Better, Faster, More Cost-Effective – TENEX Leverages AI and Automation to Transform Security Operations

contact us

8586 Potter Park Dr.
Sarasota, FL 34238

TENEX.ai Threat Intelligence Report: Citrix NetScaler Zero-Day Attackers Plants Footholds That Survive Patching

Analysis of active exploitation of newly discovered CVE-2026-88771 zero-day exploit traces one operator’s infrastructure to a four-node command-and-control cluster and releases more than 60 indicators that defenders can use and share without restriction

SARASOTA, Fla. — October 5, 2026 — TENEX, a fully-agentic, human-led security operations provider, released What TENEX.AI Observed Inside Active Exploitation of NetScaler Zero-Day on Oct. 1, documenting how attackers exploiting the Citrix NetScaler zero-day are installing a superuser account, hidden web shell and command-and-control agent that remain on the appliance even after it is patched.

Based on TENEX Threat Intelligence analysis of exploitation attempts against a NetScaler Gateway and payloads recovered from the attacker’s staging servers, the report maps the operator’s infrastructure to a four-node cluster sharing a single TLS certificate. Citrix released fixed builds on Sept. 27, CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day, and a public proof-of-concept on Sept. 28 was followed by mass scanning within a day.

Bashar Abouseido, President, TENEX 

“Threat actors are using AI to compress the time between identifying a vulnerability, exploiting it, and at times to reverse engineer a patch. The speed of this one fits that pattern. The adversary isn’t waiting for anyone to catch up, so neither can we.”

Report Highlights

  • Four staging servers used in roughly a day: The exploitation attempts rotated through four staging servers, each serving a different payload over a different port and download method. One path led to the Platypus agent, one to a Perl post-exploitation script, one to a Python reverse shell, and one to a direct binary download.
  • One certificate exposed the cluster: All four command-and-control nodes present the same self-signed certificate, and a single pivot on its fingerprint turned one suspicious address into the full cluster. The certificate’s public-key hash and issuing CA give defenders pivots that survive a reissue.
  • Footholds survived the patch: The Perl stage writes a superuser account named sec_monitor into the saved configuration, sets the SUID bit on /bin/sh, exfiltrates the configuration directory, and aliases a PHP web shell behind a stylesheet URL on the Citrix logon page. The Python stage replaces the appliance’s customsnmpd daemon with a reverse shell that NetScaler restarts itself.
  • An agent built to outlast blocklists: The Platypus binary carries no C2 address. A bootstrap hands it the server and a one-time install token and installs it under appliance-style paths renamed as a NetScaler Perl script. Every build carries the same operator signing key, which outlasts any rebuild.
  • Two waves over one flaw: A disciplined operator rebuilding its agent as the patch shipped, and a separate wave of commodity tooling (Global Socket Toolkit, netcat) after the public proof-of-concept. TENEX does not attribute the activity to a named actor.

Recommended Actions

The report recommends that any organization running NetScaler ADC or Gateway:

  • Upgrade now: Move to 14.1-73.37, 13.1-64.23, or the FIPS and NDcPP equivalents, after confirming the identity provider signs SAML assertions.
  • Check before clearing: On any appliance exposed before the upgrade, look for the sec_monitor account, a setuid /bin/sh, unexpected files under LogonPoint/, httpd.conf alias changes, a modified customsnmpd, and a client certificate under /var/core/.ns-cache/.
  • Rotate after upgrading: Replace every credential, key, and certificate the appliance could reach, then revoke active sessions.
  • Monitor the segment: Watch the appliance’s local network for the agent’s _platypus-mesh._tcp mDNS announcement.

To read the full report and download the indicator set, visit https://tenex.ai/blog/what-tenex-observed-inside-active-exploitation-of-netscaler-zero-day/.

About TENEX

TENEX.ai delivers fully-agentic, human-led security operations built by operators who have previously scaled MDR and founding engineers from Google Chronicle and leading AI labs. TENEX serves enterprise customers across the Google and Microsoft security ecosystems. Its Agentic Security Operations platform automates security workflows across the existing technology stack, with experienced human analysts providing oversight, judgment and accountability for critical decisions.

Backed by Crosspoint Capital Partners, Shield Capital, DTCP, Deepwork Capital and the Florida Opportunity Fund, with its seed round led in 2025 by Andreessen Horowitz (a16z), TENEX is headquartered in Sarasota, Florida, with offices in Overland Park, San Jose and Phoenix. Learn more at TENEX.ai.

Media Contact

TENEX Press Team
[email protected] 

Keep Up with TENEX.AI

Press Releases and Company News

What TENEX Observed Inside Active Exploitation of NetScaler Zero-Day

TENEX THREAT INTELLIGENCE TEAM [email protected] Published: September 30, 2026 What TENEX...

Who Watches the Agents? NVIDIA OpenShell and the SOC

By Venkata Koppaka, Co-Founder and CTO, TENEX.ai NVIDIA invited TENEX.ai to participate in the...

The Problem Was Never Network Detection: What TENEX and ExtraHop RevealX Deliver Together

The problem was never network detection. It was the distance between a good detection and a...

Reviews

Perspectives from Those Who Know Us Best

Eric Foster
★★★★★
CEO of TENEX
"TENEX was founded to help enterprises overcome persistent security challenges by leveraging the scale and efficiency of modern cloud provider security stacks combined with AI-driven services. We aim to deliver exceptional outcomes with agility and cost-effectiveness."
Zane Lackey
★★★★★
General Partner, Andreessen Horowitz
"TENEX is tackling one of the most critical challenges in cybersecurity: the inefficiency of managing comprehensive security programs”
Iman Ghanizada
★★★★★
Godfather of Autonomic Security
"In an era where modern threat actors can bypass years of security controls in minutes, the industry needed a fundamentally different approach to security operations. Tenex represents the first true implementation of what autonomic defenses must look like in an AI-first world."
Elias "Lou" Manousos
★★★★★
Shield Cap
"At TENEX, we’re not just delivering another cybersecurity service—we’re redefining how security operates in an AI-driven world."
Zane Lackey
★★★★★
General Partner, Andreessen Horowitz
With their AI-driven, cloud-native platform and deep security expertise, TENEX is strongly positioned to deliver automated, scalable solutions that modern enterprise customers need. We are proud to support Eric Foster and the TENEX team as they redefine the way cybersecurity is delivered.
Chad Kreimendahl
★★★★★
CEO, Onspring
Imagine a cybersecurity partner that redefines industry standards. An AI-first approach that integrates seamlessly with your infrastructure, automating routine tasks and enabling your team to focus on strategic priorities. With advanced technology and expertise, we envision a future that sustains and enhances our operational excellence. That's what the team at Tenex has done for us, and what they can do for you.
#side-panel.side-panel .side-panel_sidebar {background-color: #070C1F;}