Citrix ShareFile and NetScaler Vulnerabilities Exploited in Mass Campaign

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a critical vulnerability in Citrix ShareFile, a secure file transfer solution. Tracked as CVE-2023-24489, the flaw allows unauthenticated attackers to compromise customer-managed storage zones. Cybersecurity firm AssetNote discovered the vulnerability and disclosed it to Citrix. Threat actors have already begun exploiting the flaw, prompting CISA to add it to its catalog of known exploited vulnerabilities. While no public exploitation or data theft has been reported, CISA has mandated that Federal Civilian Executive Branch agencies apply patches by September 6th, 2023. Organizations are advised to update their systems promptly.
- CISA warns of critical Citrix ShareFile flaw exploited in the wild BleepingComputer
- Nearly 2,000 Citrix NetScaler Instances Hacked via Critical Vulnerability The Hacker News
- (Re)check your patched NetScaler ADC and Gateway appliances for signs of compromise Help Net Security
- CISA, experts warn of Citrix vulnerabilities being exploited by hackers The Record from Recorded Future News
- Mass-Exploitation Campaign Targets Citrix NetScalers With Backdoors Infosecurity Magazine
- View Full Coverage on Google News
Reading Insights
0
11
2 min
vs 3 min read
82%
551 → 100 words
Want the full story? Read the original article
Read on BleepingComputer