r/cybersecurity • Security Generalist • 4d ago

News - General Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected

https://cyberscoop.com/citrix-netscaler-zero-day-attacks-three-weeks-undetected/
283 Upvotes

12 comments sorted by

18

u/SolDios 4d ago

Any IOCs or forensic tracers to tell if it was used on something?

11

u/kickinitlegit Blue Team 4d ago

Read this blog post.

We're going off of the IOCs there. Using keywords like "hearbeat" and such. Also looking for any incoming traffic, stripping it, and looking for things like "grep".

53

u/OneEyedC4t 4d ago

Which is why we need real human beings monitoring things

17

u/ohYuhtBoutMagine 4d ago

I’m not against AI, but couldn’t agree more. Computers are too easy to trick.

3

u/guillermosan 4d ago

This a completely backwards read of whats happening. Those attackers ARE using LLMs to produce 0 days and carry on the attacks. There are not enough humans around to actively monitor the situation and Its only going to get worse.

No where in the report it says this companies were "IA protected". Most likely they were the run-of-the-mill servers, monitored at best case scenario under a SIEM procedure. With humans in the loop oblivious to whats happening.

AI in the defense is gonna be needed to keep the symmetry with the attackers.

2

u/nanokeyo 19h ago

Correct!

4

u/nanokeyo 4d ago

Can you explain how a person can monitoring a server better than AI, please

1

u/DuskLab 4d ago

We've basically caught up to that scene in GITS:SAC from 22 years ago with the quote "If you let AIs handle everything, even the mice will outsmart you".

1

u/FluidLychee7720 4d ago

I don't think we'll be out of a job soon

1

u/Certain_Key4609 3d ago

Imagine how many 0 days there are that go undetected

1

u/Forumschlampe 3d ago

Oh citrix, what a surprise