Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

Citrix servers hacked using zero-day exploit

  • August 16, 2023
Total
0
Shares
0
0
0


Roughly 2,000 Citrix NetScaler servers were compromised in what appears to be a large-scale attack against the endpoints. This is according to a new report from cybersecurity researchers Fox-IT, part of NCC Group. 

In its report, Fox-IT says the unnamed threat actor leveraged a high-severity vulnerability first discovered in mid-July to breach the servers. The vulnerability is being tracked as CVE-2023-3519, and holds a severity score of 9.8. 

It allows threat actors to run code remotely on Citrix NetScaler ADC and NetScaler Gateway. Even though it was disclosed a month ago, hackers managed to use it as a zero-day.

Indicators of compromise

On the day the report was published (August 14), Fox-IT said 1,828 NetScaler servers were compromised, despite the fact that 1,248 were previously patched against the flaw. 

“A patched NetScaler can still contain a backdoor,” the researchers explained. “It is recommended to perform an Indicator of Compromise check on your NetScalers, regardless of when the patch was applied.” 

Citrix NetScaler is a web application delivery controller (ADC) that speeds up apps, reduces web app ownership costs, and ensures higher app availability. According to WhiteHat Virtual Technologies, as of 2021 there were over 200,000,000 sites using Citrix NetScalers, including tech giants such as Microsoft, eBay, Weather.com, CNET, and MasterCard. 

Given the fact that even patched servers were still compromised, users are advised to secure forensic data, a SiliconANGLE report states. Fox-IT’s researchers recommend users make a forensic copy of both the disk and the memory of the appliance, before deciding on any course of action. In case of a Citrix appliance being installed on a hypervisor, users can make a snapshot, as well. 

Those that find a web shell in their premises should analyze if it was used, and to what end.

Via: BleepingComputer


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • Technology

Peak XV eyes $50M investment in former Edelweiss executives’ Neo

  • August 16, 2023
View Post
Next Article
  • News

Stock shortages for Nvidia’s RTX 4000 desktop GPUs? Rising prices? New rumor forecasts a bleak future

  • August 16, 2023
View Post
You May Also Like
View Post
  • News

The ‘world’s smallest’ external GPU has been tested and it could be the best laptop upgrade yet — here’s why

  • October 1, 2023
View Post
  • News

Quordle today – hints and answers for Sunday, October 1 (game #615)

  • September 30, 2023
View Post
  • News

Mortal Kombat 1 creator teases that a host of terrifyingly familiar faces may be on the way

  • September 30, 2023
View Post
  • News

Google Pixel Buds Pro leak gives us an early look at some new colors

  • September 30, 2023
View Post
  • News

The Pokémon Company apologizes and blames “overwhelming demand” for its Van Gogh collab stock issues

  • September 30, 2023
View Post
  • News

Your next laptop could run faster, last longer and pack more memory thanks to Samsung’s revolutionary new technology — but it won’t be cheap

  • September 30, 2023
View Post
  • News

Early iPhone 16 leak hints at larger screens for the Pro and Pro Max models

  • September 30, 2023
View Post
  • News

Bad news – turns out even long passwords can be cracked easily

  • September 30, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.