Security News

Exploits Published for Citrix ADC Vulnerability, Patches Coming Soon
2020-01-13 12:10

Exploits targeting the recent Citrix Application Delivery Controller vulnerability have already been published online, yet security patches will not be available for at least another week. Impacting both Citrix ADC and Citrix Gateway, the vulnerability is tracked as CVE-2019-19781 and could lead to code execution without authentication, Citrix revealed on December 17, 2019.

Exploits for Citrix ADC and Gateway flaw abound, attacks are ongoing
2020-01-13 11:53

With several exploits targeting CVE-2019-19781 having been released over the weekend and the number of vulnerable endpoints still being over 25,000, attackers are having a field day. Some other researchers then published exploits and scanners for it.

Severe Citrix Flaw: Proof-of-Concept Exploit Code Released
2020-01-13 11:19

Technology giant Citrix says it's racing to develop patches to fix a severe flaw in its software, for which proof-of-concept exploit code has now been released. Designated CVE-2019-19781, the directory traversal flaw has been present in Citrix's code for nearly six years, but only came to light - at least publicly - in December 2019.

If you haven't shored up that Citrix hole, you were probably hacked over the weekend: Exploit code now available
2020-01-13 06:05

Late last month Citrix disclosed a critical security hole in its Application Delivery Controller and Unified Gateway offerings. Up to 80,000 systems were thought to be at risk, with some 25,000 instances found online over the weekend.

Week in review: Citrix bug under attack, Windows 7 ransomware risk, ATT&CK for ICS
2020-01-12 14:50

Attackers exploiting critical Citrix ADC, Gateway flaw, company yet to release fixesNearly a month has passed since Citrix released mitigation measures for CVE-2019-19781, a critical vulnerability affecting Citrix Application Delivery Controller and Citrix Gateway, which could lead to remote code execution. PCs still running Windows 7 will soon be significantly more at risk of ransomwarePCs still running when Windows 7 reaches end of life on the 14th of January will be significantly more at risk of ransomware, Veritas Technologies has warned.

PoC Exploits Released for Citrix ADC and Gateway RCE Vulnerability
2020-01-11 02:22

Why the urgency? Earlier today, multiple groups publicly released weaponized proof-of-concept exploit code [1, 2] for a recently disclosed remote code execution vulnerability in Citrix's NetScaler ADC and Gateway products that could allow anyone to leverage them to take full control over potential enterprise targets. Just before the last Christmas and year-end holidays, Citrix announced that its Citrix Application Delivery Controller and Citrix Gateway are vulnerable to a critical path traversal flaw that could allow an unauthenticated attacker to perform arbitrary code execution on vulnerable servers.

Hackers use system weakness to rattle doors on Citrix systems
2020-01-10 11:02

Attackers are using a serious bug in Citrix products to scan the internet for weaknesses, according to experts. The flaw, CVE-2019-19781, affects the company's NetScaler ADC Application Delivery Controller and its Citrix Gateway.

Hackers Scan for Vulnerable Citrix ADC Systems
2020-01-10 06:23

Weeks after Citrix revealed a critical vulnerability impacting its Application Delivery Controller and Gateway products, hackers have started to scan the Internet for vulnerable systems, security researchers report. Now, only three weeks later, security researchers are already observing online scans for vulnerable systems, as well as exploitation attempts targeting CVE-2019-19781.

Attackers exploiting critical Citrix ADC, Gateway flaw, company yet to release fixes
2020-01-09 13:56

Nearly a month has passed since Citrix released mitigation measures for CVE-2019-19781, a critical vulnerability affecting Citrix Application Delivery Controller and Citrix Gateway, which could lead to remote code execution. Citrix Gateway is a secure remote access network gateway solution that is offered as a cloud service or an on-premises solution.

Critical Citrix Bug Puts 80,000 Corporate LANs at Risk
2019-12-26 19:17

The flaw resides in the Citrix Application Delivery Controller and Gateway.