GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 26-Aug-2025 21:28:30 JST Kevin Beaumont Kevin Beaumont

    There’s a bunch of new Netscaler vulns being exploited as zero days. Patches just out now.

    Preauth RCE being used to drop webshells to backdoor orgs. CVE-2025-7775 is the main problem.

    Orgs will need to do IR afterwards as technical details emerge of backdoor.

    https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938&articleTitle=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2025_7775_CVE_2025_7776_and_CVE_2025_8424

    In conversation about a year ago from cyberplace.social permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Loading...
    • Embed this notice
      tehfishman (tehfishman@ioc.exchange)'s status on Tuesday, 26-Aug-2025 21:58:38 JST tehfishman tehfishman
      in reply to

      @GossiTheDog cve 7775 instead of 5777. Practically manufactured to be easy to get confused.

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 26-Aug-2025 22:05:57 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Must be Tuesday.

      In conversation about a year ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/115/095/210/903/340/348/original/69fef6a43d5700dd.jpeg
    • Embed this notice
      Ciarán (mc) (ciaranmak@mastodon.ie)'s status on Tuesday, 26-Aug-2025 22:30:33 JST Ciarán (mc) Ciarán (mc)
      in reply to

      @GossiTheDog These arent the CISA ones from yesterday 🫣

      In conversation about a year ago permalink
    • Embed this notice
      Catalin Cimpanu (campuscodi@mastodon.social)'s status on Tuesday, 26-Aug-2025 22:35:42 JST Catalin Cimpanu Catalin Cimpanu
      • tehfishman

      @GossiTheDog @tehfishman so... the DeelbXirtic vulnerability?

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 27-Aug-2025 04:06:56 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Internet scanning for hosts vulnerable to CVE-2025-7775 (CitrixDeelb) has begun, will put up results tomorrow or Friday.

      In conversation about a year ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/115/096/610/568/633/920/original/946528d89975e12a.png
    • Embed this notice
      ⠠⠵ avuko (avuko@infosec.exchange)'s status on Wednesday, 27-Aug-2025 04:17:19 JST ⠠⠵ avuko ⠠⠵ avuko
      in reply to

      @GossiTheDog pretty please, not Friday.

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 27-Aug-2025 06:20:28 JST Kevin Beaumont Kevin Beaumont
      in reply to

      16% patch rate, 84% unpatched if anybody interested

      In conversation about a year ago permalink
    • Embed this notice
      Various_Canaries (various_canaries@cyberplace.social)'s status on Wednesday, 27-Aug-2025 08:26:12 JST Various_Canaries Various_Canaries
      in reply to

      @GossiTheDog ouch

      In conversation about a year ago permalink
    • Embed this notice
      Bildos (bildos@cyberplace.social)'s status on Wednesday, 27-Aug-2025 22:36:30 JST Bildos Bildos
      in reply to

      @GossiTheDog where I can find 7775 scan python script ?

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 28-Aug-2025 00:46:01 JST Kevin Beaumont Kevin Beaumont
      in reply to
      • Shodan

      Citrix Netscaler boxes presented to the internet over time, for anybody interested, pulled via @shodan

      In conversation about a year ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/115/101/496/418/190/982/original/c90ad953e3b5b920.png
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 28-Aug-2025 03:52:50 JST Kevin Beaumont Kevin Beaumont
      in reply to

      The NCSC have published an advisory on CVE-2025-7775 (CitrixDeelb), saying it is highly likely it will be mass exploited:

      https://advisories.ncsc.nl/2025/ncsc-2025-0268.html

      They've also published a script to check for post exploitation, i.e. backdoor access which persists post patching: https://github.com/NCSC-NL/citrix-2025/blob/main/live-host-bash-check/TLPCLEAR_check_script_cve-2025-6543-v1.8.sh

      In conversation about a year ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
        citrix-2025/live-host-bash-check/TLPCLEAR_check_script_cve-2025-6543-v1.8.sh at main · NCSC-NL/citrix-2025
        Contribute to NCSC-NL/citrix-2025 development by creating an account on GitHub.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 28-Aug-2025 03:54:54 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Cloud Software Group, who own Netscaler, have published their own blog about CVE-2025-7775 (CitrixDeelb)

      https://www.netscaler.com/blog/news/critical-security-update-announced-for-netscaler-gateway-and-netscaler/

      ...however they've incorrectly said it applies to IPv6 setups only. This is wrong. They've missed the "OR" statements from their own advisory.

