🛡 VULNERABILIDADES 🛡

Incidentes de Kiteworks y Citrix Revelan Desafíos en la Respuesta a Zero-Day

🛡CyberObservatorio
Incidentes de Kiteworks y Citrix Revelan Desafíos en la Respuesta a Zero-Day
Idioma

Incidentes de Kiteworks y Citrix Revelan Desafíos en la Respuesta a Zero-Day

Fuente: Dark Reading

El 24 de septiembre, la firma de detección de amenazas GreyNoise Intelligence identificó un único dirección IP basada en EE. UU. que estaba realizando escaneos de instalaciones de Citrix NetScaler y llevando a cabo ataques de ejecución remota de código (RCE). Ante esta actividad maliciosa, GreyNoise emitió alertas a sus clientes.

En los días siguientes, comenzaron a surgir en redes sociales reportes sobre posibles ataques de día cero a las instalaciones de NetScaler. La comunidad de ciberseguridad se dividió en opiniones sobre la veracidad de estos rumores, con algunos argumentando que las actividades observadas se dirigían a vulnerabilidades ya corregidas en agosto. Sin embargo, el 26 de septiembre, Benjamin Harris, fundador y CEO de la firma de gestión de exposiciones WatchTowr, instó a los usuarios de NetScaler a desconectar sus sistemas. "El lunes será demasiado tarde", afirmó en una publicación de LinkedIn.

Para el domingo, Citrix parecía haber tomado nota de la situación, publicando una actualización que corrigió ocho vulnerabilidades (CVE-2026-88771 a CVE-2026-88778), incluidas dos de día cero que ya estaban siendo explotadas activamente. Sin embargo, el blog de la compañía no recomendó que los servidores se desconectaran hasta que se aplicaran los parches, sino que instó a los clientes a "actualizar a las versiones que contienen la solución de inmediato." A pesar de esto, las dos vulnerabilidades de día cero, CVE-2026-88771 y CVE-2026-88772, fueron objeto de una explotación generalizada.

El mismo fin de semana, el proveedor de protección de datos Kiteworks adoptó un enfoque diferente. El 25 de septiembre, la compañía emitió una recomendación a sus clientes, instándoles a desconectar proactivamente sus sistemas basándose en información sobre un ataque inminente. Con su equipo de ingeniería y expertos en inteligencia nacional colaborando para identificar el problema de seguridad, Kiteworks advirtió que un ataque de día cero podría estar en camino. El lunes, la empresa publicó un aviso identificando la vulnerabilidad y lanzando una actualización para corregirla. Al final, Kiteworks determinó que la vulnerabilidad solo habría afectado al 1% de sus clientes, según su declaración.

"Tomar la decisión de pedir a los clientes que desconecten sus sistemas de producción no es algo que cualquier proveedor haga a la ligera, y sabíamos exactamente lo que estábamos pidiendo", afirmó Frank Balonis, CISO de la firma. "Lo hicimos de todos modos, porque cuando la elección es entre certeza y conveniencia, los datos de los clientes no son algo con lo que estemos dispuestos a jugar. Esa decisión fue lo que hizo posible el resto. Haríamos la misma llamada mañana para proteger los datos de nuestros clientes."

Los IPs expuestos por Kiteworks afectan a países de todo el mundo, aunque están concentrados en EE. UU. y Europa. Esta situación pone de manifiesto los riesgos que enfrentan los proveedores que toman medidas de defensa agresivas. La respuesta de Citrix ha sido criticada por muchos en la comunidad de ciberseguridad, considerándola insuficiente y tardía. ¿Por qué no compartió la compañía la inteligencia antes sobre los aparentes ataques de día cero?

Por otro lado, la rara recomendación de Kiteworks de desconectar sus dispositivos podría considerarse excesiva, especialmente dado que solo el 1% de sus clientes era vulnerable, o una respuesta adecuadamente calibrada ante un posible ataque que podría afectar a sus clientes, muchos de los cuales pertenecen a agencias gubernamentales o industrias reguladas.

