Citrix Under Attack + AI Agents Accelerate Cybersecurity
S5 #8

Citrix Under Attack + AI Agents Accelerate Cybersecurity

00:00:00:01 - 00:00:13:20
Martin
By the time the first alert fires that ransomware is already deployed. This is talk to You by harness, where we break down how software delivery is actually changing in the AI era. I'm Martin Reynolds.

00:00:13:21 - 00:00:33:00
Adam
And I'm Adam Arellano We have a great guest today. We have Starr Brown, who is director of Open source projects at OWASp. I think I'm more excited than I should be about this Citrix thing. Like, it's like a train wreck that's still happening and I'm a little bit too entertained. I don't know about you.

00:00:33:01 - 00:01:10:13
Martin
All right, let's get into this. So last week, Citrix dropped a security bulletin on Sunday covering eight vulnerabilities in net scaler, ADC, and gateway. Two are unconfirmed under active exploitation right now, both scoring 9.5 out of ten. So the first is an authenticated RC four that hits nearly every version of net scaler, even default deployments. And the second is a memory overflow that also leads to RC and details is on default on VPN virtual servers.

00:01:10:13 - 00:01:12:20
Martin
So almost all of them are in scope.

00:01:13:00 - 00:01:26:13
Starr
Yeah, I don't know who led in with the thing that happened to them, which was their MSP calling Sunday night to say pull the devices. And like any Monday that starts with that as your marching orders. Not so fun.

00:01:26:14 - 00:02:01:09
Adam
Well, okay, so the timeline that's given in that article that you're reading from Martin is, we'll say, creative. What actually happened was that Saturday, Citrix customers were already pulling devices offline the day prior. So Saturday around noon eastern time, the call went out across the CSO, Illuminati. You know, the the the secret society of of chief Information security officers that there was a big problem with Citrix and people before Citrix even admitted that anything had happened on Saturday.

00:02:01:12 - 00:02:25:15
Adam
We're seeing exploits in the wild with indicators of compromise hours after a researcher brought it up, which is crazy. So like researcher publishes within 4 or 5 hours active exploit not too many hours. After that, there were companies like enterprise companies pulling their Citrix devices offline. That's nuts. That's what's entertaining to me about it. Have you ever seen anything like that star?

00:02:25:16 - 00:02:30:00
Starr
Not at something that affects the scale in which these devices would have been deployed at.

00:02:30:01 - 00:02:35:04
Adam
The Citrix devices in particular, are basically the gateway to the internet for most of these companies.

00:02:35:06 - 00:02:49:03
Starr
You know, it's like when when the things that control the internet and impact all the things that we rely on with the internet, you're banking your telecom, your whatevers. That's that's a pretty profound place to find two days.

00:02:49:04 - 00:02:55:15
Adam
What I'm not clear on is if the exploit was noticed first or if the researcher released the exploitation.

00:02:55:16 - 00:03:00:20
Starr
And that's more or less the crux of my my curiosity is the question you just posed.

00:03:00:22 - 00:03:02:10
Martin
Right. And do we have an answer?

00:03:02:11 - 00:03:04:08
Starr
No I don't.

00:03:04:10 - 00:03:12:19
Adam
Do you know what else we don't have? We don't have a well verified, regression tested patch from Citrix yet. They released a patch Sunday night that was not tested.

00:03:12:20 - 00:03:28:04
Martin
We don't. But like a lot of the response to this was people were responding, you know, before it was verified at all. They were they were taking that chatter. They were doing their own analysis and saying, okay, let's get ahead of this and just pull it. Regardless.

00:03:28:05 - 00:03:53:11
Adam
The the way in which Citrix normally deploys releases is real careful because they are the front gate or the wall between most like these companies and the internet, their ability to be methodical and careful was actually taken from them by force. They had to move, they had to release that patch, and they didn't even. And they told their customers, we don't know, like what's going to happen when we do this.

00:03:53:12 - 00:04:02:07
Adam
And so the customers were in a position where they had to remove or knock down their wall at the risk, because what was there to protect it wasn't going to protect anymore.

