A zero-day in Citrix NetScaler’s SAML processing is being exploited in live attacks, taking authentication infrastructure offline. Denmark’s centralized national identity register lost 8.8 million records. Apple is moving to restrict AI agents from silently inheriting Full Disk Access. And a China-aligned actor is stealing MFA-protected sessions from AI policy researchers using adversary-in-the-middle phishing. Identity infrastructure - human and non-human - is the target surface today.
In the News
CVE-2026-88779: NetScaler SAML Zero-Day Exploited in Targeted Attacks
Citrix has released emergency patches for CVE-2026-88779, a memory overflow vulnerability in the SAML authentication processing path of NetScaler ADC and NetScaler Gateway. The flaw is scored CVSS 8.7 and is confirmed exploited in the wild.
The attack vector is specific: an attacker sends a crafted SAML assertion to the NetScaler appliance, triggering a memory overflow that crashes the SAML processing engine. The immediate impact is denial of service against the authentication infrastructure - every application relying on that NetScaler for SSO goes offline simultaneously. Researchers are investigating whether the memory corruption is exploitable for remote code execution, which would elevate this from a disruptive to a catastrophic finding.
For organizations using NetScaler as their SAML identity provider or service provider, this is a same-day patching priority. The SAML path is exposed to the internet by design - it has to be, for federated authentication to work. That makes pre-authentication exploitation trivial for any attacker who can reach the login endpoint.
What defenders should do: Apply the Citrix emergency patches immediately. If patching requires a maintenance window, consider temporarily disabling SAML authentication on affected appliances and falling back to alternative authentication methods. Monitor NetScaler logs for abnormal SAML assertion sizes or unexpected crashes in the SAML processing daemon.
Denmark’s National Population Register Breached - 8.8 Million Identity Records
Denmark’s central population register (CPR) - the identity database that underpins every government service from healthcare enrollment to tax filing - was compromised in an unauthorized access incident exposing 8.8 million identity records. The CPR stores national identification numbers, names, addresses, and citizenship data for the entire Danish population.
This is a single-point-of-failure failure mode. The CPR is not one system among many - it is the root of trust for Danish identity. Every downstream service that validates a citizen’s identity checks against the CPR. When the root of trust is compromised, every assertion it has ever made is suspect.
The breach also coincides with a separate incident at the Technical University of Denmark (DTU), where attackers breached the university’s IAM system and exfiltrated up to 200,000 identity records. Two Danish identity infrastructure breaches in the same reporting cycle is not coincidence - it is a pattern that suggests either shared infrastructure dependencies or a coordinated campaign.
What defenders should do: Any organization operating a centralized identity store should treat it as crown-jewel infrastructure with dedicated microsegmentation, privileged access monitoring, and continuous behavioral detection. The Denmark breach is the case study for why identity infrastructure needs its own threat model, separate from the applications it serves.
Apple Restricts macOS Full Disk Access Over AI Agent Data Hoarding
Apple is planning restrictions on macOS Full Disk Access permissions after identifying a pattern of AI agents abusing the entitlement to silently scrape email, messages, browser history, and local files. The change will require more granular consent for AI tools that request broad filesystem access.
The identity implication is direct: AI agents running on endpoints are inheriting the user’s full access scope without independent authorization. From an IAM perspective, every AI agent with Full Disk Access is a non-human identity (NHI) operating with the user’s privileges but without the user’s judgment about what should and should not be read. There is no access review, no scope limitation, and no audit trail specific to the agent’s activity.
Apple’s move validates what identity practitioners have been articulating for the past year - AI agent permissions are a new IAM layer that existing controls do not cover. The operating system is now stepping in where enterprise IAM programs have not.
What defenders should do: Inventory AI tools and agents running on managed endpoints. Assess what permissions they hold - Full Disk Access, Accessibility, Contacts, Calendar - and whether those permissions exceed the agent’s functional requirements. Treat AI agents as non-human identities in your IAM governance program: apply least-privilege, review access quarterly, and log agent activity separately from user activity.
TA419 Uses AitM Phishing to Steal MFA-Protected Sessions from AI Researchers
A China-aligned threat actor tracked as TA419 is phishing US AI policymakers and think-tank researchers by impersonating Anthropic staff and prominent economists. The campaign uses adversary-in-the-middle (AitM) infrastructure to proxy Microsoft authentication in real time, capturing session tokens after MFA completes.
