CVE detail
CVE-2019-19781
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 17.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
101 source links · newest first
Warnings went out this week to infosec leaders about two groups of Iranian threat actors attacking American and other organizations. The US Cybersecurity and Infrastructure Security Agency (CISA), the FBI and the Defense Department’s Cyber Crime Centre said a group of Iranian hackers are working with ransomware gangs on attacks. “The Iranian cyber actors’ involvement […]
newswww.csoonline.comAug 29, 2024, 6:31 PM- Top 12 vulnerabilities routinely exploited in 2022Help Net Security
Cybersecurity agencies from member countries of the Five Eyes intelligence alliance have released a list of the top 12 vulnerabilities routinely exploited in 2022, plus 30 additional ones also “popular” with attackers. The top 12 “In 2022, malicious cyber actors exploited older software vulnerabilities more frequently than recently disclosed vulnerabilities and targeted unpatched, internet-facing systems. Proof of concept (PoC) code was publicly available for many of the software vulnerabilities or vulnerability chains likely facilitating exploitation … More →
newswww.helpnetsecurity.comAug 4, 2023, 1:17 PM Over the past several years, hackers have targeted public-facing network devices such as routers, VPN concentrators, and load balancers to gain a foothold into corporate networks. While finding remote code execution vulnerabilities in such devices is not uncommon, incidents where attackers were able to deploy malware on them that can survive restarts or firmware upgrades […]
newswww.csoonline.comNov 9, 2022, 6:53 PMSeveral US government agencies have issued a joint cybersecurity advisory to provide information on the techniques and tactics that China-linked threat actors have been using to compromise telecom companies and network services providers.
newswww.securityweek.comJun 9, 2022, 1:00 PMChina-linked threat actors have breached telecommunications companies and network service providers to spy on the traffic and steal data. US NSA, CISA, and the FBI published a joint cybersecurity advisory to warn that China-linked threat actors have breached telecommunications companies and network service providers. The nation-state actors exploit publicly known vulnerabilities to compromise the target […]
newssecurityaffairs.comJun 8, 2022, 9:53 AMWe provide an overview of known cyberthreats related to Russia-Ukraine cyber activity, including DDoS attacks, HermeticWiper and defacement, and share recommendations for proactive defense.
vendorunit42.paloaltonetworks.comFeb 22, 2022, 11:00 PMIt started like any other day, but within hours the IT team was scrambling as the business ground to a halt—victim of a ransomware cyberattack that popped up a ransomware notice, locked the company’s servers, and triggered a chain of system shutdowns that brought the entire business to a halt. Executives moved quickly, engaging the […]
newswww.csoonline.comFeb 20, 2022, 7:00 PMUS authorities warn critical infrastructure operators of the threat of cyberattacks orchestrated by Russia-linked threat actors. US Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the National Security Agency (NSA) issued a joint alert to warn critical infrastructure operators about threats from Russian state-sponsored hackers. “This joint Cybersecurity Advisory (CSA)—authored […]
newssecurityaffairs.comJan 12, 2022, 8:01 PMSecurity researchers have recently seen a notorious cyberespionage group with ties to the Russian government deploy a new backdoor that’s designed to hook into Active Directory Federation Services (AD FS) and steal configuration databases and security token certificates. In a new report, Microsoft attributes the malware program called FoggyWeb to a group the company tracks […]
newswww.csoonline.comSep 30, 2021, 7:12 PM- 23rd August – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 23rd August, please download our Threat Intelligence Bulletin. Top Attacks and Breaches The Hive ransomware gang has encrypted computers of Memorial Health System, a chain that operates hospitals and clinics in the US, eventually forcing workers to operate with paper charts and cancel surgeries. […]
vendorresearch.checkpoint.comAug 23, 2021, 6:20 PM Threat actors breached the servers of US Census Bureau on January 11, 2020, exploiting an unpatched Citrix ADC zero-day vulnerability, OIG revealed. A report published by the US Office of Inspector General (OIG) revealed that threat actors breached the servers of US Census Bureau on January 11, 2020, exploiting an unpatched Citrix ADC zero-day flaw. […]
newssecurityaffairs.comAug 19, 2021, 8:18 AM- SolarWinds hackers breached 27 state attorneys’ officesSecurity Affairs
Microsoft Office 365 email accounts of employees at 27 US Attorneys’ offices were breached by the Russia-linked SVR group as part of the SolarWinds hack, DoJ warns. The US Department of Justice revealed that the Microsoft Office 365 email accounts of employees at 27 US Attorneys’ offices were hacked by the Russia-linked SVR (aka APT29, Cozy Bear, and The Dukes) during the SolarWinds attack. The […]
newssecurityaffairs.comJul 31, 2021, 6:00 PM The U.S. government and its allies are pleading with defenders to pay attention to gaping holes in perimeter-type devices, warning that advanced threat actors are feasting on known security defects in VPN appliances, network product gateways and enterprise cloud applications.
