Skip to main content
NetScaler

NetScaler

Search complete. 77 mentions across 31 episodes found for "NetScaler".

Oct 2, 2026

Ryan NaraineHOST
62:40
...
Ryan NaraineHOST
62:40
so we did have a CISA advisory on an, on a Citrix NetScaler, uh, zero days, remote code execution zero days that was exploited globally.
Ryan NaraineHOST
62:49
It made some news over the weekend, um, after our episode last week and through this week about the zero day on the attack.
Ryan NaraineHOST
62:57
Um, these things are, have been a dime a dozen.
Ryan NaraineHOST
63:06
Why was this one deemed so important, Costin? For some reason, I felt like people here were on f- were, were on fire for this particular one more than the normal Fortinet Ivanti things.
Costin RaiuHOST
63:17
So this happened a bit after our, um, last episode.
Costin RaiuHOST
63:21
Um, so what I heard is that, uh, last week on Sundays, uh, people were getting, uh, phone calls on, um, during the weekend to go shut down their Citrix supply, their NetScaler, um, gateway, uh, appliances for some time until a patch is available, uh, which kind of suggested there was some kind of an ongoing, uh, exploitation zero-day activity.
Costin RaiuHOST
63:47
And, um, we got, actually, we got a blog post from, uh, Mandiant, which I, I think it's quite interesting to read.
Ben HarrisGUEST
4:07
And so that changes the risk profile.
Ben HarrisGUEST
4:09
I think the other kind of multiplier for us, or kind of modifier for us perhaps, was that NetScaler's It isn't WordPress.
Ben HarrisGUEST
4:14
It is not your kind of local, you know, friendly clubhouse running this website.
Ben HarrisGUEST
4:19
Net scalers are used by some very serious organizations that will impact all of us, like personally and professionally, if they get compromised.
Paul AsadoorianHOST
0:14
Nvidia wants to put AI agents in timeout.
Paul AsadoorianHOST
0:17
Citrix NetScaler gets exploited again and, and again.
Paul AsadoorianHOST
0:21
Spectre still refuses to die.
Paul AsadoorianHOST
0:23
Your S-bomb is incomplete.

44 MINS LATER

Paul AsadoorianHOST
44:16
And that's really why I built Fettel, right? Was to just tell me about things that are weird, right? And not everything runs default every day and I can run different commands to get better telemetry, but I want to know about weird shit on my system.
Paul AsadoorianHOST
44:30
And I think we need to, as is evidenced by how attackers are gaining persistence and access to Linux systems today, we're not doing a great job of looking for the weird shit on an ongoing basis on our Linux systems.
Paul AsadoorianHOST
44:47
Because if we did the Citrix Bleed attack, the latest NetScaler thing, we would have found that.
Paul AsadoorianHOST
44:58
And I'll give you an example.
Paul AsadoorianHOST
45:36
One, there were some protections.
Paul AsadoorianHOST
45:41
I'm getting F5 and Citrix NetScaler kind of confused.
Paul AsadoorianHOST
45:45
But there were some protections.
Paul AsadoorianHOST
45:48
Stat Canaries, ASLR, those kind of things.
Jess HebenstreitHOST
7:02
Yeah.
Jess HebenstreitHOST
7:02
Yeah, and it's based on like this research paper, but I wanna talk about the NetScaler thing-
Jake WilliamsHOST
7:06
Let's do that first
Jess HebenstreitHOST
7:07
... first.
Jake WilliamsHOST
7:07
NetScaler first.
Jake WilliamsHOST
7:08
Okay.
Jess HebenstreitHOST
7:08
Yes.
Jake WilliamsHOST
7:08
Go.
Paul AsadoorianHOST
45:36
One, there were some protections.
Paul AsadoorianHOST
45:41
I'm getting F5 and Citrix NetScaler kind of confused.
Paul AsadoorianHOST
45:45
But there were some protections.
Paul AsadoorianHOST
45:48
Stat Canaries, ASLR, those kind of things.
Claire AirdHOST
1:12
Dutch police are also investigating Vanderstap for attempting to arrange two murders.
Claire AirdHOST
1:19
In other news, two recently patched Citrix NetScaler zero-days are seeing widespread exploitation.
Claire AirdHOST
1:25
Attacks began hours after detailed write-ups and proof of concepts were published on Monday.
Claire AirdHOST
1:31
Citrix released patches for both of the bugs on the weekend after attacks were in the wild last week.
speaker_0HOST
1:52
Oh, yeah.
speaker_0HOST
1:53
The NetScaler situation.
speaker_1HOST
1:55
Yeah.
speaker_1HOST
1:56
Like, what happens when the appliance you bought specifically to inspect inbound traffic becomes the attacker's actual entry point?
Rory MonaghanHOST
17:26
I just read it verbatim.
Rory MonaghanHOST
17:28
NetScaler customers were also warned of actively exploited vulnerabilities by Citrix in their gateways and ADCs over the weekend with patches released on Sunday.
Rory MonaghanHOST
17:40
Microsoft have announced that they will deprecate the Windows Deployment Services server role starting with the next Windows Server release.
Rory MonaghanHOST
17:49
So Windows Deployment Services is of course WDS.
Michael HooshHOST
0:38
Let's break down the most critical developments shaping enterprise risk management today and what they mean for security leaders, risk executives, and boards.
Michael HooshHOST
0:47
Let's start with the most urgent threat, the active exploitation of a critical zero-day vulnerability in Citrix NetScaler, tracked as CVE-2026-88772.
Michael HooshHOST
0:56
This isn't just another technical flaw.
Michael HooshHOST
1:01
This is a gateway that state-sponsored actors have been using since early September to gain root-level access to enterprise systems.

21 more episodes mention NetScaler.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.