Public Citrix NetScaler IoCs (PitScaler)
This table only contains indicators that have been published openly. The Sharing column shows each source's own marking. [36][40][24][25]
- GreyNoise published its set on 28 September, marked TLP:CLEAR. GreyNoise has announced a longer "GreyNoise Labs" version, but the link on its blog was still a placeholder on 29 September.
- IFIN says the observables it shares were shared without restriction.
- Truesec's page is public and has no TLP marking.
- GTIG/Mandiant's blog is public and has no TLP marking. GTIG keeps its full IoC collection for registered GTI users only.
Indicators are not proof of compromise by themselves. Validate any hit against appliance logs, filesystem integrity, process history and configuration changes, following your incident-response procedure.
How to read these. Each indicator was observed by the source named in its row. None of them is a universal indicator for every victim. Beaumont reports that webshell names and attacker IPs are unique per victim. [47][51] An empty search result proves nothing.
| Type | Exact value | Source | Context | Caveat | Sharing |
|---|---|---|---|---|---|
| IPv4 | 149.104.78.141 | GreyNoise blog [36]; GreyNoise Visualizer [38]; eSentire TRU [32] | Exploitation source, Sep 24 (3 sessions 07:32:19-07:32:20 UTC). GreyNoise Visualizer on Sep 29: AS154177 LIGHT NODE LIMITED, Japan; not observed mass scanning in the past day. | Observed in GreyNoise sensor data; not a universal indicator for every victim. Beaumont reports attacker IPs vary per victim. eSentire also lists it as an exploitation source. | TLP:CLEAR |
| File path | /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver | GreyNoise blog [36] | Webshell path on disk | Observed in GreyNoise sensor data; not a universal indicator for every victim. Beaumont reports webshell names are unique per victim. | TLP:CLEAR |
| URL alias | receiver.min.css | GreyNoise blog [36] | Webshell alias | Observed in GreyNoise sensor data; not a universal indicator for every victim. | TLP:CLEAR |
| AliasMatch regex | receiver\.min\.[0-9a-f]+\.css | GreyNoise blog [36]; CERT-EU [19] | Apache config (httpd.conf) AliasMatch | Observed in GreyNoise sensor data; not a universal indicator for every victim. Pattern as published; also check httpd.conf integrity generally. | TLP:CLEAR |
| SHA-256 | 6f5a2a452a7901323abd21879c6cecccb47c06aeeaccb1b467212f3b11e4b1e7 | GreyNoise blog [36] | Webshell hash | Observed in GreyNoise sensor data; not a universal indicator for every victim. Per-victim webshells may differ. | TLP:CLEAR |
| GreyNoise tag | Citrix NetScaler CVE-2026-88771 Login Command Injection RCE Attempt | GreyNoise tag [39]; GreyNoise blog [36] | Sensor detection tag, created Sep 27. GreyNoise Visualizer on Sep 29: 76 unique IPs tagged between Sep 19 and Sep 29, all classified malicious. All are listed in this table; two are Cloudflare WARP exits, marked as such. | Classifies traffic seen by GreyNoise and community sensors only. Most tagged IPs also carry crawler and CitrixBleed 2 tags, so many look like opportunistic scanning. | TLP:CLEAR |
| SHA-256 | ed082f744f035035900f67edf438f2f7d0528ac501234f63d476d65273cdb9a1 | IFIN [40] | .ctxs.receiver webshell sample (237-byte PHP file) posted by a Reddit user, relayed by IFIN | Unconfirmed single-victim sample. The hardcoded token likely differs per victim, so the hash will too - match on file content, not hash. | Public, no restriction |
| IPv4 | 104.248.244.66 | Truesec [24]; IFIN [40] | Potential C2 IP observed by Truesec | IR-vendor observation. Beaumont reports attacker IPs in IR writeups can be unique to one victim; absence is not proof of a clean host. | Public page, no TLP marking |
| IPv4 | 139.180.152.138 | Truesec [24]; IFIN [40]; eSentire TRU [32] | Potential C2 IP observed by Truesec; webshell delivery per eSentire | IR-vendor observation. Beaumont reports attacker IPs in IR writeups can be unique to one victim; absence is not proof of a clean host. | Public page, no TLP marking |
| IPv4 | 77.83.199.39 | Truesec [24]; IFIN [40]; eSentire TRU [32] | Potential C2 IP observed by Truesec; webshell delivery per eSentire | IR-vendor observation. Beaumont reports attacker IPs in IR writeups can be unique to one victim; absence is not proof of a clean host. | Public page, no TLP marking |
| IPv4 | 78.135.96.136 | IFIN [40] | Associated exploit source (IFIN compiled observables) | Compiled by IFIN from shared reports; the original reporter of each value is not stated. | Public, no restriction |
| IPv4 | 149.28.29.221 | IFIN [40] | Associated exploit source (IFIN compiled observables) | Compiled by IFIN from shared reports; the original reporter of each value is not stated. | Public, no restriction |
| IPv4 | 80.240.22.229 | IFIN [40] | Associated exploit source (IFIN compiled observables) | Compiled by IFIN from shared reports; the original reporter of each value is not stated. | Public, no restriction |
| IPv4 | 89.36.231.206 | IFIN [40] | Associated exploit source (IFIN compiled observables) | Compiled by IFIN from shared reports; the original reporter of each value is not stated. | Public, no restriction |
| IPv4 | 91.195.240.123 | IFIN [40] | Associated exploit source (IFIN compiled observables) | Compiled by IFIN from shared reports; the original reporter of each value is not stated. WHOIS: SEDO-NET, Sedo Domain Parking - a shared parking IP used by many unrelated parked domains. Expect heavy false positives; do not block on it alone. | Public, no restriction |
| IPv4 | 143.198.7.94 | Google GTIG / Mandiant [25] | Scanning and staging infrastructure | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| IPv4 | 157.254.167.12 | Google GTIG / Mandiant [25] | NetScaler exploitation and installation of a basic webshell backdoor | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| HTTP header | HTTP_NSC_LDAP | Google GTIG / Mandiant [25] | Inbound command execution header used by nsginstaller.deb | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| HTTP header | HTTP_NSC_CLIENTTYPE | Google GTIG / Mandiant [25] | Inbound command execution header used by nsgclient.sig | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| HTTP header | HTTP_X_UX / HTTP_X_UX_[0-9]+ | Google GTIG / Mandiant [25] | Chunked base64 transport headers used by WHIPSHOT | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| URI path | /vpn/media/nsgclient.ico / /vpn/media/*.ico | Google GTIG / Mandiant [25] | Masquerading icon request routed to a .sig