La decisión de instar a los clientes a desconectar sus sistemas fue calificada de "desmesurada" por John Strand, propietario de Black Hills Information Security, una firma de capacitación en ciberseguridad y pruebas de penetración. "Esto no es un ataque activo —la gente no está siendo vulnerada activamente— y, sin embargo, el proveedor está diciendo a los clientes que desconecten sus sistemas", comentó. "Nunca he escuchado nada como esto antes. Queda por ver si Kiteworks está exagerando o si esta es exactamente la respuesta correcta, especialmente dependiendo de lo difícil que sea implementar el parche."

Para Kiteworks, la decisión de instruir a los clientes a desconectar sus sistemas no fue fácil, según Jonathan Yaron, CEO y presidente de Kiteworks. "El estándar de la industria es esperar pruebas de un ataque", dijo. "Preferimos ser proactivos ante una advertencia creíble que esperar a tener certeza y llegar demasiado tarde. Ese es el estándar que pretendemos mantener."

Lamentablemente, los profesionales de la seguridad tenían menos información sobre los ataques a Citrix NetScaler: algunos cuestionaron si la actividad maliciosa apuntaba a dos vulnerabilidades ya corregidas en agosto (CVE-2026-19490 y CVE-2026-19489). Citrix no respondió a preguntas específicas sobre el asunto, pero dirigió a Dark Reading a su declaración anterior y boletín de seguridad.

La compañía tenía como objetivo "desarrollar y lanzar de inmediato una nueva versión del software que aborde los problemas", declaró Citrix a través de su portavoz. "Siempre aconsejamos a los clientes que adopten rápidamente la última versión de nuestro software, y estamos subrayando esa orientación aquí para garantizar que nuestros clientes se beneficien de inmediato de las actualizaciones en esta última versión."

Incluso sin un aviso de desconexión por parte de Citrix, proveedores y equipos de seguridad estaban aconsejando proactivamente a los administradores de NetScaler que desconectaran sus dispositivos, citando una advertencia del gobierno, según Satnam Narang, ingeniero de investigación senior en Tenable, que publicó un aviso sobre el asunto. "La conversación sobre la desconexión ocurrió en ambos casos; simplemente vino de diferentes lugares", dice Narang.

Si otro fin de semana trae la misma decisión, aún no hay una respuesta clara sobre cuál es la estrategia adecuada, señala Andrew Thompson, vicepresidente senior de operaciones de adversarios en GreyNoise. Aunque la compañía detectó actividad contra dispositivos NetScaler el 24 de septiembre, los investigadores de GreyNoise no conectaron inicialmente el ataque a CVEs específicos.

"Si la advertencia temprana proviene de una fuente creíble, deberían actuar sobre ella, [pero] lo que se considera una acción aceptable variará de una organización a otra", afirma Thompson.

Narang de Tenable señala que desconectar sistemas tiene un costo. Cerrar las VPN, por ejemplo, significa cortar el acceso para los trabajadores remotos, bloquear el acceso a aplicaciones que podrían afectar a los clientes y cerrar el acceso a datos que pueden interrumpir las operaciones. "Si los proveedores lo piden, deben ser específicos sobre qué clientes y configuraciones están en riesgo, y cuánto tiempo debería durar la desconexión", dice. "Kiteworks desconectó los sistemas que aloja y aconsejó una desconexión de nueve horas. Un 'apágalo' general sin fecha de finalización es difícil de cumplir."

Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response

Source: Dark Reading

On Sept. 24, threat detection firm GreyNoise Intelligence observed a single US-based IP address scanning for Citrix NetScaler installations and conducting remote code execution (RCE) attacks. The company issued alerts to customers about the malicious activity. Over the next two days, reports of potential zero-day attacks on NetScaler installations emerged on social media, and cybersecurity professionals debated whetherthe rumored attackswere true — some argued the activity targeted vulnerabilities already patched in August. On Sept. 26, however, Benjamin Harris, founder and CEO of exposure-management firm watchTowr, urged NetScaler users to take their systems offline. "Monday will be too late," hestated in a LinkedIn post. By Sunday, Citrix seemingly agreed, postingan updatethat patched eight vulnerabilities (CVE-2026-88771 through CVE-2026-88778), including two zero-days that had been exploited in the wild. The blog post did not recommend taking servers offline until they were patched, instead urging customers to "upgrad[e to] the versions containing the fix immediately." However, the two zero-days — CVE-2026-88771 and CVE-2026-88772 — came underwidespread exploitation. The same weekend, data protection provider Kiteworks took a different road. On Sept. 25, the company issued a recommendation to customers, urging them to proactively take their systems offline based on intelligence about an imminent attack. With its engineering team and external national intelligence experts working together on identifying the security issue, the company warned that a zero-day attack could be coming. On Monday, Kiteworks published an advisory identifying the vulnerability with an update to patch it. In the end, the company determined the vulnerability would have affected only 1% of its customers, Kiteworkssaid in its statement. "Telling customers to take production systems offline is not a decision any vendor makes lightly, and we knew exactly what we were asking of them," Frank Balonis, the firm's CISO, said in the statement. "We made it anyway, because when the choice is between certainty and convenience, customer data is not something we are willing to gamble with. That decision is what made the rest possible. We would make the same call again tomorrow to protect our customers' data." Kiteworks exposed IP addresses affect countries worldwide but are concentrated in the United States and Europe. Source: Shadowserver.org The two approaches underscore the hazards for vendors that take aggressive defensive measures. Citrix's response hascome under firefrom many in the cybersecurity community as being too little, too late. Why didn't the company share intelligence sooner about the apparent zero-day attacks? On the other hand, Kiteworks' rare recommendation to shut down appliances could be considered overkill — especially since only 1% of customers were vulnerable — or an appropriately gauged response to a potentially significant attack targeting their customers, many of whom are government agencies or in regulated industries. The decision to call for customers to shut down their systems was "wild," according to John Strand, owner of Black Hills Information Security, a cybersecurity-training and penetration-testing firm. "This isn't an active attack — people aren't actively being breached — and yet the vendor is telling customers to take their systems offline," he said in a statement. "I've never heard of anything like this before. It remains to be seen whether Kiteworks is overreacting or whether this is exactly the right response, especially depending on how difficult the patch is to deploy." For Kiteworks, the decision to tell customers to shut down their systems did not come easy, Jonathan Yaron, Kiteworks' CEO and chairman, said in the company's statement. "The industry standard is to wait for proof of an attack," he said. "We would rather be proactive on credible warning than wait for certainty and be too late. That is the standard we intend to keep." Unfortunately, security professionals had less information on the attacks on Citrix NetScaler: Some questioned whether the malicious activity targeted two vulnerabilities patched in August (CVE-2026-19490 and CVE-2026-19489). Citrix did not answer specific questions on the issue but pointed Dark Reading to its previous statement andsecurity bulletin. The company aimed to "immediately develop and release a new version of the software that addresses the issues," Citrix stated through its spokesperson. "We always advise customers to promptly adopt the latest version of our software, and we are underscoring that guidance here to ensure our customers immediately benefit from the updates in this latest release." Even without a shutdown advisory from Citrix, suppliers and security teams were proactively telling NetScaler admins to take their appliances offline, citing a government warning, according to Satnam Narang, a senior staff research engineer at Tenable, which publishedan advisoryon the issue. "The shutdown conversation happened in both cases — it just came from different places," Narang says. If another weekend brings the same decision, there is still no clear answer as to the right strategy, says Andrew Thompson, senior vice president of adversary operations at GreyNoise. While the company firstdetected activity against NetScaler applianceson Sept. 24, GreyNoise researchers did not initially connect the attack to specific CVEs. "If early warning is from a credible source, they should act on it, [but] what's considered to be acceptable action will vary from organization to organization," Thompson says. Tenable's Narang notes that shutting down systems has a cost. Shuttering VPNs, for example, means cutting off access for remote workers, blocking access to applications that could impact customers, and shutting down data access that can disrupt operations. "If vendors ask for it, they need to be specific about which customers and configurations are at risk, and how long the shutdown should last," he says. "Kiteworks took down the systems it hosts and advised a nine-hour shutdown. A blanket 'turn it off' with no end date is hard to comply with."

Incidentes de Kiteworks y Citrix Revelan Desafíos en la Respuesta a Zero-Day | Ciberseguridad - NarcoObservatorio