• News/
  • https://www.theregister.com/2025/11/12/amazon_cisco_citrix_0day_exploits/

Attackers turned Citrix, Cisco 0-day exploits into custom-malware hellscape

The Register
·
Jessica Lyons
·
Published Nov 12, 2025
·
Updated

An "advanced" attacker exploited CitrixBleed 2 and a max-severity Cisco Identity Services Engine (ISE) bug as zero-days to deploy custom malware, according to Amazon Chief Information Security Officer CJ Moses. The cloud giant's MadPot honeypot detected the unnamed miscreant(s) attempting to break into buggy Citrix NetScaler ADC and NetScaler Gateway devices via CVE-2025-5777 before the critical vulnerability was publicly disclosed, Moses said in a Wednesday security blog. CVE-2025-5777 is an out-of-bounds read flaw in NetScaler Gateway and AAA virtual servers that can allow remote attackers to leak memory contents. Security researchers dubbed it CitrixBleed 2 due to similarities with the original CitrixBleed that allowed both nation-state spies and ransomware gangs to steal session secrets. Citrix disclosed and issued a fix for CVE-2025-5777 on June 17, and soon after bug hunters started warning that things could get really, really bad if customers didn't patch immediately. By July, the US Cybersecurity and Infrastructure Security Agency and private researchers said the flaw was under exploitation and being abused to hijack user sessions - although Citrix still hasn't commented on the attacks. "Through further investigation of the same threat exploiting the Citrix vulnerability, Amazon Threat Intelligence identified and shared with Cisco an anomalous payload targeting a previously undocumented endpoint in Cisco ISE that used vulnerable deserialization logic," Moses wrote. Th...

Read full article

Affected Software

2 affected components
Citrix NetScaler ADC
Citrix NetScaler Gateway
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses how attackers exploited zero-day vulnerabilities in Citrix and Cisco products to deploy custom malware.

2

What security implications are discussed in the article?

The article highlights the risks associated with zero-day exploits and the advanced techniques used by attackers to infiltrate systems.

3

What products or software are affected?

The affected products include Citrix NetScaler ADC and Citrix NetScaler Gateway.

4

Who reported the security incident?

The incident was reported by Amazon's Chief Information Security Officer, CJ Moses.

5

What type of vulnerabilities were exploited in this attack?

The attackers exploited a zero-day vulnerability known as CitrixBleed 2 and a severe bug in the Cisco Identity Services Engine (ISE).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
Attackers turned Citrix, Cisco 0-day exploits into custom-malware hellscape - SecAlerts