webshell via AliasMatch | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| URI path | /vpn/scripts/linux/nsginstaller*.deb | Google GTIG / Mandiant [25] | Staging path for malicious PHP webshells | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| URI path | /vpn/scripts/linux/nsgclient*.deb | Google GTIG / Mandiant [25] | Staging path for malicious PHP webshells | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| URI path | /vpn/scripts/linux/*.php | Google GTIG / Mandiant [25] | Staging path for malicious PHP webshells | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| File path | /tmp/.uxdport | Google GTIG / Mandiant [25] | SLAPSHOT active port artefact | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| File path | /tmp/.uxdlock | Google GTIG / Mandiant [25] | SLAPSHOT process lock artefact | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| Config directive | AddHandler application/x-httpd-php .deb | Google GTIG / Mandiant [25] | httpd.conf change making .deb files run as PHP (GTIG persistence method A) | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. Any AddHandler/AddType mapping a non-PHP extension to PHP indicates compromise, per GTIG. | Public blog, no TLP marking |
| Config directive | AddHandler application/x-httpd-php .sig | Google GTIG / Mandiant [25] | httpd.conf change making .sig files run as PHP (GTIG persistence method B) | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| Config directive | AliasMatch ^/vpn/media/(.+).ico$ /var/netscaler/gui/vpn/scripts/linux/$1.sig | Google GTIG / Mandiant [25] | Routes /vpn/media/*.ico requests to a .sig webshell with the same base name | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| File path | /netscaler/ns_gui/vpn/scripts/linux/ | Google GTIG / Mandiant [25] | Directory where WHIPSHOT was placed | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. Legitimate client binaries live here too; look for ASCII text or PHP markers. | Public blog, no TLP marking |
| Filename pattern | nginstaller* | Google GTIG / Mandiant [25] | Installer webshell names seen across intrusions, often followed by a number | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. GTIG says filenames varied between victims. | Public blog, no TLP marking |
| Filename | nsgclient.sig | Google GTIG / Mandiant [25] | .sig webshell in VPN script directories | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| Filename | e6ee7c85.sig | Google GTIG / Mandiant [25] | GTIG example .sig webshell: reads base64 payloads from HTTP_NSC_CLIENTTYPE, runs them via eval() and returns a fake 404. Reached as /vpn/media/e6ee7c85.ico through the AliasMatch above | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. Example from one intrusion; GTIG says filenames varied between victims, so absence proves nothing. | Public blog, no TLP marking |
| Log string | pitboss NOT restarting NSPPE | Google GTIG / Mandiant [25] | Watchdog message in /var/log/messages after an NSPPE crash | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. Strongest when it follows a DTLSv1.0 SSL_HANDSHAKE_FAILURE on the same appliance. | Public blog, no TLP marking |
| String | UXD_IDLE_EXIT | Google GTIG / Mandiant [25] | SLAPSHOT idle-exit variable | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| Command | chmod u+s /bin/sh | Google GTIG / Mandiant [25]; GreyNoise blog [36] | Sets setuid on /bin/sh for persistent root; ls -l /bin/sh showing -rwsr-xr-x owned by root means modified | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| IPv4 | 138.199.200.90 | Help Net Security (Sep 29) [65] | Destination for data exfiltrated via log poisoning (Hetzner), seen by Lupovis | Lupovis honeypot observation (its own post on X, plus press and Beazley). Mostly opportunistic activity after the public PoC. | Public article, no TLP marking |
| IPv4 | 138.28.234.38 | Lupovis (@LupovisDefence) on X, Sep 28 [43]; Beazley Security advisory (updated Sep 29) [27] | Exploitation with attempted DNS exfiltration (Lupovis) | Lupovis honeypot observation (its own post on X, plus press and Beazley). Mostly opportunistic activity after the public PoC. | Public article, no TLP marking |
| IPv4 | 82.167.14.7 | Beazley Security advisory (updated Sep 29) [27]; GreyNoise tag [39]; eSentire TRU [32] | Exploitation check that writes a test marker (Lupovis); exploitation source per eSentire; also tagged by GreyNoise | Lupovis honeypot observation (its own post on X, plus press and Beazley). Mostly opportunistic activity after the public PoC. May be a researcher-style check. | Public article, no TLP marking |
| IPv4 | 85.203.46.191 | Beazley Security advisory (updated Sep 29) [27]; GreyNoise tag [39] | Reconnaissance (Lupovis) | Lupovis honeypot observation (its own post on X, plus press and Beazley). Mostly opportunistic activity after the public PoC. WHOIS netname Express-Equinix-London; GreyNoise tags it as VPN, so likely a commercial VPN exit shared by many users. | Public article, no TLP marking |
| IPv4 | 154.217.251.226 | Beazley Security advisory (updated Sep 29) [27]; GreyNoise tag [39] | CVE-2026-88772 scanning (Lupovis); also tagged by GreyNoise | Lupovis honeypot observation (its own post on X, plus press and Beazley). Mostly opportunistic activity after the public PoC. | Public article, no TLP marking |
| IPv4 | 194.26.29.88 | Corelight [28] | Host of the reverse shell documented by Corelight (WHOIS: Media Land LLC, RU) | Reverse-shell infrastructure; hunt for connections from NetScaler NSIP/SNIP addresses. | Public blog, no TLP marking |
| DNS pattern | *.instances.httpworkbench.com | Help Net Security (Sep 29) [65]; Beazley Security advisory (updated Sep 29) [27] | Outbound lookups from a NetScaler suggest an out-of-band callback (Lupovis hunt advice) | httpworkbench.com is a public HTTP/DNS testing service, also used by researchers. Hunt signal only when the lookup comes from a NetScaler; do not block the apex. | Public article, no TLP marking |
| HTTP request pattern | POST /nf/auth/doAuthentication.do with body containing "pitboss PPE unexpectedly died NSPPE" | Help Net Security (Sep 29) [65] | Log-poisoning exploitation attempt (Lupovis hunt advice) | Lupovis honeypot observation (its own post on X, plus press and Beazley). Mostly opportunistic activity after the public PoC. | Public article, no TLP marking |