00:04:02:08 - 00:04:27:00
Martin
I agree it is. The risk is just too great. It is a no win situation and especially you're right on the timeline. I think, you know, even on average industry wide, like it's normally at least two weeks before patches get released from identification. The thing is, is that accelerated timeline of how to like being able to exploit has definitely come down dramatically.

00:04:27:00 - 00:04:41:14
Martin
I think I read somewhere that it's like -six hours is the current you know. Identify to exploit. So like, wait, it's exploded six hours before I know about it. That's. Which is scary.

00:04:41:16 - 00:04:51:01
Adam
What is -six hours even mean? Like really like it means that before we're even aware of it, it's being exploited by six.

00:04:51:03 - 00:05:22:01
Martin
And I know that not that long ago, like 12 months ago, whatever it was, that was like 55 days between identification and exploit. And that compression is just such a huge flip. I have a slightly related story. So back in September, we got that first confirmed large scale AI orchestrated ransomware campaign. There was a group of autonomous AI agents that identified a critical, unauthenticated flaw in papercut.

00:05:22:01 - 00:05:49:12
Martin
Print Management Service had a score of 9.8, beating the 9.5 we heard about earlier the highest severity rating, and then handled everything themselves reconnaissance, credential staging, ransomware deployment across 440 servers, 395 organizations, 48 countries and no human directed it at any phase.

00:05:49:14 - 00:05:50:13
Adam
I mean, started it.

00:05:50:16 - 00:06:14:00
Martin
So every time they were targeting a system, it would take them ten minutes. And that's not an attack you can catch in your logs. By the time the first alert fires that ransomware is already deployed. And, you know, the question this raises for me is, you know, well, how do instant incident response teams even detect fast enough to do that?

00:06:14:00 - 00:06:23:09
Martin
And is detection based response the right architecture like going forwards, or do we need to know why not.

00:06:23:11 - 00:06:44:09
Adam
Remote code execution. Thank you. Remote. It's an authentic remote code execution. So even if they had figured out that it was happening in the first 30s, the changes that needed to be made to that service would require a patch or a turn off. So the only thing that could have happened is they just shut the whole thing down.

00:06:44:10 - 00:06:52:09
Martin
Star, I'm interested in your view on this, but like, you know, what is the realistic role for human defenders in those kind of real time response scenarios?

00:06:52:10 - 00:06:54:03
Starr
Well, with what Adam said, it.

00:06:54:03 - 00:07:16:10
Starr
Really just made me go back into the days of disaster recovery and plant like backups and business continuity and what things, and really working the business processes around those tasks to make sure my business can endure. What if we had to turn off the internet? What would happen? I don't know what the answer is.

00:07:16:11 - 00:07:36:03
Martin
It ultimately comes down to automation. I do like your view on the business continuity thing, but I do. Ultimately, it's going to come down to automation, and I think the human defenders are the people setting the intent and the rules. And, you know, the if you like, the ahead of time, if this happens, you know, you can do this.

00:07:36:03 - 00:08:00:05
Martin
These are the things that you're allowed to do in response. If you spot, you know, something with a dwelling in our system, just cut it off. You have the authority to do that, right. And please tell us. But like just do it because that's, you know, going back to the Citrix thing where they're saying the the risk appetite was we'd rather just deal with this now even before we know it's a thing.

00:08:00:06 - 00:08:29:04
Adam
Yeah. Well, the thing is, is right now, especially in Silicon Valley especially.

00:08:29:06 - 00:08:54:01
Adam
And really think hard about the fact that your the survivability and the resilience of your system is more important than a feature because I tell you, like, like for example, on my bank's app, like they just released this new thing that'll like show your credit score and I'm sure somebody worked on that. Great for them. I don't care if that new feature got released as much as I care that they're protecting their system properly.

00:08:54:01 - 00:09:09:18
Adam
And that whole idea that a board wants to see new features to attract new customers, they need to wake up and realize that that is less valuable than the thing that you were talking about, Martin, which is trust, like the trust of the customer, is more important than the feature that you're releasing.

