ZeroHour
CyberScooppublished ()ingested @CyberScoopNews

NSA says Chinese hackers are actively attacking flaw in widely used networking device

criticalExploit / PoC exploited in the wildimportance 60
Full article827 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

A severe flaw in a Citrix device allowed hackers believed to be part of the group known as APT5 to carry out remote code execution.

A worker holds China's national flag to be installed on a street lamp post on September 27, 2022 in Wuhan, Hubei province, China. (Getty Images)

The National Security Agency said on Tuesday that Chinese state-backed hackers are exploiting a flaw in a widely used networking device that allows an attacker to carry out remote code execution. 

In its advisory, the NSA said it believes a Chinese hacking crew known as APT5 “has demonstrated capabilities” against an application delivery controller made by Citrix. Citrix released an emergency patch to fix the vulnerability on Monday and said that “exploits of this issue on unmitigated appliances in the wild have been reported.”

The spy agency’s advisory effectively burns down an apparent Chinese intelligence operation by exposing its tools and advising potential victims on how to prevent further attacks. The NSA has historically preferred to monitor such attacks rather than publicizing them, but in recent years it has grown more proactive in sharing intelligence on attackers such as APT5.

Now that they’ve been burned, the hackers behind the operation targeting Citrix may step up the pace of their attacks. “Chinese actors with a history of using zero days often ramp up after they’ve been discovered,” said John Hultquist, the vice president for intelligence analysis at Mandiant. While they are undetected, these groups will try to avoid tripping the alarm, but “after the zero day is observed all bets are off,” he said.

Active since at least 2007, APT5 is a well-known Chinese hacking group with a history of attacking networking companies and devices. The group has a history of attacking telecommunications and technology firms, with a particular interest in defense-related technology. In 2019, the group was caught attacking virtual private networks to steal user credentials and monitor traffic. 

The revelation of the Citrix flaw on Tuesday comes a day after Fortinet revealed a severe vulnerability that also allows remote code execution for one of its VPN products. The company said it was aware of “an instance where this vulnerability was exploited in the wild” but did not attribute the attack. The company urged its customers to patch affected systems immediately. 

The news of the Citrix vulnerability so shortly after the Fortinet flaws means that large numbers of systems may be exposed to attack until patches are implemented on affected systems.

“Combined with the recent Fortinet vulnerability it could make for a lousy Christmas,” said Allan Liska, an intelligence analyst at Recorded Future. “The two are equally bad in terms of being remote code execution and pre-auth. They are also both devices that tend to be publicly accessible from the internet, which means bad guys are likely already scanning for potential victims.” 

More Scoops

(Getty Images)

Officials disrupt Chinese espionage operation that hit multiple federal agencies

The full hacking suite, seized by authorities, allowed Chinese government funded attackers to intrude highly sensitive networks undetected for more than eight years.

Sen. Ron Wyden, D-Ore., leaves a Senate Democratic meeting at the U.S. Capitol Building on Oct. 3, 2025. (Photo by Kevin Dietsch/Getty Images)

Sen. Wyden urges feds to discard older, insecure, public-facing VPNs

US President Donald Trump (R) and Open AI CEO Sam Altman (L) react during a working lunch meeting of G7 members, partner countries, and artificial intelligence business leaders as part of the G7 summit, in Evian, eastern France, on June 17, 2026. The Trump administration has been moving to regulate AI models for cybersecurity use. (Photo by Julia Demaree Nikhinson / POOL / AFP via Getty Images)

Where’s the Trump administration line on AI regulation?

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/citrix-china-apt5-hackers/