A widespread campaign exploited critical flaws in Citrix NetScaler ADC and Gateway - two high-severity vulnerabilities (CVE-2026-88771 and CVE-2026-88772, each scored 9.5) that allow remote code execution and memory-corruption attacks. Security firms attribute the intrusions to actors with state-linked sophistication and report impacts across government, healthcare, energy, finance, education and other sectors in Europe and North America. Researchers and incident responders have identified dozens to scores of compromised organizations (Arctic Wolf cites at least 78), Shadowserver reports over 20,000 exposed NetScaler instances, and some hospitals temporarily suspended patient portals after taking NetScaler systems offline. U.S. and European authorities added the flaws to exploited-vulnerability lists and issued emergency mitigation warnings.
Analysis traces activity back to late August/early September, during which attackers modified Apache configurations to interpret arbitrary files as PHP and deployed custom tools including a PHP webshell called Whipshot (which hides Base64 C2 payloads in HTTP headers) and a Python tunneler named Slapshot for reconnaissance and credential theft. Citrix published patches and specific fixed builds; responders emphasize that patching alone won’t remove post-exploitation access. Recommended measures include isolating or disabling vulnerable NetScaler instances, turning off DTLS or blocking inbound UDP/443 on exposed servers, rotating credentials, revoking sessions, auditing downstream Citrix components, and reviewing Windows logs for anomalous logins and RDP activity.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.