newswww.securityweek.comJul 28, 2021, 3:28 PM- Atomic research institute breached via VPN vulnerabilityMalwarebytes Labs
Remember when we told you to patch your VPNs already? I hate to say “I told you so”, but I informed…
newswww.malwarebytes.comJun 20, 2021, 5:00 PM The UK and US cybersecurity agencies have published a report detailing techniques used by Russia-linked cyberespionage group known APT29 (aka Cozy Bear). Today, UK NCSC and CISA-FBI-NSA cybersecurity agencies published a joint security advisory that warns organizations to patch systems immediately to mitigate the risk of attacks conducted by Russia-linked SVR group (aka APT29, Cozy Bear, and The Dukes)). The […]
newssecurityaffairs.comMay 7, 2021, 9:03 PMThe FBI and DHS have issued a Joint Cybersecurity Advisory on the threat posed by the Russian Foreign Intelligence Service (SVR) via the cyber actor known as APT 29 (aka the Dukes, Cozy Bear, Yttrium and CozyDuke).
newswww.securityweek.comApr 27, 2021, 7:33 PM- 19th April – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 19th April, please download our Threat Intelligence Bulletin. Top Attacks and Breaches The U.S National Security Agency (NSA), the Cybersecurity and infrastructure security agency (CISA), and the Federal Bureau of Investigation (FBI) have published a joint advisory warning that a Russia-linked APT group, APT25, […]
vendorresearch.checkpoint.comApr 19, 2021, 5:54 PM - Russia-linked APT SVR actively targets these 5 flawsSecurity Affairs
The US government warned that Russian cyber espionage group SVR is exploiting five known vulnerabilities in enterprise infrastructure products. The U.S. National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the Federal Bureau of Investigation (FBI) have published a joint advisory that warns that Russia-linked APT group SVR (aka APT29, Cozy Bear, and The Dukes). […]
newssecurityaffairs.comApr 16, 2021, 12:26 PM The U.S. government on Thursday warned that Russian APT operators are exploiting five known — and already patched — vulnerabilities in corporate VPN infrastructure products, insisting it is “critically important” to mitigate these issues immediately.
newswww.securityweek.comApr 15, 2021, 2:15 PMOrganizations in the financial and insurance sectors were the most targeted by threat actors in 2020, continuing a trend that was first observed roughly five years ago, IBM Security reports.
newswww.securityweek.comApr 2, 2021, 12:42 PMJust one day after VMware announced the availability of patches for a critical vulnerability affecting vCenter Server, hackers have started scanning the internet for vulnerable servers.
newswww.securityweek.comFeb 25, 2021, 11:47 AM- Attackers are looking to exploit critical VMware vCenter Server RCE flaw, patch ASAP!Help Net Security
The day after VMware released fixes for a critical RCE flaw (CVE-2021-21972) found in a default vCenter Server plugin, opportunistic attackers began searching for publicly accessible vulnerable systems. We've detected mass scanning activity targeting vulnerable VMware vCenter servers (https://t.co/t3Gv2ZgTdt). Query our API for "tags=CVE-2021-21972" for relevant indicators and source IP addresses. #threatintel https://t.co/AcSZ40U5Gp — Bad Packets (@bad_packets) February 24, 2021 “In our opinion, the RCE vulnerability in the vCenter Server can pose no less a … More →
newswww.helpnetsecurity.comFeb 25, 2021, 10:53 AM VMware on Tuesday informed customers that its vCenter Server product is affected by a critical vulnerability that can be exploited by an attacker to execute commands with elevated privileges.
newswww.securityweek.comFeb 24, 2021, 12:02 PMDuring the COVID-19 pandemic, companies stayed operational while keeping staff safe by enabling their employees to work from home. While this kept businesses running, it introduced another risk: security problems at the network perimeter. Our Security Navigator 2021 report notes that the rush to remote working, combined with a marked rise in discovered vulnerabilities, has […]
newswww.csoonline.comFeb 12, 2021, 10:40 AMAttacks conducted by Iranian hackers against Israeli companies involved the deployment of ransomware and theft of information, threat intelligence company ClearSky reported last week.
newswww.securityweek.comDec 21, 2020, 4:52 AMPalo Alto Networks commends FireEye for transparency around its reported breach and is working to use the information shared to protect our customers.
vendorunit42.paloaltonetworks.comDec 11, 2020, 5:10 AM- FBI and CISA joint alert blames Russia’s Energetic Bear APT for US government networks hackSecurity Affairs
The US government declared that Russia-linked APT group Energetic Bear has breached US government networks and exfiltrated data. A joint security advisory published by The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) revealed that Russia-linked APT group Energetic Bear has breached US government networks and exfiltrated data. The Energetic Bear […]
newssecurityaffairs.comOct 23, 2020, 11:10 AM The United States says Russian state-sponsored hacking group Energetic Bear has successfully compromised state, local, territorial, and tribal (SLTT) government networks and stole data from at least two servers.
newswww.securityweek.comOct 23, 2020, 10:35 AMThe U.S. National Security Agency this week released an advisory containing information on 25 vulnerabilities that are being actively exploited or targeted by Chinese state-sponsored threat actors.
