Last Updated On

CCTTII--22002266--00882277
CCrriittiiccaall
AAccttiivvee  EExxppllooiittaattiioonn  CCoonnffiirrmmeedd

Your Edge Is Already Executing Someone Elses Root Code

Root is landing on Citrix NetScaler through CVE-2026-8452 while Gitea CVE-2026-60004 turns a public registration portal into a hook driven shell. Oracle CVE-2026-21962 sits at CVSS 10.0 with a 72 hour federal clock that started days after years of available patches.

UAT-10147 is no longer dabbling with chat prompts. The group is using agentic AI to write exploit guides, automate ViewState RCE, and QA its own payloads against about 170000 URLs pulled from an exposed directory at 139.180.197[.]150.

ATF confirmed a major incident on a standalone system after Qilin made a leak site claim, and that actor link remains unproven. Patch the gateways, the Git servers, the Oracle proxies, and the old SQL boxes before the calendar does the escalating for you.

10

CVSS Score

24

IOC Count

11

Source Count

80

Confidence Score

CVEs

CVE-2026-8452, CVE-2026-60004, CVE-2026-21962, CVE-2019-1068, CVE-2022-0995, CVE-2015-5287, CVE-2015-3246, CVE-2021-23758, CVE-2022-27925, CVE-2021-29441, CVE-2021-29442, CVE-2019-18935, CVE-2021-3156, CVE-2010-3904, CVE-2022-0847

Actors

UAT-10147, Qilin, Under Attribution

Sectors

Defense Industrial Base, Financial Services, Critical Manufacturing, Energy, Water and Wastewater Systems, Technology, Government, Healthcare, Education, Media, Gaming, Federal Law Enforcement

Regions

North America, Europe, Asia Pacific, United States, Brazil, Bolivia, China, Canada, Vietnam

Chapter 01 - Executive Overview

Active edge perimeter exploitation, developer infrastructure compromise, maximum severity middleware abuse, AI assisted web server raids, and a federal standalone system incident are the strategic exposure vectors in this window. Consulted sources confirm threat actors are weaponizing unauthenticated memory corruption in enterprise gateway appliances, API driven code injection in source repositories, and an unauthenticated Oracle HTTP Server and WebLogic proxy flaw, while a Chinese speaking financially motivated group tracked as UAT-10147 is scaling one day web server exploits with agentic AI tooling.

[+] Citrix NetScaler Pre Auth Memory Overflow: Critical, Cross Sector. Threat actors are actively weaponizing CVE-2026-8452, an unauthenticated heap based buffer overflow affecting Citrix NetScaler ADC and Gateway appliances configured as SAML Service Providers, Identity Providers, Gateway VPNs, or AAA virtual servers. The original vendor category was denial of service. Validated research and weaponized tooling demonstrate arbitrary remote code execution inside the nsppe packet processing engine at root privileges. That bypasses authentication and opens deep internal footholds. Telemetry recorded 36 exploitation attempts over 12 days from 12 unique attacker IPs, with web shells named x.php and z.php and basic discovery commands. Senior leadership must mandate an immediate audit of all perimeter NetScaler appliances and verify patched firmware builds within 24 hours. Federal civilian entities face a 29 August 2026 remediation deadline.

[+] Gitea Diffpatch Git Hook Injection: Critical, Technology and Enterprise DevOps. Adversaries are attacking self hosted Gitea platforms via CVE-2026-60004, abusing the /diffpatch API endpoint to inject malicious executable Git hooks and trigger arbitrary shell execution as the Gitea service account. Public facing or internal deployments that permit open self registration let unauthenticated actors create accounts, generate repositories, and execute malicious patches on backend hosts. Exploitation exposes source repositories, embedded secrets, CI/CD pipelines, and infrastructure access keys. Security leadership must isolate or upgrade instances to version 1.27.1 or higher and disable open public self registration.

[+] Oracle HTTP Server and WebLogic Proxy: Critical, Sector Agnostic Middleware. CVE-2026-21962 is an unauthenticated, network exploitable flaw scored at CVSS 10.0. It was patched in January 2026 and added to the KEV catalog on 24 August 2026, 216 days after the patch was available. CISA issued a 72 hour Binding Operational Directive 26-04 window, the shortest permitted under that directive. Attacks can yield unauthorized creation, deletion, or modification of critical data, or full read access, with scope change scoring. Patch Oracle Fusion Middleware components 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0 for the Apache proxy plug in, and 12.2.1.4.0 for the IIS variant, inside that window.

