Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data.

LevelBlue’s Threat Hunt Operations & Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Emily Bender Sets the Record Straight on “Stochastic Parrots”

Emily Bender Sets the Record Straight on “Stochastic Parrots” Source: Hacker News

Astra and Fable still hack on simple variants of alignment evals from 2025

Astra and Fable still hack on simple variants of alignment evals from 2025 Source: Hacker News

AI demands more engineering discipline. Not less

AI demands more engineering discipline. Not less Source: Hacker News