CISA Advisories

Citrix VPNs Under Attack 🚨 + The Proton Mail Sender You Can't Trust 📧

Two stories today hit the tools people trust most: the VPN gateway that lets employees in the front door, and the "From" line on your email. Attackers are actively exploiting one, and the other has stayed unfixed for over a year.

🚨 Hackers Are Already Inside Citrix NetScaler Gateways Worldwide

The U.S. cybersecurity agency CISA has confirmed that attackers around the world are exploiting two critical flaws in Citrix NetScaler, the remote-access and VPN gear many companies use to let staff connect from anywhere. Both bugs score 9.5 out of 10 for severity. They let an attacker run commands on the device or knock it offline without logging in. One flaw depends on a setting that's switched on by default for VPN servers, so many organizations are exposed without knowing it. If your business uses Citrix NetScaler, patching isn't enough: check for signs of a break-in, reset passwords and keys, and review any systems connected to the device.

Read more

📧 That Email "From Google" in Proton Mail Might Be a Fake

A researcher found that Proton Mail's web app can display a forged sender that looks identical to a real one. The trick uses look-alike characters: a capital "I" looks the same as a lowercase "l" in the default font, so an address like gmaiI.com passes as gmail.com at a glance. Emails from domains without strong email authentication can land in your inbox with no warning banner, and your replies can be quietly redirected to the attacker. The fake name even appears in Mac desktop notifications. The issue was reported in early 2025 and is still reproducible today, so Proton users should double-check full sender details before clicking links or replying to anything sensitive.

Read more

Stay ahead of threats with GOCO Security at gocosecurity.com.

Comments

Popular Posts