Patch NetScaler, then check your subprocessors
Free weekly email
This went to subscribers on October 6. Get the next one.
One email every Tuesday: what changed in security and compliance that week, and what it means if you sell to enterprise buyers.
Free. Unsubscribe in one click, and replies reach Jacob directly. Read the latest issue or browse the archive.
Quiet week for headlines, busier week for anything you actually have to do something about. Two items here need action from an engineering team this week, and the other three change how a US buyer's security reviewer is going to read your answers. I have left out the municipal ransomware and the hospital breaches, which are sad and have nothing to teach a SaaS company in Toronto.
Cyber Centre updates its NetScaler alert again
Source: Cyber Centre (CCCS)
The Canadian Centre for Cyber Security issued alert AL26-024 on September 27 covering two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-88771 and CVE-2026-88772. The alert was updated again on October 3. It is addressed to IT professionals and managers, with detection and mitigation advice.
When the Cyber Centre updates the same alert twice inside a week, that usually means the situation on the ground is moving rather than the paperwork. If you have a NetScaler in front of anything, patch it and then go looking for signs it was already touched, because applying an update does not undo access somebody already has. I have seen enough internet-facing appliances during assessments to say this plainly: the gateway is the part of the stack that gets owned, and it is almost never the part anyone has an owner for.
Frontline Education breached through someone else's software
Source: BleepingComputer
Frontline Education is notifying school districts that attackers exploited a vulnerability in third-party software to reach its systems and steal employee information, including Social Security numbers. The affected people are staff at Frontline's customer districts, not Frontline's own employees.
This is the shape of incident that most damages a B2B vendor, because the people harmed are your customer's people and your customer has to tell them. Pull your subprocessor list this week and read what your own contracts actually commit you to when one of your vendors is the one that gets hit, including how many hours you have to notify and who signs the notice. Most of the Canadian teams I work with can produce the list, and very few can produce the notification clock from memory.
AWS agent tooling can leak credentials
Source: Infosecurity
Researchers reported flaws in the Amazon Bedrock AgentCore SDK that could allow an attacker to run commands inside AI sandboxes and reach AWS credentials. The issue sits in the agent runtime layer rather than in a customer's own application code.
If you shipped an AI feature in the last year, it probably got a lighter design review than the rest of your product, and the credentials behind it are probably broader than they need to be. Treat the agent runtime as an untrusted execution environment: separate account, scoped role, no long-lived keys sitting where the model can see them. US buyers have started adding agent questions to their security questionnaires, and "we use Bedrock" is not an answer to any of them.
An arrest, then an escalation
Source: Krebs on Security
Dutch police arrested a 23-year-old convicted cybercriminal suspected of helping ShinyHunters with data thefts and extortion. In the days after the arrest, the remaining members escalated, stealing data from the FBI and extorting the Russian ransomware group Cl0p.
Police action against this crowd reads well and changes very little about your exposure, as the week after the arrest demonstrated. ShinyHunters makes its money pulling customer records out of SaaS platforms and connected business applications, which is a precise description of what your production database holds. The control that matters is boring and unglamorous: tight scoping on OAuth integrations, detection on bulk export, and an honest answer to how much data one compromised support account can pull.
Your exception register is a security document
Source: The Hacker News
A piece aimed at banks, insurers and asset managers walks through the familiar cycle where security wants a class of vulnerabilities gone, engineering prices out the platform upgrade and regression testing, the change-freeze calendar gets raised, and the finding ends up with an exception, a compensating control and a date.
Fintech readers will recognise this because their own customers run the same cycle, and it is why enterprise security reviewers now ask to see the exception list rather than the clean scan. An exception with a named owner, a stated compensating control and a date that has not moved twice is defensible in a SOC 2 audit and in a buyer call. One that has rolled over three quarters tells the reviewer something about your engineering culture, and it is never the thing you wanted it to say.
Short list this week because most of what came through the feeds was someone else's bad month. The NetScaler item is the one I would handle before Wednesday.
Jacob
Free weekly email
Get the next issue on Tuesday
One email a week from Jacob Masse: the security and compliance stories that changed something that week, and what each one means if you sell software to enterprise buyers. Five stories, a take on each, five minutes to read.
Free. Unsubscribe in one click, and replies reach Jacob directly.