newswww.securityweek.comOct 21, 2020, 11:06 AM- 25 vulnerabilities exploited by Chinese state-sponsored hackersHelp Net Security
The US Cybersecurity and Infrastructure Security Agency (CISA) has released a list of 25 vulnerabilities Chinese state-sponsored hackers have been recently scanning for or have exploited in attacks. “Most of the vulnerabilities […] can be exploited to gain initial access to victim networks using products that are directly accessible from the Internet and act as gateways to internal networks. The majority of the products are either for remote access or for external web services, and … More →
newswww.helpnetsecurity.comOct 21, 2020, 10:23 AM - NSA details top 25 flaws exploited by China-linked hackersSecurity Affairs
The US National Security Agency (NSA) has shared the list of top 25 vulnerabilities exploited by Chinese state-sponsored hacking groups in attacks in the wild. The US National Security Agency (NSA) has published a report that includes details of the top 25 vulnerabilities that are currently being exploited by China-linked APT groups in attacks in the […]
newssecurityaffairs.comOct 20, 2020, 7:28 PM The Nefilim ransomware operators have posted a long list of files that appear to belong to Italian eyewear and eyecare giant Luxottica. Luxottica Group S.p.A. is an Italian eyewear conglomerate and the world’s largest company in the eyewear industry. As a vertically integrated company, Luxottica designs, manufactures, distributes and retails its eyewear brands, including LensCrafters, Sunglass […]
newssecurityaffairs.comOct 20, 2020, 11:13 AMUS government networks are under attack, threat actors chained VPN and Windows Zerologon flaws to gain unauthorized access to elections support systems. The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) published a joint security alert to warn of attackers combining VPN and Windows Zerologon flaws to target government networks. […]
newssecurityaffairs.comOct 12, 2020, 11:29 AM- Healthcare security update: death by ransomware, what’s next?Malwarebytes Labs
A recent ransomware attack which played a significant role in the death of a German woman has put into focus both…
newswww.malwarebytes.comOct 7, 2020, 5:00 PM - 29th September – Threat Intelligence BulletinCheck Point Research
For the latest discoveries in cyber research for the week of 29th September 2020, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Following last week’s emergency directive issued by CISA, Microsoft has warned that attackers are actively exploiting the critical Zerologon vulnerability (CVE-2020-1472) to attack Microsoft Windows servers using publicly available PoC exploits. […]
vendorresearch.checkpoint.comSep 29, 2020, 9:58 AM - Hackers hit Luxottica, production stopped at two Italian plantsSecurity Affairs
The Italian eyewear and eyecare giant Luxottica has reportedly suffered a cyber attack that disrupted its operations in Italy and China. Luxottica Group S.p.A. is an Italian eyewear conglomerate and the world’s largest company in the eyewear industry. As a vertically integrated company, Luxottica designs, manufactures, distributes and retails its eyewear brands, including LensCrafters, Sunglass […]
newssecurityaffairs.comSep 22, 2020, 12:39 PM US Department of Justice announced indictments against 5 Chinese nationals alleged members of a state-sponsored hacking group known as APT41. The United States Department of Justice this week announced indictments against five Chinese nationals believed to be members of the cyber-espionage group known as APT41 (Winnti, Barium, Wicked Panda and Wicked Spider). US authorities are […]
newssecurityaffairs.comSep 17, 2020, 9:59 AMThe United States Department of Justice on Wednesday announced indictments against five Chinese nationals believed to be part of a state-sponsored hacking group known as APT41. Also known as Winnti , Barium, Wicked Panda and Wicked Spider, the hackers allegedly launched cyberattacks on more than 100 companies in the United States and abroad. Their targets, the DoJ says, include software and video game companies, computer hardware makers, telecom providers, and social media organizations, but also governments, non-profit entities, universities , and think tanks, not to mention pro-democracy politicians and activists in Hong Kong. In August 2019 and August 2020, a federal grand jury returned two separate indictments charging the five Chinese nationals with facilitating “theft of source code, software code signing certificates, customer account data, and valuable business information,” the DoJ revealed. The hackers also engaged in ransomware and crypto-jacking attacks. The five residents…
newswww.securityweek.comSep 16, 2020, 6:38 PMThreat actors affiliated with the Chinese Ministry of State Security (MSS) continue to target U.S. government agencies, the Cybersecurity and Infrastructure Security Agency (CISA) says in a new alert.
newswww.securityweek.comSep 15, 2020, 2:21 PM- China-linked hackers target government agencies by exploiting flaws in Citrix, Pulse, and F5 systems, and MS ExchangeSecurity Affairs
CISA published an advisory on China-linked groups targeting government agencies by exploiting flaws in Microsoft Exchange, Citrix, Pulse, and F5 systems. CISA published a security advisory warning of a wave of attacks carried out by China-linked APT groups affiliated with China’s Ministry of State Security. Chinese state-sponsored hackers have probed US government networks looking for vulnerable networking […]
newssecurityaffairs.comSep 15, 2020, 9:16 AM The biggest security trend for 2020 has been the increase of COVID-19-related phishing and other attacks targeting remote workers. New York City, for example, has gone from having to protect 80,000 endpoints to around 750,000 endpoints in its threat management since work-from-home edicts took place. As noted in a recent Check Point Software Technologies mid-year […]
newswww.csoonline.comSep 9, 2020, 10:00 AMA hacking group believed to be linked to the Iranian government was observed targeting a critical vulnerability that F5 Networks addressed in its BIG-IP application delivery controller (ADC) in early July.