| URI path | /nf/auth/doAuthentication.do | Defused (@DefusedCyber) on X, Sep 29 [42]; Help Net Security (Sep 29) [65] | CVE-2026-88771 exploitation attempts seen on Defused decoys (any logged field works) | Hunting lead from Defused decoys, not an IoC. These are legitimate NetScaler endpoints; flag requests only when a logged field carries shell metacharacters or a payload. | Public post, no TLP marking |
| URI path | /cgi/login | Defused (@DefusedCyber) on X, Sep 29 [42] | CVE-2026-88771 exploitation attempts seen on Defused decoys | Hunting lead from Defused decoys, not an IoC. These are legitimate NetScaler endpoints; flag requests only when a logged field carries shell metacharacters or a payload. | Public post, no TLP marking |
| URI path | /p/u/doLogon.do | Defused (@DefusedCyber) on X, Sep 29 [42] | CVE-2026-88771 exploitation attempts seen on Defused decoys | Hunting lead from Defused decoys, not an IoC. These are legitimate NetScaler endpoints; flag requests only when a logged field carries shell metacharacters or a payload. | Public post, no TLP marking |
| URI path | /logon/LogonPoint/tmindex.html | Defused (@DefusedCyber) on X, Sep 29 [42] | CVE-2026-88771 exploitation attempts seen on Defused decoys | Hunting lead from Defused decoys, not an IoC. These are legitimate NetScaler endpoints; flag requests only when a logged field carries shell metacharacters or a payload. | Public post, no TLP marking |
| HTTP header | User-Agent (payload in the header on requests to /) | Defused (@DefusedCyber) on X, Sep 29 [42]; CERT-EU [19] | CVE-2026-88771 exploitation attempts seen on Defused decoys | Hunting lead from Defused decoys, not an IoC. These are legitimate NetScaler endpoints; flag requests only when a logged field carries shell metacharacters or a payload. CERT-EU separately flags base64 User-Agent strings starting with INDEX:. | Public post, no TLP marking |
| Filename | nx_verify.html | Defused (@DefusedCyber) on X, Sep 29 [42] | Marker file dropped to tag vulnerable boxes for a target list (Defused) | Also written by testers; means the box was reached and is exploitable, not necessarily that an actor installed a backdoor. | Public post, no TLP marking |
| SHA-256 | 5ea5ea61e9062822bee3f66ef5ff47c217178d9e31936ad6daf10c5dfae44d12 | eSentire TRU [32] | PHP webshell, .ico variant (publicly on VirusTotal per eSentire) | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| SHA-256 | 7add390ceee4a1373211b3e340451b34f08965fc4d805f94c9b8cebdc0775774 | eSentire TRU [32] | PHP webshell, .deb variant (not in public repositories per eSentire) | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| File path | /var/netscaler/gui/vpn/scripts/linux/*.sig | eSentire TRU [32]; Google GTIG / Mandiant [25] | .ico-variant webshell location (eSentire); also matches GTIG method B | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| HTTP request pattern | GET /vpn/media/*.ico with base64 PHP (starting "PD9") appended to the User-Agent | eSentire TRU [32]; CERT-EU [19] | Payload staging via the access log (eSentire; matches CERT-EU technique) | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| IPv4 | 34.90.151.231 | eSentire TRU [32] | Reconnaissance and webshell delivery (eSentire) | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. Google Cloud address space; may be reassigned. | Public advisory, no TLP marking |
| IPv4 | 31.56.197.72 | eSentire TRU [32] | Payload host (eSentire) | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| IPv4 | 64.94.85.67 | eSentire TRU [32]; GreyNoise tag [39] | Payload host (eSentire); also tagged by GreyNoise | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| IPv4 | 23.27.143.20 | eSentire TRU [32] | Payload host (eSentire) | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| IPv4 | 62.133.62.80 | eSentire TRU [32] | Payload host (eSentire) | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| IPv4 | 144.172.108.78 | eSentire TRU [32] | Exploitation source (eSentire) | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| IPv4 | 185.156.46.162 | eSentire TRU [32]; GreyNoise tag [39] | Exploitation source (eSentire); also tagged by GreyNoise | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. GreyNoise tags it as VPN; may be shared. | Public advisory, no TLP marking |
| IPv4 | 153.75.82.220 | eSentire TRU [32]; GreyNoise tag [39] | Exploitation source (eSentire); also tagged by GreyNoise | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| IPv4 | 216.203.21.233 | eSentire TRU [32]; GreyNoise tag [39] | Exploitation source (eSentire); also tagged by GreyNoise | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| IPv4 | 185.243.41.247 | eSentire TRU [32] | Campaign infrastructure (eSentire) | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| Network | UDP/443 (DTLSv1.0) | Google GTIG / Mandiant [25] | Delivery protocol for the CVE-2026-88772 exploit (GTIG) | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. Legitimate DTLS VPN traffic uses the same port; baseline normal DTLS sources. | Public blog, no TLP marking |
| Config directive | Alias /logon/LogonPoint/custom/receiver.min.css | Beazley Security Labs [33]; GreyNoise blog [36] | httpd.conf route to the .ctxs.receiver webshell (GreyNoise, via Beazley) | Hunting lead compiled by Beazley Security Labs; not proof of compromise on its own. | Public advisory, no TLP marking |
| Config directive | AliasMatch ^/logon/LogonPoint/custom/receiver\.min\.[0-9a-f]+\.css$ | Beazley Security Labs [33]; GreyNoise blog [36] | httpd.conf route variant to the webshell (GreyNoise, via Beazley) | Hunting lead compiled by Beazley Security Labs; not proof of compromise on its own. | Public advisory, no TLP marking |
| Config directive | php_flag engine on (changed from off) plus a SetHandler block for the webshell file | Beazley Security Labs [33]; CERT-EU [19] | PHP enabled for the webshell in httpd.conf (GreyNoise, CERT-EU, via Beazley) | Hunting lead compiled by Beazley Security Labs; not proof of compromise on its own. Compare /etc/httpd.conf with a clean appliance on the same build. | Public advisory, no TLP marking |
| HTTP cookie | CsrfToken + NSC_TASS | Beazley Security Labs [33]; IFIN [40] | Cookies used to access the .ctxs.receiver webshell (GreyNoise, via Beazley) | NetScaler uses both cookies legitimately. Suspicious only when NSC_TASS carries URL-encoded commands on requests to the webshell path. | Public advisory, no TLP marking |
| Log string | pitboss log lines containing IFS or b64decode | Beazley Security Labs [33] | Log-poisoning exploitation of CVE-2026-88771 (Beaumont, via Beazley); check ns.log, /var/log/messages and your SIEM | Hunting lead compiled by Beazley Security Labs; not proof of compromise on its own. | Public advisory, no TLP marking |
