Rewterz

Rewterz Threat Alert – Active LokiBot IOCs

December 24, 2020
Rewterz

Rewterz Threat Advisory – CVE-2019-1552 – Veritas Backup Exec privilege escalation Vulnerability

December 26, 2020

Rewterz Threat Advisory – DTLS Amplification DDoS Attack on Citrix ADC

Severity

High

Analysis Summary

Citrix ADC has been impacted by DDoS attack pattern. An attacker or bots can overwhelm the Citrix ADC DTLS network throughput, potentially leading to outbound bandwidth exhaustion. Limited bandwidth connections have been more prominently effected by this.

The attack scope has been so far limited and currently there are no vulnerabilities associated as of yet.

Impact

Distributed Denial of service

Affected Vendors

Citrix

Affected Products

Citrix ADC

Remediation

  • Disable DTLS to stop and eliminate the susceptibility to the attack. To disable DTLS use the following command : set vpn vserver -dtls OFF

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.