logo

Mass exploitation of CitrixBleed vulnerability, including a ransomware group

ID: af5cccee-4848-57d3-a03e-ae3a8d044e55

STIX ID: report--af5cccee-4848-57d3-a03e-ae3a8d044e55

Feed Name: DoublePulsar

Threat Score
85/100

Date Published: 2023-10-27

Date Updated: 2026-04-19

Author: Kevin Beaumont

...
...

A public write-up on CitrixBleed (CVE-2023-4966) describes a memory disclosure in Citrix Netscaler/ADC that leaks session tokens enabling attackers to bypass login and multi-factor authentication by replaying stolen tokens; the author provides exploit details (a crafted GET with an extremely long Host header), detection guidance (grep logs for GetUserName traffic and GreyNoise-listed IPs), remediation steps (apply vendor patch and invalidate sessions), and reports mass exploitation and at least two ransomware groups actively abusing the flaw.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.