Citrix releases fix for software bug that hackers ‘will move quickly to exploit’

A newly revealed set of vulnerabilities in popular software made by Citrix, whose clients include Fortune 500 companies, could let hackers who exploit the bugs gain control of a mobile server and steal sensitive data. The Florida-based company, which has dealt with multiple critical vulnerabilities this year, has released fixes for the new round of bugs and urged customers to apply them. “While there are no known exploits as of this writing, we do anticipate malicious actors will move quickly to exploit,” Citrix CISO Fermin J. Serna wrote in a blog post Tuesday. The bugs are in a software product known as Citrix Endpoint Management or XenMobile, which allows clients to remotely connect to corporate networks with their mobile devices. Exploiting one of the bugs could let a hacker steal domain account credentials for a corporate network, according to Andrey Medov, a security researcher at Positive Technologies, which found the […]

The post Citrix releases fix for software bug that hackers ‘will move quickly to exploit’ appeared first on CyberScoop.

Continue reading Citrix releases fix for software bug that hackers ‘will move quickly to exploit’

Citrix Web App and API Protection: Security for apps and APIs in the multi-cloud

Citrix Web App and API Protection is a new, cloud-delivered service that provides comprehensive security for applications and APIs in multi-cloud environments. “The flexible models for work and multi-cloud application deployment that companies must now… Continue reading Citrix Web App and API Protection: Security for apps and APIs in the multi-cloud

Attackers are probing Citrix controllers and gateways through recently patched flaws

Earlier this week, Citrix released security updates for Citrix Application Delivery Controller (ADC), Citrix Gateway, and the Citrix SD-WAN WANOP appliance, and urged admins to apply them as soon as possible to reduce risk. At the time, there was no pu… Continue reading Attackers are probing Citrix controllers and gateways through recently patched flaws

New round of bugs found in Citrix software, but this time a patch is ready

Six months ago, a critical vulnerability found in software made by Citrix set off an uncomfortable few weeks for the virtual private networking vendor and the Fortune 500 companies that rely on its products. It took Citrix a month to release a software fix, well after researchers were warning that malicious hackers were actively exploiting the vulnerability. Even with a fix available, Chinese spies conducted a sweeping operation that took advantage of the software flaw in critical infrastructure sectors. On Tuesday, Citrix revealed 11 new vulnerabilities in those same cloud-based and remote access products. This time, the Florida-based VPN service provider is hoping to head off attacks by having patches available immediately. The vulnerabilities, under certain conditions, could allow an attacker to inject malicious code into a network running Citrix software, or conduct a denial-of service attack on virtual servers. Citrix urged customers to install the fixes. There haven’t been […]

The post New round of bugs found in Citrix software, but this time a patch is ready appeared first on CyberScoop.

Continue reading New round of bugs found in Citrix software, but this time a patch is ready

Citrix Bugs Allow Unauthenticated Code Injection, Data Theft

Admins should patch their Citrix ADC and Gateway installs immediately. Continue reading Citrix Bugs Allow Unauthenticated Code Injection, Data Theft

Citrix launches back-to-office solution to help orgs efficiently adapt to the new world of work

As governments around the world ease their lockdowns, businesses must decide how, when and if to return their employees to offices. And Citrix Systems is leveraging its decades of experience in delivering flexible work solutions to help organizations o… Continue reading Citrix launches back-to-office solution to help orgs efficiently adapt to the new world of work

Top 10 most exploited vulnerabilities list released by FBI, DHS CISA

The agencies say it’s vital to prioritize patching. Otherwise, we’re making it easy for attackers who don’t have to work at finding 0 days. Continue reading Top 10 most exploited vulnerabilities list released by FBI, DHS CISA