{"id":1198044,"date":"2023-10-30T17:39:07","date_gmt":"2023-10-30T21:39:07","guid":{"rendered":"https:\/\/www.prime-wow.com\/?p=1198044"},"modified":"2023-10-30T17:39:07","modified_gmt":"2023-10-30T21:39:07","slug":"this-vulnerability-is-now-under-mass-exploitation-citrix-bleed-bug-bites-hard","status":"publish","type":"post","link":"https:\/\/www.prime-wow.com\/?p=1198044","title":{"rendered":"\u201cThis vulnerability is now under mass exploitation.\u201d Citrix Bleed bug bites hard"},"content":{"rendered":"<div id=\"rss-wrap\">\n<figure class=\"intro-image intro-left\">\n  <img decoding=\"async\" src=\"https:\/\/www.prime-wow.com\/wp-content\/uploads\/2023\/10\/system-hacked-800x450-3.jpg\" alt=\"&#x201C;This vulnerability is now under mass exploitation.&#x201D; Citrix Bleed bug bites hard\" \/><\/p>\n<p class=\"caption\" style=\"font-size:0.8em\"><a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/05\/system-hacked.jpg\" class=\"enlarge-link\" data-height=\"563\" data-width=\"1000\">Enlarge<\/a> (credit: Getty Images)<\/p>\n<\/figure>\n<div><a name=\"page-1\" \/><\/div>\n<p>A vulnerability that allows attackers to bypass multifactor authentication and access enterprise networks using hardware sold by Citrix is under mass exploitation by ransomware hackers despite a patch being available for three weeks.<\/p>\n<p>Citrix Bleed, the common name for the vulnerability, carries a severity rating of 9.4 out of a possible 10, a relatively high designation for a mere information-disclosure bug. The reason: the information disclosed can include session tokens, which the hardware assigns to devices that have already successfully provided credentials, including those providing MFA. The vulnerability, tracked as CVE-2023-4966 and residing in Citrix\u2019s NetScaler Application Delivery Controller and NetScaler Gateway, has been under active exploitation <a href=\"https:\/\/arstechnica.com\/security\/2023\/10\/the-latest-high-severity-citrix-vulnerability-under-attack-isnt-easy-to-fix\/\">since August<\/a>. Citrix issued a patch on October 10.<\/p>\n<h2>Repeat: This is not a drill<\/h2>\n<p>Attacks have only ramped up recently, prompting security researcher Kevin Beaumont on Saturday to <a href=\"https:\/\/doublepulsar.com\/mass-exploitation-of-citrixbleed-vulnerability-including-a-ransomware-group-1405cbb9de18\">declare<\/a>: \u201cThis vulnerability is now under mass exploitation.\u201d He went on to say, \u201cFrom talking to multiple organizations, they are seeing widespread exploitation.\u201d<\/p>\n<\/div>\n<p><a href=\"https:\/\/arstechnica.com\/?p=1979860#p3\">Read 7 remaining paragraphs<\/a> | <a href=\"https:\/\/arstechnica.com\/?p=1979860&amp;comments=1\">Comments<\/a><\/p>\n<p>&#013;<br \/>\n&#013;<br \/>\nSource: Ars Technica &#8211; <a href=\"https:\/\/arstechnica.com\/?p=1979860\" target=\"_blank\" rel=\"noopener\">\u201cThis vulnerability is now under mass exploitation.\u201d Citrix Bleed bug bites hard<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Enlarge (credit: Getty Images) A vulnerability that allows attackers to bypass multifactor authentication and access enterprise networks using hardware sold by Citrix is under mass exploitation by ransomware hackers despite a patch being available for three weeks. Citrix Bleed, the &hellip; <a href=\"https:\/\/www.prime-wow.com\/?p=1198044\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":1198047,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[27,110],"tags":[73],"class_list":["post-1198044","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ars-technica","category-unfiltered-rss","tag-ars-technica"],"_links":{"self":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/1198044","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1198044"}],"version-history":[{"count":0,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/1198044\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/media\/1198047"}],"wp:attachment":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1198044"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1198044"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1198044"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}