00:09:09:20 - 00:09:36:05
Starr
I would love for you to be correct. My concern is that the minute the business faces the value returned to them by their AI spend with shipping features left and right, and then now, now it's jam packed. Their product is fully featured. Now how do we make it cheaper? How do we start to return more revenue to the business?

00:09:36:10 - 00:10:01:04
Starr
You're talking about money spending activities, not money saving activities. And I fear the business will not. Despite having more money in theory and more features, more customers. Just make sure you return that investment back to keeping your product safe is, I think, my wish. I don't think it's I think it's more going to be turned towards efficiency and more profits.

00:10:01:06 - 00:10:05:12
Starr
I just think it's the nature of business. It's why businesses exist, right?

00:10:05:12 - 00:10:12:08
Martin
What you're saying in an ideal world, it would be great if they people did that.

00:10:12:10 - 00:10:30:09
Martin
When you were talking. It did absolutely make me think back to the kind of the AI companies and regulating themselves. And I know this week they've signed some agreements to self-regulate. I mean, my question is, though, is like, is it going to make a difference? Do those companies really care? They just speaking.

00:10:30:09 - 00:10:49:02
Adam
About those are two different questions. Is it going to make a difference is a different question about then do they care. So do they care. Hell no. Like they have shareholders to take care of. I will say, knowing as many people as I know at anthropic up and down the chain there, they actually are a pirate ship full of people that give a shit.

00:10:49:04 - 00:11:15:19
Adam
But there's a lot of money being thrown around and it's difficult to give a shit. Hard enough for that money to not sway you. However, comma pause for effect. The rest of them don't care at all. It's not what they're there for. They're there to move fast. But this public, the publicity and the advertising value of self-regulation and talking about self-regulation actually will move the needle more than if they didn't.

00:11:15:20 - 00:11:31:07
Adam
So if they didn't talk about it, if they didn't try and put forth their own belief into their own regulations and just were like, we don't care, as soon as the government tells us what to do, we'll do it. That is less effective than what's happening, what's happening now, which is advertising via agreements to self-regulate.

00:11:31:08 - 00:11:44:23
Starr
It all just feels like marketing to me at this point. All of it every day. It's a new marketing stunt and it has real world impacts. That's the other part where it might still just be marketing, but at the same time, it might also still cause real harm.

00:11:44:23 - 00:12:02:03
Martin
I think they should have a voice in the regulation. I don't think they should be the people who are creating the regulations. You need the smartest people in the room, but honestly, or the governance frameworks or whatever you want to call it, I feel like it should be its own independent organization and it should actually have teeth.

00:12:02:04 - 00:12:10:20
Adam
I guarantee you that amongst the three of us, none of us have ever read a piece of legislation or regulation I.

00:12:10:20 - 00:12:11:05
Starr
Have that.

00:12:11:06 - 00:12:13:20
Adam
I already have.

00:12:13:22 - 00:12:37:14
Adam
A sentence. Let me finish the sentence. I've never read a piece of legislation or regulation that wasn't written by a tech company behind the doors. Do you know how I know? Ask me how I know because I wrote that regulation. I wrote half of what FedRAMP got changed into when I was at Salesforce. Like, that's so it's so originally, the FedRAMP program was largely written by people that were either associated with or working at Microsoft.

00:12:37:14 - 00:13:02:23
Adam
And FedRAMP. Originally. Was a Microsoft your way into the federal government because it was written for them and they were the ones that had it. Google broke in and changed a lot of it, but that's what that is. Who writes these regulations is the tech companies, and they write them in a way that's advantageous to them. And it kind of helps them like push out the small fries, because it was impossible to be a federal authorization for a long time.

00:13:03:01 - 00:13:28:09
Martin
Okay. I do have one more thing I wanted to bring up. And we did mention we've mentioned money multiple times. The thing I wanted to raise, which is the the Goldman Sachs and Morgan Stanley, they're lobbying racing agencies to give like OpenAI, an anthropic investment grade credit rating immediately on IPO, despite the fact that neither of those companies is being close to profitable.

00:13:28:11 - 00:13:44:05
Martin
I mean, OpenAI posted like $20.9 billion operating loss on a $13.1 billion revenue in 2025, and it isn't targeting profitability until they change this recently until 2030.