[+] UAT-10147 Agentic AI Web Server Campaign: Critical, Multi Sector. UAT-10147 has been active since early 2026 against internet exposed Windows and Linux web servers in government, education, media, technology, and gaming, with confirmed victim infrastructure in Brazil, Bolivia, China, Canada, and Vietnam. An operational security failure exposed a command and control open directory at 139.180.197[.]150 containing a target list of about 170000 URLs in 17 batches of about 10000. The group exploits known one day flaws and Linux local privilege escalation chains to deploy BadIIS SEO fraud malware and backdoors including QuasarRAT, Gh0stCringe, SPECTRE, NoodleRAT, and Meterpreter. Consulted sources describe AI generated exploitation guides, automated ViewState RCE tooling, and QA validated payloads. Four KEV additions on 26 August trace directly to this campaign. Reassess AI enabled adversary capability as a shift from AI assisted scripting to semi autonomous offensive orchestration.

[+] Microsoft SQL Server and Linux Privilege Escalation KEV Set: Critical, Legacy Exposure. CVE-2019-1068 carries a federal deadline of 29 August 2026. CVE-2022-0995, CVE-2015-5287, CVE-2015-3246, and CVE-2021-23758 carry a 9 September 2026 deadline. Public technical detail on how the 2019 vintage SQL Server RCE is being exploited in 2026 was not published in consulted sources. Prioritize internet exposed Windows and Linux web servers that match the UAT-10147 target profile.

[+] ATF Major Incident after Qilin Claims: High Uncertainty, Federal Law Enforcement. Qilin listed ATF on its dark web leak portal on 26 August 2026 without disclosing whether data was exfiltrated or a ransom demanded. ATF confirmed a major incident on a standalone system separate from its enterprise network, eForms system, and other core systems, with DOJ jointly investigating. Qilin has claimed over 2200 victims historically. Qilin involvement is not independently verified. ATF is at least the third U.S. federal agency to disclose a 2026 compromise after FBI in March and DHS/HSIN in July. Monitor federal sector ransomware exposure and isolated system segmentation.

[+] Executive Priorities: Patch CVE-2026-8452, CVE-2026-60004, CVE-2026-21962, and CVE-2019-1068 first. Hunt for NetScaler web shells and Gitea hook implants. Audit ASP.NET MachineKey exposure and Windows Defender exclusion paths on IIS hosts. Treat the ATF disclosure as a segmentation lesson, not as confirmed Qilin tradecraft.

[+] Intelligence Quality: This brief is supported by governmental advisories, vulnerability catalog listings, national CERT alerts, and primary research laboratory validation. No conflicting technical discrepancies were identified on NetScaler, Gitea, or Oracle vulnerability mechanics. Certainty is lower on ATF actor naming and on the unpublished remainder of the UAT-10147 indicator repository.

[+] What Remains Unconfirmed: Qilin's specific role in the ATF incident. The live exploitation method for CVE-2026-21962 beyond the KEV listing. The precise 2026 exploitation method for CVE-2019-1068. Exact NetScaler attacker IP values.

Chapter 02 - Threat & Exposure Analysis

Adversary activity in this window concentrates on perimeter authentication boundaries, source control nodes, middleware proxies, and unpatched internet facing web servers. Related gateway, repository, and middleware flaws are grouped first because they share unauthenticated or trivially authenticated remote execution. The UAT-10147 campaign and the ATF incident follow as separate operational pictures.

[+] NetScaler Attack Progression: The attacker sends an unauthenticated HTTP request containing a crafted SAML message to an appliance running SAML SP/IdP or AAA services. During SAML signature canonicalization, an oversized PrefixList attribute inside the ds:SignedInfo element bypasses boundary checks and overflows adjacent NetScaler memory chunk (nsb) headers. Pointer corruption lets the attacker run shellcode inside the nsppe packet processing daemon as root and then drop persistent web shells on the appliance filesystem.

[+] NetScaler Exploitability: CVSS 3.1 base 9.8 and CVSS 4.0 base 8.8. Attack complexity is low, authentication is not required, and public weaponized scripts exist. Consulted sources originally framed the bug as denial of service. Later laboratory validation proved unauthenticated root execution.

[+] NetScaler Campaign Indicators: Post exploitation telemetry shows PHP and CGI web shells named x.php and z.php, modification of internal configuration files, memory extraction against active VPN sessions, and discovery commands such as id and echo. Thirty six attempts over 12 days originated from 12 unique IPs in Switzerland, Germany, Hong Kong, Japan, Netherlands, Russia, Singapore, Türkiye, the United States, and Vietnam.

[+] NetScaler Actor and Infrastructure: Under Attribution. Activity matches opportunistic cybercrime groups and initial access brokers. Fingerprints include TCP/443 listeners on /vpn/index.html, /logon/LogonPoint/index.html, and SAML ACS/IdP URLs.

[+] NetScaler Exposure: Defense Industrial Base, Financial Services, Critical Manufacturing, Healthcare, and Government remote access gateways. Geographic concentration is North America, Europe, and Asia Pacific, with global appliance inventory.

