Exploited by advanced and suspected state-sponsored threat actors
Assessment
Mandiant Consulting CTO Charles Carmakal wrote this on LinkedIn on 29 September 2026, and it has been repeated as attribution. It is a suspicion, stated as one: the word is 'suspected', no actor or country is named, and Google Threat Intelligence Group's own technical report published the next day makes no attribution at all. CISA, the Canadian Centre for Cyber Security, NCSC UK and NCSC-NL also attribute nothing. The tradecraft and sector mix are consistent with espionage, which Kevin Beaumont also asserts, but no body has published the basis for a state link.
Where this claim appeared
Charles Carmakal, Mandiant (LinkedIn) · 2026-09-29
https://www.linkedin.com/feed/update/urn:li:activity:7510702011294769152/What “Assessed, Not Confirmed” means
A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.
4 of 5 · rating scale
Assessed in
Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-88772: three weeks of exploitation before the patchThink this assessment is wrong? Report an error.