newswww.securityweek.comSep 1, 2020, 10:43 AMIran-linked APT group Pioneer Kitten is now trying to monetize its efforts by selling access to some of the networks it has hacked to other hackers. Iran-linked APT group Pioneer Kitten, also known as Fox Kitten or Parisite, is now trying to monetize its efforts by selling access to some of the networks it has […]
newssecurityaffairs.comSep 1, 2020, 9:22 AMThe typical timing of patch releases, exploits and CVE publication underscores the need for timely patching and effective vulnerability management.
vendorunit42.paloaltonetworks.comAug 26, 2020, 1:00 PMThe world’s largest cruise line operator Carnival Corporation has disclosed that one of their brands suffered a ransomware attack over the past weekend. Cruise line operator Carnival Corporation has disclosed that one of their brands was hit with a ransomware attack over the past weekend. Carnival Corporation & plc is a British-American cruise operator, currently […]
newssecurityaffairs.comAug 18, 2020, 8:21 AM- Maze Ransomware operators published data from LG and XeroxSecurity Affairs
Maze ransomware operators published internal data from LG and Xerox after the company did not pay the ransom. Ransomware crews are very active during these months, Maze ransomware operators have published tens of GB of internal data allegedly stolen from IT giants LG and Xerox following failed extortion attempts. Maze ransomware operators published 50.2 GB […]
newssecurityaffairs.comAug 4, 2020, 10:04 AM - Biomedical orgs working on COVID-19 vaccines open to cyber attacksHelp Net Security
In a recently released report by the UK National Cyber Security Centre (NCSC), whose findings have been backed by Canada’s Communications Security Establishment (CSE) and the US NSA and CISA (Cybersecurity and Infrastructure Security Agency), the agency has warned about active cyber attacks targeting biomedical organizations that are involved in the development of a COVID-19 vaccine. On Friday, BitSight researchers shared the results of a study that looked for detectable security issues at a number … More →
newswww.helpnetsecurity.comJul 17, 2020, 12:22 PM - Hackers are scanning the web for vulnerable Citrix systemsSecurity Affairs
Threat actors are scanning the Internet for Citrix systems affected by the recently disclosed vulnerabilities. This week Citrix has addressed 11 vulnerabilities affecting the ADC, Gateway, and SD-WAN WANOP networking products. The vulnerabilities could be exploited by attackers for local privilege escalation, to trigger a DoS condition, to bypass authorization, to get code injection, and to launch […]
newssecurityaffairs.comJul 11, 2020, 4:48 AM Hackers are apparently scanning the web for systems affected by the recently disclosed Citrix vulnerabilities, which the vendor suggested are less likely to be exploited.
newswww.securityweek.comJul 10, 2020, 12:04 PM- Attackers are probing Citrix controllers and gateways through recently patched flawsHelp Net Security
Earlier this week, Citrix released security updates for Citrix Application Delivery Controller (ADC), Citrix Gateway, and the Citrix SD-WAN WANOP appliance, and urged admins to apply them as soon as possible to reduce risk. At the time, there was no public attack code and no indication that any of the fixed flaws were getting actively exploited. On Thursday, though, SANS ISC’s Dr. Johannes Ullrich spotted attackers attempting to exploit two of the Citrix vulnerabilities on … More →
newswww.helpnetsecurity.comJul 10, 2020, 9:17 AM Citrix informed customers on Tuesday that it has patched 11 vulnerabilities in its ADC, Gateway, and SD-WAN networking products, and highlighted that the flaws are not related to CVE-2019-19781, which has been exploited in many attacks.
newswww.securityweek.comJul 7, 2020, 7:05 PMAustralian ACSC published a detailed report on the techniques, tactics, and procedures associated with the threat actor that targeted organizations in the country. Recently, Australia ‘s prime minister Scott Morrison revealed that a “state-based actor” is targeting government, public services, and businesses. Warning Australians of “specific risks” and an increased frequency of attacks, the Australian […]
newssecurityaffairs.comJun 28, 2020, 6:12 PMCLOP ransomware operators have allegedly hacked IndiaBulls Group, an Indian conglomerate headquartered in Gurgaon, India. CLOP ransomware operators have allegedly hacked the Indian conglomerate IndiaBulls Group, its primary businesses are housing finance, consumer finance, and wealth management. Indiabulls Group has around 19,000 employees, the company has been earning an average revenue of 25,000 crore Indian rupees. The […]
newssecurityaffairs.comJun 23, 2020, 9:55 AM- 8th June – Threat Intelligence BulletinCheck Point Research
For the latest discoveries in cyber research for the week of 8th June 2020, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Westech, a US military missile contractor, has been hit by the Maze ransomware after threat actors compromised its network and stole confidential documents from it. It is suspected that the hackers […]
vendorresearch.checkpoint.comJun 8, 2020, 3:22 PM Business process services provider Conduent has been the victim of a ransomware attack that appears to be the work of Maze operators. Formed in 2017 as a divestiture from Xerox and headquartered in New Jersey, the company offers digital platforms for both business and government organizations and has over 68,000 employees in more than 40 countries.
