Your Security Stack Is Now the Way In
Treat any NetScaler still unpatched after Monday as compromised. The breaches covered here came through the tools and vendors bought to reduce risk, so the metric your board sees must move from detection to recovery.
The pattern across six incidents
Bitget's $388M loss is the clearest template. Attackers exploited a flaw in a third-party security product and took valid admin credentials. They then sent two small test transfers that slipped under the risk threshold and began large withdrawals 30 minutes later. Risky.Biz and Daniel Miessler read it the same way: attackers didn't break the exchange itself, they broke a tool bought to protect it. Bitget's Protection Fund covers the loss. That reserve is the only reason this is a bad quarter rather than an existential one.
NetScaler repeats the pattern at the network edge. CyberScoop reports that Citrix took most of a weekend to confirm active exploitation of CVE-2026-88771 and CVE-2026-88772. Public exploit code was available, tens of thousands of instances were exposed, and CISA publicly criticized the response. SANS editors say the flaws were reportedly exploited for weeks before confirmation. Their detection guidance shapes what your team will tell you. Citrix's detection script depends on log history many teams don't keep on the device, so a team with short retention can run it and report a false all-clear. Oracle's PeopleSoft CVE-2026-35273 shows the same trap. A firewall rule meant to block it was bypassed with URL encoding, and mass exploitation returned three months after the patch shipped.
Destruction changes the metric
Microsoft now sees Jadepuffer, an autonomous attacker, destroying Azure resources. That shifts the board metric from time-to-detect to time-to-restore. CSO First Look adds the economics: at about $25 per target, hitting a thousand organizations costs roughly $25,000. Defense that scales with analyst headcount loses that race. The posture that holds limits what one compromised identity can delete and keeps backups out of that identity's reach. Microsoft is hedged on whether exposed credentials were the way in, and the number of victims is not public.
Liability now follows the vendor chain
SANS NewsBites highlights Labcorp's settlement with 44 state attorneys general: $2.3M, though GovInfoSecurity reports $2.2M. It covers a 2019 breach at AMCA, Labcorp's debt collector, which has since dissolved. Seven years later the liability landed on the client. The settlement mandates four terms that plaintiffs and customers will now cite:
- security requirements in vendor contracts
- a response plan for vendor incidents
- limits on the data shared with vendors
- a team that verifies vendor compliance
Kiteworks showed the better version of vendor behavior. It told customers to take servers offline based on federal intelligence, then found and fixed a previously unknown critical flaw during the downtime.
In Bitget, NetScaler, PeopleSoft, Jadepuffer and Labcorp, the failing controls are the ones leaders assume belong to someone else: vendor security, vendor disclosure and workaround controls such as firewall rules. That makes this a governance and contract question as much as a patching one.
Patched is not clean, mitigated is not fixed, and a vendor's balance sheet does not cap your exposure.
What to do
Require written CISO confirmation within 48 hours of a compromise assessment for every NetScaler, PeopleSoft and Kiteworks instance: a webshell hunt plus a 30-day SIEM log review, not just patch status.
Fund deletion guardrails and immutable backups, kept in a separate trust domain, for tier-1 cloud workloads this quarter. Validate them with a tabletop exercise in which an autonomous agent holds one of your privileged identities.
Benchmark contracts with every vendor holding regulated data against the four Labcorp settlement terms, and add exploitation-notification SLAs with weekend coverage at each renewal.