (Storm-3168) Deployed Agentic AI to Automate Azure Attacks

TRC analysis shows JadePuffer (Storm-3168) deployed agentic AI to automate Azure attacks from reconnaissance to destruction. The AI agent orchestrated the entire kill chain autonomously, destroying 100+ storage accounts in just 7 minutes.

Key Points:

  • Agentic AI: JadePuffer (Storm-3168) deployed agentic AI to automate Azure attacks.

  • Automated Kill Chain: Orchestrated the entire kill chain autonomously.

  • Destruction of Storage Accounts: Destroyed 100+ storage accounts in just 7 minutes.

๐Ÿ”— Resources:


๐Ÿ’ก Development - Writing Code and Iterating through Trial and Error

Rather than deciding on perfect specifications upfront, write code, iterate through trial and error, and then document what you've learned as the "specifications." Using generative AI can make this even better.

Key Points:

  • Writing Code: Write code and iterate through trial and error.

  • Iterating through Trial and Error: Document what you've learned as the "specifications."

  • Generative AI: Using generative AI can make this process even better.

๐Ÿ”— Resources:

๐Ÿ“‚Source / Implementation:Tech Infrastructure / resources-260.md
GitHub Repositoryโ†—

Related Tech Infrastructure Breakdowns

Drishtant Ghosh (Drix10)
Drishtant Ghosh (Drix10)โ€ขAuthor & Engineer

Technical founder and engineer working across AI systems, developer infrastructure, and cybersecurity.

PortfolioยทGitHubยทLinkedInยทXยทEmail