[+] Gitea Attack Progression: The adversary obtains repository write privileges through stolen developer credentials or default open user registration, then posts a crafted patch to the /diffpatch API. Weak validation of patch metadata and directory traversal during staging writes a malicious Git hook into .git/hooks/. The next Git transaction runs that hook under the git or Gitea service user.

[+] Gitea Exploitability: CVSS 3.1 base 9.8. Write access is required, but that requirement collapses to unauthenticated on instances with open registration.

[+] Gitea Campaign Indicators: Automated scanning of self hosted Git instances, registration spikes, immediate /diffpatch invocation, and outbound curl or wget staging that drops miners or secondary payloads.

[+] Gitea Actor and Infrastructure: Under Attribution. Fingerprints include TCP/3000 or custom HTTPS reverse proxies exposing /api/v1/repos///diffpatch and /api/v1/user/sign_up.

[+] Gitea Exposure: Technology, Telecommunications, Software Development, Financial Services, and DevOps infrastructure, with worldwide self hosted inventory.

[+] Oracle Attack Progression: CVE-2026-21962 is unauthenticated and network reachable against Oracle HTTP Server and WebLogic Server Proxy Plug in on Apache and IIS. Consulted sources describe unauthorized creation, deletion, or modification of critical data, or full read access, with scope change scoring. The precise in the wild method was not published.

[+] Oracle Exploitability: CVSS 3.1 base 10.0, vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N. The January 2026 patch existed for 216 days before the 24 August 2026 KEV listing and the 72 hour federal window.

[+] Oracle Exposure: Sector agnostic wherever Fusion Middleware proxy components 12.2.1.4.0, 14.1.1.0.0, or 14.1.2.0.0 remain unpatched.

[+] UAT-10147 Attack Progression: Initial access uses one day RCEs in Zimbra, AjaxPro, Nacos, and Telerik UI, including Metasploit built exploits and ysoserial ViewState deserialization. Nacos abuse uses ScriptEngineFactory SPI to spawn shells through Runtime.exec(). On Windows, batch scripts named back.bat use certutil to fetch EfsPotato, a follow on script named bai.bat, and QuasarRAT disguised as svchosts.exe. The actor adds Defender exclusions on System32\inetsrv and SysWOW64\inetsrv and persists with scheduled tasks named like Google Chrome Start. On Linux a web shell is dropped first, then escalated with CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, or CVE-2022-0847, then NoodleRAT, SPECTRE, or Meterpreter.

[+] UAT-10147 Campaign Indicators: A staging host at 139.180.197[.]150 served an open directory with about 170000 target URLs, tooling, and a secondary web shell on port 54321. Payload distribution used adminapi.tippusoni[.]in for dll.zip and user.bat. Callbacks blended into webhook[.]site. DLL names followed a randomized [10 digits].[7 digits].dll pattern. ViewState success presented as HTTP 500 with InvalidCastException.

[+] UAT-10147 Actor and Exposure: Chinese speaking, financially motivated, not described as state sponsored in consulted sources. Victims in government, education, media, technology, and gaming across Brazil, Bolivia, China, Canada, and Vietnam. Four 26 August KEV listings trace to this campaign.

[+] SQL Server and Linux KEV Set: CVE-2019-1068 is confirmed exploited and due 29 August 2026 for federal civilian entities. The 2026 exploitation method was not published. The Linux local privilege escalation set is the UAT-10147 escalation ladder and is due 9 September 2026.

[+] ATF and Qilin Picture: Qilin listed ATF on 26 August 2026. ATF confirmed a major incident on a standalone system and did not name an actor. No technical intrusion vector or indicator set was published. Treat this as a federal breach claim under attribution, not as confirmed Qilin tradecraft.

[+] Cross Incident Pattern: NetScaler, Gitea, and Oracle all bypass or collapse authentication through input handling flaws and yield immediate privileged effect on edge or operational tooling. UAT-10147 is different in kind: it industrially recycles old public exploits and now wraps that recycling in agentic AI guidance, automated ViewState tooling, and QA style payload checks. The ATF event is a disclosure and segmentation data point, not a third technical exploit chain.

Chapter 03 - Operational Response

Organizations must raise perimeter appliances, source control portals, middleware proxies, and internet facing web servers into an elevated defensive posture now.

[+] NetScaler Do This Now: Inspect perimeter gateway firewall logs and appliance syslog for unauthenticated crash loops, abnormal nsppe segmentation faults, PrefixList anomalies, and newly created x.php or z.php files.

[+] NetScaler Do This Within 24 Hours: Apply vendor firmware across standalone, HA pairs, and VPX/MPX/SDX form factors. Upgrade 14.1 to 14.1-72.61 or later, 13.1 to 13.1-63.18 or later, and FIPS or NDcPP builds to 14.1-72.61 FIPS or 13.1-37.272 FIPS/NDcPP. Federal civilian deadline is 29 August 2026.