| Log string | "missed too many heartbeats" or "unexpectedly died" in authentication log lines | Beazley Security Labs [33]; CERT-EU [19] | Crafted login usernames imitating packet-engine messages (watchTowr, CERT-EU, via Beazley); ns.log | Hunting lead compiled by Beazley Security Labs; not proof of compromise on its own. | Public advisory, no TLP marking |
| User-Agent | ns-88771-poc | Beazley Security Labs [33] | Public PoC/scanner User-Agent seen by Lupovis (via Beazley); Apache access logs | A public testing tool, not an actor indicator. Means someone tested the box. | Public advisory, no TLP marking |
| String | NX-CVE-OK | Beazley Security Labs [33] | Test-marker text dropped in web folders by exploitation checks (Lupovis, via Beazley); grep /netscaler/ns_gui | Means the box was reached and is exploitable, not necessarily backdoored. | Public advisory, no TLP marking |
| File permission | /bin/sh expected -r-xr-xr-x (setuid means modified) | Beazley Security Labs [33]; Google GTIG / Mandiant [25] | Check with ls -l /bin/sh before patching; the installer sets setuid (Beazley, GTIG) | Hunting lead compiled by Beazley Security Labs; not proof of compromise on its own. | Public advisory, no TLP marking |
| IPv4 | 172.247.44.85 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (CNSERVERS LLC, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 165.227.201.112 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (DigitalOcean, LLC, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 173.231.39.244 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (WebNX, Inc., United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 64.225.103.14 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (DigitalOcean, LLC, Germany) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 159.65.104.231 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (DigitalOcean, LLC, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 142.93.205.229 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (DigitalOcean, LLC, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 182.101.54.57 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (CHINANET BACKBONE, China) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 87.224.84.82 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Spitfire Network Services Limited, United Kingdom) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 137.220.53.135 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (The Constant Company, LLC, Canada) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 120.28.233.211 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Globe Telecoms, Philippines) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 149.28.58.71 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (The Constant Company, LLC, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 23.234.111.22 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (tzulo, inc., United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. VPN or proxy exit shared by many users; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 198.13.159.233 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (BL Networks, Netherlands) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 85.221.203.85 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (INEA sp. z o.o., Poland) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 46.150.68.55 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Kyivski Telekomunikatsiyni Merezhi, Ukraine) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 159.26.103.184 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Proton AG, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. VPN or proxy exit shared by many users; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 45.249.89.172 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (SpeedyPage Ltd, Japan) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 197.52.9.138 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (TE-AS, Egypt) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 180.242.113.168 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (PT Telekomunikasi Indonesia, Indonesia) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 85.117.117.248 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Mobile Telecom-Service LLP, Kazakhstan) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 73.43.85.7 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Comcast Cable Communications, LLC, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 88.180.103.22 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Free SAS, France) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 194.28.195.90 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Dialog-K LLC, Russia) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 95.63.246.50 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Vodafone Espana S.A.U., Spain) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 31.13.192.160 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (SKAT POPOVO Ltd., Bulgaria) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 185.170.55.89 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (LLC Electron-Telecom, Russia) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 104.203.50.26 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Blue Stream, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 37.19.221.171 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Datacamp Limited, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. VPN or proxy exit shared by many users; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 45.143.167.96 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (BlueVPS OU, Netherlands) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 206.232.71.215 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Leaseweb Deutschland GmbH, Germany) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 130.94.106.141 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (LIGHT NODE LIMITED, Argentina) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 58.187.56.89 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (FPT Telecom Company, Vietnam) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 171.106.10.118 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (CHINANET BACKBONE, China) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 82.24.212.15 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Shock Hosting