The technique is not novel - AitM phishing has been operational since at least 2022 - but the targeting is notable. TA419 is specifically pursuing individuals involved in AI policy, suggesting an intelligence collection mission focused on understanding Western AI governance frameworks. The impersonation of Anthropic employees adds social engineering credibility that generic phishing cannot achieve.
Traditional MFA - push notifications, SMS codes, TOTP - does not defend against AitM phishing. The attacker sits between the user and the legitimate Microsoft login page, relaying credentials and MFA tokens in real time. The only authentication method that defeats this technique is phishing-resistant passwordless authentication using FIDO2/WebAuthn, where the cryptographic assertion is bound to the legitimate domain origin. The phishing proxy cannot replicate the domain binding, and the authentication fails.
What defenders should do: Enroll high-value users - executives, policy staff, anyone with access to sensitive strategic information - in FIDO2 passwordless authentication. Deploy identity threat detection to identify token replay and anomalous session creation. Treat AitM as a known, active technique and brief users that completing MFA successfully does not mean the session is safe.
Defender Action Items
- Patch CVE-2026-88779 on NetScaler ADC/Gateway today. If you run SAML on NetScaler, the exploit is active. If patching requires a window, disable SAML temporarily and fall back to alternative auth.
- Patch CVE-2026-63688 on Dell CSM. CVSS 10.0 - unauthenticated admin and root access via gRPC. Any Dell storage in Kubernetes is exposed.
- Enroll high-value users in FIDO2 passwordless authentication. TA419’s AitM campaign proves again that traditional MFA does not stop session theft through phishing proxies.
- Audit AI agent permissions on managed endpoints. Inventory Full Disk Access, Accessibility, and other broad entitlements granted to AI tools. Apply least-privilege.
- Treat centralized identity stores as crown-jewel infrastructure. Microsegment, monitor privileged access, deploy behavioral detection. The Denmark CPR breach is the case study.
Detection Queries
NetScaler SAML crash detection - look for abnormal SAML assertion processing failures that may indicate CVE-2026-88779 exploitation attempts. This Splunk SPL query surfaces SAML processing errors and crashes on NetScaler appliances:
index=netscaler sourcetype=ns:syslog
("SAML" AND ("core dumped" OR "memory" OR "overflow" OR "assertion" OR "crash"))
| stats count by _time, src_ip, ns_vpn_vserver
| where count > 5
| sort -_time
For AitM session theft detection, this KQL query for Microsoft Sentinel identifies sign-ins where the session token was created from a different IP than the interactive authentication:
SigninLogs
| where TimeGenerated > ago(24h)
| where ResultType == 0
| extend AuthIP = IPAddress
| join kind=inner (
AADNonInteractiveUserSignInLogs
| where TimeGenerated > ago(24h)
| extend SessionIP = IPAddress
) on CorrelationId
| where AuthIP != SessionIP
| project TimeGenerated, UserPrincipalName, AuthIP, SessionIP, AppDisplayName, CorrelationId
This catches the signature AitM pattern: the user authenticates from one IP (the phishing proxy), but the stolen session token is replayed from a different IP (the attacker’s infrastructure).
References
- Citrix patches NetScaler SAML zero-day exploited in attacks - BleepingComputer
- Denmark breach: national population register cyberattack - The Record (Recorded Future)
- Apple plans tighter macOS Full Disk Access controls - The Hacker News
- China-aligned TA419 targets US AI policy experts - The Hacker News
- Dell CSM flaws enable unauthenticated admin access - The Hacker News
- DTU breach exposes data of up to 200,000 people - BleepingComputer
- Attackers target Rejetto HFS flaw for admin session forgery - The Hacker News
- GitLab patches critical self-hosted AI Gateway RCE - The Hacker News
Related Briefs
- NetScaler SAML Zero-Day CVE-2026-88779 Exploited
- Microsoft X Account Hijacked - Identity Gaps Exposed
- FortiMail Zero-Day CVE-2026-104286 Exploited
- Cisco SD-WAN Zero-Day CVE-2026-76504 Exploited
- Entra ID Script Injection Blocked - October Rollout
Subscribe to The Identity Brief
Get The Identity Brief in your inbox (Mon/Wed/Fri) - Human, machine, and AI identity security — NHI, ITDR, and the IAM market.