[+] NetScaler Hardening: Restrict NSIP/CLIP management to out of band management subnets with strict ACLs. Audit /var/vpn/, /netscaler/ns_gui/, and /flash/ for new .php, .sh, .cgi, or binary artifacts. SOC must alert on abnormal SAML payload strings. Incident response must be notified on unprompted restarts or memory dumps.

[+] Gitea Do This Now: Disable open public registration in app.ini with DISABLE_REGISTRATION = true under the [service] section.

[+] Gitea Do This Within 24 Hours: Upgrade all self hosted deployments to 1.27.1 or later. Place instances behind enterprise SSO or corporate VPN so untrusted clients cannot reach /api/v1/ endpoints.

[+] Gitea Hardening: Audit $GITEA_CUSTOM/data/gitea-repositories///hooks/ for unauthorized pre-receive, update, or post-receive scripts. Revoke write permissions for unverified accounts created in the last 30 days. Run the daemon as a non privileged git account with nologin where feasible. Watch process lineage from gitea into /bin/sh, /bin/bash, or cmd.exe. Coordinate DevOps restarts with application security.

[+] Oracle Do This Now: Identify HTTP Server and WebLogic Server Proxy Plug in versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0 (Apache) and 12.2.1.4.0 (IIS). Apply the January 2026 Critical Patch Update inside the 72 hour BOD 26-04 window that started 24 August 2026.

[+] SQL Server Do This Now: Confirm patch status for CVE-2019-1068 against the 29 August 2026 federal deadline.

[+] Linux Escalation Set This Cycle: Treat CVE-2022-0995, CVE-2015-5287, CVE-2015-3246, and CVE-2021-23758 as a 9 September 2026 federal deadline and prioritize internet exposed Linux web servers that match UAT-10147 victimology.

[+] UAT-10147 This Week: Audit ASP.NET MachineKey ValidationKey and DecryptionKey exposure, including material recoverable by tools such as badsecrets. Review Defender exclusion paths targeting System32\inetsrv and SysWOW64\inetsrv. Audit scheduled tasks that mimic Google Chrome Start or other benign browser names. Alert on certutil -urlcache -split -f downloads and on HTTP 500 responses containing InvalidCastException from ASP.NET apps.

[+] ATF Pattern This Week: Federal and regulated entities should review third party and isolated system segmentation. The disclosed standalone system reduced blast radius even while actor naming stayed unconfirmed.

[+] Defender Priority Order: CVE-2026-8452 first because it is unauthenticated root on the enterprise boundary. CVE-2026-21962 second because of CVSS 10.0 and the 72 hour clock. CVE-2026-60004 third because open registration turns source control into a command execution host. CVE-2019-1068 and the UAT-10147 Linux set next. ATF monitoring last as a governance and segmentation action, not as a patchable CVE.

[+] Follow Up Gaps: Full UAT-10147 hash and domain lists were referenced but not retrieved. Exact NetScaler attacker IPs were not published. Qilin's ATF vector remains undisclosed.

[+] Early 2026: UAT-10147 campaign activity begins. Exact date was not disclosed.

[+] 2026-06-30: Cloud Software Group releases CTX696604 and discloses CVE-2026-8452 as a memory overflow leading to denial of service.

[+] 2026-07-29: Gitea releases 1.27.1, patching CVE-2026-60004 after coordinated disclosure.

[+] 2026-08-14: watchTowr Labs publishes analysis showing CVE-2026-8452 yields unauthenticated root execution, not only denial of service.

[+] 2026-08-15: JPCERT/CC alerts on unauthenticated remote code execution in NetScaler ADC and Gateway. The 12 day window of 36 NetScaler exploitation attempts begins around this date.

[+] 2026-08-20 to 2026-08-21: Consulted sources publish the UAT-10147 campaign analysis, including the exposed open directory and the 170000 URL target list.

[+] 2026-08-24: CISA adds CVE-2026-21962 to KEV and issues the 72 hour federal remediation window.

[+] 2026-08-25: Telemetry identifies active Gitea /diffpatch exploitation against exposed instances.

[+] 2026-08-26: CISA adds CVE-2026-8452, CVE-2026-60004, CVE-2019-1068, CVE-2022-0995, CVE-2015-5287, CVE-2015-3246, and CVE-2021-23758 to KEV. NetScaler and SQL Server federal deadline is set at 29 August 2026. Linux set deadline is set at 9 September 2026. Qilin lists ATF. ATF confirms a major incident on a standalone system.

[+] 2026-08-27: Active NetScaler telemetry continues to show web shell deployment. Automated Gitea exploitation scripts target open registration portals. Trade press coverage of the KEV wave and the ATF disclosure lands inside this reporting window.

