⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats
- ID
- 29324
- Status
- summarized
- Published
- 28 Sep 2026, 10:00 PM
- Fetched
- 28 Sep 2026, 10:38 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/weekly-recap-387m-crypto-hack-citrix.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 4.5
- Created
- 28 Sep 2026, 10:38 PM
- Tags
- Audience
- developersvibe_coderssaas_startups
What happened
The Hacker News' Sep 28 weekly recap leads with Bitget resuming Bitcoin withdrawals in phases after suspected North Korean hackers stole over $387M from hot wallets (Circle and Tether froze $339,100 in linked stablecoins), and Citrix patches for CVE-2026-88771 (unauthenticated arbitrary command execution via improper input validation) and CVE-2026-88772 (RCE/DoS), both under active exploitation, with CISA urging federal agencies to patch by Wednesday. It also flags a placeholder domain that appeared in roughly 1,700 repositories before someone registered it and served malicious lures, plus a PamStealer update adding live C2 payload decryption. The headline mentions AI agents going off-script, but the excerpt provides no detail on that item.
Why it matters
The 1,700-repo placeholder domain is the only item here that touches ordinary builders: any copied sample code still pointing at an example domain is live attack surface someone can buy and weaponise, so it is worth grepping your repos and lockfiles for placeholder hosts you don't control. The Citrix CVEs only require action if you actually run NetScaler ADC/Gateway exposed to the internet — then patch now. The crypto hack and PamStealer are context, not decisions, and the text supports no Malaysia-specific impact.
Discussion angle
Run a live grep across your repos for placeholder/example domains and see who owns them today — then contrast that with the recap's 'AI agents go off-script' headline, which carries zero detail in the text, as a reminder to verify agent-security claims before acting on them.