GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 21-Jun-2025 00:52:51 JST Kevin Beaumont Kevin Beaumont

    Citrix Netscaler customers - keep calm and patch CVE-2025-5777 from Tuesday.

    It allows unauth memory reads, has similarities to CitrixBleed (CVE-2023-4966) as may allow session token theft.

    In conversation about a year ago from cyberplace.social permalink
    • Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      LongHorn (longhorn@cyberplace.social)'s status on Saturday, 21-Jun-2025 10:21:46 JST LongHorn LongHorn
      in reply to

      @GossiTheDog Here is a joke:
      It didn't scale.

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 24-Jun-2025 23:27:13 JST Kevin Beaumont Kevin Beaumont
      in reply to

      An update on CVE-2025-5777, explaining why orgs should identify systems and patch.

      https://doublepulsar.com/citrixbleed-2-electric-boogaloo-cve-2025-5777-c7f5e349d206

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 25-Jun-2025 04:09:45 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Worth noting that every write up says this vuln applies to the management interface - but that hasn’t true, it’s because the initial CVE entry was wrong, and nobody does CVE entry updates in write ups.

      In conversation about a year ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/114/739/914/543/633/846/original/05f13e42cf7d8e9d.jpeg

      2. https://cyberplace.social/system/media_attachments/files/114/739/914/794/834/057/original/afe83e2aec35116e.jpeg

      3. https://cyberplace.social/system/media_attachments/files/114/739/915/105/896/143/original/2b34d8786359d203.jpeg

      4. https://cyberplace.social/system/media_attachments/files/114/739/915/370/373/323/original/5027d93c26e9d3e6.jpeg
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 25-Jun-2025 16:53:21 JST Kevin Beaumont Kevin Beaumont
      in reply to

      A bit more on this. https://www.theregister.com/2025/06/24/critical_citrix_bug_citrixbleed/

      In conversation about a year ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: regmedia.co.uk
        Up next on the KEV? All signs point to 'CitrixBleed 2'
        : Why are you even reading this story? Patch now!
    • Embed this notice
      fuzzyfuzzyfungus (fuzzyfuzzyfungus@cyberplace.social)'s status on Wednesday, 25-Jun-2025 21:37:30 JST fuzzyfuzzyfungus fuzzyfuzzyfungus
      in reply to

      @GossiTheDog I hope nobody is still misled by the pre-correction CVE into thinking that this is just a 'mitigate by controlling access to management interface like you should probably do anyway' thing that they can just defer to lower priority maintenance.

      Relatively severe either way; but that teensy little correction was not loud enough for how dramatically an otherwise plausible mitigation turned out to be useless.

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 25-Jun-2025 21:48:36 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Citrix on this one:

      "At this time, there have been no reports or indications that the vulnerabilities described in CTX693420 (CVE-2025-5349 and CVE-2025-5777) are being actively exploited in the wild. However, due to the critical severity of these issues (CVSS scores of 8.7 and 9.3), We strongly recommends that affected customers apply the updated patches immediately to mitigate any potential risks."

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 25-Jun-2025 21:51:37 JST Kevin Beaumont Kevin Beaumont
      in reply to

      NHS Digital's cyber alert database has been updated too. https://digital.nhs.uk/cyber-alerts/2025/cc-4670

      I highly recommend bookmarking this site for the alerts, they're really good at filtering noise:

      https://digital.nhs.uk/cyber-alerts

      E.g. if you select 'high' category, there's only one a month on average

      In conversation about a year ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/114/744/081/453/775/232/original/d2a60aa2f5f34b29.png


    • Embed this notice
      Dennis Haverkamp (dhaverkamp@infosec.exchange)'s status on Wednesday, 25-Jun-2025 23:09:33 JST Dennis Haverkamp Dennis Haverkamp
      in reply to

      @GossiTheDog Citrix just published a new Bulletin for CVE-2025-6543 (CVSS 9.2)

      https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694788

      In conversation about a year ago permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        Loading...
    • Embed this notice
      MemoryLeech (cyberleech@cyberplace.social)'s status on Friday, 27-Jun-2025 01:20:57 JST MemoryLeech MemoryLeech

      @GossiTheDog FOAF (essentially hearsay) will let you know when there's something more.

