Hackers Exploiting ‘Citrixbleed’ Bug For Mass Cyberattacks Globally
Thousands of organisations remain unpatched against the vulnerability, tracked officially as CVE-2023-4966 and called“CitrixBleed,” reports TechCrunch.
Citrix last month disclosed the vulnerability affecting on-premise versions of its NetScaler ADC and NetScaler Gateway platforms.
These are used by large enterprises and governments for application delivery and VPN connectivity. Citrix released security patches and later updated its advisory to indicate that it had observed exploitation in the wild.
The US Cybersecurity and Infrastructure Security Agency (CISA) has also added“CVE-2023-4966” to their known exploited vulnerabilities (KEV) catalog.
Cybersecurity firm Rapid7 recommended taking emergency action to mitigate the Citrix bug.
“Threat actors, including ransomware groups, have historically shown strong interest in Citrix NetScaler ADC vulnerabilities. We expect exploitation to increase,” it said.
Cyber-security researcher Kevin Beaumont said that the Russia-based LockBit hackers' gang gang last week hacked into the US branch of Industrial and Commercial Bank of China (ICBC) by compromising an unpatched Citrix Netscaler box.
“LockBit is breaching some of the world's largest organisations, many of whom have incredibly large security budgets. Recently, it has become clear they have been targeting a vulnerability in Citrix Netscaler, called CitrixBleed,” Beaumont wrote in a blog post.
ICBC has reportedly paid ransom demand to LockBit.
ICBC, the world's largest lender by assets, said that its financial services arm, called ICBC Financial Services, experienced a ransomware attack“that resulted in disruption to certain” systems that disrupted trades in the US Treasury market.
China's Ministry of Foreign Affairs said that ICBC is“striving to minimise the impact and losses after the attack”.
According to Beaumont, Allen & Overy, one of the world's biggest law firms, was also hit by attackers via CitrixBleed vulnerability Netscaler instance, which was patched post incident.
--IANS
na/prw

Legal Disclaimer:
MENAFN provides the
information “as is” without warranty of any kind. We do not accept
any responsibility or liability for the accuracy, content, images,
videos, licenses, completeness, legality, or reliability of the information
contained in this article. If you have any complaints or copyright
issues related to this article, kindly contact the provider above.
Most popular stories
Market Research

- $MBG Token Supply Reduced By 4.86M In First Buyback And Burn By Multibank Group
- Mining Chemicals Market Size, Industry Trends, Growth Factors, Opportunity And Forecast 2025-2033
- Excellion Finance Launches MAX Yield: A Multi-Chain, Actively Managed Defi Strategy
- Pluscapital Advisor Empowers Traders To Master Global Markets Around The Clock
- UK Cosmetics And Personal Care Market To Reach USD 23.2 Billion By 2033
- Nonprofit Organization Consultancy Business Plan2025: Essentials For Entrepreneurs
Comments
No comment