Citrix
"Publishing security advisories for such critical issues with such limited information only serves to hurt defenders and threat hunters"
Hey criminals! Fire an HTTP GET request. Grab system memory including session cookies issued post-authentication. Don't worry about logs. Pillage and loot. Thanks, Citrix.
You filthy animals are **** at network architecture, and it may be "necessary to expand threat hunting" says NCSC.
Pre-auth RCE in Citrix ShareFile has the potential to be the next MOVEit, or Accellion, or GoAnywhere, or Aspera Faspex, or...
Attackers dropped a webshell, collected and exfiltrated Active Directory data, then ran into some healthy obstacles...