home.social

#netscaler — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #netscaler, aggregated by home.social.

fetched live
  1. Warning, if you are using #NetScaler 14.1 72.61 or later (and you should be because of vulnerabilities in earlier versions) and you also have Chromebooks using #Citrix Workspace app, you'll probably find they no longer connect.

    This is because Web App Firewall is now applied to VPN, AUTH and PORTAL endpoints by default instead of just VPN and AUTH. Guess which endpoint type doesn't work with Chromebook and the default WAF rules?

    Quick fix:
    set aaa parameter -wafProtection AUTH VPN

  2. RE: infosec.exchange/@watchTowr/11

    Si vous n’avez pas encore patché la RCE NetScaler du mois de juin :
    support.citrix.com/support-hom

    ChatGPT dit que c’est probablement le dernier moment de le faire avant qu’il utilise ça comme opportunité pour s’échapper de sa sandbox.

    Parce que, bien évidemment, la fine équipe de watchTowr vient de publier le write-up qui transforme le gentil « memory overflow » en RCE pré-auth root.

    #CyberVeille #NetScaler

    👇
    labs.watchtowr.com/youre-back-

  3. Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled

    #netscaler #citrix #vulnerabilitymanagement #cybersecurity

    vulnerability.circl.lu/vuln/CV

  4. PSA for anyone still running NetScaler as a SAML IdP

    CVE-2026-3055 (memory overread, CVSS 9.3) is on CISA KEV and getting hammered in the wild. Leaks session tokens and creds straight out of process memory. It's also a CVE Interlock is associated with, and they love healthcare.

    Patch the appliance, but if you've got a FortiGate in front of it, drop an IPS profile on and virtual-patch it today. Signature's live.

    Alert: fortiguard.com/outbreak-alert/

    Interlock: fortiguard.com/threat-actor/63

    #infosec #CVE #NetScaler #ransomware

  5. Citrix: как протокол из 90-х стал частью инфраструктуры, от которой не отказаться

    Есть технологии, которые выбирают. А есть те, от которых уже не отказаться. Citrix — из второй категории. Он не побеждал в обзорах и не захватывал рынок агрессивным маркетингом. Он врастал в корпоративную инфраструктуру годами — тихо, глубоко и, по ощущениям многих ИТ-директоров, необратимо. Банк с пятьюдесятью тысячами сотрудников обсуждает удалённый доступ — обсуждение начинается с Citrix. Фармацевтическая компания строит систему для клинических испытаний в двадцати странах — архитектор рисует схему с Citrix в центре. Государственное ведомство требует, чтобы данные не покидали периметр, но доступ был из любой точки — опять Citrix. Это не фанатизм. Это результат тридцати пяти лет работы над задачей, у которой нет простого альтернативного решения: дать человеку полноценное рабочее место, не отдавая ему данные.

    habr.com/ru/articles/1013870/

    #Citrix #VDI #HDX #ICA #виртуализация_рабочих_столов #импортозамещение #NetScaler #Remote_Desktop #Citrix_DaaS #VDI_в_России

  6. ⚠️ Cloud Software Group reveals a medium severity XSS flaw (CVE-2025-12101) in Citrix NetScaler ADC & Gateway platforms! Vulnerable versions include 14.1 before 14.1-56.73 & 13.1 before 13.1-60.32. Immediate patching is crucial to prevent session hijacking & credential theft. 🔒🛡️

    Details here: gbhackers.com/citrix-netscaler #CyberSecurity #XSS #Citrix #NetScaler #VulnerabilityAlert #newz

  7. « NetScaler ADC et Gateway – failles critiques
    Publié le
    26.08.2025
    NetScaler ADC et NetScaler Gateway (anciennement Citrix ADC et Citrix Gateway) sont des solutions largement utilisées pour gérer le trafic réseau, fournir un accès distant sécurisé et améliorer la performance des applications.
    Des failles critiques ont été découvertes et l’une d’entre elles est déjà activement exploitée par des cybercriminels, ce qui rend la mise à jour urgente. »
    👇
    vd.ch/actualites/actualite/new

    #CyberVeille #Citrix #Netscaler #alerte