00:13:44:09 - 00:13:47:09
Adam
So that's an eternity like that is 2030.

00:13:47:13 - 00:14:23:19
Martin
Well, they adjusted the 2030 because they wanted to borrow more money. You know, investment grade starters essentially opens up a massive corporate bond market including pension funds. I know this all feels somehow inherently wrong to me, and I can't put my finger on the one thing. Am I just being deliberately obtuse about the way how much this is costing, how much debt is being incurred, and whether it ends up in my pension fund, which I desperately care about?

00:14:23:21 - 00:14:27:01
Adam
You just are you just yelling at some kids on your lawn or is this really something?

00:14:27:02 - 00:14:29:23
Martin
Yes. Get off my lawn. Okay.

00:14:30:01 - 00:14:51:02
Adam
My money. I want it now. I don't think you're. I don't think you're being overly paranoid. I just don't see it. I don't see all the cards falling to the ground like I. It would be. It's fun to talk about. I just don't see it happening. Like that's what was supposed to happen several times over the last ten, 15 years with, with tech companies.

00:14:51:02 - 00:15:06:21
Martin
That were lobbying for that investment grade rating while posting like a $20.9 billion losses. I it feels like a huge, audacious financial ask. It's like we work calling themselves a tech company. It's like, hey, it's.

00:15:06:23 - 00:15:09:17
Adam
All AI company.

00:15:09:19 - 00:15:13:20
Martin
Yeah, it just feels off.

00:15:13:22 - 00:15:22:12
Adam
So it doesn't make a lot of sense. But also, I may or may not know for a fact that both of those banks are customers of anthropic in models.

00:15:22:13 - 00:15:35:08
Martin
I feel like you also have to sit with that fact. Those companies building AI systems and asking for all this, this money, are also the ones that carry that greater than 10% risk that they're going to make us all extinct. So maybe I don't have to worry about it.

00:15:35:08 - 00:15:56:06
Adam
So fascinating conversation. The world's ending. There's nothing we can do about it. So I'm glad we answered that. So to leave on a high note star, we're going to ask you the question that we ask everybody when they come on our podcast. What is one thing that companies are doing wrong in the see when it comes to AI?

00:15:56:08 - 00:16:14:00
Starr
Assuming that they're shipping security with whatever tool they're using, that's the most common answer I face in talking to developers. When I ask them, how do they approach security? Do they want to learn about security? They're like, nah, it just ships with it. It's fine.

00:16:14:02 - 00:16:24:15
Adam
So the fact that that they bought a tool makes them secure. So they've got a N95 mask on. Yep. Sideways on the head. And they're like, no, I got a mask.

00:16:24:15 - 00:16:32:04
Starr
I'm good. One of my dear friends is a senior level developer with Microsoft, and he that was said to me in person.

00:16:32:04 - 00:16:34:21
Adam
We appreciate your time. Thanks for coming on with us star.

00:16:34:22 - 00:16:37:02
Starr
Thank you guys. It's been great being here.

00:16:37:02 - 00:16:43:07
Martin
It's been awesome having star on. What's your big takeaway from today's episode?

00:16:43:09 - 00:17:04:11
Adam
My big takeaway is the massive number of people who volunteer with OS Foundation and the open source projects that are actually trying to do good without being paid for it. I think I knew about it generally, but I didn't realize how massive that movement is, and I think that's the bright spot of everything we discussed today.

00:17:04:13 - 00:17:25:10
Martin
I don't want to just pick a low spot, but you know, when star highlighted that, you know, these AI frontier companies are now just taking on those senior senior security people. That was kind of like a bit of a.

00:17:25:12 - 00:17:36:00
Martin
Pay attention to what's going on, because that's it is a little alarming. And I could not not take that away. So high and a low I guess from that.

00:17:36:01 - 00:17:36:07
Adam
Yeah.

00:17:36:08 - 00:17:48:06
Adam
And that is ship talk brought to you by harness. If Martin's point of view got under your skin, subscribe and tell us why. But until next time, stop talking stat shipping.