Xfinity waited to patch critical Citrix Bleed 0-day. Now it’s paying the price

A parked Comcast service van with the Enlarge Getty Images | Smith Collection/Gado reader comments 140

Comcast waited as many as nine days to patch its network against a high-severity vulnerability, a lapse that allowed hackers to make off with password data and other sensitive information belonging to 36 million Xfinity customers.

Further Reading The latest high-severity Citrix vulnerability under attack isn’t easy to fix The breach, which was carried out by exploiting a vulnerability in network hardware sold by Citrix, gave hackers access to usernames and cryptographically hashed passwords for 35.9 million Xfinity customers, the cable TV and Internet provider said in a notification filed Monday with the Maine attorney general’s office. Citrix disclosed the vulnerability and issued a patch on October 10. Comcast didn't patch its network until October 16 at the earliest and October 19 at the latest, a lapse of six to nine days. On October 18, researchers reported that the vulnerability, tracked as CVE-2023-4966 and by the name Citrix Bleed, had been under active exploitation since August.

“However, we subsequently discovered that prior to mitigation, between October 16 and October 19, 2023, there was unauthorized access to some of our internal systems that we concluded was a result of this vulnerability,” an accompanying notice stated. “We notified federal law enforcement and conducted an investigation into the nature and scope of the incident. On November 16, 2023, it was determined that information was likely acquired.”

Comcast is still investigating precisely what data the attackers obtained. So far, Monday’s disclosure said, information known to have been taken includes usernames and hashed passwords, names, contact information, the last four digits of social security numbers, dates of birth, and/or secret questions and answers. Xfinity is Comcast’s cable television and Internet division.

Advertisement

Citrix Bleed has emerged as one of the year’s most severe and widely exploited vulnerabilities, with a severity rating of 9.4 out of 10. The vulnerability, residing in Citrix’s NetScaler Application Delivery Controller and NetScaler Gateway, can be exploited without any authentication or privileges on affected networks. Exploits disclose session tokens, which the hardware assigns to devices that have already successfully provided login credentials. Possession of the tokens allows hackers to override any multi-factor authentication in use and log in to the device.

Other companies that have been hacked through Citrix Bleed include Boeing; Toyota; DP World Australia, a branch of the Dubai-based logistics company DP World; Industrial and Commercial Bank of China; and law firm Allen & Overy.

The name Citrix Bleed is an allusion to Heartbleed, a different critical information disclosure zero-day that turned the Internet on its head in 2014. That vulnerability, which resided in the OpenSSL code library, came under mass exploitation and allowed the pilfering of passwords, encryption keys, banking credentials, and all kinds of other sensitive information. Citrix Bleed hasn’t been as dire because fewer vulnerable devices are in use.

A sweep of the most active ransomware sites didn’t turn up any claims of responsibility for the hack of the Comcast network. An Xfinity representative said in an email that the company has yet to receive any ransom demands, and investigators aren’t aware of any customer data being leaked or of any attacks on affected customers.

Comcast is requiring Xfinity customers to reset their passwords to protect against the possibility that attackers can crack the stolen hashes. The company is also encouraging customers to enable two-factor authentication. The representative declined to say why company admins didn't patch sooner.

Post updated to change patch lapse from 13 days to six to nine days.


Will an expired at-home COVID-19 test still work? Maybe. Here’s how you can tell.

No result found, try new keyword!You simply locate your test’s lot number and original expiration date on the outside of the package. On the online FDA chart, you will see its extended expiration date and lot number on the chart.

What the MCAT Test Is Like and How to Prepare

No result found, try new keyword!The difficulty of the Medical College Admission Test, or MCAT, means that anyone who plans to take this entrance exam should spend a significant amount of time studying for it. "Make sure that you ...
 


Unquestionably it is hard assignment to pick dependable certification questions/answers assets regarding review, reputation and validity since individuals get sham because of picking incorrectly benefit. Killexams.com ensure to serve its customers best to its assets concerning exam dumps update and validity. The vast majority of other's sham report dissension customers come to us for the brain dumps and pass their exams joyfully and effortlessly. We never trade off on our review, reputation and quality on the grounds that killexams review, killexams reputation and killexams customer certainty is imperative to us. Uniquely we deal with killexams.com review, killexams.com reputation, killexams.com sham report objection, killexams.com trust, killexams.com validity, killexams.com report and killexams.com scam. On the off chance that you see any false report posted by our rivals with the name killexams sham report grievance web, killexams.com sham report, killexams.com scam, killexams.com protest or something like this, simply remember there are constantly awful individuals harming reputation of good administrations because of their advantages. There are a huge number of fulfilled clients that pass their exams utilizing killexams.com brain dumps, killexams PDF questions, killexams hone questions, killexams exam simulator. Visit Killexams.com, our specimen questions and test brain dumps, our exam simulator and you will realize that killexams.com is the best brain dumps site.

