NetScaler (CTX697096): if you patch first, you may never know you were compromised
Citrix published CTX697096, a critical vulnerability already exploited, with no workaround and no published indicators of compromise. The correct order is not ”patch”, but inventory, then a compromise check, then patch. How the Braincap team works with clients running NetScaler ADC and Gateway, what it looks for on the appliances, and what it finds almost every time.
Read the article