🚨 Exploit activity continues high over the weekend, with new recon activity on the horizon
1. A FortiSandbox endpoint (a VM-provisioning / VNC-start route that appears in none of the 2026 FortiSandbox advisories) saw attempted exploitation on our decoys - added to Defused Radar
2. First in-the-wild exploitation of the Citrix NetScaler pre-auth RCE from
@watchtowrcyber (CVE-2026-8452) hit Defused EX customer sensors Sunday morning. Public writeup was released on Friday
3. A multi-vendor edge-VPN enumeration sweep hit across our honeypot fleet - FortiGate, GlobalProtect, SonicWall, Citrix, Ivanti, Cisco - spraying product-specific login probes at every sensor. Activity originates from known malicious ASNs
Stay on top of acute exploit activity 👉
console.defusedcyber.com/sig…