newswww.securityweek.comJun 5, 2020, 6:00 PMSeveral Microsoft Office vulnerabilities that were patched years ago continue to be among the security flaws most exploited in attacks, the U.S. government warns.
newswww.securityweek.comMay 13, 2020, 4:43 PM- Have you patched these top 10 routinely exploited vulnerabilities?Help Net Security
The US Cybersecurity and Infrastructure Security Agency (CISA) is urging organizations to patch a slew of old and new software vulnerabilities that are routinely exploited by foreign cyber actors and cyber criminals. “Foreign cyber actors continue to exploit publicly known—and often dated—software vulnerabilities against broad target sets, including public and private sector organizations. Exploitation of these vulnerabilities often requires fewer resources as compared with zero-day exploits for which no patches are available,” the agency noted. … More →
newswww.helpnetsecurity.comMay 13, 2020, 9:49 AM Advanced persistent threat (APT) groups continue to leverage the COVID-19 (coronavirus) crisis in cyberattacks, the United States and United Kingdom said in a joint alert today.
newswww.securityweek.comMay 5, 2020, 8:27 PMThe United Sates National Security Agency (NSA) and the Australian Signals Directorate (ASD) have issued a joint Cybersecurity Information Sheet (CSI) that provides details on vulnerabilities exploited by threat actors to install web shell malware on web servers.
newswww.securityweek.comApr 26, 2020, 4:46 PM- NSA and ASD issue a report warning of web shells deploymentsSecurity Affairs
A joint report released by the U.S. NSA and the Australian Signals Directorate (ASD) warns of attackers increasingly exploiting vulnerable web servers to deploy web shells. A joint report published by the U.S. National Security Agency (NSA) and the Australian Signals Directorate (ASD) is warning of bad actors increasingly exploiting vulnerable web servers to deploy […]
newssecurityaffairs.comApr 24, 2020, 10:27 AM - Web shell malware continues to evade many security toolsHelp Net Security
Cyber attackers are increasingly leveraging web shell malware to get persistent access to compromised networks, the US National Security Agency and the Australian Signals Directorate warn. What are web shells? Web shells are malicious scripts that are uploaded to target systems (usually web servers) to enable attackers to control it remotely. In affect, they create a backdoor into the target system. The threat is not limited to internet-facing web servers, though, and can be deployed … More →
newswww.helpnetsecurity.comApr 23, 2020, 1:50 PM Unit 42 identifies new payload, named Speculoos, exploiting CVE-2019-19781 to target organizations around the world, including state government in the United States.
vendorunit42.paloaltonetworks.comApr 14, 2020, 12:45 AM- China-linked APT41 group exploits Citrix, Cisco, Zoho flawsSecurity Affairs
The China-linked group tracked as APT41 exploited vulnerabilities in Citrix, Cisco, and ManageEngine in a campaign on a global scale. The China-linked cyberespionage group tracked as APT41 exploited vulnerabilities in Citrix, Cisco, and Zoho ManageEngine in a campaign on a global scale. The campaign was uncovered by FireEye, threat actor targeted many organizations worldwide the […]
newssecurityaffairs.comMar 25, 2020, 10:17 PM Security researchers warn that a Chinese cyberespionage group has been attacking organizations worldwide by exploiting vulnerabilities in popular business applications and devices from companies such as Cisco, Citrix and Zoho. In light of the ongoing COVID-19 crisis, the risk to companies is even greater, because IT staffs are working remotely and the rush to accommodate […]
newswww.csoonline.comMar 25, 2020, 7:40 PMA China-linked threat actor tracked as APT41 has targeted many organizations around the world by exploiting vulnerabilities in Citrix, Cisco and Zoho ManageEngine products, FireEye reported on Wednesday.
newswww.securityweek.comMar 25, 2020, 2:12 PMA recently disclosed vulnerability affecting Zoho’s ManageEngine Desktop Central endpoint management solution is already being exploited in attacks.
