Citrix and Kiteworks take opposing approaches to zero-day disclosure over same weekend
Citrix patched eight NetScaler vulnerabilities, including two actively exploited zero-days, after researchers reported RCE attacks scanning for vulnerable installations and urged customers to take systems offline immediately. Citrix instead advised customers to upgrade promptly rather than disconnect servers, and the two zero-days continued to be exploited despite the patch. Separately, Kiteworks told customers to proactively take systems offline based on intelligence of an imminent attack before confirming the next day that only about 1% of customers were actually affected.