The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

Citrix NetScaler security snafus get even worse amid more 0-day reports

The attackers just keep coming after Citrix NetScaler appliances, as both the feds and private security researchers warn that someone found - and has already exploited - yet another Citrix bug before it had a patch. This latest vulnerability, tracked as CVE-2026-88779, is a memory overflow bug that leads to denial of service attacks. It only affects NetScaler ADC and Gateway appliances configured as a SAML (Security Assertion Markup Language) service provider or identity provider, used for single sign-on authentication. Late Friday, amid exploitation reports, Citrix confirmed that it was investigating a “newly observed issue related to SAML authentication in customer-managed NetScaler deployments.” By Saturday night, the vendor released a security advisory for NetScaler ADC and NetScaler Gateway with patches, urging vulnerable customers to “install the relevant updated versions as soon as possible.” Citrix also posted a blog about the vulnerability, confirming that it has observed targeted attacks on unmitigated NetScaler deployments that can lead to denial of service. Citrix did not answer our questions about CVE-2026-88779 - including how many instances have been affected and what attackers are doing after exploiting the bug - but urged customers to "quickly apply" the fix to NetScaler instances. "We were recently alerted to a new issue that affects service availability for some NetScaler deployments," a Citrix spokesperson told The Register. "After we were alerted to this issue we immediately developed and published a mitigation while concurrently developing, testing and deploying a fix." On Sunday, the US Cybersecurity and Infrastructure Security Agency (CISA) confirmed CVE-2026-88779 was under active exploitation and ordered federal agencies to patch the bug by Wednesday. While the new vulnerability is not technically related to the earlier eight CVEs finally disclosed by Citrix on September 27 - weeks after miscreants began abusing two of these security holes (CVE-2026-88772 and CVE-2026-88771) - watchTowr researchers told us they suspect it has been used to purposefully crash machines, making exploitation of CVE-2026-88771 faster. “This vulnerability is incredibly simple to trigger, with a single specially crafted request being all that is needed to knock an appliance offline,” watchTowr’s head of threat intelligence, Jake Knott, told The Register. “Exploitation is already occurring in the wild, and disrupting an authentication gateway can prevent legitimate users from accessing the services behind it.” WatchTowr reproduced the vulnerability on Friday, and Citrix credited the attack-surface management company along with Bishop Fox with helping it address the issue. “Citrix provides an indicator-of-compromise script that teams can run to check exposed appliances for signs of compromise, though a clean result is not definitive proof,” Knott said. “Security teams should prioritize appliances configured as a Gateway or AAA virtual server with SAML authentication enabled, and affected organizations should apply the fixed build or Citrix’s interim mitigation if an immediate upgrade is not possible.”®

The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Mamardashvili saves penalty as Georgia hold Northern Ireland in Nations League

This game concluded with mutual irritation and a touch of chaos. It is an indicator of Northern Ireland’s progress that scoreless parity led to wincing from players, management and fans alike. Isaac Price’s 84th-minute missed opportunity from the penalty spot added to the sense of annoyance.

Michael O’Neill’s team are atop B2 after a window which, going by the players’s physical condition in the dying stages, has been exhausting. Northern Ireland and their youthful setup are a fascinating international story. They are a team on an upward curve, with standards elevated accordingly. O’Neill bemoaned “immaturity” in the second half, saying: “The disappointing thing is we have eight points instead of 10.”

Continue reading...

Conservatives propose £10bn ‘Britannia Shield’ inspired by Israel’s Iron Dome

Party to unveil plans for one of UK’s ‘most significant military programmes since the cold war’

The Conservatives will announce plans to build a £10bn British “Iron Dome” similar to Israel’s air and missile defence system, which the party will christen “Britannia Shield” in an announcement at conference on Tuesday.

The shadow defence secretary, James Cartlidge, will say Britain needs to be ready to defend itself from potential aerial attacks and that new investment was needed in advanced radar and interceptor missiles.

Continue reading...

Jeffrey Archer, former Conservative politician and novelist, dies aged 86

Lord Archer died peacefully at home between writing sessions, his publisher said

The author and former politician Jeffrey Archer has died aged 86.

Archer, who was a Conservative MP for five years before serving as the party’s deputy chairman, died peacefully at his home between writing sessions on Monday, his publisher Harper Collins said.

Continue reading...

London to Chicago BA flight declares emergency after dropping 28,000 feet

British Airways Boeing abruptly lost altitude over Ireland due to ‘technical issue’ and returned to Heathrow

A flight from London to Chicago declared an emergency after a sudden and steep descent of 28,000 feet over Ireland and was forced to turn back to Britain.

British Airways flight BA295 was bound for Chicago’s O’Hare airport but after a “technical issue” during which oxygen masks were deployed from the ceiling, the plane landed safely back at London Heathrow.

Continue reading...

Slashdot

News for nerds, stuff that matters

Mac Users Reclaim 12GB+ of Storage With Apple Intelligence Removal Tool

A new open-source command-line tool called RemoveMacAI lets macOS 27 users disable Apple Intelligence and reclaim around 12GB or more of storage. MacRumors reports: In macOS 27, Apple removed the toggle to disable Apple Intelligence wholesale, and simply disabling individual features doesn't remove the models from your Mac's drive. As explained by the developer, RemoveMacAI gets around this by using a configuration profile to switch off Apple's own asset management service and remove the models.