newswww.securityweek.comMar 10, 2020, 2:30 PMThe Australian Defence Department took an online recruitment system down in February over concerns hackers had compromised personnel data using a security flaw in Citrix software, it was revealed this week. The Australian Broadcasting Corporation reported on Wednesday that the department shut the Defence Force Recruiting Network (DFRN) electronic records system for 10 days from […]
newswww.csoonline.comMar 5, 2020, 6:30 PM- March 2nd – Threat Intelligence BulletinCheck Point Research
For the latest discoveries in cyber research for the week of March 2nd 2020, please download our Threat Intelligence Bulletin TOP ATTACKS AND BREACHES An unprotected ElasticSearch database belonging to the sport retailer Decathlon in Spain has been discovered, exposing over 123 million records of employee and customer data. The archive, over 9GB in size, […]
vendorresearch.checkpoint.comMar 2, 2020, 10:30 AM Iranian hackers have been hacking VPN servers to plant backdoors in companies around the world Iran-linked attackers targeted Pulse Secure, Fortinet, Palo Alto Networks, and Citrix VPNs to hack into large companies as part of the Fox Kitten Campaign. During the last quarter of 2019, experts from security firm ClearSky uncovered a hacking campaign tracked […]
newssecurityaffairs.comFeb 17, 2020, 6:07 AMMore than 80 percent of organizations impacted by CVE-2019-19781, a critical vulnerability in the Citrix Application Delivery Controller (ADC) and Gateway, have already taken steps to secure their deployments.
newswww.securityweek.comFeb 7, 2020, 5:48 PM- 3rd February – Threat Intelligence BulletinCheck Point Research
For the latest discoveries in cyber research for the week of 3rd February 2020, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Crooks are exploiting the global panic concerning the outbreak of the Coronavirus to infect Japanese users with Emotet through emails pretending to be a notice regarding infection prevention measures. Check Point […]
vendorresearch.checkpoint.comFeb 3, 2020, 12:33 PM - Security Affairs newsletter Round 249Security Affairs
A new round of the weekly newsletter arrived! The best news of the week with Security Affairs Authorities arrest 3 Indonesian hackers behind many Magecart attacks City of Potsdam offline following a cyberattack A new piece of Ryuk Stealer targets government, military and finance sectors Aggah: How to run a botnet without renting a Server […]
newssecurityaffairs.comFeb 2, 2020, 10:20 AM Citrix has released security patches for the recently disclosed CVE-2019-19781 flaw, but the number of attacks on vulnerable systems is increasing. Last week, Citrix addressed the actively exploited CVE-2019-19781 flaw in Citrix Application Delivery Controller (ADC), Citrix Gateway, and Citrix SD-WAN WANOP appliances. While security researchers were warning of ongoing scans for Citrix Application Delivery Controller (NetScaler […]
newssecurityaffairs.comJan 28, 2020, 7:39 AMCitrix has released the full set of patches for the recently disclosed security flaw tracked as CVE-2019-19781, but attacks on vulnerable systems are ramping up.
newswww.securityweek.comJan 27, 2020, 7:38 PM- 27th January – Threat Intelligence BulletinCheck Point Research
For the latest discoveries in cyber research for the week of 20th January 2020, please download our Threat Intelligence Bulletin TOP ATTACKS AND BREACHES UN calls for an investigation on Saudi Arabia’s role in amazon CEO Jeff Bezos’s phone hack. The alleged attack was carried via WhatsApp. Bezos was sent a video in 2018 […]
vendorresearch.checkpoint.comJan 27, 2020, 4:58 PM - City of Potsdam offline following a cyberattackSecurity Affairs
The City of Potsdam suffered a major cyberattack that took down its servers earlier this week, but emergency services were not impacted. The German City of Potsdam has suffered a major cyberattack that took down its servers earlier this week, the good news is that emergency services, including the city’s fire department fully operational and payments […]
newssecurityaffairs.comJan 26, 2020, 3:42 PM - Week in review: Kubernetes security challenges, NIST Privacy Framework, Mitsubishi Electric breachHelp Net Security
Here’s an overview of some of last week’s most interesting news and articles: Mitsubishi Electric discloses data breach, possible data leak Japanese multinational Mitsubishi Electric has admitted that it had suffered a data breach some six months ago, and that “personal information and corporate confidential information may have been leaked.” It’s time to patch your Cisco security solutions again Cisco has released another batch of security updates and patches for a variety of its offerings, … More →
newswww.helpnetsecurity.comJan 26, 2020, 3:15 PM - Security Affairs newsletter Round 248Security Affairs
A new round of the weekly newsletter arrived! The best news of the week with Security Affairs Bot list with Telnet credentials for more than 500,000 servers and IoT devices leaked online Hackers patch Citrix servers to deploy their own backdoor Citrix releases permanent fixes for CVE-2019-19781 flaw in ADC 11.1 and 12.0 JhoneRAT uses […]
newssecurityaffairs.comJan 26, 2020, 10:09 AM Citrix has released a new set of patches for the recently disclosed CVE-2019-19781 vulnerability and partnered with FireEye for a tool that tells users if their systems have been compromised via the security flaw.
