大規模なCitrix NetScalersの脆弱性悪用キャンペーンをFOX-ITとDIVD報告。日本国内含め修正前に攻撃に遭ったとみられるものも多く更新有無関わらず侵害確認推奨。

Approximately 2000 Citrix NetScalers backdoored in mass-exploitation campaign

August 15, 2023

Fox-IT (part of NCC Group) has uncovered a large-scale exploitation campaign of Citrix NetScalers in a joint effort with the Dutch Institute of Vulnerability Disclosure (DIVD). An adversary appears to have exploited CVE-2023-3519 in an automated fashion, placing webshells on vulnerable NetScalers to gain persistent access. The adversary can execute arbitrary commands with this webshell, even when a NetScaler is patched and/or rebooted. At the time of writing, more than 1900 NetScalers remain backdoored. Using the data supplied by Fox-IT, the Dutch Institute of Vulnerability Disclosure has notified victims.
quoted from Fox-IT

Approximately 2000 Citrix NetScalers backdoored in mass-exploitation campaign
第三世代のウィルス対策
Nash
DeepInstinct
webサイト脆弱性診断
セキュリティポリシー
jyrosecurity (3)
Nash (4)
DeepInstinct
previous arrowprevious arrow
next arrownext arrow
Shadow