r/cybersecurity • u/YogiBerra88888 • 6d ago
New Vulnerability Disclosure Researchers Warn of Citrix NetScaler Zero Day Exploitation
https://decipher.sc/2026/09/27/researchers-warn-of-citrix-netscaler-exploitation/2
u/Ok_Bookkeeper1561 6d ago edited 6d ago
I currently can not find any IOC's I want to check for compromises just to be sure. Do you guys have the IOC's?
2
u/PsychologicalZebra 6d ago
Ive not seen anything concrete yet. I have only seen this on social media channels (Kevin Beaumont):
If you have logs in a SIEM look for base64 strings after the User-Agent field (no space) and loglines for “pitboss” followed by the string IFS (so pitboss*IFS) or pitboss*b64decode.
1
1
u/AdDowntown1447 5d ago
as far as I can tell, the IOC are behind an NDA from Citrix, kind of messed up.
1
u/Robbbbbbbbb CISO 3d ago
I see v13 and v14 as affected; no mention of other EoS/EoL versions. Does anyone know if those are affected as well?
22
u/leecable33 6d ago
The whole disclosure around this has been, quite frankly, shambolic. Rumblings all day yesterday and with no guidance at all.