LLC, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 178.66.43.241 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (PJSC Rostelecom, Russia) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 185.209.15.246 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (ESTOXY OU, Netherlands) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 94.190.77.195 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (INTERRA telecommunications group, Ltd., Russia) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 93.177.60.233 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (PJSC Rostelecom, Russia) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 68.46.140.222 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Comcast Cable Communications, LLC, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 178.218.40.232 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (ATEXS PLUS Ltd., Russia) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 49.36.107.103 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Reliance Jio Infocomm Limited, India) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 191.37.30.194 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (WRNET LTDA, Brazil) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 23.234.74.48 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (tzulo, inc., United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. VPN or proxy exit shared by many users; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 72.73.231.73 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Verizon Business, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 95.229.84.239 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Telecom Italia S.p.A., Italy) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 113.137.102.68 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (CHINANET BACKBONE, China) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 47.243.125.255 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 47.76.92.109 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 8.217.173.25 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 8.210.67.91 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 47.239.205.29 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 47.76.132.65 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 8.218.219.56 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 47.76.102.1 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 47.76.63.52 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 8.210.119.74 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 64.177.93.71 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (The Constant Company, LLC, Mexico) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 44.252.255.141 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Amazon.com, Inc., United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 194.242.130.193 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (WAHYU, Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 125.122.56.47 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (CHINANET BACKBONE, China) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 23.132.164.35 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Netiface America, Inc., Switzerland) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 92.118.204.229 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Catixs Ltd, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 54.70.59.128 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Amazon.com, Inc., United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 44.226.128.41 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Amazon.com, Inc., United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 4.246.63.96 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Microsoft Corporation, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 176.65.148.54 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Pfcloud UG, Netherlands) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 104.28.193.147 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 29 (Cloudflare, Inc., Japan) | Cloudflare WARP egress address, shared by very many ordinary Cloudflare WARP / 1.1.1.1 users. Never block it and never import it into an IoC feed; use it only to correlate timing within your own logs. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 104.28.211.105 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 29 (Cloudflare, Inc., Japan) | Cloudflare WARP egress address, shared by very many ordinary Cloudflare WARP / 1.1.1.1 users. Never block it and never import it into an IoC feed; use it only to correlate timing within your own logs. | GreyNoise Visualizer tag search, viewed Sep 29 |
| User-Agent | Python-urllib | Lupovis (@LupovisDefence) on X, Sep 28 [43] | Client used for CVE-2026-88771 log-poison exploitation on Lupovis decoys (payload runs id;uname, DNS callback to httpworkbench) | Lupovis honeypot observation (its own post on X, plus press and Beazley). Mostly opportunistic activity after the public PoC. Python-urllib is a common library default; only meaningful together with the auth-endpoint payload. | Public post, no TLP marking |
| URI path | /vpn/scripts/linux/nsgclient18.deb | Maurice_Sec on X [72]; CyberMaxx [35]; Google GTIG / Mandiant [25] | GET requests referenced in a NetScaler Console IoC scanner finding (Maurice_Sec field notes) | Single practitioner report; the author is "not 100%" on this finding. Matches the GTIG nsgclient*.deb staging pattern. A legitimate client package normally lives at similar paths, so check file content, not just the name. | Public post, no TLP marking |
| URI path | /vpn/scripts/linux/nsgclient18_32.deb | Maurice_Sec on X [72]; CyberMaxx [35]; Google GTIG / Mandiant [25] | GET requests referenced in a NetScaler Console IoC scanner finding (Maurice_Sec field notes) | Single practitioner report; the author is "not 100%" on this finding. Matches the GTIG nsgclient*.deb staging pattern. Check file content, not just the name. | Public post, no TLP marking |
| Domain | echvista.com | IFIN [40] | Associated exploit source (IFIN compiled observables) | Compiled by IFIN from shared reports; the original reporter of each value is not stated. No A record when checked on Sep 29. | Public, no restriction |
Post-exploitation steps attempted on a GreyNoise sensor
GreyNoise says the attacker did not gain a foothold on its sensor. The steps below show the attacker's playbook, not a successful compromise.
