The Implant Survives the Upgrade: NetScaler Root Access and Three Million Defense Records

by: Craig WoodPublished on: 05/10/2026

Mandiant found root-level implants on exploited NetScaler appliances and says upgrading alone will not evict them. Six KEV additions, one hacked tanker.

Threat IntelligenceCISA KEVCitrix NetScalerFortiMailCMMCDIBMaritime CybersecurityPSYber360
The Implant Survives the Upgrade: NetScaler Root Access and Three Million Defense Records

GitLab Hits CVSS 10.0, ScreenConnect Joins KEV Same Week

by: Craig WoodPublished on: 14/09/2026

GitLab's CVSS 10.0 path-traversal flaw and a ConnectWise ScreenConnect KEV addition landed the same week — one hits source code, the other hits every client an MSP touches.

threat intelligenceCISA KEVGitLab vulnerabilityConnectWise ScreenConnectCMMCDIB cybersecurityvCISOmaritime cybersecurity
GitLab Hits CVSS 10.0, ScreenConnect Joins KEV Same Week

Weekly Threat Intelligence Briefing — August 10, 2026

by: Craig WoodPublished on: 10/08/2026

N-able N-central exploited through an incomplete patch, signed ScreenConnect agents abused with no CVE, and six KEV additions on three-day clocks.

N-able N-central CVE-2026-18577ScreenConnect abuseMSP supply chain riskCloudflare tunnel persistenceCISA KEV
Weekly Threat Intelligence Briefing — August 10, 2026

Weekly Threat Intelligence Briefing — July 06, 2026

by: Craig WoodPublished on: 06/07/2026

SharePoint, PTC Windchill and edge devices join CISA KEV where CUI lives, while TeamPCP credential theft feeds Vect ransomware. What DIB teams must check.

PTC Windchill CVE-2026-12569SharePoint CVE-2026-45659CUI exposuresupply chain credential theftCISA KEV
Weekly Threat Intelligence Briefing — July 06, 2026