TLP: CLEAR
 
TO: All MS-ISAC Members
 
The Cybersecurity and Infrastructure Security Agency (CISA) has  released   an update to a previously published Cybersecurity Advisory (CSA), Threat   Actors Exploiting Citrix CVE-2023-3519 to Implant Webshells. The CSA—originally released to warn network defenders of critical infrastructure organizations about threat actors exploiting   CVE-2023-3519, an unauthenticated remote code execution (RCE) vulnerability affecting NetScaler (formerly Citrix) Application Delivery Controller (ADC) and NetScaler Gateway—contains victim information gathered in August 2023.  
Since July 2023, the Joint Cyber Defense Collaborative (JCDC) has facilitated continuous, real-time threat information sharing with and between partners on post-exploitation   activity of CVE-2023-3519. JCDC consolidated and shared detection methods, threat actor tactics, techniques, and procedures (TTPs), and indicators of compromise (IOCs) received from industry and international partners. The updated CSA contains new TTPs as   well as IOCs received from some of these partners and an additional victim.
  CISA strongly urges all critical infrastructure organizations to review the advisory and   follow the mitigation recommendations—such as prioritizing patching known   exploited vulnerabilities like Citrix CVE-2023-3519.
To report incidents and anomalous activity, please contact one the following organizations:
-   CISA, through the agency’s Incident   Reporting System, the 24/7 Operations Center at report@cisa.gov or   (888) 282-0870.  
-   MS- and EI-ISAC, through their  24/7   Operations Center at  soc@msisac.org or (866) 787-4722.  
Multi-State Information Sharing and Analysis Center (MS-ISAC)
Elections Infrastructure Information Sharing and Analysis Center (EI-ISAC)
31 Tech Valley Drive
East Greenbush, NY 12061
 
24×7 Security Operations Center
SOC@cisecurity.org –   1-866-787-4722
 
TLP: CLEAR
Information may be distributed without restriction, subject to standard copyright rules.
 
Please send all opt out requests to  info@cisecurity.org.  
 
This message and attachments may contain confidential information. If it appears   that this message was sent to you by mistake, any retention, dissemination, distribution or copying of this message and attachments is strictly prohibited. Please notify the sender immediately and permanently delete the message and any attachments.
 
This message and attachments may contain confidential information. If it appears that this message was sent to you by mistake, any retention, dissemination, distribution or copying of this message and attachments is strictly prohibited. Please notify the sender immediately and permanently delete the message and any attachments.
  . . . . . 





