Tech and AICISA confirms hackers are actively exploiting critical 'Citrix Bleed...

CISA confirms hackers are actively exploiting critical ‘Citrix Bleed 2’ bug

-


U.S. cybersecurity agency CISA says hackers are actively exploiting a critical-rated security flaw in a widely used Citrix product, and has given other federal government departments just one day to patch their systems.

Security researchers have dubbed the bug “Citrix Bleed 2” for its similarity to a 2023 security flaw in Citrix NetScaler, a networking product that large companies and governments rely on for allowing their staff to remotely access apps and other resources on their internal networks. Much like the earlier bug, Citrix Bleed 2 can be remotely exploited to extract sensitive credentials from an affected NetScaler device, allowing the hackers broader access to a company’s wider network.

In an alert on Thursday, CISA said it had evidence that the bug was being actively used in hacking campaigns, adding to the raft of research and findings pointing to widespread exploitation, with some reporting hacks dating back as far as mid-June. Akamai said it saw a “drastic increase” in efforts to scan the internet for affected devices after details of the NetScaler exploit were published earlier this week.

CISA said the NetScaler bug poses a “significant risk” to the federal government’s systems, and ordered federal government agencies to patch any Citrix device affected by the bug by Friday.

For its part, Citrix has not yet acknowledged that the vulnerability is being exploited. The company’s security advisory urges customers to update affected devices as soon as possible. 

Citrix representatives did not respond to TechCrunch’s request for comment.



Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest news

Trump promises ‘something great with crypto’ as World Liberty buys the dip

World Liberty Financial has been diversifying the assets in its multisignature wallet, apparently exchanging USDC for ether, LINK,...

Verily is closing its medical device program as Alphabet shifts more resources to AI

Alphabet’s life sciences arm Verily laid off staff and eliminated its entire devices program Monday. CEO Stephen Gillett...

Gemini Introduces XRP Edition Credit Card | Live Crypto Updates | Aug. 27, 2025

Disclaimer: This article is for informational purposes only and does not constitute financial advice. BitPinas has no commercial...

Advertisement

[LIVE] Latest Crypto News, August 27 – Trump Media Invests in Crypto.com to Hold Billions in CRO Crypto – Best Altcoin To Buy Right...

Trump Media & Technology Group has announced a partnership with Crypto.com to form a new venture designed to...

Bears watch MicroStrategy ahead of NASDAQ 100 inclusion

Bearish onlookers are increasingly skeptical that MicroStrategy’s flywheel of bitcoin accretion per diluted share can continue much longer. Source...

Must read

You might also likeRELATED
Recommended to you