ThreatPaper
Weak Evidence

More than 100 organizations already confirmed compromised

Assessment

The figure traces to Kevin Beaumont's Mastodon post of 28 September 2026, which says he is 'tracking over 100 victim orgs'. Beaumont has a strong record on edge-device incidents, but he published no method, no list and no definition of victim, and 'tracking' is not 'confirmed'. The vendors with incident-response visibility give smaller or vaguer numbers: Mandiant says 'dozens of impacted organizations', Rapid7 confirms two among its customers, and Arctic Wolf (via Cybersecurity Dive) says at least 78 were targeted. No affected organisation has been publicly named.

Where this claim appeared

Tech Times · 2026-09-30

https://www.techtimes.com/articles/328303/20260930/citrix-netscaler-zero-days-spread-mass-exploitation-patching-wont-remove-backdoors.htm

What “Weak Evidence” means

Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.

3 of 5 · rating scale

Assessed in

Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-88772: three weeks of exploitation before the patch

Think this assessment is wrong? Report an error.