      In conversation about a year ago permalink
    • Embed this notice
      MemoryLeech (cyberleech@cyberplace.social)'s status on Friday, 27-Jun-2025 05:23:13 JST MemoryLeech MemoryLeech

      @GossiTheDog

      I was sent this for reference:

      https://reliaquest.com/blog/threat-spotlight-citrix-bleed-2-vulnerability-in-netscaler-adc-gateway-devices/

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 27-Jun-2025 05:28:26 JST Kevin Beaumont Kevin Beaumont
      in reply to
      • MemoryLeech

      ReliaQuest are reporting with medium confidence that CitrixBleed2, Electric Boogaloo, is being exploited in the world HT @CyberLeech https://reliaquest.com/blog/threat-spotlight-citrix-bleed-2-vulnerability-in-netscaler-adc-gateway-devices/

      In conversation about a year ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/114/751/549/554/776/634/original/63348d05d665b7fa.jpeg
      2. Domain not in remote thumbnail source whitelist: resources.reliaquest.com
        Threat Spotlight: CVE-2025-5777: Citrix Bleed 2 Opens Old Wounds - ReliaQuest
        CVE-2025-5777 poses serious threats to Citrix Netscaler devices—discover recommended actions to block exploitation and protect accounts from Citrix Bleed 2.
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 27-Jun-2025 05:34:03 JST Kevin Beaumont Kevin Beaumont
      in reply to

      My view on that is I don’t have the data to back it up (because Citrix haven’t provided any way to identify exploitation, including to customers), but if true and the threat actor is running those tools with that provider, it’s probably a ransomware group again.

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 01-Jul-2025 18:36:56 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Citrix blog on CVE-2025-5777 and some other ones https://www.netscaler.com/blog/news/netscaler-critical-security-updates-for-cve-2025-6543-and-cve-2025-5777/

      In conversation about a year ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: www.netscaler.com
        NetScaler Critical Security Updates for CVE-2025-6543 and CVE-2025-5777
        from Anil Shetty
        Over the past two weeks, Cloud Software Group has released builds to address CVE-2025-6543 and CVE 2025-5777, which affect NetScaler ADC and NetScaler Gateway if they are configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR an Authentication Authorization and Auditing (“AAA”) virtual server. While both of the vulnerabilities involve the same modules, the exposures differ. CVE 2025-6543, if exploited, could lead to a memory overflow vulnerability, resulting in unintended control flow and Denial of Service. CVE 2025-5777 arises from insufficient input validation that leads to memory overread. 
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 01-Jul-2025 18:43:16 JST Kevin Beaumont Kevin Beaumont
      in reply to

      If you see this GitHub PoC for CVE-2025-5777 doing the rounds:

      https://github.com/mingshenhk/CitrixBleed-2-CVE-2025-5777-PoC-

      It’s not for CVE-2025-5777. It’s AI generated. The links in the README still have ChatGPT UTM sources.

      The PoC itself is for a vuln addressed in 2023 - ChatGPT has hallucinated (made up) the cause of the vuln using an old BishopFox write up of the other vuln.

      In conversation about a year ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 01-Jul-2025 18:47:08 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Evidence if anybody cares

      In conversation about a year ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/114/777/338/654/840/171/original/eeebc832bcee3d25.jpeg

      2. https://cyberplace.social/system/media_attachments/files/114/777/338/980/825/343/original/f8e919b9579262ff.jpeg

      3. https://cyberplace.social/system/media_attachments/files/114/777/339/276/535/112/original/1711b6f63d933e6b.jpeg
    • Embed this notice
      fuzzyfuzzyfungus (fuzzyfuzzyfungus@cyberplace.social)'s status on Tuesday, 01-Jul-2025 19:07:54 JST fuzzyfuzzyfungus fuzzyfuzzyfungus
      in reply to

      @GossiTheDog Is it normal for the IoCs section to just be "we are committed to transparency" followed by "If you encounter issues when updating your affected builds or need access to IoCs, please contact Citrix Customer Support"?

