Critical Alert: Aussie orgs targeted in Citrix Netscaler hacking campaign | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker



The Australian Signals Directorate’s Australian Cyber Security Centre has updated its advice regarding exploitation of a pair of vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway products.

“The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) has received reports from Australian organisations confirming exploitation,” the agency said in an overnight Critical Alert.

You’re out of free articles for this month

“ASD’s ACSC recommends reviewing for evidence of compromise since at least 4 September 2026. Citrix has made indicators of compromise available through NetScaler Console and published additional guidance in their recent publication, Security Bulletin for CVE-2026-88771 through CVE-2026-88778.”

Citrix recently disclosed eight vulnerabilities in its ADC and Gateway products, but the pair above are the focus of the malicious activity.

“Organisations should consider internal security assessments and business plans, in determining how to effectively prioritise the implementation of this security update,” the ACSC said.

“In addition to applying the security update, organisations should review the pre-condition requirements for each of the CVEs to understand where they may have been vulnerable to exploitation.”

CVE-2026-88771 is a remote code execution vulnerability with a CVSS score of 9.5, while CVE-2026-88778 is a TCP Initial Sequence Number (ISN) prediction issue with a CVSS score of 8.8. The following product versions are impacted by the vulnerabilities.

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 BEFORE 14.1-73.37
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 BEFORE 13.1-64.23
  • Citrix NetScaler ADC FIPS BEFORE 14.1-73.37 FIPS
  • Citrix NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.279

Cyber security firm Arctic Wolf has been observing malicious activity and has released a threat intelligence report outlining hacker behaviour observed so far.

“Observed activity included command injection followed by payload retrieval, script execution, command-execution validation, reverse-shell attempts, and the retrieval of a Perl script with persistence, TCP listener, and system check-in functionality,” the company said.

Of particular concern is the use of a Perl-based tool that not only creates a TCP listener and collects host information, but also establishes and maintains persistence on compromised systems.

Cyber expert Kevin Beaumont believes the activity is unlikely to be criminal in nature.

“It’s a really interesting vuln scenario,” Beaumont said earlier this week.

“I’m tracking over 100 victim orgs now. Each one has a unique webshell which can’t be scanned for remotely unless you’re the attacker. It’s espionage.”

Click Here For The Original Source.

——————————————————–

……….

.

.





Source link

...........