- Set setuid and setgid on
/bin/sh. - Planted a PHP webshell that authenticates by cookie.
- Killed and restarted httpd, for anti-forensics or to activate the changed config.
A Reddit user described one sample of the .ctxs.receiver file, and IFIN relayed the description. This is unconfirmed. [40]
- The file is a 237-byte PHP one-liner.
- It runs a URL-decoded cookie value through
passthru(), but only when a second cookie matches a hardcoded 16-character hex token. - NetScaler uses both cookie names legitimately, so the traffic blends in.
- The file survived a reboot and the upgrade to 14.1-73.37.
The token likely differs per victim, so search the file's content rather than relying on its hash.
Source: GreyNoise, "Swarming Against Citrix 0-Day Exploitation". Victim-specific names and IPs from later IR-vendor writeups are deliberately left out. Beaumont warns that publishing them exposes organisations that have not yet remediated. [51]
Related pages
References
| # | Source | Type | URL |
|---|---|---|---|
| 1 | Citrix - CTX697096 security bulletin (Sep 27) | Primary official advisories | https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html |
| 2 | Citrix community blog - Security Bulletin for CVE-2026-88771 through CVE-2026-88778 (incl. IoC section) verification pending | Primary official advisories | https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/ |
| 3 | Citrix (CTX-Michael) on r/Citrix, Sep 27 - CRITICAL UPDATE announcement | Primary official advisories | https://www.reddit.com/r/Citrix/comments/1wro1yf/critical_update_citrix_netscaler_adc_and_citrix/ |
| 4 | NetScaler Console documentation - Indicators of Compromise detection (incl. Citrix disclaimer on limits) | Primary official advisories | https://docs.netscaler.com/en-us/netscaler-console-service/instance-advisory/ioc |
| 5 | CISA alert - Critical zero-day vulnerabilities exploited in Citrix NetScaler ADC/Gateway (Sep 27) | Primary official advisories | https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway |
| 6 | NCSC-NL advisory NCSC-2026-0394 (probability high, damage high; per-CVE scores and preconditions) | Primary official advisories | https://advisories.ncsc.nl/ |
| 7 | NCSC-UK - Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Gateway | Primary official advisories | https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway |
| 8 | CSA Singapore - AL-2026-129 | Primary official advisories | https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-129/ |
| 9 | Canadian Centre for Cyber Security - AL26-024 | Primary official advisories | https://www.cyber.gc.ca/en/alerts-advisories/al26-024-critical-vulnerabilities-affecting-citrix-netscaler-adc-netscaler-gateway-cve-2026-88771-cve-2026-88772 |
| 10 | HKCERT - Citrix Products Multiple Vulnerabilities (Sep 28) | Primary official advisories | https://www.hkcert.org/security-bulletin/citrix-products-multiple-vulnerabilities_20260928 |
| 11 | ACSC (Australia) - Critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway | Primary official advisories | https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/critical-vulnerabilities-in-citrix-netscaler-adc-and-citrix-netscaler-gateway-products |
| 12 | CISA Known Exploited Vulnerabilities catalog (both CVEs added Sep 27, due Sep 30) | Primary official advisories | https://www.cisa.gov/known-exploited-vulnerabilities-catalog |
| 13 | CERT-EU Security Advisory 2026-014 - Critical Vulnerabilities in Citrix NetScaler ADC and Gateway (Sep 27) | Primary official advisories | https://cert.europa.eu/publications/security-advisories/2026-014/ |
| 14 | DKCERT (CERT for Danish universities and research) - To kritiske NetScaler 0-dage udnyttes aktivt før patch (Sep 29) | Primary official advisories | https://cert.dk/node/639 |
| 15 | NHS England Digital cyber alert CC-4858 (Sep 28) - Exploitation of zero-day vulnerabilities affecting Citrix NetScaler | Primary official advisories | https://digital.nhs.uk/cyber-alerts/2026/cc-4858 |
| 16 | CIRCL TR-100 - per-CVE configuration-check CLI commands | Primary official advisories | https://www.circl.lu/pub/tr-100/ |
| 17 | Dutch government letter to parliament - Kwetsbaarheden Citrix Netscaler (2026D47262, Sep 29) | Primary official advisories | https://www.tweedekamer.nl/kamerstukken/brieven_regering/detail?id=2026D47262&did=2026D47262 |
| 18 | CVE.org - CVE-2026-88771 record (reserved Sep 10 07:14 UTC by NetScaler; published Sep 27 16:02 UTC) | Primary official advisories | https://www.cve.org/CVERecord?id=CVE-2026-88771 |
| 19 | CERT-EU - Taking "execute logging" a bit too literally - CVE-2026-88771 (Sep 28) | Technical research | https://www.cert.europa.eu/blog/taking-execute-logging-a-bit-too-literally-cve-2026-88771 |
| 20 | watchTowr Labs part 1 - Oh Look, the Foot Gun Went Off Again (CVE-2026-88771) (Sep 28) | Technical research | https://labs.watchtowr.com/oh-look-the-foot-gun-went-off-again-citrix-netscaler-preauth-command-injection-cve-2026-88771/ |
| 21 | watchTowr Detection Artefact Generator - CVE-2026-88771 (GitHub) | Technical research | https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88771 |