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 02-Jul-2025 05:53:58 JST Kevin Beaumont Kevin Beaumont
      in reply to

      I’ve heard that Citrix are complaining me billing this CitrixBleed 2 is causing them reputational damage, and isn’t related in any way to CitrixBleed.

      For the record - it was a dumb joke name to attraction attention for patching. I know it isn’t exactly the same cause.

      But, ya know, it is a memory disclosure vuln which reveals sensitive info, and it does require ICA sessions be reset.. which only happened before with CitrixBleed.

      In conversation about a year ago permalink
    • Embed this notice
      :rainbowCrow: (cr0w@infosec.exchange)'s status on Wednesday, 02-Jul-2025 06:08:39 JST :rainbowCrow: :rainbowCrow:
      in reply to

      @GossiTheDog

      Some commentators have drawn comparisons between CVE 2025-5777 and CVE 2023-4966. While the vulnerabilities share some characteristics, Cloud Software Group has found no evidence to indicate that they are related.

      Emphasis theirs. 🤣

      In conversation about a year ago permalink
    • Embed this notice
      :rainbowCrow: (cr0w@infosec.exchange)'s status on Wednesday, 02-Jul-2025 06:25:45 JST :rainbowCrow: :rainbowCrow:

      @GossiTheDog I also like Cloud Software Group does not provide forensic analysis; however, customers can contact Citrix Customer Support to get access to IoCs.

      And

      Does CVE 2025-6543 constitute a zero day vulnerability?

      Cloud Software Group became aware of limited exploitation activity before the patch was released.

      In conversation about a year ago permalink
    • Embed this notice
      microwavetacos (microwavetacos@infosec.exchange)'s status on Wednesday, 02-Jul-2025 06:41:56 JST microwavetacos microwavetacos
      in reply to
      • :rainbowCrow:

      @cR0w @GossiTheDog the only IOCs they will release is via a technical support request for CVE 2025-6543 and is literally a script that looks for a handful of vulnerable conditions and file types in locations they shouldnt be. No public IPs, domains, filenames, etc

      In conversation about a year ago permalink
    • Embed this notice
      Various_Canaries (various_canaries@cyberplace.social)'s status on Wednesday, 02-Jul-2025 11:19:38 JST Various_Canaries Various_Canaries
      in reply to

      @GossiTheDog What about "Electric Bugaloo?" Lmao I bet they love that

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 04-Jul-2025 17:27:38 JST Kevin Beaumont Kevin Beaumont
      in reply to

      I expect technical details of CVE-2025-5777 exploitation to become available next week.

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 04-Jul-2025 19:20:25 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Further suggestions CVE-2025-5777 details will release next week. https://xcancel.com/Horizon3Attack/status/1940879804221522279

      In conversation about a year ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/114/794/456/919/613/568/original/0921a0c3f60d7577.png

    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 04-Jul-2025 19:39:24 JST Kevin Beaumont Kevin Beaumont
      in reply to

      I've published my scan in progress of CVE-2025-5777 patching status, listing IPs, hostnames, Citrix Netscaler build numbers and if they're vulnerable to CitrixBleed2.

      The scan isn't finished yet so these are only about a quarter of the results - unfortunately my coding skills are shite and it's really slow - should be finished over weekend or early next week.

      Also, the SSL certificate hostnames are separated by comma which throws out CSV - sorry, I'll fix that later.

      https://github.com/GossiTheDog/scanning/blob/main/CVE-2025-5777-CitrixBleed2-ElectricBoogaloo-patching.txt

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 04-Jul-2025 19:43:07 JST Kevin Beaumont Kevin Beaumont
      in reply to

      If anybody is wondering btw it's 4047 definitely vulnerable (so far) from 17021 scanned instances - so 24% unpatched after about 3 weeks.

      But scan is still running obvs so the vuln number will keep growing.

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 04-Jul-2025 20:03:22 JST Kevin Beaumont Kevin Beaumont
      in reply to

      If anybody likes stats

      - Of the 42 identified NHS Netscalers so far, 37 are patched🥳 The NHS are really good at this nowadays.

