A recent surge in cyberattacks has put numerous high-profile companies on alert. Attackers are exploiting a security flaw known as CitrixBleed in Citrix systems, a vulnerability tracked as CVE-2023-4966. This issue has impacted several notable entities including aerospace leader Boeing, the international banking giant ICBC, global port operator DP World, and the prominent law firm Allen & Overy.
The CitrixBleed bug allows hackers to access large amounts of data from Citrix devices, including sensitive session tokens, without needing passwords or two-factor authentication. This vulnerability mainly affects on-premise versions of Citrix NetScaler ADC and NetScaler Gateway platforms, commonly used by large businesses and government agencies for application delivery and VPN services.
Another Victim in a List of Cybersecurity Breaches
The Shadowserver Foundation, a nonprofit organization monitoring online threats, reports that the majority of compromised systems are in North America. Following the discovery of the flaw, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a warning to federal agencies, emphasizing the importance of applying available patches to mitigate risks.
Citrix acknowledged the flaw on October 10 and released patches to address it. However, it wasn't until a week later that the company updated its advisory to confirm the active exploitation of this vulnerability.
Early targets of these attacks included sectors like professional services, technology, and government. Cybersecurity firm Mandiant noted multiple instances of successful exploitation, beginning as early as late August. Rapid7, another cybersecurity company, observed the bug's exploitation across healthcare, manufacturing, and retail industries. Their investigations revealed hackers' capability to move laterally within networks and access data.
The Link with ICBC
A particular group, the Russia-linked LockBit ransomware gang, has claimed responsibility for several major breaches linked to CitrixBleed. Security researcher Kevin Beaumont reported that this gang compromised the U.S. branch of ICBC, the world's largest lender by assets, via an unpatched Citrix device. The attack disrupted ICBC's trade-clearing operations, and the bank reportedly paid a ransom to resolve the issue.
The impact of CitrixBleed extends beyond individual companies, underscoring the importance of robust cybersecurity measures in the face of increasingly sophisticated cyber threats.


Unsustainable – or manageable? We don’t yet know how data centres will impact Australia’s environment
Europe can’t achieve space sovereignty alone. Here’s why
Cathie Wood Backs AI Slowdown as Safety Concerns Grow
SoftBank Shares Jump 8% as SB Energy IPO Optimism Builds
Databricks to Invest $350 Million in Singapore AI Expansion
Ex-Google DeepMind Researcher Warns AI Could Pose Existential Threat
France Urges Faster AI Push Despite Safety Risks
SK Hynix, Intel Discuss U.S. Memory Chip Production Deal
DOJ Will Investigate AI-Related Crimes, Attorney General Blanche Says
Meta CEO Zuckerberg Backs Independent AI Safety Reviews Over Development Slowdown
Japan, U.S. Discuss $19 Billion GlobalFoundries Chip Plant
Big AI wants to slow down AI research. Is it a safety pause or a strategic retreat?
SoftBank Shares Plunge 11% After OpenAI Rules Out 2026 IPO
Physicists zoom into the birth of cosmic rainstorms with new CERN study
Rosenblatt Starts Nokia at Buy on AI Networking Growth
Nvidia CEO Jensen Huang Expected at Trump-Xi State Dinner
Who should own the knowledge that underpins AI technology? 



