{"id":54156,"date":"2023-11-14T20:00:49","date_gmt":"2023-11-14T20:00:49","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2023\/11\/14\/hackers-are-exploiting-citrixbleed-bug-in-the-latest-wave-of-mass-cyberattacks-techcrunch\/"},"modified":"2023-11-14T20:00:49","modified_gmt":"2023-11-14T20:00:49","slug":"hackers-are-exploiting-citrixbleed-bug-in-the-latest-wave-of-mass-cyberattacks-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2023\/11\/14\/hackers-are-exploiting-citrixbleed-bug-in-the-latest-wave-of-mass-cyberattacks-techcrunch\/","title":{"rendered":"Hackers are exploiting &#8216;CitrixBleed&#8217; bug in the latest wave of mass cyberattacks | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"\">\n<p><h2 class=\"article__subtitle\">Citrix customers urged to patch as ransomware gang takes credit for hacking big-name firms<\/h2>\n<\/p>\n<div class=\"article__featured-image-wrapper \">\n\t\t\t\n\t\t<\/div>\n<\/p><\/div>\n<div>\n<p id=\"speakable-summary\"><span class=\"featured__span-first-words\">Security researchers say<\/span> hackers are mass-exploiting a critical-rated vulnerability in Citrix NetScaler systems to launch crippling cyberattacks against big-name organizations worldwide.<\/p>\n<p>These cyberattacks <a href=\"https:\/\/techcrunch.com\/2023\/11\/02\/boeing-cyber-incident-ransomware-gang-claims-data-theft\/\" target=\"_blank\" rel=\"noopener\">have so far included aerospace giant Boeing<\/a>; the world\u2019s biggest bank, ICBC; one of the world\u2019s largest port operators, DP World; and international law firm Allen &amp; Overy, according to reports.<\/p>\n<p>Thousands of other organizations remain unpatched against the vulnerability, tracked officially as <a href=\"https:\/\/support.citrix.com\/article\/CTX579459\/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20234966-and-cve20234967\" target=\"_blank\" rel=\"noopener\">CVE-2023-4966<\/a> and dubbed \u201cCitrixBleed.\u201d The majority of affected systems are located in North America, according to <a href=\"https:\/\/dashboard.shadowserver.org\/statistics\/combined\/time-series\/?date_range=7&amp;source=http_vulnerable&amp;source=http_vulnerable6&amp;tag=cve-2023-4966%2B&amp;group_by=geo&amp;style=stacked\" target=\"_blank\" rel=\"noopener\">nonprofit threat tracker Shadowserver Foundation<\/a>. The U.S. government\u2019s cybersecurity agency CISA has also sounded the alarm <a href=\"https:\/\/www.cisa.gov\/guidance-addressing-citrix-netscaler-adc-and-gateway-vulnerability-cve-2023-4966-citrix-bleed\" target=\"_blank\" rel=\"noopener\">in an advisory urging federal agencies to patch<\/a> against the actively exploited flaw.<\/p>\n<p>Here\u2019s what we know so far.<\/p>\n<h2>What is CitrixBleed?<\/h2>\n<p>On October 10, network equipment maker Citrix disclosed the vulnerability affecting on-premise versions of its NetScaler ADC and NetScaler Gateway platforms, which large enterprises and governments use for application delivery and VPN connectivity.<\/p>\n<p>The flaw is described as a sensitive information disclosure vulnerability that allows remote unauthenticated attackers to extract large amounts of data from a vulnerable Citrix device\u2019s memory, including sensitive session tokens (hence the name \u201cCitrixBleed\u201d). The bug requires little effort or complexity to exploit, allowing hackers to hijack and use legitimate session tokens to compromise a victim\u2019s network without needing a password or using two-factor.<\/p>\n<p>Citrix released patches, but a week later on October 17 updated its advisory to advise that it had\u00a0observed exploitation in the wild.<\/p>\n<p>Early victims included professional services, technology and government organizations, <a href=\"https:\/\/www.mandiant.com\/resources\/blog\/session-hijacking-citrix-cve-2023-4966\" target=\"_blank\" rel=\"noopener\">according to incident response giant Mandiant<\/a>, which said it began investigating after discovering \u201cmultiple instances of successful exploitation\u201d as early as late-August before Citrix made patches available.<\/p>\n<p>Robert Knapp, head of incident response at cybersecurity firm Rapid7 \u2014 which also <a href=\"https:\/\/www.rapid7.com\/blog\/post\/2023\/10\/25\/etr-cve-2023-4966-exploitation-of-citrix-netscaler-information-disclosure-vulnerability\/\" target=\"_blank\" rel=\"noopener\">began investigating the bug<\/a> after detecting potential exploitation of the bug in a customer\u2019s network \u2014 said the company has also observed attackers targeting organizations across healthcare, manufacturing and retail.<\/p>\n<p>\u201cRapid7 incident responders have observed both lateral movement and data access in the course of our investigations,\u201d said Knapp, suggesting hackers are able to gain broader access to victims\u2019 network and data after initial compromise.<\/p>\n<h2>Big-name victims<\/h2>\n<p>Cybersecurity company ReliaQuest said\u00a0<a href=\"https:\/\/www.reliaquest.com\/blog\/citrix-bleed-vulnerability-background-and-recommendations\/\" target=\"_blank\" rel=\"noopener\">last week<\/a>\u00a0it has evidence that at least four threat groups \u2014 which it did not name \u2014 are leveraging CitrixBleed, with at least one group automating the attack process.