Citrix addresses high-risk Citrix NetScaler ADC and NetScaler Gateway bugs
Affected customers of NetScaler ADC and NetScaler Gateway are strongly advised to upgrade to the fixed versions.
Affected customers of NetScaler ADC and NetScaler Gateway are strongly advised to upgrade to the fixed versions.
The campaign is targeting an extensive list of Magento and WooCommerce websites.
The company advised customers to cancel their credit cards.
A threat actor known as Storm-0062 has been exploiting the bug since September 14.
The vendor has also fixed an actively exploited vulnerability known as the HTTP/2 Rapid Reset attack.
One of the most interesting aspects of the campaign is the use of a distinctive DLL sideloading technique.
The released source code is the legitimate 2020 HelloKitty version used when the ransomware operation was first launched.
The campaign uses CVE-2023-3519 to insert a malicious script into the HTML content of the authentication web page.
Between August and September 2023, UAC-0006 attempted to steal millions of hryvnias from organizations.
In addition to attacks on Ukraine, Russian threat actors intensified cyber operations against Western countries.
Showing elements 1711 - 1720