Health IT Security December 4, 2023
The LockBit 3.0 ransomware gang has been exploiting the Citrix Bleed cybersecurity vulnerability to evade password requirements and multi-factor authentication.
Hospitals should take immediate action to protect against the Citrix Bleed cybersecurity vulnerability, the American Hospital Association (AHA) warned, following multiple alerts by government agencies regarding the aggressive nature of this vulnerability.
Threat actors have been observed exploiting the Citrix Bleed vulnerability (CVE-2023-4966), which impacts the NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) and allows threat actors to bypass password protections and multi-factor authentication.
In late November, the Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), the Multi-State Information Sharing and Analysis Center (MS-ISAC), and international partners issued an alert to notify critical...