Swarming Against Citrix 0-Day Exploitation

Imported from official source

Cybersecurity Classified by Officially

GreyNoise observes adversary activity through our Global Observation Grid (GOG), a network of sensors that draws attacker scanning and exploitation onto infrastructure we control. This lets us study adversary infrastructure, tooling, and tradecraft directly, without waiting for a victim investigation. GreyNoise also expands the GOG through Project Swarm, which enables the broader security community to join the effort. The activity discussed in this blog was derived from a Swarm participant sensor. 

On 24 September 2026, a malicious cyber actor (MCA) used 149.104.78.141 to attempt zero-day exploitation against a Citrix NetScaler Gateway. At the time, there were no CVE-specific detections for the attack due to it occurring pre-disclosure. However, GreyNoise still detected and labeled the activity as fundamentally malicious within seconds due to behavioral detections. GreyNoise will not publish full details of the exploitation chain at this time. Patches are available and post-exploitation details are included below.

Though the adversary was unsuccessful in gaining a foothold on the targeted Swarm sensor, their post-exploitation playbook was revealed.

This is an extract. The publication continues at the source.

Read the original at the source: https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation

Officially imported this from GreyNoise’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
GreyNoise — imported from official source
Official source
https://www.greynoise.io/blog/rss.xml RSS
Imported
September 28, 2026 17:00
Versions
1 recorded
Identity
https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.