      - Of the 65 identified .gov.uk Netscalers so far, only 48 are patched 😅 All of the unpatched are councils, which are obviously severely budget constrained in many cases - I'm also not sure they actually know they're supposed to be patching.

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 05-Jul-2025 06:10:04 JST Kevin Beaumont Kevin Beaumont
      in reply to

      First exploitation details for CVE-2025-5777 - the Netscaler vuln - are out. https://labs.watchtowr.com/how-much-more-must-we-bleed-citrix-netscaler-memory-disclosure-citrixbleed-2-cve-2025-5777/

      If you call the login page, it leaks memory in the response 🤣

      I don’t want to specify too much extra technical info on this yet - but if you keep leaking the memory via requests, there’s a way to reestablish existing ICA sessions from the leaked memory.

      In conversation about a year ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/114/797/007/484/168/699/original/28d471252a805cad.jpeg

    • Embed this notice
      Alex (alex02@cyberplace.social)'s status on Saturday, 05-Jul-2025 11:54:33 JST Alex Alex
      in reply to

      @GossiTheDog would this take 3 out of 6 months to find perl developers or am I thinking of a different vulnerability?

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Sunday, 06-Jul-2025 04:47:51 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Updated scan results for CVE-2025-5777: https://github.com/GossiTheDog/scanning/blob/main/CVE-2025-5777-CitrixBleed2-ElectricBoogaloo-patching.txt

      It's still partial due to bugs, but about 18k servers.

      In conversation about a year ago permalink

      Attachments


    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 07-Jul-2025 21:05:00 JST Kevin Beaumont Kevin Beaumont
      in reply to

      CVE-2025-5777 is under active exploitation, since before the WatchTowr blog.

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 08-Jul-2025 01:53:46 JST Kevin Beaumont Kevin Beaumont
      in reply to

      CVE-2025-5777 (Citrix Netscaler vuln) has been under active exploitation since mid June, with people dumping memory and using this to try to access sessions.

      TTPs to hunt for:

      - In Netscaler logs, large and repeated POST requests to *doAuthentication* - each one yields 126 bytes of RAM

      - In Netscaler logs, requests to doAuthentication.do with "Content-Length: 5"

      - In Netscaler user logs, lines with *LOGOFF* and user = "*#*" (i.e. # symbol in the username). RAM is played into the wrong field.

      In conversation about a year ago permalink

      Attachments


    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 08-Jul-2025 02:03:04 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Horizon3 have a good write up here, I don't think they were aware this is already being exploited for almost a month: https://horizon3.ai/attack-research/attack-blogs/cve-2025-5777-citrixbleed-2-write-up-maybe/

      Worth noting I was only able to find exploitation activity due to the WatchTowr and Horizon3 write ups - Citrix support wouldn't disclose any IOCs and incorrectly claimed (again - happened with CitrixBleed) that no exploitation in the wild. Citrix have gotta get better at this, they're harming customers.

      In conversation about a year ago permalink

      Attachments


    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 08-Jul-2025 02:15:27 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Just to be super clear, although Citrix claim that CitrixBleed 2 is in no way related to CitrixBleed, it allows direct session token theft - Citrix are wrong. Horizon3 have the POC and it's already being exploited - Citrix were also wrong.

      "Not the most novel thing in the world… but this is much much worse than it initially appears. Take a look at the following video where you’ll see that it’s possible to receive legitimate user session tokens via this vector. "

      In conversation about a year ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/114/813/067/576/799/968/original/98ff0983f5109205.png
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 08-Jul-2025 07:33:44 JST Kevin Beaumont Kevin Beaumont
      in reply to
      • Glenn 📎
      • GreyNoise

      Exploitation IOCs for CVE-2025-5777 aka CitrixBleed 2, these are actively stealing sessions to bypass MFA for almost a month. Some are also doing Netscaler fingerprint scanning first.

      64.176.50.109
      139.162.47.194
      38.154.237.100
      38.180.148.215
      102.129.235.108
      121.237.80.241
      45.135.232.2

      HT @ntkramer and the folks at @greynoise

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 08-Jul-2025 22:50:10 JST Kevin Beaumont Kevin Beaumont
      in reply to
      • GreyNoise

      More from @greynoise telemetry - they now push CVE-2025-5777 (CitrixBleed 2) exploitation to June 23rd. I can push it back further, blog incoming.

