Comcast Cable Communications, doing business as Xfinity, disclosed on Monday that attackers who breached one of its Citrix servers in October also stole customer-sensitive information from its systems. On October 25, roughly two weeks after Citrix released security updates to address a critical vulnerability now known as Citrix Bleed and tracked as CVE-2023-4966, the telecommunications company found evidence of malicious activity on its network between October 16 and October 19. Cybersecurity company Mandiant says the Citrix flaw had been actively exploited as a zero-day since at least late August 2023. Following an investigation into the impact of the security breach, Xfinity discovered on November 16 that the attackers also exfiltrated data belonging to an undisclosed number of customers from its systems. "After additional review of the affected systems and data, Xfinity concluded on December 6, 2023, that the customer information in scope included usernames and hashed passwords; for some customers, other information may also have been included, such as names, contact information, last four digits of social security numbers, dates of birth and/or secret questions and answers. However, the data analysis is continuing," the company said. While Xfinity says it has asked users to reset their passwords to protect affected accounts, customers report that they had been getting password reset requests last week without any indication as to why that was happening. "To protect your...
Xfinity discloses data breach after recent Citrix server hack
BleepingComputer
·Sergiu Gatlan
·Published Dec 19, 2023
·Updated
Affected Software
1 affected component
Unknown=CVE-2023-4966
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a data breach at Xfinity caused by a hack of its Citrix server, leading to the exposure of customer-sensitive information.
2
What security implications are discussed in the article?
The breach raises concerns about the security of customer data and the potential risks associated with vulnerabilities in Citrix servers.
3
What products or software are affected by the breach?
The affected software is Citrix, specifically a vulnerability identified as CVE-2023-4966.
4
When did the breach occur and when was it disclosed?
The breach occurred on October 25, and Xfinity disclosed it in early November.
5
What types of customer information were compromised in the breach?
The breach involved the theft of customer-sensitive information, although specific details are not provided in the article.