Last week's cybersecurity roundup for the period ending September 21, 2026, brought together three very different stories that share a common thread: attackers are finding new ways around the defenses people rely on most. A cryptocurrency exchange heist targeting Bitget, an AI-driven phishing campaign capable of slipping past multi-factor authentication, and active exploitation of NetScaler zero-day VPN security flaws all point to the same lesson. Layered protection, not any single control, is what keeps accounts and networks safe.
What Happened: Bitget Heist, AI Phishing, and NetScaler Exploitation
The week's news cycle included a heist affecting the Bitget crypto exchange, adding to a growing list of incidents targeting digital asset platforms. Alongside it, researchers flagged AI-powered phishing techniques sophisticated enough to bypass standard access controls, including multi-factor authentication that many organizations treat as a baseline defense. On the enterprise side, security teams were tracking active exploitation of NetScaler zero-day vulnerabilities, the kind of flaw that lets attackers target remote access gateways before a patch even exists.
What makes this combination notable is the range of targets. Crypto exchange users, remote employees logging in through VPN gateways, and everyday consumers clicking on convincing phishing messages are all potentially exposed by different pieces of the same news cycle. Ransomware arrests reported the same week are a reminder that law enforcement is still chasing down the people behind these campaigns, but arrests happen after the damage is done. The more useful takeaway for readers is understanding where the exposure sits and how to close it before it's exploited.
Who's at Risk: Crypto Holders, Remote Workers, and Enterprise VPN Users
Three groups should be paying closer attention this week. First, cryptocurrency holders and exchange users, since the Bitget incident is the latest reminder that centralized platforms remain attractive targets regardless of the security promises they make. Second, remote and hybrid employees who authenticate through corporate VPNs or gateway appliances, because NetScaler is widely deployed as the front door for remote access, ICA proxy sessions, and clientless VPN connections. Third, anyone relying on MFA alone as a security backstop, since the AI phishing campaign flagged last week specifically targets the human step in that process rather than trying to break the cryptography behind it.
This isn't a case where only large enterprises need to worry. Individual users who reuse credentials across a crypto exchange and a work VPN, or who approve MFA prompts without checking the login context, are exactly the kind of soft target these campaigns are built to catch. For more on how overlapping vulnerabilities and leaks compound risk across consumer and enterprise systems, last week's coverage of the ShinyHunters DMV leak and Cisco's zero-day fix is worth revisiting, since it traces the same pattern of attackers chaining together separate weaknesses.
How Encryption and VPNs Limit Exposure
It's worth being clear about what a VPN can and cannot do in a situation like this. A properly configured VPN encrypts traffic between a device and the network it connects to, which protects data in transit from interception on public Wi-Fi or untrusted networks. That's genuinely useful against opportunistic snooping. But when the vulnerability sits inside the VPN gateway itself, as is the case with actively exploited NetScaler zero-day flaws, the encryption tunnel isn't the weak point: the appliance managing it is. Attackers exploiting an unpatched gateway can potentially gain a foothold regardless of how strong the encryption protocol is, because they're targeting the software running the connection, not the data inside it.
This distinction matters for both individuals and IT teams. Personal VPN use still meaningfully reduces exposure to network-level eavesdropping and helps mask browsing activity from ISPs. But it is not a substitute for keeping the underlying infrastructure, whether a personal VPN client or an enterprise gateway appliance, current with security patches. Encryption protects data; patching protects the systems that handle it.
Immediate Steps to Harden Your Accounts and Network Access
A few concrete actions reduce exposure to all three threats covered in last week's roundup:
- Enable hardware-based or app-based MFA rather than SMS codes where possible, since AI phishing kits are increasingly designed to intercept simpler authentication flows.
- If your organization uses NetScaler ADC or NetScaler Gateway for remote access, confirm with IT or your vendor that mitigation guidance has been applied, since these are the appliances currently under active exploitation.
- Avoid storing significant crypto holdings on exchange platforms long term. Cold storage remains the more resilient option following incidents like the Bitget heist.
- Treat unexpected MFA prompts as a red flag rather than a routine approval, and verify login attempts through a separate channel if anything looks off.
What This Means For You
None of these stories exist in isolation. A crypto exchange breach, an AI phishing wave, and NetScaler zero-day VPN security flaws all exploit the same underlying reality: attackers look for the gap between a control's promise and its actual configuration. MFA that can be phished, a VPN gateway that hasn't been patched, or an exchange account without cold storage backup are all examples of that gap. Closing it doesn't require new tools so much as consistent attention to the tools already in place.
The practical response is straightforward. Check your own VPN or enterprise gateway's patch status this week rather than assuming IT has already handled it. Move meaningful crypto holdings off exchange hot wallets. And treat MFA as one layer of defense rather than a guarantee. Staying current on these fast-moving stories, including the ongoing zero-day exploitation trend flagged in the prior week's roundup, is one of the simplest ways to stay ahead of the next incident rather than reading about it after the fact.