Chapter 04 - Detection Intelligence

[+] NetScaler Attack Vector: Network, unauthenticated, remote over TCP/443 against Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server configurations.

[+] NetScaler Exploitation Mechanism: The flaw lives in SAML XML parsing during SignedInfo canonicalization. A long or malformed PrefixList string causes an off by boundary heap overflow that overwrites adjacent nsb chunk metadata. A later memcpy uses the corrupted pointers and yields a write what where primitive that hijacks control flow inside nsppe.

[+] NetScaler Observed Behavior: In memory root shellcode without a standard interactive login, then stealth web shells in web accessible directories, including x.php and z.php, plus id and echo style discovery.

[+] NetScaler Affected Builds: ADC and Gateway 14.1 before 14.1-72.61, 13.1 before 13.1-63.18, 14.1 FIPS before 14.1-72.61, and 13.1 FIPS/NDcPP before 13.1-37.272.

[+] NetScaler Scoring and Patch: CVSS 3.1 9.8 and CVSS 4.0 8.8 with vector AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:L/SI:L/SA:L on v4.0. Patched in 14.1-72.61 and 13.1-63.18 and the matching FIPS builds.

[+] Gitea Attack Vector: Network. Authenticated through low privilege repository write or through a self registered user that immediately receives that write.

[+] Gitea Exploitation Mechanism: /api/v1/repos/{owner}/{repo}/diffpatch accepts user submitted Git patch sequences. Insufficient validation of patch metadata and directory traversal during staging lets the attacker write directly into .git/hooks/.

[+] Gitea Observed Behavior: An executable lands in pre-receive, update, or post-receive. The next internal Git transaction runs the hook under the gitea daemon UID/GID.

[+] Gitea Affected Versions: 1.17 through 1.27.0. Patched in 1.27.1. CVSS 3.1 9.8.

[+] Oracle Attack Vector: Network, unauthenticated, low complexity against Oracle HTTP Server and WebLogic Server Proxy Plug in.

[+] Oracle Exploitation Mechanism: Consulted sources describe unauthorized create, delete, or modify of critical data, or full read access, with NVD scope change scoring. The specific in the wild exploit sequence was not published.

[+] Oracle Affected Versions: Apache proxy plug in 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. IIS variant 12.2.1.4.0 only. Patched in the January 2026 Critical Patch Update. CVSS 3.1 10.0.

[+] UAT-10147 Windows Chain: RCE through one day web app flaws, then back.bat, certutil retrieval of EfsPotato and QuasarRAT as svchosts.exe, PowerShell or Registry Defender exclusions on inetsrv paths, rogue local administrator creation via user.bat, and scheduled task persistence under browser themed names.

[+] UAT-10147 Linux Chain: Web shell, then local privilege escalation through CVE-2022-0995, CVE-2021-3156 Baron Samedit, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, or CVE-2022-0847 Dirty Pipe, then NoodleRAT, SPECTRE, or Meterpreter.

[+] UAT-10147 Tooling Character: Known public exploits are chosen for reliability over novelty. Agentic AI is used to generate exploitation guides, automate ViewState RCE, and QA test payloads before deployment. ViewState success is an HTTP 500 plus InvalidCastException, a signal many pipelines discard as generic 5xx noise.


Type: CVE ID
Value: CVE-2026-8452
Threat / Context: Citrix NetScaler ADC and Gateway pre authentication heap overflow RCE
Confidence: High

Type: CVE ID
Value: CVE-2026-60004
Threat / Context: Gitea diffpatch API Git hook injection RCE
Confidence: High

Type: CVE ID
Value: CVE-2026-21962
Threat / Context: Oracle HTTP Server and WebLogic Server Proxy Plug in unauthenticated data compromise
Confidence: High

Type: CVE ID
Value: CVE-2019-1068
Threat / Context: Microsoft SQL Server RCE added to KEV
Confidence: High

Type: CVE ID
Value: CVE-2022-0995, CVE-2015-5287, CVE-2015-3246, CVE-2021-23758
Threat / Context: Linux local privilege escalation set used in UAT-10147 and added to KEV
Confidence: High

Type: CVE ID
Value: CVE-2022-27925, CVE-2021-23758, CVE-2021-29441, CVE-2021-29442, CVE-2019-18935
Threat / Context: UAT-10147 initial access one day RCE set
Confidence: High

Type: CVE ID
Value: CVE-2021-3156, CVE-2010-3904, CVE-2022-0847
Threat / Context: Additional Linux local privilege escalation chain used by UAT-10147
Confidence: High

Type: URL
Value: /vpn/index.html
Threat / Context: Targeted NetScaler Gateway authentication endpoint
Confidence: High

Type: URL
Value: /logon/LogonPoint/index.html
Threat / Context: Targeted NetScaler AAA virtual server endpoint
Confidence: High

