Dark Reading reported on Oct. 2 that two vendors handled suspected zero-day threats in different ways. A zero-day is a flaw attackers use before a fix exists. Dark Reading said GreyNoise saw one US-based IP address scanning for Citrix NetScaler systems and attempting remote code execution on Sept. 24. On Sept. 26, watchTowr's CEO urged NetScaler users to go offline. Citrix then released an update fixing eight flaws, including two zero-days that Dark Reading says were exploited in the wild. Kiteworks, per Dark Reading, asked customers on Sept. 25 to take systems offline, citing intelligence about an imminent attack. It published a fix on Monday.
Several points are still open. Dark Reading says some experts doubted the NetScaler activity was new, thinking it might target two flaws patched in August. Citrix did not answer specific questions on that. GreyNoise did not first link its findings to specific CVEs, the numbered IDs for known flaws. Kiteworks said only 1% of its customers would have been affected. John Strand of Black Hills Information Security said it is unclear whether Kiteworks overreacted. Dark Reading did not report any confirmed attack on Kiteworks.
For teams that run or buy this software, Tenable's Satnam Narang said shutdowns have real costs, such as cutting off remote workers on a VPN. He said vendors asking for one should name the affected customers and setups, and give an end time. Kiteworks advised a nine-hour shutdown of the systems it hosts.