Recent attacks by the notorious Lockbit ransomware use publicly available exploits for the Citrix Bleed vulnerability (CVE-2023-4966), aiming to compromise systems of large organizations and encrypt files.

Although Citrix has long since released an update that fixes the CVE-2023-4966 vulnerability, thousands of systems exposed onlineare still vulnerable (many of them in the US).
Lockbit ransomware: Recent attacks
Threat researcher Kevin Beaumont was tracking attacks against various companies, including Industrial and Commercial Bank of China (ICBC), DP World, Allen & Overy, and Boeing. He found that they all had something in common: exposed Citrix servers, vulnerable to the CVE-2023-4966 vulnerability, which has been dubbed Citrix Bleed.
See also: LockBit: Virginia school district reopens despite ransomware attack
This vulnerability is being exploited by the Lockbit ransomware gang and has been attacking companies. This was confirmed by the Wall Street Journal, which received an email from the US Treasury Department stating that the LockBit group was responsible for the cyberattack on ICBC. The attack was carried out by exploiting the bug in question.
If LockBit used the Citrix Bleed vulnerability to breach ICBC, it is believed that it likely used the same vulnerability to breach Boeing and DP World.
However, these attacks may be carried out by an affiliate of the LockBit gang that heavily exploits this vulnerability, rather than by the group itself.
As LockBit is the largest Ransomware-as-a-Service, it has many affiliates who choose how they compromise victims .
Citrix Bleed: Big Risk
Currently, more than 10,400 Citrix servers are vulnerable to the CVE-2023-4966 vulnerability, according to data provided by Japanese researcher Yutaka Sejiyama to BleepingComputer.
The majority of servers, 3,133, are located in the US. This is followed by 1,228 in Germany, 733 in China, 558 in the UK, 381 in Australia, 309 in Canada, 301 in France, 277 in Italy, 252 in Spain, 244 in the Netherlands, and 215 in Switzerland.
Sejiyama's scans revealed vulnerable servers in large and critical organizations, which remain unpatched for a full month after the bug was publicly disclosed and an update.
See also: Two New York hospitals face problems after LockBit ransomware attack
Citrix Bleed
Citrix Bleed was disclosed on October 10th as a critical security issue affecting Citrix NetScaler ADC and Gateway. Its exploitation allows access to sensitive device information.
According to Mandiant, threat actors began exploiting Citrix Bleed in late August (zero-day).

Protection
To protect your servers from the LockBit ransomware and the Citrix Bleed vulnerability, you need to apply the latest updates.
Additionally, implementing security best practices is crucial. This includes enabling two-factor authentication, using strong passwords, restricting access to servers, and disabling unused default user accounts.
See also: Spain: Phishing emails distribute LockBit Locker ransomware
Additionally, staff training is important. Users should be up-to-date on the latest threats and avoid opening unsolicited emails or clicking on suspicious links.
Finally, regular backups are crucial. Regularly backing up data can help you recover your information in the event you fall victim to a ransomware attack.
Source: www.bleepingcomputer.com