      In conversation about a year ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/115/102/244/709/350/125/original/4eae173276716863.png

    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 28-Aug-2025 03:57:07 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Here's the Citrix advisory, if anybody knows anybody at Cloud Software Group please get them to correct the blog post - it's a repeat of the CitrixBleed 2 situation again where the wrong information has been published to customers again.

      In conversation about a year ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/115/102/251/230/760/444/original/f1330d6be0fca2ce.png
    • Embed this notice
      faebudo (faebudo@ioc.exchange)'s status on Thursday, 28-Aug-2025 05:56:24 JST faebudo faebudo
      in reply to

      @GossiTheDog As a non-native english speaker I understand "several independent preconditions" as "any of the following conditions can be true to fulfill the prerequisites for it to be exploitable".

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 28-Aug-2025 17:58:01 JST Kevin Beaumont Kevin Beaumont
      in reply to

      I've published scan results for CVE-2025-7775 (CitrixDeelb - which Bleed is spelt backwards as the CVE number is reverse of CitrixBleed2 :catjam: )

      Columns = IP, SSL hostnames, firmware version, vulnerable to CVE-2025-7775 exploitation.

      https://raw.githubusercontent.com/GossiTheDog/scanning/refs/heads/main/CVE-2025-7775-Citrix-Netscaler.csv

      In conversation about a year ago permalink
    • Embed this notice
      brummelbär (brummelbaer@infosec.exchange)'s status on Thursday, 28-Aug-2025 19:55:52 JST brummelbär brummelbär
      in reply to
      • Marius
      • FL | エフル

      @fl @fere @GossiTheDog Same here, but that's to be expected in an evolving situation

      In conversation about a year ago permalink
    • Embed this notice
      Marius (fere@infosec.exchange)'s status on Thursday, 28-Aug-2025 19:55:53 JST Marius Marius
      in reply to

      @GossiTheDog These results are atleast 20 hours old? I can confirm one hit on your list is in fact patched.

      In conversation about a year ago permalink
    • Embed this notice
      FL | エフル (fl@infosec.exchange)'s status on Thursday, 28-Aug-2025 19:55:53 JST FL | エフル FL | エフル
      in reply to
      • Marius

      @fere @GossiTheDog same thing, some entries in the list are either false positive or the scan is old

      In conversation about a year ago permalink
    • Embed this notice
      brummelbär (brummelbaer@infosec.exchange)'s status on Thursday, 28-Aug-2025 21:38:03 JST brummelbär brummelbär
      • Marius
      • FL | エフル

      @GossiTheDog @fl @fere That's great, thank you! Does anybody know if there are some IOCs out there or some additional details for the already exploited instances that would help in a compromise assessment?

      In conversation about a year ago permalink
    • Embed this notice
      Just_Patch_It (just_patch_it@cyberplace.social)'s status on Friday, 29-Aug-2025 02:13:25 JST Just_Patch_It Just_Patch_It
      in reply to

      @GossiTheDog how did you pull the versions?

      In conversation about a year ago permalink
    • Embed this notice
      lfzz (lfzz@mastodon.social)'s status on Friday, 29-Aug-2025 05:35:44 JST lfzz lfzz
      in reply to

      @GossiTheDog what is going to happen now that every permutation and bad word play of ctrix bleed had been used? I can't keep calling people ask what did they do about citrix vulnerability. Its not even funny.

      In conversation about a year ago permalink
    • Embed this notice
      Face Thumb (chrisp@cyberplace.social)'s status on Saturday, 30-Aug-2025 08:16:57 JST Face Thumb Face Thumb

      @GossiTheDog That gif is udderly ridiculous

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 01-Sep-2025 00:31:48 JST Kevin Beaumont Kevin Beaumont

      Updated scan results for CVE-2025-7775 aka CitrixDeelb

      https://github.com/GossiTheDog/scanning/blob/main/CVE-2025-7775-Citrix-Netscaler.csv

      Next results probably Tuesday

      In conversation about a year ago permalink

      Attachments


    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 01-Sep-2025 22:50:39 JST Kevin Beaumont Kevin Beaumont
      in reply to
      • The Shadowserver Foundation

      .@shadowserver results on CVE-2025-7775 patchin'

      In conversation about a year ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/115/129/295/264/945/107/original/ed25a792a3cbbe3b.png
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 01-Sep-2025 23:10:07 JST Kevin Beaumont Kevin Beaumont
      in reply to

      A kind of interesting thing from scanning Netscalers for the past month and a bit is the number that have gone offline - it's down over a thousand boxes month on month.