      In conversation about a year ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/114/817/924/304/812/273/original/367a8c9f8ece8105.png
    • Embed this notice
      husjon (husjon@fosstodon.org)'s status on Tuesday, 08-Jul-2025 23:35:09 JST husjon husjon
      in reply to

      @GossiTheDog I'm glad to see my image contribution is still going strong with new iterations 😅
      (original: https://fosstodon.org/@husjon/111308387657992171)

      In conversation about a year ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: cdn.fosstodon.org
        husjon.dev (@husjon@fosstodon.org)
        from husjon.dev
        Attached: 1 image @GossiTheDog@cyberplace.social Patch applied
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 08-Jul-2025 23:52:18 JST Kevin Beaumont Kevin Beaumont
      in reply to

      I wrote up a thing on how to hunt for CitrixBleed 2 exploitation

      https://doublepulsar.com/citrixbleed-2-exploitation-started-mid-june-how-to-spot-it-f3106392aa71

      In conversation about a year ago permalink
    • Embed this notice
      Lowlands (lowlands@infosec.exchange)'s status on Tuesday, 08-Jul-2025 23:53:54 JST Lowlands Lowlands
      in reply to

      @GossiTheDog seeing the first hits from one of the mentioned IPs on 6/20.

      In conversation about a year ago permalink
    • Embed this notice
      Lowlands (lowlands@infosec.exchange)'s status on Wednesday, 09-Jul-2025 00:23:45 JST Lowlands Lowlands

      @GossiTheDog 64[.]176[.]50[.]109

      In conversation about a year ago permalink
    • Embed this notice
      Ketumbra (ketumbra@infosec.exchange)'s status on Wednesday, 09-Jul-2025 00:26:12 JST Ketumbra Ketumbra
      in reply to

      @GossiTheDog "I wrote this vuln back on June 24th..."
      Pretty sure that's not what you meant ;)

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 09-Jul-2025 05:31:24 JST Kevin Beaumont Kevin Beaumont
      in reply to

      There’s 7 more IPs on GreyNoise exploiting CitrixBleed 2 today, all marked as malicious. https://viz.greynoise.io/query/tags:%22CitrixBleed%202%20CVE-2025-5777%20Attempt%22%20last_seen:90d

      In conversation about a year ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/114/819/508/748/835/239/original/7d845c9222f73d07.jpeg
      2. Domain not in remote thumbnail source whitelist: viz.greynoise.io
        GreyNoise Visualizer | GreyNoise Visualizer
        At GreyNoise, we collect and analyze untargeted, widespread, and opportunistic scan and attack activity that reaches every server directly connected to the Internet.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 09-Jul-2025 20:33:44 JST Kevin Beaumont Kevin Beaumont
      in reply to

      “Citrix declined to say if it's aware of active exploitation”

      It is aware. https://arstechnica.com/security/2025/07/critical-citrixbleed-2-vulnerability-has-been-under-active-exploit-for-weeks/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social

      In conversation about a year ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: cdn.arstechnica.net
        Critical CitrixBleed 2 vulnerability has been under active exploit for weeks
        Exploits allow hackers to bypass 2FA and commandeer vulnerable devices.
    • Embed this notice
      JJ (guitarfosec@cyberplace.social)'s status on Wednesday, 09-Jul-2025 23:23:06 JST JJ JJ
      in reply to

      @GossiTheDog Thanks so much for this info and for all the info provided prior to this. I was able to confirm with our Citrix team two weeks ago that we were patched already, and I'm just getting emails this week from higher ups to look into this, so I'm very much ahead of the game.

      Aside from social media, is there anywhere you suggest keeping an eye on daily for vulnerability info?

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 10-Jul-2025 02:27:51 JST Kevin Beaumont Kevin Beaumont
      in reply to

      I believe Citrix may have made a mistake in the patching instructions for CitrixBleed2 aka CVE-2025-5777.

      They say to do the instructions on the left, but they appear to have missed other session types (e.g. AAA) which have session cookies that can be stolen and replayed with CitrixBleed2. On the right is the CitrixBleed1 instructions.

