I got put back in red team after ten years this week and damn it felt good to pop a few boxes and flex those muscles, but damn bloodhound had some drama and it’s all too dramatic for me.
I got put back in red team after ten years this week and damn it felt good to pop a few boxes and flex those muscles, but damn bloodhound had some drama and it’s all too dramatic for me.
🚨 Reports of NetScaler Incidents After Latest Patch Raise Concerns Over Continued Exploitation
Multiple Citrix administrators are reporting suspicious activity affecting NetScaler appliances even after updating to version 14.1-73.37.
The reports surfaced on Reddit, where one administrator said multiple customers experienced incidents that caused externally accessible NetScaler appliances to repeatedly reboot.
Other administrators reported similar behavior on newly rebuilt appliances, including systems where Enhanced ISN Generation had already been enabled. Several affected organizations said they collected forensic data and opened cases with Citrix.
It is currently unclear whether the activity represents successful exploitation of a new or existing vulnerability, residual compromise, vulnerability scanning, or an issue with the updated firmware.
The reports come days after Citrix disclosed active exploitation of CVE-2026-88771 and CVE-2026-88772, two critical vulnerabilities affecting NetScaler ADC and NetScaler Gateway.
The latest post-patch activity has not yet been confirmed by Citrix as exploitation.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Source: https://www.reddit.com/r/Citrix/comments/1wvwva9/netscaler_active_exploit_after_patch/?rdt=60164

*Citrix picks up the card*
In 2026 we were still selling a remote access product, while running all system services as root, with a 200mb binary of obfuscated security fixes which crashes so much we run a Perl script as root to restart it, while also running PHP and absolutely no basic security hardening, while hiding security behind fake NDAs.
We told customers to worry about quantum and frontier AI *smiles*
Our previous CEO was paid $23m with the previous guy having a $32m leaving gift.

It looks like we may have #PitScaler 2 on our hands. I can see my patched honeypots, 13.1 and 14.1, are crashing. Multiple source IPs.
grep -Ei 'proc nsaaad.*(SIGNALED|EXITED)|maximum number of restarts|Pitboss declaring system failure|All monitored processes have exited, rebooting' /var/log/ns.log
grep -nF '213.209.159.55' /var/log/ns.log
zgrep -nF '213.209.159.55' /var/log/ns.log*.gz


Right, cybersecurity, I love thee but I’m taking a break this weekend. It’s not me, it’s definitely you.
Citrix have a blog out for #PitScaler 2
It’s a new security vuln, zero day. You can spam SAML requests and something will execute commands again.
Although Citrix are saying it is independent of the prior vulns.. eh.. :braindead_bart:
🚨 Citrix Warns of New NetScaler SAML Authentication Security Issue
Citrix is investigating a newly observed security issue affecting customer-managed NetScaler deployments using SAML authentication with Gateway or AAA functionality.
According to Citrix, the issue is configuration dependent and may affect appliances containing either of the following SAML configuration patterns:
add authentication samlAction.*
add authentication samlIdPProfile.*
Citrix says customers should review their NetScaler Gateway and AAA configurations for these SAML authentication actions and contact Citrix Support if they are currently experiencing impacts related to the issue.
A new security bulletin and updated NetScaler builds are planned. Citrix says affected appliances should be upgraded as soon as the fixed versions become available.
The company confirmed that this issue is separate from the vulnerabilities recently disclosed under CTX697096.
No CVE or definitive list of affected and fixed versions has been published for the new issue at this time.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Feeling very stressed about everything, and I went out to do some astrophotography. I was hoping for auroras, and was first excited to see an orange glow on the horizon, then annoyed as I realized it's probably a combine still harvesting, then delighted again as I realized it's the moon! Hello, moon. (Also hello Pleiades, hello Andromeda galaxy, hello Milky Way, and fuck you, Starlink)

RE: https://mastodon.social/@vtrlx/117287856439061540
My post calling for a total ban on AI in #GNOME is now the most liked post in the forum's history (was previously the second–most liked).