Type: URL
Value: /api/v1/repos/*/*/diffpatch
Threat / Context: Targeted Gitea vulnerability ingestion URI
Confidence: High

Type: URL
Value: /api/v1/user/sign_up
Threat / Context: Public self registration endpoint abused for unauthorized account creation
Confidence: High

Type: IP Address
Value: 139.180.197[.]150
Threat / Context: UAT-10147 C2 and staging server that hosted the exposed open directory and a secondary web shell on port 54321
Confidence: Pending enrichment

Type: Domain
Value: adminapi.tippusoni[.]in
Threat / Context: Distribution host for BadIIS payload dll.zip and secondary batch script user.bat via certutil
Confidence: Pending enrichment

Type: Domain
Value: webhook[.]

[+] NetScaler Infrastructure Attribution: Exact attacker IP values were not published. Only country level geolocation for 12 unique sources is confirmed. Adversaries routed malicious SAML requests through distributed VPS providers and compromised residential proxies.

[+] UAT-10147 Infrastructure Patterns: Reuse of a single staging IP for malware hosting and secondary web shell delivery. Randomized reverse shell DLL names matching [10 digits].[7 digits].dll. No cross incident infrastructure overlap with the ATF claim or with the unnamed NetScaler and Gitea exploiters was documented in consulted sources.

[+] ATF and Qilin Indicators: No IPs, domains, or hashes were publicly disclosed for that incident before this window closed.

[+] NetScaler Detection Opportunity: Alert on unexpected PHP or CGI file creation in appliance web roots, especially generic two character names such as x.php and z.php. Alert on outbound connections from management interfaces right after inbound Gateway or AAA requests from previously unseen sources. Hunt the roughly 15 to 27 August 2026 window for anomalous POSTs to those endpoints from geographies with no prior traffic history.

[+] Gitea Detection Opportunity: Alert on shell, Python, curl, wget, or netcat children of the gitea parent. Alert on file creation inside repository hooks directories. Alert on registration bursts followed immediately by repository creation and /diffpatch posts from non internal networks.

[+] UAT-10147 Detection Opportunity: Alert on certutil -urlcache -split -f remote downloads. Alert on PowerShell Add-MpPreference -ExclusionPath against inetsrv paths. Alert on scheduled tasks named Google Chrome Start or similar mismatched browser names at SYSTEM. Alert on HTTP 500 responses containing InvalidCastException from ASP.NET apps, which consulted sources flag as a ViewState deserialization success condition that most 5xx filters discard. Alert on w3wp.exe spawning cmd.exe, powershell.exe, or appcmd.exe. Flag outbound HTTPS from web servers to webhook[.]site.

[+] ATF Detection Opportunity: No incident specific technical detection is possible without a disclosed vector or indicator set. General ransomware hygiene still applies: segmentation validation, immutable backups, and credential rotation on isolated systems.

[+] SIGMA Rule 1: Suspicious child process spawned by the Gitea service.


[+] SIGMA Rule 2: Web shell creation or modification on a Citrix NetScaler appliance.


[+] YARA Rule: Gitea hook planting payloads in diff streams.


[+] Splunk Logic: NetScaler crash, core dump, and PrefixList monitoring.

index=netscaler sourcetype="citrix:netscaler:syslog" 
(message="*crash*" OR message="*segfault*" OR message="*nsppe*

[+] Elasticsearch KQL: Gitea diffpatch anomaly from non RFC1918 clients.

http.request.method: "POST" and url.path: *diffpatch*

[+] SIEM Pseudocode: NetScaler web shell drop.

event.category == "web" AND
url.path MATCHES "/.*\.

[+] SIEM Pseudocode: UAT-10147 certutil, Defender exclusion, and task masquerade.


[+] Immediate 24 Hour Detection Actions: Deploy the NetScaler PHP write rule, the Gitea child process rule, the certutil LOLBIN alert, and the inetsrv Defender exclusion alert on all internet facing Windows web servers and exposed Git or Gateway estates.

[+] Hunt This Week: Review NetScaler access logs for the 12 day exploitation window. Review scheduled tasks and Defender exclusion changes on IIS hosts for the last 90 days against change management. Search Gitea audit logs for new accounts that immediately called diffpatch.

Mentioned techniques apply to NetScaler and Gitea. Inferred techniques apply to UAT-10147 behavior described by consulted sources and are not treated as source confirmed ATT&CK IDs.

[+] T1190 Exploit Public Facing Application, Mentioned and Inferred: Initial Access. NetScaler receives crafted SAML XML on internet exposed ADC or Gateway virtual servers. Gitea receives crafted patches on exposed API ports. UAT-10147 uses internet exposed Zimbra, AjaxPro, Nacos, Telerik, and Oracle proxy surfaces. Detection: oversized PrefixList strings, /diffpatch posts after new registrations, and one day web app exploit traffic. D3FEND: D3-INP Inbound Network Traffic Filtering and D3-UAC User Account Authentication Verification.

