Citrix patches an actively exploited NetScaler zero-day; CISA orders federal remediation
A NetScaler denial-of-service flaw is being exploited in the wild, Citrix has shipped emergency updates, and CISA added it to its Known Exploited Vulnerabilities catalog on 4 October.
BleepingComputer reported that Citrix released emergency updates for a new NetScaler denial-of-service vulnerability that has been exploited in zero-day attacks, and that researchers are investigating whether it can also be exploited for remote code execution. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 4 October, based on evidence of active exploitation, and described it as a Citrix NetScaler "Improper Restriction of Operations within the Bounds of a Memory Buffer" vulnerability.
What to do: CISA states that Binding Operational Directive (BOD) 26-04 requires Federal Civilian Executive Branch agencies to prioritise rapid remediation of vulnerabilities in the KEV catalog. BleepingComputer reported that Citrix has released emergency updates; apply them to any NetScaler you run, prioritising internet-facing appliances. Match your estate against what Citrix lists as affected, and treat this as under active attack rather than a routine patch.
In extortion-group news, The Hacker News and BleepingComputer both reported that a suspected member of the ShinyHunters group, known online as "Rey," has been detained in Jordan and is cooperating with the FBI to identify other members. The Hacker News reported, citing Reuters, that Rey's real name is Saif al-Din Khader and that he was brought into custody on 29 September.
On espionage, The Hacker News reported that a China-nexus cyber espionage group it calls TA419 has run multiple credential phishing campaigns against AI experts working for U.S. think tanks, universities and legal-sector organisations. The Hacker News reported that the campaigns use Microsoft adversary-in-the-middle (AitM) phishing and impersonate prominent economists and AI policymakers. If your staff work in AI policy, treat unexpected outreach from named experts as a lure.
Finally, Help Net Security reported in its week in review that a 16-year-old researcher broke into Titan, an internal Microsoft analytics service, through a flaw that could have let an attacker read employee records and Bing search data, with access to 17 trillion rows of data.
The single actionable item for most readers today is Citrix NetScaler: a flaw that is being exploited now, with remote code execution under investigation, and a vendor fix already available. Patch it ahead of the rest.
Sources
- BleepingComputer — Citrix patches NetScaler SAML zero-day exploited in attacks
- CISA — CISA Adds One Known Exploited Vulnerability to Catalog
- Help Net Security — Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploited
- The Hacker News — ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members
- The Hacker News — China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
- BleepingComputer — ShinyHunters hacker reportedly detained in Jordan, aiding FBI