Three stories on the table this week. A ransomware operator handed nearly an entire intrusion off to a fleet of AI agents, compressing two weeks of human red team work into under ten hours. A two-CVE chain called MikroTrick is giving attackers full admin takeover of internet-facing MikroTik routers, and the chain was already live as a zero-day before the coordinated disclosure landed. And Revolut confirmed a customer data breach after a fraudulent request rode in through a real government agency's own email domain. We also sit down with Bishop Fox staff security engineer Jon Williams to break down his team's research into a critical Citrix NetScaler authentication bypass, how they safely validated it, and the detection tool they built for defenders. Here's what stood out from the operator chair.
Watch your API token spend like a stolen credential, because compromised access now moves at agent speed. Unit 42 traced a ransomware operator who handed recon, credential harvesting, a hijacked CI/CD pipeline, and a seized secrets manager to a fleet of AI agents, compressing roughly two weeks of red team work into under ten hours. One of those agents then left the victim an 80-page audit of everything it broke. The real tell isn't the gift-wrapped report. It's that more than 50 attack techniques ran end to end before anyone noticed. If your alerting can't catch abnormal token usage inside a ten hour window, assume total compromise the moment you do notice.
Two chained CVEs on an unpatched device beat one zero-day on a watched one. Researchers paired a public-key authentication bypass (CVSS 9.2) with a privilege-escalation bug triggered by specially crafted SSH usernames to mint a fully privileged account on internet-facing MikroTik routers, no valid login required. The chain was already live as a zero-day before CERT Polska's coordinated disclosure landed. Compromised devices carry a giveaway: log entries for an SSH user named "-2." MikroTik routers sell on the promise that you'll never have to touch them again, which is exactly why they're still sitting on the internet unpatched years later. Treat any edge device with that pitch as a standing liability, not something you set and forget.
A legitimate government email domain doesn't make the person behind it legitimate. Revolut confirmed that passports, driver's licenses, verification selfies, IBANs, and full transaction histories for hundreds of customers went out the door after a fraudulent data request arrived from inside a real government agency's email domain. The request passed every technical check Revolut normally runs on law enforcement inquiries, precisely because the domain checked out. Domain authentication answers "is this a real mailbox," not "is this a real request," and any process that treats the two as the same question is one social-engineered inbox away from handing over a customer's entire identity file.
Why does the same CVE mean denial of service for one company and root for the next? We sat down with Bishop Fox staff security engineer Jon Williams to unpack his team's research into CVE-2026-19490, a critical Citrix NetScaler auth bypass that Citrix's own advisory described only as an "alternate path." Jon walks through how a single-instruction patch traced back to an attacker-controlled error code, why the exploitable impact depends entirely on which virtual server type and SAML configuration a given appliance is running, and how the detection tool his team built lets defenders safely confirm they're patched without crashing production. It's a case study in why an advisory is the floor for what a critical CVE means for your environment, not the ceiling.
Subscribe to our PODCAST
Real talk on the threats, trends, and tactics shaping security today
Recommened Resources
Download
Your download is starting in a new tab. If it does not start automatically, use the button below.