newswww.securityweek.comJan 24, 2020, 2:31 PMCitrix Systems and FireEye announced the launch of a new tool for detection of compromise in connection with the previously announced CVE-2019-19781 vulnerability, which affects certain versions of Citrix Application Delivery Controller (ADC), Citrix Gateway, and two older versions of Citrix SD-WAN WANOP. This tool is freely accessible in both the Citrix and FireEye GitHub repositories. The free tool is designed to allow customers to run it locally against their Citrix instances and receive a … More →
newswww.helpnetsecurity.comJan 23, 2020, 11:15 PMCitrix and FireEye have teamed up to provide sysadmins with an IoC scanner that shows whether a Citrix ADC, Gateway or SD-WAN WANOP appliance has been compromised via CVE-2019-19781. Finding evidence of compromise By now it should be widely known that CVE-2019-19781 – aka “Shitrix” – is a real and present danger: exploits for it abound and attackers are using them, while we wait for fixes for all affected devices to be released. Though the … More →
newswww.helpnetsecurity.comJan 23, 2020, 2:02 PM- First patches for the Citrix ADC, Gateway RCE flaw releasedHelp Net Security
As attackers continue to hit vulnerable Citrix (formerly Netscaler) ADC and Gateway installations, Citrix has released permanent fixes for some versions and has promised to provide them for other versions and for two older versions of SD-WAN WANOP by January 24. A short timeline before the situation update CVE-2019-19781, a critical vulnerability affecting Citrix ADC and Gateway that may allow unauthenticated attackers to achieve remote code execution and obtain direct access to an organization’s local … More →
newswww.helpnetsecurity.comJan 21, 2020, 2:58 PM Citrix has started rolling out security patches for the recently revealed Citrix Application Delivery Controller (ADC) and Citrix Gateway vulnerability.
newswww.securityweek.comJan 20, 2020, 12:39 PM- 20th January – Threat Intelligence BulletinCheck Point Research
For the latest discoveries in cyber research for the week of 20th January 2020, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Hackers have stolen personal information in an attack on the Australian P&N bank. The attack focused on the bank’s CRM system that stored a great deal of sensitive personal and financial […]
vendorresearch.checkpoint.comJan 20, 2020, 12:08 PM Citrix addressed the actively exploited CVE-2019-19781 flaw in Citrix Application Delivery Controller (ADC), Citrix Gateway, and Citrix SD-WAN WANOP appliances. Citrix has released security patches to address actively exploited CVE-2019-19781 vulnerability in Citrix Application Delivery Controller (ADC), Citrix Gateway, and Citrix SD-WAN WANOP appliances. While security researchers were warning of ongoing scans for Citrix Application Delivery Controller […]
newssecurityaffairs.comJan 20, 2020, 11:36 AM- Week in review: Windows crypto flaw, API security risks, exploits for Citrix security hole aboundHelp Net Security
Here’s an overview of some of last week’s most interesting news and articles: Cable Haunt: Unknown millions of Broadcom-based cable modems open to hijacking A vulnerability (CVE-2019-19494) in Broadcom‘s cable modem firmware can open unknown millions of broadband modems by various manufacturers to attackers, a group of Danish researchers has warned. High-risk Google account owners can now use their iPhone as a security key Google users who opt for the Advanced Protection Program (APP) to … More →
newswww.helpnetsecurity.comJan 19, 2020, 2:00 PM - Hackers patch Citrix servers to deploy their own backdoorSecurity Affairs
Attacks on Citrix servers are intensifying, one of the threat actors behind them is patching them and installing its own backdoor to lock out other attackers. Security experts are monitoring a spike in the number of attacks against Citrix servers after that researchers announced the availability online of proof-of-concept exploits for the CVE-2019-19781 flaw in Citrix NetScaler […]
newssecurityaffairs.comJan 19, 2020, 9:32 AM A threat group targeting the recently disclosed critical vulnerability in Citrix Application Delivery Controller (ADC) is installing their own backdoor while cleaning up other malware infections and blocking others from exploiting the vulnerability, FireEye has discovered.
newswww.securityweek.comJan 17, 2020, 7:51 PMWe provide the root cause analysis of the vulnerability identified in Citrix Application Delivery Controller (ADC) and Citrix Gateway, CVE-2019-19781, as well as Proof of Concept examples (PoC), additional Indicators of Compromise we've identified and attack activities we observed in the wild.