Which is the best dumps website?
You bet, Killexams is completely legit and fully good. There are several includes that makes killexams.com genuine and genuine. It provides up to date and completely valid exam dumps that contain real exams questions and answers. Price is minimal as compared to the majority of the services online. The questions and answers are modified on typical basis with most recent brain dumps. Killexams account setup and item delivery is very fast. Report downloading is usually unlimited and really fast. Assist is avaiable via Livechat and E mail. These are the features that makes killexams.com a sturdy website which provide exam dumps with real exams questions.



Is killexams.com test material dependable?
There are several Questions and Answers provider in the market claiming that they provide Actual Exam Questions, Braindumps, Practice Tests, Study Guides, cheat sheet and many other names, but most of them are re-sellers that do not update their contents frequently. Killexams.com is best website of Year 2024 that understands the issue candidates face when they spend their time studying obsolete contents taken from free pdf download sites or reseller sites. Thats why killexams.com update Exam Questions and Answers with the same frequency as they are updated in Real Test. Exam dumps provided by killexams.com are Reliable, Up-to-date and validated by Certified Professionals. They maintain Question Bank of valid Questions that is kept up-to-date by checking update on daily basis.

If you want to Pass your Exam Fast with improvement in your knowledge about latest course contents and topics of new syllabus, We recommend to Download PDF Exam Questions from killexams.com and get ready for actual exam. When you feel that you should register for Premium Version, Just choose visit killexams.com and register, you will receive your Username/Password in your Email within 5 to 10 minutes. All the future updates and changes in Questions and Answers will be provided in your Download Account. You can download Premium Exam Dumps files as many times as you want, There is no limit.

Killexams.com has provided VCE Practice Test Software to Practice your Exam by Taking Test Frequently. It asks the Real Exam Questions and Marks Your Progress. You can take test as many times as you want. There is no limit. It will make your test prep very fast and effective. When you start getting 100% Marks with complete Pool of Questions, you will be ready to take Actual Test. Go register for Test in Test Center and Enjoy your Success.




SCP-500 exam questions | 312-96 study guide | 7220X Practice Questions | PAL-I exam test | CMA Exam Questions | HCISPP PDF Questions | ESPA-EST sample questions | CCFH-202 past bar exams | CTAL-TM-UK test questions | 31860X VCE | LFCS exam answers | A00-250 brain dumps | CAT-220 Questions and Answers | DEE-1721 cheat sheet | H31-211 dump | I10-002 practice test | H35-582-ENU free prep | HIO-301 question test | STAAR Study Guide | AZ-900 test sample |


1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration test
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration information search
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration Question Bank
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration course outline
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration Exam dumps
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration Free Exam PDF
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration PDF Dumps
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration Free Exam PDF
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration outline
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration book
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration PDF Dumps
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration dumps
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration exam format
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration Practice Questions
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration PDF Download
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration exam format
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration test
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration PDF Braindumps
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration Cheatsheet
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration exam success
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration test
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration Latest Questions
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration techniques
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration Study Guide
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration education
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration exam syllabus
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration study help
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration learning
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration testing
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration cheat sheet
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration Practice Questions
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration PDF Dumps
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration answers
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration information hunger
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration Free Exam PDF
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration braindumps
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration guide
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration exam
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration certification
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration test
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration Exam Cram
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration Exam Cram
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration Latest Topics
1Y0-204 - Citrix Virtual Apps and Desktops 7 Administration Practice Test

Other Citrix Exam Dumps


1Y0-203 practical test | 1Y0-241 real questions | 1Y0-341 exam answers | 1Y0-231 english test questions | 1Y0-312 pass marks | 1Y0-204 exam questions | 1Y0-440 braindumps | 1Y0-403 Free Exam PDF |


Best Exam Dumps You Ever Experienced


CDCA-ADEX Test Prep | CCP training material | JN0-553 Practice Test | 1D0-623 questions and answers | 300-835 sample questions | CIFC Latest Topics | TMPF questions answers | GRE-Verbal PDF Braindumps | CBBF cbt | Servicenow-CAD exam preparation | CPA-CPP Exam Questions | NCMA-CMA PDF Download | 7003 real questions | CEN Cheatsheet | HIO-301 Questions and Answers | 4A0-N02 test practice | NCCT-TSC practice exam | MD-102 braindumps | Google-PDE Practice test | MORF online exam |





References :


https://arfansaleemfan.blogspot.com/2020/08/1y0-204-citrix-virtual-apps-and.html
http://feeds.feedburner.com/1y0-204RealExamQuestionsByKillexamscom
https://drp.mk/i/QyDt5XWhNs
https://sites.google.com/view/killexams-1y0-204-exam-brain
https://files.fm/f/gy6pd44c9
https://www.instapaper.com/read/1400178757



Similar Websites :
Pass4sure Certification Exam dumps
Pass4Sure Exam Questions and Dumps




Back to Main Page