Hackers exploiting 'CitrixBleed' bug for mass cyberattacks globally

by IANS |



San Francisco, Nov 15 (IANS) Hackers are mass-exploiting a critical vulnerability in desktop virtualisation company Citrix’s NetScaler systems to apparently attack big organisations like Boeing, China’s ICBC and mega port operator DP World globally, cyber-security researchers have claimed.


Thousands of organisations remain unpatched against the vulnerability, tracked officially as CVE-2023-4966 and called “CitrixBleed,” reports TechCrunch.


Citrix last month disclosed the vulnerability affecting on-premise versions of its NetScaler ADC and NetScaler Gateway platforms.


These are used by large enterprises and governments for application delivery and VPN connectivity. Citrix released security patches and later updated its advisory to indicate that it had observed exploitation in the wild.


The US Cybersecurity and Infrastructure Security Agency (CISA) has also added “CVE-2023-4966” to their known exploited vulnerabilities (KEV) catalog.


Cybersecurity firm Rapid7 recommended taking emergency action to mitigate the Citrix bug.


“Threat actors, including ransomware groups, have historically shown strong interest in Citrix NetScaler ADC vulnerabilities. We expect exploitation to increase,” it said.


Cyber-security researcher Kevin Beaumont said that the Russia-based LockBit hackers’ gang gang last week hacked into the US branch of Industrial and Commercial Bank of China (ICBC) by compromising an unpatched Citrix Netscaler box.


“LockBit is breaching some of the world’s largest organisations, many of whom have incredibly large security budgets. Recently, it has become clear they have been targeting a vulnerability in Citrix Netscaler, called CitrixBleed,” Beaumont wrote in a blog post.


ICBC has reportedly paid ransom demand to LockBit.


ICBC, the world’s largest lender by assets, said that its financial services arm, called ICBC Financial Services, experienced a ransomware attack “that resulted in disruption to certain” systems that disrupted trades in the US Treasury market.


China’s Ministry of Foreign Affairs said that ICBC is “striving to minimise the impact and losses after the attack”.


According to Beaumont, Allen & Overy, one of the world’s biggest law firms, was also hit by attackers via CitrixBleed vulnerability Netscaler instance, which was patched post incident.



Latest News
BJP & JD-S making false accusations against me in MUDA case: Siddaramaiah Tue, Oct 22, 2024, 04:36 PM
Himachal Cabinet's nod to involve private players to expand EV charging stations Tue, Oct 22, 2024, 04:16 PM
Mongolia reports outbreak of contagious caprine pleuropneumonia Tue, Oct 22, 2024, 04:12 PM
Tamil parents should choose beautiful Tamil names for their children: Udhayanidhi Stalin Tue, Oct 22, 2024, 04:08 PM
Will win all seven seats in Rajasthan: BJP state chief on bypolls Tue, Oct 22, 2024, 03:59 PM
Akansha Ranjan Kapoor opens up about her role in Alia Bhatt's ‘Jigra’ Tue, Oct 22, 2024, 03:58 PM
Muthoot FinCorp ONE is now all-in-one financial suite Tue, Oct 22, 2024, 03:43 PM
Caste census report must be discussed before making it public: K’taka Home Minister Tue, Oct 22, 2024, 03:43 PM
People should become Hindu if they want to live in Bihar's Araria: BJP MP Tue, Oct 22, 2024, 03:39 PM
SC extends interim anticipatory bail of Malayalam actor Siddique in rape case Tue, Oct 22, 2024, 03:22 PM
India gearing up for 2nd white revolution, says HM Shah at NDDB diamond jubilee celebrations Tue, Oct 22, 2024, 03:20 PM
Paytm reports Rs 930 crore net profit after one-time gain, stock down over 4 pc Tue, Oct 22, 2024, 02:57 PM
Egypt urges safety of maritime navigation in Red Sea Tue, Oct 22, 2024, 02:52 PM
Venezuela confirms arrest of former Oil Minister for 'serious crimes' Tue, Oct 22, 2024, 02:44 PM
I find it hard to see anyone playing as well as Joe Root: Cook Tue, Oct 22, 2024, 02:38 PM