Image
Episode 35  •  Sep 18, 2026  •  54 Min

Ten-Hour Breaches, MikroTik Backdoors, Router Takeovers & the NetScaler Root Cause

Three stories on the table this week. A ransomware operator handed nearly an entire intrusion off to a fleet of AI agents, compressing two weeks of human red team work into under ten hours. A two-CVE chain called MikroTrick is giving attackers full admin takeover of internet-facing MikroTik routers, and the chain was already live as a zero-day before the coordinated disclosure landed. And Revolut confirmed a customer data breach after a fraudulent request rode in through a real government agency's own email domain. We also sit down with Bishop Fox staff security engineer Jon Williams to break down his team's research into a critical Citrix NetScaler authentication bypass, how they safely validated it, and the detection tool they built for defenders. Here's what stood out from the operator chair.

Watch your API token spend like a stolen credential, because compromised access now moves at agent speed. Unit 42 traced a ransomware operator who handed recon, credential harvesting, a hijacked CI/CD pipeline, and a seized secrets manager to a fleet of AI agents, compressing roughly two weeks of red team work into under ten hours. One of those agents then left the victim an 80-page audit of everything it broke. The real tell isn't the gift-wrapped report. It's that more than 50 attack techniques ran end to end before anyone noticed. If your alerting can't catch abnormal token usage inside a ten hour window, assume total compromise the moment you do notice.

Two chained CVEs on an unpatched device beat one zero-day on a watched one. Researchers paired a public-key authentication bypass (CVSS 9.2) with a privilege-escalation bug triggered by specially crafted SSH usernames to mint a fully privileged account on internet-facing MikroTik routers, no valid login required. The chain was already live as a zero-day before CERT Polska's coordinated disclosure landed. Compromised devices carry a giveaway: log entries for an SSH user named "-2." MikroTik routers sell on the promise that you'll never have to touch them again, which is exactly why they're still sitting on the internet unpatched years later. Treat any edge device with that pitch as a standing liability, not something you set and forget.

A legitimate government email domain doesn't make the person behind it legitimate. Revolut confirmed that passports, driver's licenses, verification selfies, IBANs, and full transaction histories for hundreds of customers went out the door after a fraudulent data request arrived from inside a real government agency's email domain. The request passed every technical check Revolut normally runs on law enforcement inquiries, precisely because the domain checked out. Domain authentication answers "is this a real mailbox," not "is this a real request," and any process that treats the two as the same question is one social-engineered inbox away from handing over a customer's entire identity file.

Why does the same CVE mean denial of service for one company and root for the next? We sat down with Bishop Fox staff security engineer Jon Williams to unpack his team's research into CVE-2026-19490, a critical Citrix NetScaler auth bypass that Citrix's own advisory described only as an "alternate path." Jon walks through how a single-instruction patch traced back to an attacker-controlled error code, why the exploitable impact depends entirely on which virtual server type and SAML configuration a given appliance is running, and how the detection tool his team built lets defenders safely confirm they're patched without crashing production. It's a case study in why an advisory is the floor for what a critical CVE means for your environment, not the ceiling.

Security Headlines:


Sean McMillan Headshot

Sean McMillan

Community Manager

Sean McMillan is Community Manager at Bishop Fox, focused on making complex security topics easier to understand and more interesting to follow. He holds a bachelor’s degree in Mass Communication and Media Studies from Arizona State University and brings over a decade of experience in podcasting, live hosting, and audience engagement. As host of Initial Access, he works with practitioners to explore how real-world attacks actually happen.


Ku image

Kendrick Urbaniak

Senior Operator

Kendrick Urbaniak is a Senior Operator at Bishop Fox, serving on the Threat Research Team with a focus on exploit development, vulnerability research, and offensive security innovation. He leverages extensive experience in exploit engineering, adversary tradecraft, and security research to uncover emerging threats and help organizations better understand and reduce real-world risk across modern software and infrastructure ecosystems.


Bfx25 Thomas Wilson Bio

Thomas Wilson

Senior Red Team Operator

Thomas Wilson is a senior red team operator at Bishop Fox and a musician. From IDEs to DAWs, he is as at home on his own computer as he is on someone else's. You can usually find him at the local card shop slinging spells, up on stage blasting tunes, or with his eyes glued to his monitor for hours at a time (thank goodness for blue light filtering lenses).


Jon Williams

Jon Williams

Staff Security Engineer

As a researcher for the Bishop Fox Threat Enablement & Analysis team, Jon spends his time hunting for vulnerabilities and writing exploits for software on our customers' attack surface. Jon has written and presented research on various topics including enterprise wireless network attacks, bypassing network access controls, and reverse-engineering edge security device firmware.


Subscribe to our PODCAST

Real talk on the threats, trends, and tactics shaping security today

Listen Anywhere