Zero-Days, Exposed Credentials, & Hijacked Cloud Pipelines
Attackers continue to exploit the connections between internet-facing infrastructure, developer credentials, and trusted cloud platforms—turning a single weakness or compromised identity into a path toward broader organizational access.
zero-days actively exploited
found exposed on GitHub
stolen by Storm-3068
This week, threat actors demonstrated how trusted infrastructure can become an attacker’s foothold. Citrix NetScaler zero-days were exploited to deploy web shells and tunnel into internal networks. Researchers found more than 543,000 active credentials exposed across public GitHub repositories. Meanwhile, Microsoft detailed how Storm-3068 compromised a legitimate account and used Azure DevOps pipelines to steal Kubernetes credentials. Together, the incidents highlight the importance of securing not only individual systems, but also the relationships between identities, applications, infrastructure, and development environments.
Citrix NetScaler Zero-Days Used to Plant Web Shells and Tunnel Into Networks
CVE-2026-88771 / Critical · CVE-2026-88772 / Critical · Citrix NetScaler ADC & Gateway
Threat actors have been actively exploiting two critical zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, tracked as CVE-2026-88771 and CVE-2026-88772. The attacks, which began as early as September 2026, have affected organizations across North America and Europe, including government, financial services, education, and professional services.
Citrix confirmed that both vulnerabilities were exploited before patches became available. CVE-2026-88771 allows unauthenticated remote code execution, while CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service when Datagram Transport Layer Security (DTLS) is enabled.
Attackers leveraged the vulnerabilities to gain root-level access, deploy custom PHP web shells, and establish persistent access to compromised appliances. Researchers identified two previously undocumented malware families, WHIPSHOT and SLAPSHOT, which were used to facilitate remote access and tunneling into internal networks.
These tools allowed attackers to conduct reconnaissance, steal credentials, and potentially move deeper into organizational infrastructure.
Insights & Recommendations
- Patch immediately. Apply the latest Citrix security updates to all affected NetScaler ADC and Gateway appliances. Patching alone is not sufficient if attackers have already established persistence.
- Investigate for persistence. Review appliances for suspicious PHP web shells, unauthorized web server configuration changes, unexpected system permission modifications, unusual processes, and abnormal network connections.
- Restrict administrative access. Limit management interfaces to trusted sources and restrict administrative access to NetScaler appliances wherever operationally feasible.
- Evaluate DTLS exposure. Where operationally feasible, disable Datagram Transport Layer Security as a temporary mitigation for CVE-2026-88772, recognizing that this does not protect against CVE-2026-88771.
How nGuard Helps
- Continuous Vulnerability Management helps organizations identify exposed infrastructure, prioritize critical vulnerabilities, and track remediation before attackers can exploit unpatched systems.
- External Penetration Testing evaluates internet-facing infrastructure and identifies potential attack paths that could allow threat actors to gain unauthorized access.
- If an appliance is suspected of compromise, Cybersecurity Incident Response helps organizations investigate malicious activity, identify persistence, contain the threat, and support recovery.
More Than 543,000 Active Credentials Left Exposed on GitHub
543,699 unique active credentials / 224M+ public repositories scanned · 1.1M+ individual exposures
Security researchers discovered more than 543,000 active credentials exposed in public GitHub repositories, highlighting the continued risks associated with accidentally publishing sensitive information.
Researchers scanned more than 224 million public repositories and identified 543,699 unique credentials that were still active when tested in July 2026. Those credentials appeared in more than 1.1 million individual exposures across files and repositories, including copies contained in repository forks.
The scale of the exposure
Some credentials had remained exposed for years, including an AWS key originally committed in 2009. Removing a secret from a repository does not automatically invalidate the underlying credential.
Nearly 200,000 of the active credentials were published after GitHub enabled default push protection, a security feature intended to prevent developers from accidentally committing secrets.
The exposed information included Google Cloud service account credentials, MongoDB connection strings, and Google API keys. Although GitHub provides secret-scanning alerts and notifies credential providers about exposed secrets, credentials are not automatically revoked in every case.
As a result, organizations may continue to face exposure even when security scanning and preventative controls are already in place.
Insights & Recommendations
- Enable secret scanning and push protection. Apply these controls across all applicable GitHub repositories to identify exposed credentials and block new secrets from being committed.
- Revoke and rotate exposed credentials. Immediately invalidate exposed API keys, cloud service account credentials, database connection strings, and other secrets.
- Audit development environments. Regularly review repositories, development environments, and CI/CD pipelines for hardcoded credentials and other sensitive information.
- Apply least privilege. Limit service accounts and API keys to only the permissions and resources necessary for their intended functions.
How nGuard Helps
- Web Application & API Penetration Testing can identify weaknesses in authentication, authorization, and API security that could expose sensitive information or enable unauthorized access.
- A Strategic Security Assessment evaluates security policies and practices to identify gaps in credential management, access controls, and secure development processes.
How One Hijacked Account Gave Storm-3068 a Path to Kubernetes
Attack vector / Compromised user account · Platform / Azure DevOps · Target / Kubernetes credentials
Microsoft recently detailed an intrusion involving Storm-3068, a threat actor that compromised a user account and leveraged Azure DevOps to steal Kubernetes credentials.
The attack began with the abuse of a self-service password reset process, allowing the threat actor to take control of a legitimate account. After gaining access, the attackers registered their own authentication methods, established persistent access, and began enumerating repositories, projects, pipelines, and deployment environments within Azure DevOps.
From one compromised identity to Kubernetes access
The attackers subsequently created a malicious pipeline designed to collect Kubernetes configuration files, which contain sensitive cluster connection and authentication information. The malicious pipeline was authorized to access more than 50 resources and services.
The threat actor also modified pipeline scripts to install the Atera remote management agent and Chisel tunneling utility, creating additional methods for remote access and communication with compromised environments.
Insights & Recommendations
- Monitor account recovery activity. Watch self-service password reset activity for unexpected authentication method registrations, repeated reset attempts, and unusual account behavior.
- Strengthen authentication. Require phishing-resistant multifactor authentication for privileged accounts wherever possible.
- Restrict pipeline permissions. Enforce least-privilege access across Azure DevOps, cloud infrastructure, and development environments. Limit who can create, modify, or execute pipelines.
- Protect critical branches and deployments. Implement branch protection policies and require approvals for changes to critical repositories and deployment pipelines.
- Review service connections. Regularly evaluate service connections, pipeline permissions, and stored credentials to ensure compromised accounts cannot access unnecessary resources or production environments.
How nGuard Helps
- Configuration Assessments identify weaknesses in cloud configurations, identity management, and access controls that could allow attackers to move from compromised accounts into critical infrastructure.
- Cybersecurity Incident Response provides the expertise needed to investigate account compromises, identify malicious pipeline activity, contain threats, and recover affected environments.
Wrap
Whether exploiting internet-facing infrastructure, exposing sensitive credentials, or hijacking trusted development pipelines, this week’s incidents demonstrate how attackers continue to target the connections between an organization’s systems.
A single vulnerability or compromised account can provide an entry point into critical infrastructure, sensitive data, and cloud environments. Organizations must prioritize vulnerability remediation, enforce strong identity and access controls, and regularly assess the security of their development and production environments to reduce the risk of widespread compromise.
Know where your attack paths lead? nGuard helps organizations identify exposed infrastructure, weaknesses in applications and APIs, credential risks, and gaps in incident readiness.
Talk to nGuard