vendorunit42.paloaltonetworks.comJan 16, 2020, 2:00 PM- 13th January – Threat Intelligence BulletinCheck Point Research
For the latest discoveries in cyber research for the week of 13th January 2020, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Austria’s foreign ministry has suffered a serious cyber-attack, allegedly conducted by a foreign state. US government-funded low-cost UMX mobile phones include preinstalled “unremovable” malware. The malware, a variant of HiddenAds, is […]
vendorresearch.checkpoint.comJan 13, 2020, 12:45 PM CISA Releases Utility to Test for Citrix ADC and Gateway Vulnerability
newswww.securityweek.comJan 13, 2020, 12:10 PM- Exploits for Citrix ADC and Gateway flaw abound, attacks are ongoingHelp Net Security
With several exploits targeting CVE-2019-19781 having been released over the weekend and the number of vulnerable endpoints still being over 25,000, attackers are having a field day. Do you use Citrix’s Application Delivery Controller (ADC) or Gateway? If you haven’t implemented the mitigations provided by the company, there’s a good change you might have been hit already. Numerous CVE-2019-19781 exploits available The existence of CVE-2019-19781 – humorously dubbed Shitrix by cybersecurity researcher Kevin Beaumont – … More →
newswww.helpnetsecurity.comJan 13, 2020, 11:53 AM Here’s an overview of some of last week’s most interesting news and articles: Travelex extorted by ransomware gang, services still offline a week after the hit On the last day of 2019, foreign exchange company Travelex was hit by cyber attackers wielding the Sodinokibi (aka REvil) ransomware. More than a week later, the company’s websites and online services are still offline despite the company’s remediation efforts. January 2020 Patch Tuesday forecast: Let’s start the new … More →
newswww.helpnetsecurity.comJan 12, 2020, 2:50 PMExperts announced the availability online of proof-of-concept exploit code for CVE-2019-19781 flaw in Citrix NetScaler ADC and Citrix NetScaler Gateway servers. While security researchers were warning of ongoing scans for Citrix Application Delivery Controller (NetScaler ADC) and Citrix Gateway (NetScaler Gateway) servers affected by the CVE-2019-19781 vulnerability, many experts are announcing the availability online of proof-of-concept exploit […]
newssecurityaffairs.comJan 11, 2020, 3:52 PM- Hackers Scan for Vulnerable Citrix ADC SystemsSecurityWeek
Weeks after Citrix revealed a critical vulnerability impacting its Application Delivery Controller (ADC) and Gateway products, hackers have started to scan the Internet for vulnerable systems, security researchers report.
newswww.securityweek.comJan 10, 2020, 6:23 AM Threat actors are probing Citrix servers in the attempt to exploit the CVE-2019-19781 remote code execution vulnerability. Security researchers are warning of ongoing scans for Citrix Application Delivery Controller (NetScaler ADC) and Citrix Gateway (NetScaler Gateway) servers affected by the CVE-2019-19781 vulnerabilities. The anomalous activities were detected last week, as reported by the popular expert Kevin […]
newssecurityaffairs.comJan 9, 2020, 9:34 PM- Attackers exploiting critical Citrix ADC, Gateway flaw, company yet to release fixesHelp Net Security
Nearly a month has passed since Citrix released mitigation measures for CVE-2019-19781, a critical vulnerability affecting Citrix Application Delivery Controller and Citrix Gateway, which could lead to remote code execution. The end of the year festivities and holidays can be blamed for the announcement not receiving a lot of attention, but those have now passed and, according to SANS ISC and security researcher Kevin Beaumont, there are attackers out there scanning for vulnerable systems and … More →
newswww.helpnetsecurity.comJan 9, 2020, 1:56 PM - 30th December – Threat Intelligence BulletinCheck Point Research
For the latest discoveries in cyber research for the week of 30th December 2019, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point researchers have detected a phishing campaign impersonating the royal bank of Canada and other Canadian banks. The attack contained emails sent to targeted customers that use look-alike domains to […]
vendorresearch.checkpoint.comDec 30, 2019, 2:53 PM - Security Affairs newsletter Round 246Security Affairs
A new round of the weekly newsletter arrived! The best news of the week with Security Affairs Experts warn of Greta Thunberg-themed Emotet malware campaign Former contractor sentenced to 10 months in prison for hacking airline Jet2 UK authorities sentenced hacker who blackmailed Apple for $100,000 Champagne Bakery Cafe and Islands burger chain disclose payment […]
newssecurityaffairs.comDec 29, 2019, 12:33 PM - CVE-2019-19781 Citrix flaw exposes 80,000 companies at riskSecurity Affairs
Critical CVE-2019-19781 flaw in Citrix NetScaler ADC and Citrix NetScaler Gateway could be exploited to access company networks, 80,000 companies at risk worldwide. A critical vulnerability in Citrix Application Delivery Controller (NetScaler ADC) and Citrix Gateway (NetScaler Gateway), tracked as CVE-2019-19781, could be exploited by attackers to access company networks. It has been estimated that […]
newssecurityaffairs.comDec 23, 2019, 9:46 PM A critical vulnerability in Citrix Application Delivery Controller (NetScaler ADC) and Citrix Gateway (NetScaler Gateway) could allow criminal access to the networks of 80,000 companies in 158 countries. The countries most at risk are the U.S. (with 38% of the vulnerable networks), the UK, Germany, the Netherlands, and Australia.
newswww.securityweek.comDec 23, 2019, 1:59 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2020-8198CVSS 6.1 · Medium
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11…
- CVE-2020-8197CVSS 8.8 · High
Privilege escalation vulnerability on Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows a low privileged user with…
- CVE-2020-8194CVSS 6.5 · Medium
Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.…
- CVE-2020-8191CVSS 6.1 · Medium
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11…
- CVE-2020-8190CVSS 7.5 · High
Incorrect file permissions in Citrix ADC and Citrix Gateway before versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows privilege escalation.
- CVE-2019-18225CVSS 9.8 · Critical
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway before 10.5 build 70.8, 11.x before 11.1 build 63.9, 12.0 before build 62.10, 12.1 before build…