started · updated
Cybersecurity threats target AI users and Citrix NetScaler systems
Cybersecurity researchers have identified two distinct digital threats targeting users and enterprise infrastructure.
First, a malware strain known as RevStealer is being distributed via a fraudulent desktop application named ‘Claude Opus 5 Free Desktop’. This fake app masquerades as a free version of Anthropic’s Claude AI assistant to lure Windows users. Once installed, the malware attempts to steal passwords, browser cookies, VPN data, and information from over 50 different cryptocurrency wallets. To evade detection, the software checks for signs of virtual testing environments and aborts its activity if it suspects it is being analyzed by security researchers.
Separately, a critical authentication bypass vulnerability (CVE-2026-19490) in Citrix NetScaler is being actively exploited. The vulnerability allows unauthenticated attackers to gain access to systems configured as Gateways, AAA virtual servers, or SAML Identity Providers. Because NetScaler is frequently used to provide remote access to corporate applications and intranets, a compromise could grant attackers significant access to internal business environments. Citrix released a security update on August 19 to address the flaw.
Entities
Anthropic · Centre for Cybersecurity Belgium · Citrix · Citrix NetScaler · Morphisec