Back to all news
Security

Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

The Hacker News·October 1, 2026·1 min read
Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

Threat actors exploited a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and Gateway to drop web shells and steal configuration data. LevelBlue's THOR team analyzed the activity across multiple customer environments, identifying malicious NetScaler payloads that created superuser access and mapped web shells to CSS-like URLs for stealthy data exfiltration.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store