Citrix NetScaler Exploit Drops Web Shells, Steals Config Data
Threat actors are exploiting a critical pre-authentication command injection flaw in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and steal configuration data. LevelBlue's THOR team observed the activity across multiple customer environments.
- Critical pre-auth command injection in NetScaler ADC and Gateway exploited
- Attackers drop web shells and attempt configuration data theft
- Activity spotted across multiple customer environments by LevelBlue THOR
Read next
Security