The news
Security vendor risk moved up the agenda in late September 2026. Crypto exchange Bitget said an attacker got in through a flaw in a third-party security product, Citrix said two exploited gateway flaws needed urgent patching, and Kiteworks told customers to shut down servers.
Bitget detected unauthorized transfers from some hot wallets at 18:31 UTC on September 24, Bloomberg reported. On September 28, Bitget said the attacker had exploited a zero-day, a flaw with no fix available, in an unnamed third-party security product, according to The Hacker News. That flaw opened an internal management system to the attacker, who then planted bogus withdrawal orders that the exchange's wallet systems accepted as genuine.
The Hacker News put the theft at about $388 million; Bitget initially said $351.6 million was affected, Bloomberg reported. Chief executive Gracy Chen said user funds were safe and the loss was covered by the exchange's User Protection Fund, which holds more than $464 million. Bitget said it has alerted the product's maker, walled off the affected systems and replaced its internal credentials. Chen said in a livestream on X that the company suspects North Korea, Bloomberg reported. Blockchain analytics firm TRM Labs found overlaps with wallets tied to earlier North Korean thefts but made no firm attribution, The Hacker News reported.
Kiteworks, a provider of secure communication platforms formerly known as Accellion, on September 25 advised customers running self-managed systems on premises, in AWS or in Azure to shut them down for nine hours. It cited credible threat intelligence from federal intelligence authorities. The company lifted the recommendation on September 27 and told customers to run release 9.5.1, which it said addresses all known vulnerabilities.
Chief information security officer Frank Balonis said Kiteworks had no indication that its or customers' systems were compromised. SecurityWeek reported that the company found a severe vulnerability in its Advanced Forms data-collection product, which Kiteworks said is enabled for fewer than 1% of customers, under 50 organizations.
On September 27, Citrix published fixes for eight flaws in its NetScaler ADC and Gateway products and said exploits of two, CVE-2026-88771 and CVE-2026-88772, had been observed on unmitigated devices. Both carry a severity score of 9.5 out of 10. The US Cybersecurity and Infrastructure Security Agency (CISA) added both to its Known Exploited Vulnerabilities catalog. Shadowserver Foundation reported more than 20,000 instances exposed and potentially at risk, according to Cybersecurity Dive.
The numbers
- Bitget theft (The Hacker News)
- About $388 million
- Bitget's initial figure (Bloomberg)
- $351.6 million
- Bitget User Protection Fund (Bloomberg)
- More than $464 million
- Kiteworks recommended shutdown window
- 9 hours
- Kiteworks Advanced Forms users (company, via SecurityWeek)
- Fewer than 1% of customers; under 50 organizations
- NetScaler flaws patched / confirmed exploited (Citrix)
- 8 / 2
- NetScaler instances exposed (Shadowserver, via Cybersecurity Dive)
- More than 20,000
Why CEOs should care
For CISOs, vendor reviews often focus on software vendors that hold company data, while security, gateway and file-transfer products get treated as trusted plumbing. These incidents argue the reverse. Chen said the Bitget attacker used legitimate credentials and disguised activity as routine administrative work. Inventory every security and remote-access product, list who holds admin rights on each, and monitor actions those tools take the same way you monitor privileged people.
CISA told NetScaler users to check for signs of compromise before patching, which means a patch alone does not close the incident. Ask whether the team has the logs and forensic capacity to answer that question within a day. For payment and treasury systems, ask whether any single internal system can issue a high-value instruction without a second, independent check, the gap Bitget's account describes.
For CFOs and boards, Bitget had a fund large enough to absorb the loss; most companies would lean on insurance and cash. Confirm that cyber policies cover losses that start with a third-party product flaw. Kiteworks' advisory also shows the operational cost of a vendor's emergency: business continuity plans should cover taking a file-transfer system or remote-access gateway offline for most of a working day.
The bigger picture
Gateways, file-transfer platforms and security tools have to face the internet or hold broad internal access to do their jobs. That makes a single flaw valuable to attackers, because one exploit can open many companies at once, as the Shadowserver count for NetScaler suggests. Kiteworks' decision to warn customers before any confirmed compromise is one model for vendor disclosure, though it put the burden of downtime on customers.
What’s next
Bitget has not named the vendor, so other users of the same product cannot yet check their exposure; watch for that disclosure and any fix. For Citrix, watch for compromise reports from organizations that patched late and for further guidance from CISA. For Kiteworks, open questions are what the federal threat intelligence described and whether the Advanced Forms flaw receives a public vulnerability identifier.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error