| 22 | watchTowr Labs part 2 - Here We Go Again (CVE-2026-88772), Sina Kheirkhah (Sep 29) | Technical research | https://labs.watchtowr.com/here-we-go-again-citrix-netscaler-dtls-preauth-memory-overflow-cve-2026-88772/ |
| 23 | watchTowr Detection Artefact Generator - CVE-2026-88772 (GitHub) | Technical research | https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772 |
| 24 | Truesec - Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (Sep 28) | Technical research | https://www.truesec.com/hub/blog/multiple-critical-vulnerabilities-in-citrix-netscaler-adc-and-netscaler-gateway |
| 25 | Google GTIG / Mandiant - Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances (Sep 29) | Technical research | https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances |
| 26 | Nextron Systems (Florian Roth) - New THOR Detection Coverage for CVE-2026-88771 and CVE-2026-88772 (Sep 29) | Technical research | https://www.nextron-systems.com/2026/09/29/new-thor-detection-coverage-for-citrix-netscaler-cve-2026-88771-and-cve-2026-88772/ |
| 27 | Beazley Security advisory (updated Sep 29) - IoC table incl. Lupovis honeypot IPs | Technical research | https://beazley.security/alerts-advisories/critical-vulnerability-in-citrix-netscaler-zero-day-prompts-emergency-shutdowns-cve-2026-88771-cve-2026-88772 |
| 28 | Corelight - Hunting Citrix NetScaler zero-days (Zeek queries, Sep 28) | Technical research | https://corelight.com/blog/hunting-citrix-netscaler-zero-days-corelight |
| 29 | Elastic detection rule - Potential NetScaler Log Poisoning Command Injection Attempt (merged Sep 28) | Technical research | https://github.com/elastic/detection-rules/blob/main/rules/network/initial_access_netscaler_log_poisoning_command_injection.toml |
| 30 | SigmaHQ pull request #6352 - NetScaler auth endpoint shell metacharacters (open, Sep 29) | Technical research | https://github.com/SigmaHQ/sigma/pull/6352 |
| 31 | Nuclei templates pull request #17336 - CVE-2026-88771 active probe (open, Sep 28) | Technical research | https://github.com/projectdiscovery/nuclei-templates/pull/17336 |
| 32 | eSentire TRU - Update: ongoing exploitation of NetScaler CVE-2026-88771 / -88772 (first-hand IR, Sep 29) | Technical research | https://www.esentire.com/security-advisories/update-ongoing-exploitation-of-citrix-netscaler-adc-and-netscaler-gateway-vulnerabilities-cve-2026-88771-cve-2026-88772 |
| 33 | Beazley Security Labs - BSL-A1216 advisory (updates 3-4, Sep 29): consolidated IoCs and hunting commands | Technical research | https://labs.beazley.security/advisories/BSL-A1216 |
| 34 | watchTowr (@watchtowrcyber) on X, Sep 26 - "Unpatched, 0days. Exploited in-the-wild - discovered during forensics." | Technical research | https://x.com/watchtowrcyber/status/2103972792043479307 |
| 35 | CyberMaxx - Patches required: Citrix NetScaler vulns exploited in the wild (IoC notes) | Technical research | https://www.cybermaxx.com/resources/patches-required-citrix-netscaler-vulns-exploited-in-the-wild-cve-2026-88771-and-cve-2026-88772/ |
| 36 | GreyNoise - Swarming Against Citrix 0-Day Exploitation (TLP:CLEAR IoCs, Sep 28) | Telemetry and IoCs | https://greynoise.io/blog/swarming-against-citrix-0-day-exploitation |
| 37 | GreyNoise Chronicle - GNTL-20260928 CVE-2026-88771 timeline | Telemetry and IoCs | https://www.greynoise.io/chronicle/gntl-20260928-citrix-cve-2026-88771 |
| 38 | GreyNoise Visualizer - IP 149.104.78.141 | Telemetry and IoCs | https://viz.greynoise.io/ip/149.104.78.141 |
| 39 | GreyNoise tag - Citrix NetScaler CVE-2026-88771 Login Command Injection RCE Attempt | Telemetry and IoCs | https://viz.greynoise.io/tag/citrix-netscaler-cve-2026-88771-login-command-injection-rce-attempt |
| 40 | IFIN - Multiple Citrix Netscaler 0-Days Exploited (tracking thread, from Sep 26; observables "shared without restriction") | Telemetry and IoCs | https://ifin.network/t/multiple-citrix-netscaler-0-days-exploited/867 |
| 41 | Censys advisory - NetScaler exposure (42,735 hosts, Sep 28) | Telemetry and IoCs | https://censys.com/advisory/cve-2026-10747-2/ |
| 42 | Defused (@DefusedCyber) on X, Sep 29 - decoy hits across multiple CVE-2026-88771 paths | Telemetry and IoCs | https://x.com/DefusedCyber/status/2104888497693708505 |
| 43 | Lupovis (@LupovisDefence) on X, Sep 28 - decoys catch CVE-2026-88771 exploitation hours after the PoC | Telemetry and IoCs | https://x.com/lupovisdefence/status/2104595071362326680 |
| 44 | Beaumont, Sep 27 - chained CVEs, webshells all September, "Probably nation state aligned" | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117343729453093307 |
| 45 | Beaumont, Sep 27 - patches live; detection script behind NDA; patching does not remove backdoors | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117343821114841048 |
| 46 | Beaumont, Sep 27 - Console check misses attempts when logs have rotated | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117345540231975640 |
