New Content & Platform Update
New CTI Lab: CVE-2026-88771 (NetScaler Log-to-Shell)
Release date: October, 6th, 2026
NetScaler ADC (Application Delivery Controller), made by Citrix, is a network appliance deployed at the edge of enterprise environments to manage load balancing, remote access, and VPN services for corporate users. Because it sits between the internet and internal systems, and often handles authentication for remote users, a compromised NetScaler appliance gives an attacker a direct window into the network and access to everything routed through it.
A critical unauthenticated remote code execution vulnerability (CVSS 9.8) was disclosed in NetScaler ADC and NetScaler Gateway in September 2026 and has since been confirmed as actively exploited. The exploit chain works by allowing an attacker to write a shell command into a system log through a failed login attempt, and a root-context background daemon executes it hours later.
In this lab, users will taking on the role of a SOC analyst investigating a suspected compromise, they'll work through real NetScaler log files to identify the attacker's actions, learning to recognize the indicators this attack leaves behind.
Who are we doing it for?
This lab is designed for SOC analysts, incident responders, and threat hunters responsible for monitoring network appliances and edge infrastructure, as well as anyone who performs log analysis or detection engineering for enterprise environments.
It's also highly valuable for any cybersecurity practitioner who wants to understand how enterprise network appliances can be weaponized through their own internal processes, and why delayed-execution attack chains demand a broader investigation window than most incidents.
Why are we doing it now?
NetScaler appliances are deeply embedded in enterprise networks worldwide, and CVE-2026-88771 requires no credentials, just a single request to the management interface. At a CVSS score of 9.8 and with active exploitation already confirmed, unpatched appliances represent an open door to the internal network.
We're delivering this lab now to equip defenders with the log analysis skills to spot this attack in progress, reconstruct what an attacker has done, and respond before a foothold becomes a full compromise.
Link to the lab: here
New Crisis Simulation: The Hex Files - A brew-tal-breach
Release date: October, 1st, 2026
Playing the Editor-in-Chief, IT Manager, Communications Manager, and Data Protection Officer, participants contain the intrusion, brief staff, work with the National Crime Agency, recover website and account access under time pressure, weigh a UK GDPR notification to the ICO, and make the call every newsroom dreads: publish the verified story under threat, or hold it.
Who are we doing it for?
- Incident responders and IT leads: containment, credential recovery, and sequencing recovery work when break-glass accounts are the only way back in.
- Communications and PR teams: internal staff briefing during a lockout and external messaging once a defacement is public.
- Legal, privacy, and executive leaders: the UK GDPR notification call on an exposed subscriber export, and a publish-or-hold decision under an active threat.
- Cross-functional crisis teams: the value here is the handoffs between all four seats under one clock.
New Crisis Simulation: The Hex Files - The Nightshade Incident
Release date: October, 1st, 2026
You step in as the new Head of Security Operations, then sit with the crisis management team as the picture widens: a second account leaking quietly, a regulator decision, a ransom demand, and a leaked-emails subplot, all while the release date holds firm and the share price moves. What you do early shapes how much of Nightshade, and how much else, ends up outside the building.
Who are we doing it for?
- Security operations and incident responders: triage sign-ins that no tool flagged, scope a compromise that turns out to span more than one account, and weigh restoring fast against preserving the evidence of how the attacker got in.
- Crisis management and executive teams: decide regulator timing, staff communications, and how to answer both a ransom and a public leak without trading away future leverage.
- Communications and cross-functional teams: practice holding a public line under press and social-media pressure while the facts are still landing.
It's Cyber Awareness Month, and this one leans into the season. The scenario rehearses a pattern that keeps showing up in real intrusions: attackers profile a remote worker on social media, phish a single account, and quietly open a second route that closing the first one never touches. It puts business and technical players in the same room to practice the decisions that decide how bad a ransomware incident gets, from how a trusted sign-off gets abused to whether you restore before you understand the way in.