Apple CoreGraphics Zero-Day, Bitget $387.5 Million Theft and NetScaler Backdoors Highlight Trusted-Tool Risks
A critical Apple CoreGraphics flaw triggered by malicious PDFs, a $387.5 million theft from Bitget via a third-party zero-day, and stealthy backdoors on Citrix NetScaler devices show attackers turning widely used software and security tools into entry points.
Recent disclosures about Apple devices, a major cryptocurrency exchange and enterprise networking gear point to the same problem: attackers are going after tools that users and administrators normally trust.
Apple has warned that a vulnerability in its CoreGraphics component, tracked as CVE‑2026‑86950, allows a malicious PDF to trigger controlled memory corruption. The company says the flaw may already have been used in targeted attacks. Security researchers have released the first public proof‑of‑concept exploit, making it easier for others to test and potentially weaponize the bug.
Because PDFs are a routine way to share documents, even between security‑conscious users, they offer an attractive delivery channel. Early analysis referenced in the reporting notes that checks on WhatsApp PDF traffic hint at a possible delivery path, though this remains unconfirmed. If attackers can get a booby‑trapped PDF opened on a vulnerable Apple device, they may gain a foothold without needing to bypass passwords or install traditional malware.
In a separate case, cryptocurrency exchange Bitget has confirmed that it lost $387.5 million after attackers exploited a zero‑day in a third‑party security product. According to analysis by incident responders at Mandiant, the intruders compromised security appliances, moved laterally into Bitget’s wallet environment, and then deployed malicious packages on the wallet job server to steal funds.
That sequence shows how a product intended to secure infrastructure can become the initial weakness. Once the attackers had control of the appliance, they used it as a launchpad into more sensitive systems that held digital assets.
Enterprises running Citrix NetScaler appliances face related concerns. Researchers following post‑exploitation activity report that attackers are using a second‑stage payload that quietly creates a superuser account and hides a PHP web shell behind URLs that resemble harmless CSS resources. The same Perl script collects configuration data for upload, changes permissions on /bin/sh, and deletes itself after execution.
Security specialists are also warning about the abuse of cloud identity flows. Demonstrations show how a single click on “Continue” when approving an OAuth application can give it wide access to a user’s mailbox, including the ability to read, exfiltrate and delete email, without installing malware or capturing a password.
Taken together, these incidents show how criminal and advanced attackers are putting more effort into exploiting widely deployed software, document formats and security appliances, rather than only targeting endpoints with obvious malicious files.
Signals to watch include emergency patches and guidance from Apple on CVE‑2026‑86950, updates or mitigations from the unnamed third‑party vendor involved in the Bitget breach, and fresh indicators of compromise for Citrix NetScaler deployments. How quickly organizations review access to OAuth apps and audit their perimeter security products will shape whether similar attacks succeed at scale.
Sources
- OSINT