1
Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances
Mandiant and Google identified active exploitation of two zero‑day bugs in Citrix NetScaler ADC/Gateway that let attackers gain root via malformed DTLS packets, then persist with custom PHP web shells and a Python tunneler. The blog details the exploit mechanics, persistence tricks, detection signatures, and remediation steps.
Google Cloud Bloggoogle.com22 min
