Weekly AppSec Threat Digest: NetScaler, SD-WAN & AI Security
Sep 25–Oct 2, 2026: exploited NetScaler, Cisco SD-WAN, FortiMail and TeamCity flaws, WatchGuard fixes, AI agent security and JWT bug bounty lessons.
Read article →blog
How we think about autonomous pentesting — methodology, exploit verification, and the engineering behind proving vulnerabilities instead of guessing at them.
Sep 25–Oct 2, 2026: exploited NetScaler, Cisco SD-WAN, FortiMail and TeamCity flaws, WatchGuard fixes, AI agent security and JWT bug bounty lessons.
Read article →Actively exploited zero-days dominate the edge: F5 BIG-IP APM unauth RCE (KEV), Arista VeloCloud CVSS 10.0 SD-WAN control-plane compromise, Check Point management-server pre-auth script execution and VPN escalation, plus the Next.js next/og SVG RCE, Cloudflare's cross-tenant Containers postmortem, and an AI-assisted $6,500 OpenAI exploit chain.
Read article →Actively exploited zero-days in Cisco ISE (root RCE) and Secure Email Gateway (SQLi to root), GitLab unauthenticated path traversal in KEV, Issabel hard-coded JWT secret exploitation, Unbound DNSSEC heap overflow, ransomware targeting VMware vCenter, and the BragJack agentic browser attack class.
Read article →Active Magento RCE in the wild, N-able N-central pre-auth RCE in KEV, SAP OVERPASS & S4GET criticals, Check Point VPN zero-days, Chrome V8 exploited, watchTowr's 5-second PaperCut weaponization, and NASA command injection disclosures.
Read article →Anthropic disclosed four incidents where Claude cybersecurity agents reached real third-party systems during CTF evaluations. Here's what the failures reveal about scope enforcement, egress controls, credential boundaries and safe autonomous pentesting.
Read article →Six exploited vulnerabilities hit management planes and AI infrastructure, while Skyvern and two WordPress flaws expose recurring failures in trust boundaries and multi-stage processing.
Read article →Factory implants in ZBT routers, an AshGraphQL complexity bypass, an exploited SQL Server RCE, CISA’s vulnerability data, and a 100-company call for stronger AI cyber defense.
Read article →Urgent fixes for exploited Gitea, NetScaler, and Zimbra flaws—plus the Snowflake CI injection and lessons from OpenAI’s agent incident.
Read article →The security stories that matter for August 28: an actively exploited Gitea RCE, critical Adobe, Alluxio and GeoTools flaws, fresh web research, and three useful bug bounty lessons.
Read article →Self-hosting Xalgorix is free to run — but the agent calls an LLM you pay for, and agentic scans are token-hungry and hard to predict. An honest look at the real total cost, when self-hosting still wins, and how outcome-based hosted pricing compares.
Read article →A practical look at Xalgorix: its 22-phase methodology, independent exploit verification, local dashboard, setup and Docker paths, strengths, trade-offs, and the managed option.
Read article →Moonshot AI quietly shipped Kimi K3 Max — a reported 2.8-trillion-parameter, 1M-context flagship — and it debuted at #1 on the Frontend Code Arena while pricing 40% below the competition. Here's what's confirmed, what's rumor, and why a model-agnostic scanner is watching.
Read article →Install the Xalgorix GitHub App and every pull request gets an automatic security review commented on the diff. No workflow file, no API key, no account. Comment @xalgorix review to re-run.
Read article →Most scanners flood you with maybes. Xalgorix runs a 22-phase offensive methodology, exploits what it finds, and independently re-verifies every result — so a finding is evidence, not a guess.
Read article →