<\/p>\n<p>One of the threat actors is believed to be the\u00a0<a href=\"https:\/\/techcrunch.com\/2023\/02\/07\/lockbit-ransomware-royal-mail\/\" target=\"_blank\" rel=\"noopener\">Russia-linked LockBit ransomware gang<\/a>, which has already claimed responsibility for several large-scale breaches believed to be associated with CitrixBleed.<\/p>\n<p>Security researcher <a href=\"https:\/\/doublepulsar.com\/lockbit-ransomware-group-assemble-strike-team-to-breach-banks-law-firms-and-governments-4220580bfcee\" target=\"_blank\" rel=\"noopener\">Kevin Beaumont wrote in a blog post<\/a> Tuesday that the LockBit gang last week hacked into the U.S. branch of Industrial and Commercial Bank of China (ICBC) \u2014 said to be the world\u2019s largest lender by assets \u2014 by compromising an unpatched Citrix Netscaler box. The outage disrupted the banking giant\u2019s ability to clear trades. <a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2023-11-14\/icbc-flies-top-executives-to-us-in-race-to-contain-hack-fallout\" target=\"_blank\" rel=\"noopener\">According to Bloomberg on Tuesday<\/a>, the firm has yet to restore normal operations.<\/p>\n<p>ICBC, which reportedly paid LockBit\u2019s ransom demand, declined to answer TechCrunch\u2019s questions but said in a statement on its website that it \u201cexperienced a ransomware attack\u201d that \u201cresulted in disruption to certain systems.\u201d<\/p>\n<p>A LockBit representative <a href=\"https:\/\/www.reuters.com\/technology\/cybersecurity\/icbc-paid-ransom-after-hack-that-disrupted-markets-cybercriminals-say-2023-11-13\/\" target=\"_blank\" rel=\"noopener\">told Reuters on Monday<\/a> that ICBC \u201cpaid a ransom \u2014 deal closed,\u201d but did not provide evidence of their claim. LockBit also <a href=\"https:\/\/twitter.com\/vxunderground\/status\/1724260883679920462\" target=\"_blank\" rel=\"noopener\">told malware research group\u00a0vx-underground<\/a> that ICBC paid a ransom, but declined to say how much.<\/p>\n<p>Beaumont <a href=\"https:\/\/cyberplace.social\/@GossiTheDog\/111400297911839699\" target=\"_blank\" rel=\"noopener\">said in a post on Mastodon<\/a> that Boeing also had an unpatched Citrix Netscaler system at the time of its LockBit breach, citing data from Shodan, a search engine for exposed databases and devices.<\/p>\n<p>Boeing spokesperson Jim Proulx previously told TechCrunch that the company is \u201caware of a cyber incident impacting elements of our parts and distribution business\u201d but would not comment on LockBit\u2019s alleged publication of stolen data.<\/p>\n<p>Allen &amp; Overy, one of the world\u2019s largest law firms, was also running an affected Citrix system at the time of its compromise, Beaumont noted. LockBit added both Boeing and Allen &amp; Overy to its dark web leak site, which ransomware gangs typically use to extort victims by publishing files unless <a href=\"https:\/\/techcrunch.com\/2023\/10\/31\/ransomware-victims-paying-hackers-ransom\/\" target=\"_blank\" rel=\"noopener\">the victims pay a ransom demand<\/a>.<\/p>\n<p>Allen &amp; Overy spokesperson Debbie Spitz confirmed the law firm experienced a \u201cdata incident\u201d and said it was \u201cassessing exactly what data has been impacted, and we are informing affected clients.\u201d<\/p>\n<p>The Medusa ransomware gang is also exploiting CitrixBleed to compromise targeted organizations, <a href=\"https:\/\/cyberplace.social\/@GossiTheDog\/111408758925049114\" target=\"_blank\" rel=\"noopener\">said Beaumont<\/a>.<\/p>\n<p>\u201cWe would expect CVE-2023-4966 to be one of the top routinely exploited vulnerabilities from 2023,\u201d Rapid7\u2019s head of vulnerability research Caitlin Condon told TechCrunch.<\/p>\n<\/p><\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2023\/11\/14\/citrix-bleed-critical-bug-ransomware-mass-cyberattacks\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Citrix customers urged to patch as ransomware gang takes credit for hacking big-name firms Security researchers say hackers are mass-exploiting a critical-rated vulnerability in Citrix NetScaler systems to launch crippling cyberattacks against big-name organizations worldwide. These cyberattacks have so far included aerospace giant Boeing; the world\u2019s biggest bank, ICBC; one of the world\u2019s largest port [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":54157,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-54156","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/54156","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=54156"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/54156\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/54157"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=54156"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=54156"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=54156"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}