• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
hundreds of citrix netscaler adc and gateway servers hacked in

Hundreds of Citrix NetScaler ADC and Gateway Servers Hacked in Major Cyber Attack

You are here: Home / General Cyber Security News / Hundreds of Citrix NetScaler ADC and Gateway Servers Hacked in Major Cyber Attack
August 3, 2023

Hundreds of Citrix NetScaler ADC and Gateway servers have been breached by destructive actors to deploy web shells, according to the Shadowserver Foundation.

The non-revenue claimed the attacks consider advantage of CVE-2023-3519, a critical code injection vulnerability that could direct to unauthenticated distant code execution.

The flaw, patched by Citrix last thirty day period, carries a CVSS score of 9.8.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


The greatest range of impacted IP addresses are based mostly in Germany, adopted by France, Switzerland, Italy, Sweden, Spain, Japan, China, Austria, and Brazil.

The exploitation of CVE-2023-3519 to deploy web shells was formerly disclosed by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), which claimed the attack was directed from an unnamed critical infrastructure organization in June 2023.

Cybersecurity

The disclosure will come as GreyNoise explained it detected 3 IP addresses making an attempt to exploit CVE-2023-24489 (CVSS rating: 9.1), an additional critical flaw in Citrix ShareFile computer software that enables for unauthenticated arbitrary file add and distant code execution.

The issue has been resolved in ShareFile storage zones controller model 5.11.24 and later on.

Citrix NetScaler ADC and Gateway Servers

Attack area management business Assetnote, which found and documented the bug, traced it to a less difficult version of a padding oracle attack.

“[Cipher Block Chaining] manner and PKCS#7 padding are the default values for AES encryption in .NET,” security researcher Dylan Pindur claimed.

“Seem at how it behaves when invalid as opposed to legitimate padding is offered. Does it result in an mistake? Are the mistakes unique? Does it choose more time or shorter to method? All of these can direct to a likely padding oracle attack.”

Located this short article fascinating? Abide by us on Twitter  and LinkedIn to study far more special content material we post.


Some parts of this posting are sourced from:
thehackernews.com

Previous Post: «a penetration testing buyer's guide for it security teams A Penetration Testing Buyer’s Guide for IT Security Teams
Next Post: New Version of Rilide Data Theft Malware Adapts to Chrome Extension Manifest V3 new version of rilide data theft malware adapts to chrome»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.