Pennsylvania attorney general says cyberattack knocked phone, email systems offline
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-5349 | Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway NVD description · AI analysis pending | 8.7 | 5% |
| — | ||
| CVE-2025-5777 | Out-of-Bounds Read (Memory Overread) in Citrix NetScaler ADC and Gateway Citrix NetScaler ADC and NetScaler Gateway contain an out-of-bounds read (CWE-125) caused by insufficient input validation, which can cause the appliance to read beyond the intended memory buffer (a memory overread). The flaw is only triggerable when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server, so attackers who can reach those services can potentially induce the overread and obtain sensitive memory contents. Such disclosure could aid follow-on compromise, for example by exposing session or authentication data, and CISA notes known ransomware use. Organizations running NetScaler ADC or NetScaler Gateway in the affected Gateway/AAA configurations are exposed. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-07-10 with known ransomware use and an EPSS of 100% (100th percentile), indicating active exploitation, while no public PoC is known and a CVSS score has not yet been assigned. Do: Apply the fixed NetScaler ADC/Gateway builds per Citrix's security advisory (exact affected/fixed version ranges are not in the available data, so consult the bulletin); per CISA KEV, apply vendor mitigations, follow BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable. Inventory appliances for Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server configurations, since unconfigured/other deployments are not triggerable. After patching, terminate active and idle VPN sessions and hunt for anomalous access, given the known ransomware exploitation and the information-disclosure nature of the flaw. | 9.3 | 100% | KEV ransomware |
| massplausibly hundreds of thousands of installed/internet-exposed NetScaler ADC and Gateway appliances (public scans have historically shown on the order of… | |
| CVE-2025-6543 | Memory Buffer Overflow in Citrix NetScaler ADC and Gateway Exploited in the Wild Citrix NetScaler ADC and NetScaler Gateway appliances contain a memory buffer overflow (CWE-119) that can lead to unintended control flow and denial of service. The flaw is only reachable when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server, and it is network-exploitable without authentication or user interaction, though attack complexity is rated high. A successful attacker could achieve unintended control flow — with the CVSS 4.0 vector rating impact high across confidentiality, integrity, and availability — or crash the appliance, disrupting VPN access and application delivery. Any organization running NetScaler ADC or NetScaler Gateway in an affected Gateway/AAA configuration is exposed, a population that public scan data places in the tens of thousands of internet-exposed devices. The vulnerability was added to CISA's KEV catalog on 2025-06-30, confirming exploitation in the wild, with EPSS at 10.1% and no public proof-of-concept known. Do: Apply the patched NetScaler release specified in Citrix's security bulletin for CVE-2025-6543 immediately, prioritizing appliances in Gateway or AAA configurations, per CISA KEV and BOD 22-01 requirements. Audit which virtual servers (VPN, ICA Proxy, CVPN, RDP Proxy, AAA) are in use and whether they are internet-exposed, and check appliances for signs of compromise before and after upgrading. | 9.2 | 10% | KEV |
| large≈50,000+ internet-exposed NetScaler ADC/Gateway devices (only Gateway/AAA configurations vulnerable) |
Full article543 words · extracted from therecord.media · click to collapse
The office of Pennsylvania's attorney general is warning state residents that its email and phone lines are down as a result of a cyberattack. The office published a statement on Monday afternoon saying it was investigating the cause of the incident and was working to restore services. Its website was still down as of Wednesday morning. “This is a frustrating situation, and everyone is doing their very best. I am grateful for the dedication and professionalism of our Information Technology staff who are working around the clock to resolve the matter,” Attorney General Dave Sunday said on social media. “In collaboration with our law enforcement partners, we will work diligently to restore systems. We will continue to do the work of protecting Pennsylvanians no matter the obstacle.” The statement said prosecutors are still working on cases in spite of the cyberattack. Sunday took over the position in January after winning an election last fall. The notice comes one month after prominent cybersecurity expert Kevin Beaumont said he came across devices connected to the office as he was searching the internet for exposed instances of Citrix NetScaler that are vulnerable to CVE-2025-5777, known colloquially as Citrix Bleed 2, and several other related bugs. Citrix NetScaler devices are used to ensure that websites and applications remain quickly accessible and the devices also facilitate remote work. Employees can remotely access corporate environments or the intranet of an organization via NetScaler Gateway. The tools have faced widespread attacks since CVE-2025-5777 and bugs tracked as CVE-2025-5349 and CVE-2025-6543 came to light last month. In his search for vulnerable devices, Beaumont shared evidence of two internet-exposed Citrix NetScaler devices tied to the Office of the Attorney General of Pennsylvania that were later removed from the internet. The office provided an alternative email address for the press but did not respond to questions about whether the attack was conducted through Citrix NetScaler devices. Beaumont said the office’s NetScaler devices were taken offline over the last week and a half. On Monday, the Dutch National Cyber Security Centre released an urgent warning that hackers are still targeting Citrix NetScaler products and have successfully breached critical infrastructure organizations in the Netherlands through the vulnerabilities. Two weeks ago, Dutch officials said the country’s Public Prosecution Service — the equivalent of the U.S. Justice Department — was impacted by the campaign of attacks on Citrix NetScaler devices. The attacks also hampered the court system of multiple Caribbean island governments that are still linked to The Netherlands. The U.S. legal system is under constant pressure from various cyberthreats. Russia is suspected to be behind a breach of the filing system for federal courts, the New York Times reported on Tuesday. The office of Virginia’s attorney general responded to an unspecified cyberattack in February. Cleveland’s municipal courts shut down for several days earlier this year because of a cybersecurity incident. Washington’s state courts reported a breach in November 2024.
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/pennsylvania-attorney-general-office-cyberattack