WEBVTT

1
00:00:03.200 --> 00:00:07.040
This is Decrypted. Sunday, the twenty-seventh of September.

2
00:00:07.040 --> 00:00:12.080
Citrix's NetScaler has two zero-days and no patch yet.

3
00:00:12.080 --> 00:00:18.880
Citrix NetScaler customers spent the weekend doing something you'd normally only do on the worst day of the

4
00:00:18.880 --> 00:00:24.400
year. They took their own front door offline, with no idea when it might reopen.

5
00:00:24.400 --> 00:00:34.460
On Friday, a pre-notification attributed to the Dutch national cyber security centre, N C S C-N L, started ci

6
00:00:34.460 --> 00:00:36.720
rculating on a Citrix subreddit.

7
00:00:36.720 --> 00:00:45.670
It described unpatched remote code execution flaws in NetScaler A D C and Gateway, and reportedly told one ma

8
00:00:45.670 --> 00:00:49.360
naged service provider to shut its appliances down immediately.

9
00:00:49.360 --> 00:00:56.400
No further detail given. By Saturday, the security firm watchTowr said the intelligence was credible.

10
00:00:56.400 --> 00:01:03.760
Two zero-day R C E vulnerabilities, found during forensic work on customer environments that had already been

11
00:01:03.760 --> 00:01:06.240
compromised, being exploited right now.

12
00:01:06.240 --> 00:01:10.720
No patch. No advisory. No C V E number issued.

13
00:01:10.720 --> 00:01:14.000
Citrix has confirmed nothing publicly.

14
00:01:14.000 --> 00:01:19.600
But reporting says it's told partners a fix is expected in the week starting 28 September.

15
00:01:19.600 --> 00:01:23.360
Next.

What we know, and what we still don't.

16
00:01:23.360 --> 00:01:31.257
The two new flaws are separate from C V E twenty twenty-six, one nine four nine zero, an authentication bypa

17
00:01:31.257 --> 00:01:33.680
ss Citrix patched on 19 August.

18
00:01:33.680 --> 00:01:36.640
Beyond that, almost nothing is verified.

19
00:01:36.640 --> 00:01:47.600
The pre-notification itself was reportedly marked T L P A M B E R+S T R I C T, a classification meant to keep

20
00:01:47.600 --> 00:01:49.840
it inside a small, trusted circle.

21
00:01:49.840 --> 00:01:53.440
It didn't stay there. No affected build ranges.

22
00:01:53.440 --> 00:01:55.360
No indicators of compromise.

23
00:01:55.360 --> 00:01:59.680
No proof-of-concept. No exploitation path published.

24
00:01:59.680 --> 00:02:03.840
Which means defenders can't even search their own logs for evidence, either way.

25
00:02:03.840 --> 00:02:10.400
That hasn't stopped managed service providers and national agencies telling clients over the weekend to isola

26
00:02:10.400 --> 00:02:13.680
te or power down their NetScaler appliances anyway.

27
00:02:13.680 --> 00:02:20.640
Because the alternative, waiting for confirmation while an unauthenticated R C E sits on the internet-facing

28
00:02:20.640 --> 00:02:25.160
edge, is worse. It's an unusual position to be in.

29
00:02:25.160 --> 00:02:30.720
Acting on a credible tip, with none of the technical detail that would normally justify the disruption.

30
00:02:30.720 --> 00:02:34.240
And also.

Why the rules just changed.

31
00:02:34.240 --> 00:02:39.600
The EU's Cyber Resilience Act brought in a new duty on 11 September.

32
00:02:39.600 --> 00:02:48.764
Manufacturers must now tell a national C S I R T and E N I S A within 24 hours of learning that one of their

33
00:02:48.764 --> 00:02:53.040
products is being actively exploited, even before a fix exists.

34
00:02:53.040 --> 00:02:58.480
Whether that specific filing is what reached the Citrix subreddit is unconfirmed.

35
00:02:58.480 --> 00:03:06.613
But the dynamic we saw this weekend, a C S I R T holding pre-patch knowledge that then surfaces publicly ahea

36
00:03:06.613 --> 00:03:11.680
d of the vendor's own advisory, is exactly the scenario that duty creates.

37
00:03:11.680 --> 00:03:14.800
And to be clear, that's not a flaw in the law.

38
00:03:14.800 --> 00:03:18.880
Early warning before a fix exists is the whole point.

39
00:03:18.880 --> 00:03:26.533
But it does mean the UK, sitting outside the regulation, is currently relying on Dutch disclosure and a secur

40
00:03:26.533 --> 00:03:30.800
ity vendor's tweet, rather than its own N C S C advisory.

41
00:03:30.800 --> 00:03:33.280
Which hadn't appeared by the time of writing.

42
00:03:33.280 --> 00:03:37.360
And finally.

What UK organisations should take from this.

43
00:03:37.360 --> 00:03:45.787
NetScaler joins F5 and Zyxel as the third edge or remote-access appliance in a month to end up in this posit

44
00:03:45.787 --> 00:03:48.800
ion. And the pattern is the design flaw.

45
00:03:48.800 --> 00:03:55.867
These boxes are built to be reachable from anywhere, and to hold the keys, sessions, certificates, authentica

46
00:03:55.867 --> 00:03:58.320
tion decisions, to everything behind them.

47
00:03:58.320 --> 00:04:05.227
Citrix's own incident guidance says the NetScaler Management Service should never be exposed to the public in

48
00:04:05.227 --> 00:04:12.107
ternet. And yet the lesson that keeps repeating, every single time one of these incidents happens, is that pat

49
00:04:12.107 --> 00:04:14.400
ch speed can't be your only defence.

50
00:04:14.400 --> 00:04:19.920
Because sometimes, as this weekend proved, there is no patch to apply for days.

51
00:04:19.920 --> 00:04:26.217
The organisations coping best right now are the ones that logged appliance activity somewhere the appliance i

52
00:04:26.217 --> 00:04:32.624
tself can't delete, segmented what the gateway can actually reach, and can survive taking it offline if they h

53
00:04:32.624 --> 00:04:36.640
ave to. That's a design decision made months before the incident.

54
00:04:36.640 --> 00:04:39.840
Not a response to it.

That was Decrypted.

55
00:04:39.840 --> 00:04:43.120
The written version and every source are linked in the show notes.

56
00:04:43.120 --> 00:04:44.400
Thanks for listening.

