Cybersecurity Dive November 8, 2023
CISA urged organizations to patch, mitigate and report any positive findings as Citrix NetScaler ADC and NetScaler Gateway users remain exposed to session hijack.
Organizations are scrambling to respond to an active and targeted exploitation of an ongoing vulnerability in Citrix NetScaler ADC and NetScaler Gateway, which can expose users to session hijacking and other threat activity.
The Cybersecurity and Infrastructure Security Agency is asking organizations to apply the patch, hunt for malicious activity and report any positive findings back to the agency. Exploitation of the vulnerability, dubbed CitrixBleed, has escalated for several weeks, despite a patch being issued Oct. 10.
Researchers at Rapid7 are “continuing to see a steady stream of compromises” related to CitrixBleed, according to...