It then configures the system so attempts to download the removed models are redirected to a closed local port, preventing them from immediately coming back. And it does all this without disabling System Integrity Protection (SIP) or manually deleting files from protected system locations, unlike some older tools have. The tool can free up roughly 12GB of space depending on which models are present on your Mac. That said, some users are reporting cases of Apple Intelligence models having taken up a lot more space, which they've now reclaimed.

Read more of this story at Slashdot.

Wel.nl

Minder lezen, Meer weten.

Techbedrijven winnen op Wall Street

NEW YORK (ANP) - Techbedrijven hoorden maandag bij de winnaars op de aandelenbeurzen in New York. Het enthousiasme over techaandelen deed de zorgen over de nog altijd hoge olieprijzen en obligatierentes even naar de achtergrond verdwijnen.

De Dow-Jonesindex eindigde de handelsdag 0,2 procent hoger op 51.267,90 punten. De bredere S&P 500-index klom 0,7 procent naar 7773,95 punten. Techgraadmeter Nasdaq ging 1,1 procent vooruit tot 27.477,31 punten. Vrijdag noteerde de technologiebeurs ook al een plus van 1,2 procent.

Bij de winnaars hoorden onder meer SpaceX (plus 7,6 procent), het AI- en ruimtevaartbedrijf van Elon Musk, Meta (plus 1,9 procent) en Microsoft (plus 1,5 procent). Ook de belangrijke verkoper van AI-chips Nvidia eindigde hoger (plus 2,1 procent), evenals elektrische autofabrikant Tesla (plus 2,2 procent).

"Beleggers hebben genoeg om zich zorgen over te maken, maar de bedrijfswinsten blijven als tegenwicht dienen", zei marktstrateeg Mark Hackett tegen persbureau Bloomberg. "De relatieve rust op de aandelenmarkt midden in de 'perfecte storm' op de obligatiemarkt is begrijpelijk, gezien de versnellende economische groei en het feit dat de AI-hausse niet gevoelig is voor de rente", zei Lisa Shalett van Morgan Stanley Wealth Management op haar beurt.

Beleggers hebben hun aandacht deze week onder meer gericht op de notulen van de rentevergadering van de Federal Reserve van vorige maand, die woensdag naar buiten komen. Ook gaat het kwartaalcijferseizoen langzaam weer van start, met resultaten van onder meer PepsiCo en Levi Strauss.

Intel zakte 2,6 procent. Aandelen van het Amerikaanse chipbedrijf werden minder waard na nieuws over gesprekken over een mogelijke samenwerking tussen TSMC en Terafab, het chipfabriek-initiatief van Elon Musk. Intel had eerder ook gezegd een samenwerking aan te gaan met Terafab.

CH Robinson Worldwide verloor ruim een tiende van zijn beurswaarde. Het Amerikaanse transportbedrijf neemt vrachtbemiddelaar RXO over voor ongeveer 5,8 miljard dollar. De overname draait om de verwachting dat AI beide bedrijven efficiënter kan maken in een lastige vrachtmarkt. RXO ging in navolging van het nieuws juist 22,5 procent omhoog.


DNA Lounge: Wherein we return this blog to our core competency: plumbing disasters

We had a leak in the main men's room by the urinals. It turns out that one of the urinals has some kind of internal leak, and it's a spot-welded mess, so we weren't able to get in there with any kind of sealant. It probably has to be replaced. And, in the intervening two decades, it turns out that these urinals have become unobtainium. While the model shows up in some catalogs, you can't actually get them. Someone theorized that it may be because of newer water-conservation requirements; who knows.

This makes me sad primarily because these urinals look exactly like Cybertrucks (vice versa, actually) and pissing on a stand-in for an Incel Camino brough me some amount of joy.

There don't seem to be any stainless steel urinals out in the world that aren't cheap junk, so I guess we'll have to go with porcelain this time, against my better judgment. TBD.

Anyway, having pulled that urinal, we were still getting a leak from somewhere. Oh. Well there's your problem:

See that growth in the pipe? It looks slimy but it's as hard as concrete. It is crystalized urine. It is rock candy made of piss!

The first plumber we called in told us that the pipe was done for and he wanted to tear up the entire floor to replace it out to who-knows-where. That would have been an $11,000 job even before repairing the floor. "Oh, you got your pipes wet, you see, you can't get them wet, now we'll have to amputate."

Second plumber said, "Nah, I'm gonna go at it with a hydrojet and an auger, I can probably break that up." And he did! So getting rid of our piss crystals was "only" a $1,200 job.

Back in the 90s there was this disgusting cinnamon liqueur called Aftershock: it was kind of like Fireball, but the gimick was that it had rock candy in the bottom of the bottle. Anyway, someone left a bottle of this crap at my house once, and it sat in my cabinet for like a year at which point I realized that the entire bottle had turned to rock candy: there was no liquid left, just gross cinnamon sugar crystals.

Thinking of this for no reason in particular.

The Sound of Water Makes Her Dream

Thomas Hawk posted a photo:

The Sound of Water Makes Her Dream

Volume and Price

Thomas Hawk posted a photo:

Volume and Price