[+] T1068 Exploitation for Privilege Escalation, Mentioned and Inferred: Privilege Escalation. NetScaler heap overflow runs as root inside nsppe. UAT-10147 uses EfsPotato on Windows and Dirty Pipe, Baron Samedit, ABRT, and libuser flaws on Linux. Detection: nsppe crashes and core dumps, plus local exploit tool retrieval after web shell drop. D3FEND: D3-PSA Process Segment Architecture Hardening.

[+] T1078 Valid Accounts, Mentioned: Initial Access and Persistence. Gitea open registration creates legitimate looking users with repository write. Detection: rapid account creation followed by repository creation and API patch submission. D3FEND: D3-UAR User Access Revocation and D3-DAA Disable Account Access.

[+] T1059.004 Unix Shell, Mentioned: Execution. Planted Git hooks run /bin/sh or /bin/bash as the Gitea user. Detection: EDR process telemetry with gitea as parent. D3FEND: D3-PEA Process Execution Analysis.

[+] T1059.001 and T1059.003 PowerShell and Windows Command Shell, Inferred: Execution. UAT-10147 uses PowerShell and batch files named back.bat, bai.bat, and user.bat for staging and Defender tampering. Detection: script block logging and anomalous children of w3wp.exe. D3FEND: D3-PEA Process Execution Analysis.

[+] T1505.003 Web Shell, Mentioned: Persistence. NetScaler drops x.php and z.php in web roots. Gitea plants hook scripts. UAT-10147 drops web shells before Linux escalation. Detection: file integrity monitoring on web roots and hooks directories. D3FEND: D3-FIM File Integrity Monitoring.

[+] T1053.005 Scheduled Task, Inferred: Persistence. Tasks disguised as Google Chrome Start run at highest privileges. Detection: Event ID 4698 on mismatched browser themed task names. D3FEND: D3-SCF Scheduled Task/Job Analysis.

[+] T1562.001 Impair Defenses, Inferred: Defense Evasion. PowerShell and Registry changes add Defender exclusions for inetsrv paths. Detection: Event ID 4104 and exclusion audit logs. D3FEND: D3-PSA Process Spawn Analysis.

[+] T1136 Create Account, Inferred: Persistence. user.bat creates a rogue local administrator with RDP. Detection: new local admin accounts outside change control.

[+] T1071.001 Web Protocols, Inferred: Command and Control. HTTP and HTTPS C2, including webhook[.]site callbacks. Detection: outbound web protocol anomalies from web servers to generic webhook SaaS.

[+] T1027 Obfuscated Files or Information, Inferred: Defense Evasion. Base64 encoded PowerShell (powershell -nop -enc) and randomized [10 digits].[7 digits].dll names. Detection: D3-FCA File Content Analysis on those naming patterns.

Chapter 05 - Governance, Risk & Compliance

[+] NetScaler Regulatory Exposure: SEC Item 1.05 Form 8-K, EU NIS2 Article 21 and 24 hour early warning, GDPR Article 33, HIPAA Security Rule, PCI-DSS v4.0 Requirement 6.3.3, and Binding Operational Directive 26-04 with a 29 August 2026 federal deadline. Unauthorized perimeter access and credential compromise can trigger 72 hour GDPR supervisory notice and 24 hour NIS2 preliminary reporting. Preserve firewall logs, core crash dumps, web access logs, and memory images before reboot or patch.

[+] NetScaler Business Impact: Operational risk is disruption of secure remote access and emergency downtime on HA gateway clusters. Reputational risk is severe if lateral movement becomes customer data theft. Financial risk is GDPR or NIS2 penalties plus incident response and forensic cost. Actor naming remains Under Attribution. CISO decision is ESCALATE: emergency patch all edge gateway assets within 24 hours and verify exposure with external attack surface scans.

[+] Gitea Regulatory Exposure: SOC 2 Type II CC6.8 and CC7.1, ISO/IEC 27001:2022 Control A.8.8, NIST SP 800-53 SI-2, and EU NIS2 supply chain security requirements. If customer code containing PII or credentials is exposed, notify legal and privacy officers. Preserve Git history, audit logs, hooks directories, and auditd output.

[+] Gitea Business Impact: Operational risk is source integrity loss, backdoored builds, and CI/CD contamination. Reputational risk is downstream supply chain liability. Financial risk is intellectual property loss, litigation, and code audit expense. Actor naming remains Under Attribution. CISO decision is ESCALATE: lock public registration and force 1.27.1 or later across internal and public Git servers.