| 47 | Beaumont, Sep 28 22:49 UTC - names "PitScaler", >100 victim orgs (his claim) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117351107654208046 |
| 48 | Beaumont, Sep 28 23:02 UTC - Citrix checker incomplete (suid /bin/sh) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117351155381900219 |
| 49 | Beaumont, Sep 29 04:39 UTC - mass exploitation, <10% patched (his claim) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117352481501981552 |
| 50 | Beaumont, Sep 29 06:18 UTC - public message to the NSA (his unverified claim) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117352869498139711 |
| 51 | Beaumont, Sep 29 16:12 UTC - IR vendors publishing victim-unique webshell names | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117355208096613386 |
| 52 | Beaumont, Sep 28 15:13 UTC - GitHub "PoCs" for the new Citrix vulns are "fake AI slop" | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117349313638958333 |
| 53 | Beaumont, Sep 29 18:32 UTC - Dutch government shuts down all Citrix NetScalers (relaying @bert_hubert) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117355758746619146 |
| 54 | BleepingComputer (Sep 29) - Hackers exploit Citrix NetScaler zero-day to deploy web shells | Press and vendor coverage | https://www.bleepingcomputer.com/news/security/hackers-exploit-citrix-netscaler-zero-day-to-deploy-web-shells/ |
| 55 | BleepingComputer (Sep 27) - Citrix admins warned to shut down NetScalers | Press and vendor coverage | https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/ |
| 56 | SecurityWeek (Sep 28) - Citrix confirms 2 NetScaler zero-days | Press and vendor coverage | https://www.securityweek.com/citrix-confirms-2-netscaler-zero-days-after-admins-pulled-the-plug/ |
| 57 | The Record (Sep 28) - US, UK warn of Citrix NetScaler zero-day bug | Press and vendor coverage | https://therecord.media/us-uk-warn-of-citrix-netscaler-zero-day-bug |
| 58 | CyberScoop (Sep 28) - delayed-disclosure angle | Press and vendor coverage | https://cyberscoop.com/citrix-zero-days-delayed-disclosure/ |
| 59 | Sophos CTU (Sep 28) - CVE-2026-88771 / -88772 in active exploitation | Press and vendor coverage | https://www.sophos.com/en-us/blog/citrix-netscaler-cve-2026-88771-cve-2026-88772-in-active-exploitation |
| 60 | Rapid7 ETR (Sep 28) | Press and vendor coverage | https://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772/ |
| 61 | watchTowr FAQ (Sep 27-28) | Press and vendor coverage | https://watchtowr.com/intelligence/citrix-netscaler-zero-day-vulnerabilities-faq/ |
| 62 | The Register (Sep 29) - Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services | Press and vendor coverage | https://www.theregister.com/security/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-professional-services/5299867 |
| 63 | Unit 42 (Palo Alto Networks) - NetScaler zero-days threat brief (Sep 27, updated Sep 28) | Press and vendor coverage | https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/ |
| 64 | Cybersecurity Dive (Sep 28) - Shadowserver: more than 20,000 instances exposed | Press and vendor coverage | https://www.cybersecuritydive.com/news/citrix-upgrades-netscaler-exploitation/831502/ |
| 65 | Help Net Security (Sep 29) - NetScaler zero-day exploitation escalates into mass attacks (Lupovis, Censys) | Press and vendor coverage | https://www.helpnetsecurity.com/2026/09/29/netscaler-zero-day-exploitation-escalates-into-mass-attacks-cve-2026-88771/ |
| 66 | Ingeniøren (Sep 30) - Alvorlige huller i kendt software: PET, Forsvaret og Politiet hastelukker systemer | Press and vendor coverage | https://ing.dk/artikel/alvorlige-huller-i-kendt-software-pet-forsvaret-og-politiet-hastelukker-systemer |
| 67 | SDxCentral (Sep 29) - NetScaler bugs bring critical sectors down in Europe (citing Techzine) | Press and vendor coverage | https://www.sdxcentral.com/news/netscaler-bugs-bring-critical-sectors-down-in-europe/ |
| 68 | Cybersecurity Dive (Sep 29) - Citrix NetScaler exploitation began days before public notification | Press and vendor coverage | https://www.cybersecuritydive.com/news/citrix-netscaler-exploitation-days-before-notification/831634/ |
| 69 | heise online (Sep 27) - New zero-day exploits in Citrix NetScaler | Press and vendor coverage | https://www.heise.de/en/news/Security-researchers-warn-New-zero-day-exploits-in-Citrix-Netscaler-11467269.html |
| 70 | Dark Reading (Sep 29) - Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers | Press and vendor coverage | https://www.darkreading.com/vulnerabilities-threats/netscaler-zero-days-chaos-citrix |
| 71 | Omroep Brabant (Sep 27) - Storing bij ziekenhuizen door kritieke kwetsbaarheden in systeem (Amphia, ETZ, Z-CERT) | Press and vendor coverage | https://www.omroepbrabant.nl/nieuws/6028828/storing-bij-ziekenhuizen-door-kritieke-kwetsbaarheden-in-systeem |
| 72 | Maurice_Sec on X - notes from the field on NetScaler Console IoC scanner findings | Community | https://x.com/Maurice_Sec/status/2104541998858240487 |
| 73 | r/Citrix - "Netscaler leak?" thread (~Sep 26) | Community | https://www.reddit.com/r/Citrix/comments/1wqjk9a/netscaler_leak/ |