
Decrypted: The UK Cyber Briefing · Yesterday · 5 min
Citrix has patched NetScaler, but a patch will not remove the web shell
0:00-5:09
transcript
show notes
Citrix has patched its two NetScaler zero-days, the NCSC has issued an alert, and Mandiant has described the web shells left behind. Patching is not enough, so the advice is to hunt and rebuild. Plus the ICO becomes the Information Commission, and an OpenSSL DTLS leak.
Sources
- NCSC: Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway
- BleepingComputer: Hackers exploit Citrix NetScaler zero-day to deploy web shells
- CyberScoop: Citrix patches actively exploited NetScaler zero-days after a weekend of silence
- The Hacker News: Attackers exploit NetScaler flaw for root access, deploy WHIPSHOT
- ICO: ICO to become Information Commission on 30 September 2026
- The Hacker News: OpenSSL fixes high-severity DTLS flaw that can leak heap memory
links7
- NCSC: Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gatewayncsc.gov.uk
- BleepingComputer: Hackers exploit Citrix NetScaler zero-day to deploy web shellsbleepingcomputer.com
- CyberScoop: Citrix patches actively exploited NetScaler zero-days after a weekend of silencecyberscoop.com
- The Hacker News: Attackers exploit NetScaler flaw for root access, deploy WHIPSHOTthehackernews.com






