Citrix and FireEye Mandiant released a forensic tool to help organizations investigate exploitation of CVE-2019-19781, a critical vulnerability affecting Citrix ADC and Citrix Gateway appliances. The Dutch National Cyber Security Centre warned that internet-facing affected systems not mitigated before public exploits emerged on 9 January 2020 should be presumed compromised.
Organizations were advised to patch affected appliances immediately, review logs back to Citrix’s 17 December 2019 disclosure, and use forensic investigation to identify compromise. Where indicators are found, responders should rebuild affected systems from clean images and rotate credentials and certificates; organizations that applied mitigations earlier should still patch and monitor for activity by advanced threat actors.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
Citrix released a new patch for affected version 10.5.
Citrix released new patches for affected Citrix ADC and Citrix Gateway versions 12.1 and 13.0.
The Dutch NCSC published the first version of its advisory on patching and recovering Citrix ADC and Gateway systems affected by the vulnerability.
Public exploits became available for the Citrix ADC and Gateway vulnerability. The NCSC said systems not mitigated before this date should reasonably be presumed compromised.
Citrix published the vulnerability affecting Citrix ADC and Citrix Gateway products. The NCSC advised organizations to review logs beginning from this disclosure date during forensic investigations.
Citrix released refreshed 12.1 builds 50.28 and 50.31. The NCSC said the mitigation issue associated with the earlier 12.1 build 50.28 did not apply to these refreshed builds.
Citrix released version 12.1 build 50.28, which the NCSC later warned had an issue affecting implementation of the vulnerability mitigations.
Citrix and FireEye Mandiant shared a forensic tool for investigating CVE-2019-19781.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.