      In conversation about a year ago permalink
      GreenSkyOverMe (Monika) repeated this.
    • Embed this notice
      fosec (fosec@infosec.exchange)'s status on Monday, 01-Sep-2025 23:20:43 JST fosec fosec
      in reply to

      @GossiTheDog Do the network scans accurately find NetScalers if the ADC is configured for SAML and immediately redirects to the SSO login page?

      In conversation about a year ago permalink
    • Embed this notice
      Eckes :mastodon: (eckes@zusammenkunft.net)'s status on Tuesday, 02-Sep-2025 01:31:08 JST Eckes :mastodon: Eckes :mastodon:
      in reply to

      @GossiTheDog or they hide the signature as they notice they are exposed and get outcalled. But it is likely that Infrastructure More and more moves to the Cloud?

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 02-Sep-2025 19:53:21 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Updated scan results for CVE-2025-7775 aka CitrixDeelb

      https://github.com/GossiTheDog/scanning/blob/main/CVE-2025-7775-Citrix-Netscaler.csv

      Next results Thursday

      In conversation about a year ago permalink

      Attachments



    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 02-Sep-2025 20:02:13 JST Kevin Beaumont Kevin Beaumont
      in reply to

      If anybody is wondering the NSA patched CitrixDeelb pretty quickly. They've made some changes to stop scanning, but they'll be back in the next results.

      103.41.70.207,vdicorp.nsa.gov,13.1-59.22,Wed, 20 Aug 2025 12:26:13 GMT,NOT_VULNERABLE

      Re: https://cyberplace.social/@GossiTheDog/114823552387000273

      In conversation about a year ago permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        Kevin Beaumont (@GossiTheDog@cyberplace.social)
        from Kevin Beaumont
        Good news everybody, the NSA have patched this week 103.41.70.207,vdicorp.nsa.gov,13.1-59.19,NOT_VULNERABLE They were 7 months behind with patching.
    • Embed this notice
      Dave Pimlott (quikkie@infosec.exchange)'s status on Tuesday, 02-Sep-2025 22:26:22 JST Dave Pimlott Dave Pimlott
      in reply to

      @GossiTheDog 13.1 is EOL for over a year. The public announcement said that 13.1 was vulnerable and that no 13.1 patches were being released so I'm surprised to see an ADC running 13.1 that is listed as not vulnerable or is that an artifact of the changes that the NSA made?

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 03-Sep-2025 21:58:07 JST Kevin Beaumont Kevin Beaumont
      in reply to

      This blog by CheckPoint about AI LLM generating an exploit for CVE-2025-7775 is complete bollocks - it’s a bunch of fan fiction.

      The threat actor was talking about an old Netscaler vuln.

      https://blog.checkpoint.com/executive-insights/hexstrike-ai-when-llms-meet-zero-day-exploitation/

      In conversation about a year ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: blog.checkpoint.com
        Hexstrike-AI: LLM Orchestration Driving Real-World Zero-Day Exploits
        from rohann@checkpoint.com
        Researchers analyze Hexstrike-AI, a next-gen AI orchestration framework linking LLMs with 150+ security tools—now repurposed by attackers to weaponize Citrix NetScaler zero-day CVEs in minutes.
    • Embed this notice
      Yun (yun@infosec.exchange)'s status on Friday, 05-Sep-2025 01:44:19 JST Yun Yun
      in reply to
      • Just_Patch_It

      @Just_Patch_It @GossiTheDog I maintain the NetScaler version info here: https://github.com/fox-it/citrix-netscaler-triage/blob/main/scan-citrix-netscaler-version.py

      In conversation about a year ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
        citrix-netscaler-triage/scan-citrix-netscaler-version.py at main · fox-it/citrix-netscaler-triage
        Dissect triage scripts for Citrix NetScaler devices - fox-it/citrix-netscaler-triage
    • Embed this notice
      Just_Patch_It (just_patch_it@cyberplace.social)'s status on Friday, 05-Sep-2025 01:44:21 JST Just_Patch_It Just_Patch_It
      in reply to

      @GossiTheDog Bump

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 05-Sep-2025 03:04:15 JST Kevin Beaumont Kevin Beaumont

      Updated scan results for CVE-2025-7775 aka CitrixDeelb

      https://github.com/GossiTheDog/scanning/blob/main/CVE-2025-7775-Citrix-Netscaler.csv

      Next (and probably final) results Saturday

      In conversation about a year ago permalink

      Attachments



Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.