Tech and AICISA confirms hackers are actively exploiting critical 'Citrix Bleed...

CISA confirms hackers are actively exploiting critical ‘Citrix Bleed 2’ bug

-


U.S. cybersecurity agency CISA says hackers are actively exploiting a critical-rated security flaw in a widely used Citrix product, and has given other federal government departments just one day to patch their systems.

Security researchers have dubbed the bug “Citrix Bleed 2” for its similarity to a 2023 security flaw in Citrix NetScaler, a networking product that large companies and governments rely on for allowing their staff to remotely access apps and other resources on their internal networks. Much like the earlier bug, Citrix Bleed 2 can be remotely exploited to extract sensitive credentials from an affected NetScaler device, allowing the hackers broader access to a company’s wider network.

In an alert on Thursday, CISA said it had evidence that the bug was being actively used in hacking campaigns, adding to the raft of research and findings pointing to widespread exploitation, with some reporting hacks dating back as far as mid-June. Akamai said it saw a “drastic increase” in efforts to scan the internet for affected devices after details of the NetScaler exploit were published earlier this week.

CISA said the NetScaler bug poses a “significant risk” to the federal government’s systems, and ordered federal government agencies to patch any Citrix device affected by the bug by Friday.

For its part, Citrix has not yet acknowledged that the vulnerability is being exploited. The company’s security advisory urges customers to update affected devices as soon as possible. 

Citrix representatives did not respond to TechCrunch’s request for comment.



Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest news

Zora price prediction | Is Zora a good investment?

Zora has had a wild summer...

Tyler Winklevoss goes viral for not having the Gemini app

Tyler Winklevoss wanted to boast about Gemini outranking Coinbase in the Apple App Store, but he proved something...

Best Window Air Conditioners 2025: 11 Picks to Cool You for Years

Others We TestedEcoFlow Wave 2 for $1,299: Lisa Wood Shapiro tested the newest model for this update. The...

Advertisement

Opinion: The Gemini XRP credit card is stupid

Gemini’s new XRP Mastercard offers no new features, except “an innovative design for the XRP Army to show...

Plaud launches a new AI hardware notetaker, the $179 Note Pro

Hardware company Plaud.ai has released its new physical notetaker, the Plaud AI Pro, on Wednesday. The notetaker, priced...

Must read

Tyler Winklevoss goes viral for not having the Gemini app

Tyler Winklevoss wanted to boast about Gemini outranking...

You might also likeRELATED
Recommended to you