      The net impact is, if you patched but a threat actor already took system memory, they can still reuse prior sessions.

      In conversation about a year ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/114/824/439/237/364/960/original/2cceb243f6def81c.png

      2. https://cyberplace.social/system/media_attachments/files/114/824/445/741/417/263/original/6b5bf99f292f749b.png
    • Embed this notice
      TheTomas (thetomas@social.toot9.de)'s status on Thursday, 10-Jul-2025 02:36:16 JST TheTomas TheTomas
      in reply to

      @GossiTheDog First Victims in Switzerland and Germany

      https://www.borncity.com/blog/2025/07/09/it-ausfall-bei-ameos-klinikverbund-folge-eines-cyberangriffs/

      In conversation about a year ago permalink
    • Embed this notice
      fuzzyfuzzyfungus (fuzzyfuzzyfungus@cyberplace.social)'s status on Thursday, 10-Jul-2025 10:56:19 JST fuzzyfuzzyfungus fuzzyfuzzyfungus
      in reply to

      @GossiTheDog Obviously this is a Ripley Protocol type of situation; but is it known how long the session cookies would be expected to remain valid if not explicitly purged? Configurable and wide variation in plausible values? Life of connection until manual or enforced disconnect? Fixed or very likely default number of minutes after successful authentication?

      In conversation about a year ago permalink
    • Embed this notice
      Jérôme Meyer (jmeyer@infosec.exchange)'s status on Friday, 11-Jul-2025 03:31:58 JST Jérôme Meyer Jérôme Meyer
      in reply to

      @GossiTheDog I had a look at network traffic from today and some of them are proxy exit nodes; some do broad IoT scanning.

      Two of them really stick out as they seem to exclusively target Citrix endpoints: 78.128.113.30 and 38.54.59.96

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 11-Jul-2025 04:32:52 JST Kevin Beaumont Kevin Beaumont
      in reply to

      CISA have modified the CVE-2025-5777 entry to link to my blog 🙌 I’m hoping this gets more visibility as a bunch of us can see from Netflow ongoing threat actor Netscaler sessions to.. sensitive orgs.

      In conversation about a year ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/114/830/600/899/485/982/original/533003b4817313ab.png
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 11-Jul-2025 05:09:24 JST Kevin Beaumont Kevin Beaumont
      in reply to

      CVE-2025-5777 aka CitrixBleed 2 has been added to CISA KEV now over evidence of active exploitation.

      Citrix are still declining to comment about evidence of exploitation as of writing.

      https://www.cisa.gov/news-events/alerts/2025/07/10/cisa-adds-one-known-exploited-vulnerability-catalog

      In conversation about a year ago permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        CISA Adds One Known Exploited Vulnerability to Catalog | CISA
    • Embed this notice
      Phil (h0ru2@cyberplace.social)'s status on Friday, 11-Jul-2025 09:32:09 JST Phil Phil
      in reply to

      @GossiTheDog Congratulations

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 11-Jul-2025 14:44:50 JST Kevin Beaumont Kevin Beaumont
      in reply to

      https://www.theregister.com/2025/07/10/cisa_citrixbleed_kev/

      In conversation about a year ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: regmedia.co.uk
        CISA agrees that CitrixBleed 2 is under exploit
        : Add CISA to the list
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 11-Jul-2025 14:53:20 JST Kevin Beaumont Kevin Beaumont
      in reply to

      This is how Citrix are styling Citrix Bleed 2 btw. In the blog there’s no technical details or detection details or acknowledgement of exploitation.

      From Netflow I can see active victims - including systems owned by the US federal government - so strap in to see where this goes.

      In conversation about a year ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/114/833/043/171/340/880/original/87a5d9a9bee842bd.jpeg
    • Embed this notice
      『g r e y』 :uv: ☦️ (grey@poa.st)'s status on Friday, 18-Jul-2025 23:34:12 JST 『g r e y』  :uv: ☦️ 『g r e y』 :uv: ☦️
      in reply to
      @GossiTheDog
      In conversation about a year ago permalink

      Attachments


Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.