{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Daily Security Review","title":"CISA Flags Citrix NetScaler Flaws: What CVE-2025-6543 Means for Federal and Private Networks","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/c49bc639\"></iframe>","width":"100%","height":180,"duration":3401,"description":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added multiple Citrix NetScaler vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog—an urgent signal for federal agencies and private enterprises alike. At the center of this update is CVE-2025-6543, a memory overflow flaw affecting NetScaler ADC and Gateway appliances, which could lead to Denial of Service attacks under specific configurations. This joins earlier additions from 2023, including CVE-2023-6548 and CVE-2023-6549, covering code injection and buffer overflow vulnerabilities.\nIn this episode, we explore why NetScaler vulnerabilities are drawing heightened attention, how they are actively being exploited, and what organizations must do to stay ahead of increasingly sophisticated cyber threats. But the scope of this episode goes far beyond Citrix. We delve into the latest intelligence on:\nActive APT campaigns like Swan Vector, which leverages OAuth abuse, DLL sideloading, and Cobalt Strike to infiltrate institutions across Taiwan and Japan\nThe rise of “Shadow AI” in enterprises, where unsanctioned GenAI tools introduce hidden risks like data exfiltration, training leakage, and geopolitical exposure\nA roundup of critical vulnerabilities, including high-severity flaws in Cisco ISE (CVE-2025-20281/20282), Veeam Backup, Roundcube Mail Server, and Trend Micro PolicyServer—all being actively targeted or at high risk\nKey insights from the episode:\nWhy CISA’s KEV catalog should be a top priority for every organization’s patch management strategy\nHow vulnerabilities like CVE-2025-6543 can be weaponized in real-world attacks, and why even memory overflows in peripheral configurations matter\nBest practices for hardening Citrix NetScaler environments, including RBAC, TLS restrictions, session timeouts, and audit logging\nThe strategic implications of APT groups abusing legitimate services like Google Drive and PrintDialog.exe to remain stealthy\nHow organizations can shift from...","thumbnail_url":"https://img.transistorcdn.com/pL79_MJFeJHamQ_ztImsGmDSMdl27VMk_30TAkieujE/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yNzg5/ZjlhNzM5Y2M4Njli/NjkxNzgyODA2Nzhi/MDI2ZC5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}