[+] Oracle SQL and Linux KEV Regulatory Exposure: BOD 26-04. CVE-2026-21962 carries the 72 hour window from 24 August 2026, described as the shortest permitted window. CVE-2019-1068 is due 29 August 2026. Remaining Linux additions are due 9 September 2026. Private sector entities in financial services and healthcare should treat KEV listing as a de facto compliance trigger under frameworks that reference the catalog, including PCI-DSS vulnerability management and NIS2 aligned duties. No sector specific regulator guidance tied to these exact CVEs was published in consulted sources.

[+] Oracle SQL and Linux Business Impact: NetScaler and Oracle proxy compromise threatens remote access and middleware data integrity. UAT-10147 victims include government and education estates with disclosure duties. Remediation cost and fine estimates were not published. UAT-10147 is attributed with moderate to high confidence as Chinese speaking and financially motivated, not state sponsored.

[+] ATF Regulatory Exposure: FISMA reporting to CISA and OMB applies. DOJ joint investigation matches federal breach protocol. Public individual notification thresholds are unconfirmed because exfiltration is unconfirmed.

[+] ATF Business Impact: Operational risk is limited by the standalone system statement. Reputational risk is elevated as at least the third U.S. federal agency disclosure in 2026 after FBI in March and DHS/HSIN in July. Financial figures were not published. Actor naming stays Under Attribution.

[+] Board Level Risk Summary: Critical flaws in edge gateways, source control, and middleware are under active automated exploitation. A separate campaign is industrializing old web server exploits with agentic AI. A federal standalone system incident is confirmed without a named actor. Defensive upgrades, registration lockdowns, and isolated system reviews are the control agenda for this window.

Chapter 06 - Adversary Emulation

Scope is defensive verification only. No exploitation code and no functional proof of concept are provided.

[+] NetScaler Detection Validation: Replay non destructive SAML requests with an oversized PrefixList against a staging appliance in an isolated harness. Expected detection is WAF or IDS on malformed SAML canonicalization plus syslog parsing errors or buffer warnings. Failure signal is a crash or silent accept with no IDS, WAF, or syslog event.

[+] NetScaler Purple Team Suggestions: From an isolated gateway staging node, simulate lateral movement toward internal mock services to test microsegmentation and east west EDR tripwires. Test forensic collection on FreeBSD and NetScaler CLIs to validate log forwarding. In a non production affected build, validate detection of a benign test write matching the x.php or z.php pattern and of subsequent id or echo equivalent execution.

[+] NetScaler ATT&CK Aligned Test: For T1190, verify external scanners flag unpatched firmware without triggering destabilizing memory faults. Focus is defensive verification, not offensive exploitation.

[+] Gitea Detection Validation: On an isolated test instance, submit a benign patch via /diffpatch that writes a harmless canary into .git/hooks/. Expected detection is EDR on file creation by the Gitea process and on child execution from the service account. Failure signal is hook execution with no process tree alert.

[+] Gitea Purple Team Suggestions: Verify CI/CD service account privileges so developers and low privilege accounts cannot write server hook directories. Validate alerts on sudden public registration spikes.

[+] Gitea ATT&CK Aligned Test: For T1059.004, run a controlled script from a designated non privileged service account and verify SIEM process lineage detection. Focus is defensive verification, not offensive exploitation.

[+] UAT-10147 Emulation Scope: In lab only, use a deliberately outdated Telerik UI or AjaxPro instance to validate detection of exploitation attempts corresponding to CVE-2019-18935 or CVE-2021-23758 without live wild exploit code. Script a Defender exclusion addition against inetsrv paths to validate the SIEM rule. Create a scheduled task with a misleading browser themed name to validate Event ID 4698 coverage. Send benign non sensitive test payloads from a lab web server to a controlled webhook style endpoint to validate outbound web protocol anomaly detection.

[+] ATF Emulation Scope: No confirmed intrusion vector exists, so no meaningful incident specific emulation scenario can be built.

Intelligence Confidence80%

Score reflects official KEV confirmations, binding federal remediation mandates, national CERT alerts, and primary laboratory validation, offset by mixed actor attribution and unpublished indicator repositories.

Cluster

Score

Why

NetScaler CVE-2026-8452

90

KEV listing, federal deadline, multi source telemetry, laboratory weaponization

Gitea CVE-2026-60004

90

KEV listing, vendor patch, consistent exploitation mechanics

Oracle CVE-2026-21962

90

KEV listing, NVD CVSS 10.0, unambiguous 72 hour mandate

SQL and Linux KEV set

88

KEV listing and campaign linkage, thin public detail on 2026 SQL tradecraft

UAT-10147 campaign

68

Strong single laboratory forensic package, limited independent second primary confirmation, unpublished full IOC repo

ATF and Qilin claim

45

Agency confirms a major incident, actor naming is self reported and uncorroborated

Combined brief

80

Weighted toward KEV confirmed exploitation, pulled down by ATF attribution and incomplete UAT-10147 indicators