Good morning. Thursday’s news lands on a theme worth sitting with: the tools are getting cheaper for the attackers and more complicated for everyone else, whether that is a $12 a month criminal chatbot or an approved AI assistant doing something nobody planned for. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT.
Citrix patched a critical hole in the appliance that fronts a lot of company remote access, and researchers expect attacks within days. Citrix released fixes on Wednesday for CVE-2026-19490, rated 9.3 out of 10, an authentication bypass in NetScaler ADC and NetScaler Gateway that a remote attacker can trigger with no credentials and no user interaction. It affects appliances configured as a gateway, meaning SSL VPN, ICA Proxy, CVPN, or RDP Proxy, along with AAA virtual servers, which is exactly how most companies use the product. Rapid7 says there are no confirmed attacks yet but expects exploitation shortly, because these boxes sit in the DMZ facing the internet and Citrix gear has a long history of being hit fast. If your remote access runs through NetScaler, whether you manage it or your IT provider does, treat this as an emergency patch this week rather than a normal maintenance item, since a bypass here means someone walks in the front door as a trusted user. Read more at SecurityWeek
...