#Citrixbleed

#MOVEit, #Capita, #CitrixBleed and more: The biggest #data #breaches of #2023

Hackers had a busy year exploiting popular file-transfer tools and targeting under-resourced organizations

techcrunch.com/2023/12/27/move

Hugo Tunius :rust:k0nserv@infosec.exchange
2023-12-21

The Church of Sweden(Svenska Kyrkan) was ransomwared on the 23rd of November. This is now being attributed to BlackCat.

Here's a #Citrixbleed vulnerable server serving a wildcard cert for *.svenskakyrkan.se, last scanned by Shodan on the 23rd. Probably not related at all

Shodan search result for hostname:*.svenskakyrkan.se http.favicon.hash:-1292923998,-1166125415 showing one match(195.67.170.34) running Netscalar Gateway
Marcel SIneM(S)USsimsus@social.tchncs.de
2023-12-21
Marcus "MajorLinux" Summersmajorlinux@toot.majorshouse.com
2023-12-20

Like I always say, update yo stuff!

Comcast held a virtual door open for thieves to steal data - Desk Chair Analysts

dcanalysts.net/comcast-held-a-

#Citrix #CitrixBleed #Comcast #InfoSec #Security #Xfinity #TechNews #DCA

"Comcast held a virtual door open for thieves to steal data" text laid over the Comcast logo.
Avoid the Hack! :donor:avoidthehack@infosec.exchange
2023-12-20

#Comcast Xfinity data breach affects over 35 million people

A #CitrixBleed fatality.

Data accessed includes customer usernames and hashed* passwords. Xfinity is forcing password changes next time you sign into an account.

In some cases data accessed may include:

- Last 4 of SSN
- DOBs
- Secret Questions / Answers exposed

#cybersecurity #security #infosec #xfinity

theverge.com/2023/12/18/240070

2023-12-19

#Comcast has disclosed a #CitrixBleed-related data breach which affected 35 million #Xfinity customers. The impacted info included names, contact information, last four digits of social security numbers, dates of birth and secret questions and answers.

@GossiTheDog

apps.web.maine.gov/online/aevi

@blogdiva Some of it is probably just #citrixbleed being a particularly nasty combination of a solid exploit for core software infrastructure that tons of big businesses use and habitually lag behind in patching, though of course that is itself on several levels a symptom of an overall problem with how American companies are being run.
2023-12-16

CTS, a cloud provider for legal firms in the UK, who were late patching #CitrixBleed, have appeared on Cactus ransomware's portal today.

They're offering downloads of CTS customer data. #threatintel

2023-12-13

Two days left to patch those Netscalers against #Citrixbleed before you're on change freeze for a month!

2023-12-07

Great take on HHS's #CitrixBleed alert in a recent edition of SANS NewsBites.

2023-12-04

Supply-chain ransomware attack causes outages at over 60 credit unions - Ransomware hits firm that providing cloud services to credit unions in order ensure that ... tripwire.com/state-of-security #vulnerability #citrixbleed #ransomware #databreach #guestblog #dataloss #malware

2023-12-04

Supply-chain ransomware attack causes outages at over 60 credit unions.

Read more in my article on the Tripwire blog: tripwire.com/state-of-security

#cybersecurity #databreach #ransomware #vulnerability #citrixbleed

Chain snapping in front of notification of cyber security incident.
Matthew Skeltonmatthewskelton
2023-12-04

"Payments to ransomware and extortion groups need to be outlawed. I know, I know, it will be hard and there’s a million reasons to argue against it and lots of vested interests who don’t want this. ... I mean it — ransomware payments to these groups need to be outlawed, internationally." - Kevin Beaumont (aka @GossiTheDog )

doublepulsar.com/what-it-means

2023-12-04

My mate Nessus here actually putting #citrixbleed lower down the risk rating than SSLv3.

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst