PointWire

When the National Cyber Security Centre (NCSC) urges UK organisations to act, patching is the obvious first move. It is also only part of the answer. 

For CISOs and Heads of Security, this raises a fundamental question: Do you have a complete and current view of what an attacker could target?

Patch Management

What has happened

Citrix has disclosed eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Two of them are confirmed as actively exploited. The NCSC is urging UK organisations to mitigate them promptly and says it is still working to understand the impact on UK organisations.

Why a patch is not proof

A patch removes the weakness. It tells you nothing about whether someone used it beforehand. That is a limitation, not a failing, and it is why the order of the NCSC’s advice matters. 

Its priority actions ask you to check whether you are affected, isolate or replace affected systems where possible, and fully investigate signs of compromise. Installing updates comes after that, followed by bringing the system back into use and continuing to hunt for threats. Investigation sits before the update, not after it.

What checking looks like

Corelight’s hunting guidance starts with a simple question: does your understanding of where you use NetScaler match what is happening on the network? It names three common reasons the answer may be no: legacy systems, unmanaged deployments and out-of-date documentation. 

Network records can then help identify likely appliances, show which services are active, and show who communicates with them. From there, teams can look for signs of misuse, such as web shells, connections back to attacker infrastructure and known exploit strings. 

Corelight is also candid about limits. Seeing a particular service in use does not prove an appliance is vulnerable or was exploited. Not seeing it does not prove it is switched off. Evidence narrows the question. It rarely closes it on its own.

Four questions for your team this week

  • Do we have a verified list of every NetScaler appliance, including ones nobody owns? 
  • Did we investigate for compromise before updating, and who signed that off? 
  • Can we see network traffic to and from these appliances from before the patch? 
  • Who is monitoring new indicators as they are published? 

Why this matters in Cybersecurity Awareness Month

October is Cybersecurity Awareness Month, a time when organisations focus on good habits and strong foundations. Patching is one of those habits. The foundation behind it is knowing what you run and being able to see what happens on the endpoints. Both need to be in place before the next alert arrives.

“Packets don’t lie you just need the visibility to hear what they’re telling you.”  – Sean Sparshott, PointWire Technology Associate

Next step

Investigate first, then patch. If you can’t say with confidence that your appliances weren’t compromised, that is the gap to close before you bring the system back into use.

PointWire offers complete patch and vulnerability management consultancy and solutions. Talk to us today about your cybersecurity challenges.

Leave a Reply

Your email address will not be published. Required fields are marked *