Google Cloud Blog·4d ago·26 read·seniorDefending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances
Mandiant and Google Threat Intelligence analysts identified active exploitation of zero-day vulnerabilities in Citrix NetScaler appliances that grant attackers root-level access. By exploiting heap memory corruption in the NSPPE packet engine, attackers deploy custom web shells and tunneling tools to facilitate internal network reconnaissance and credential theft.
AI summary