logo

Citrix shares mitigations for ongoing Netscaler password spray attacks

ID: 687d1cce-fda5-5ffa-8ccd-b023557a736a

STIX ID: report--687d1cce-fda5-5ffa-8ccd-b023557a736a

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-12-13

Date Updated: 2026-03-27

Author: Lawrence Abrams

...
...

Widespread password-spraying attacks targeting Citrix NetScaler appliances have been observed since November, with some victims reporting 20,000 to 1,000,000 brute-force attempts; the activity is attributed to broad, distributed IP sources that complicate IP blocking and can cause authentication overload or service disruption. Citrix and Germany's BSI issued advisories and recommended mitigations including enforcing MFA before LDAP, creating responder policies to restrict FQDNs, blocking unnecessary pre-nFactor endpoints, and using WAFs; mitigations apply to on-prem/cloud appliances on firmware ≥13.0.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.