Skip to main content

Share story

Security Infrastructure

Two unpatched NetScaler flaws reportedly exploited in attacks

Two unpatched NetScaler flaws reportedly exploited in attacks Image: Primary
Security firm watchTowr says attackers have exploited two previously undisclosed flaws that could allow remote code execution on Citrix NetScaler appliances. The firm said it identified the flaws during forensic investigations and expects Citrix communications and fixes early next week. Citrix had not issued an advisory for the reported flaws when the article was written. Without affected build numbers or technical details, administrators cannot determine from this report alone which appliances are vulnerable. Some organizations have reportedly shut down internet-exposed NetScaler systems, potentially interrupting VPN access and application delivery.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from cybersecuritynews.com and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security Infrastructure
Security Infrastructure

Researchers find personal data exposed in around 16,000 Supabase databases

Security firm UpGuard found around 16,000 databases hosted by Supabase with some personal data exposed to the public web, TechCrunch reports. The accessible information included names, addresses and phone numbers; a smaller number...

Security Infrastructure
Security Infrastructure

Kiteworks urges customers to shut down systems over potential attack

Kiteworks has urged customers to shut down their file transfer systems before the weekend after receiving what it called credible law enforcement intelligence about a possible attack, TechCrunch reports. The company recommended a ...

Infrastructure Security
Infrastructure Security

Amazon Transcribe lets customers choose encryption keys for custom resources

Amazon Transcribe now lets customers encrypt stored custom vocabularies, vocabulary filters and language models with an AWS key they manage. Previously, AWS-owned keys always protected those resources. Customers can supply their o...

Infrastructure Security
Infrastructure Security

AWS adds private access to identity verification endpoints

AWS says workloads in restricted virtual private clouds can now retrieve identity verification metadata and public keys through private network endpoints. Previously, those discovery endpoints were reachable only over the public i...

Security
Security

Attackers evade firewall rules to exploit Oracle PeopleSoft flaw

Attackers have renewed widespread exploitation of an Oracle PeopleSoft vulnerability by altering requests to evade web application firewall rules, Google's Mandiant said. The campaign has targeted organizations in several sectors,...

Infrastructure Capital
Infrastructure Capital

Nscale secures $3.36 billion in financing ahead of planned IPO

British AI data center developer Nscale said it secured $3.36 billion in convertible-note financing ahead of a planned US stock-market listing. The Third Point-led deal makes $2.36 billion available immediately, while a further $1...