Swarming Against Citrix 0-Day Exploitation

GreyNoise Version 1 original current

Imported from official source

On 24 September 2026, a malicious cyber actor (MCA) used 149.104.78.141 to attempt zero-day exploitation against a Citrix NetScaler Gateway. At the time, there were no CVE-specific detections for the attack due to it occurring pre-disclosure. However, GreyNoise still detected and labeled the activity as fundamentally malicious within seconds due to behavioral detections.

This version

Version
1 of 1
Recorded
September 28, 2026 17:00
Change
Initial
Content hash
f78a65dbcdcedd994413fb443dd7ae93
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.